Summary

  • ATMP let an ordinary PPP or SLIP client use an address from its home network while a remote NAS/Foreign Agent and a Home Agent handled the tunnel invisibly.
  • Registration, a CHAP-like shared-secret exchange, a pair-local Tunnel ID and GRE carrying that ID created the operational appearance of local attachment for IP or IPX.
  • A home address, accepted registration or matching GRE key proved bounded protocol state—not physical location, human identity, application authorization, delivery or IETF consensus.

Home was a routing decision

In 1997, a user could dial a distant Network Access Server and still present an address drawn from the user's home network. The telephone line terminated elsewhere. The routing story said home.

That contradiction is the point of RFC 2107. The Ascend Tunnel Management Protocol, or ATMP, did not move the workstation. It created a controlled fiction around it. A Foreign Agent inside the remote NAS registered the client with a Home Agent on the home network. The two agents then carried traffic through a tunnel so that systems on either side could behave as though the client were locally attached.

The client did not run ATMP. Ordinary PPP or SLIP software was enough. The NAS and Home Agent owned the machinery, while other systems were meant to remain unaware that the client was remote. This reduced change at the edge, but it concentrated routing judgment at the boundary.

The home address could be configured by the client, tied to a user ID or drawn from a home-network pool. RFC 2107 deliberately left both address assignment and the NAS decision to invoke ATMP outside its scope. That omission matters. The protocol could carry a selected address; it could not prove how the selection had been authorized or whether the address still described the right user.

Registration manufactured the attachment

ATMP's mobility binding joined three things: a Home Address, a Foreign Agent IP address and a Tunnel ID. That was not a statement about geography. It was a compact routing instruction.

When the NAS detected a client needing ATMP, its Foreign Agent obtained the Home Agent address and a shared secret from local configuration. It could also obtain a Home Network Name for a connection profile. The Foreign Agent sent a Registration Request and retried every two seconds. Ten unanswered attempts ended in a logged failure and disconnection.

The Home Agent answered with a challenge. The Foreign Agent concatenated the authenticator with the shared secret, calculated an MD5 digest and returned it. The Home Agent repeated the calculation. A match allowed the registration to proceed; a mismatch or exhausted capacity produced a non-zero result.

This exchange authenticated one configured relationship between the two agents. It did not identify the human at the dial-up client. It did not prove that an application had authorized the session. It did not encrypt the payload. The distinction is especially important because the RFC described the mechanism as similar to CHAP: similarity of construction does not expand the claim that the construction can support.

A Tunnel ID turned state into a path

After accepting the challenge reply, the Home Agent assigned a Tunnel ID. The identifier had to be unique only within a given Foreign Agent–Home Agent pair. The Home Agent created a control block associating that ID with routing information; the Foreign Agent stored the ID with the mobile-node session.

Traffic then moved inside GRE. The Tunnel ID occupied the GRE Key field. On the way home, the Home Agent used its control block to route a decapsulated packet. On the way back, the Foreign Agent matched the key against an active client and forwarded the inner packet. An unknown ID caused an Error Notification and silent discard.

The design made the authority shift visible. The remote client supplied traffic, but the agents decided which home context the traffic entered, which local state named it and whether a received packet still belonged to a live attachment. The address looked stable because the control blocks absorbed the change in physical access.

ATMP carried both IP and IPX. IPX exposed the cost of the illusion more clearly. Tunnel management still required IP underneath, while each Home Agent needed an enterprise-unique IPX network number distinct from its LAN networks. Clients shared that network number and still needed unique node addresses. Portability at one layer therefore depended on fresh coordination at another.

Teardown was part of the truth

Virtual presence existed only while both sides agreed on its lifecycle. When the Foreign Agent wanted to disconnect a client, it sent Deregistration Requests every two seconds. A valid reply caused the Home Agent to remove the mobility binding and the Foreign Agent to deallocate the Tunnel ID. After ten failed attempts, the Foreign Agent logged the error and disconnected anyway.

That asymmetry is operationally important. A local endpoint could be gone while remote state had not yet been confirmed as removed. A Tunnel ID in a packet could refer to state one side considered live and the other had lost after a reset. RFC 2107 even defined an invalid-tunnel error for that condition. The system's truth was not one field; it was the alignment of two control blocks, retry history, current client attachment and packet handling.

Private protocol, public historical lesson

The IESG note was unusually direct. RFC 2107 documented a private tunnel-management protocol, not an IETF working-group product and not a standards-track document. The current Datatracker calls it Legacy and says it has no formal standing in the IETF standards process.

That warning does not make ATMP historically unimportant. It makes the evidence cleaner. The document records how one vendor product family made network location portable before L2TP: centralize state between access and home, authenticate that boundary, assign a local tunnel name and let ordinary clients remain unaware.

It also shows what publication could not prove. RFC 2002 Mobile IP had a broader standards-track mobility model and allowed a changing point of attachment. L2F and later L2TP separated dial access from link-layer or PPP termination. GRE supplied an envelope. ATMP combined a narrower set of mechanisms for one product architecture. An RFC number preserved the design; it did not convert deployment into consensus.

Sources