Summary
- Revision 07 of
draft-ietf-lsr-l2-bundle-member-remote-idproposes remote interface identifiers for OSPF, IS-IS and BGP-LS so a controller can join each local L2 bundle member to the neighbor's corresponding member. An aggregate being visible or up does not supply that member-level pairing. - The reciprocal relation is a correlation receipt, not physical truth. Acquisition sits outside the routing protocols; IGP authentication protects a mapping after a router creates it; and a matched pair still does not prove current liveness, measured performance, forwarding use or a successful traffic-engineering outcome.
One logical link can conceal several unanswered questions
Link aggregation deliberately presents several physical members as one logical interface. That abstraction is valuable for routing and resilience. It is also lossy. The parent L3 adjacency may be healthy while an operator or controller needs to reason about a particular underlying member: which far-end interface it reaches, which delay sample belongs to it, which failure is shared, or which two directions form one co-routed path.
Existing bundle-member attributes can carry a router's local identifiers. Suppose R1 advertises local members A, B and C, while R2 advertises X, Y and Z. Those inventories show that six endpoint labels exist. They do not prove whether A meets X, Y or Z. The bundle masks the join.
Revision 07 proposes to publish the missing half. For a local member A, R1 advertises the exact non-zero 32-bit value that R2 uses as the local identifier of the same member. If that value is X, R2 should symmetrically advertise A as the remote identifier of its local member X. The controller can then observe A→X and X→A and correlate the two directional descriptions.
This is more than convenience. Member-level delay, bandwidth and loss measurements become misleading if joined to the wrong endpoint. A bidirectional TE calculation can send its two directions over different physical strands while reporting that both belong to the same logical bundle. Failure correlation can widen or narrow the incident incorrectly. The new field supplies a join key that the parent link did not contain.
But the key describes a claim. It is not a cable probe.
The protocol authenticates the messenger after the mapping was made
The most important sentence in the security considerations is a boundary sentence. IGP authentication protects the advertisement after the originating router has created it. It does not authenticate the local Layer 2 information from which the router obtained the remote-member mapping.
OSPF or IS-IS does not operate directly on the individual bundle members. It has no native way to ask the far-end member for the 32-bit identifier that neighbor chose. The draft therefore leaves acquisition outside its scope. An implementation may use configuration or an implementation-specific discovery procedure. It may consult LLDP or LACP.
Those discovery protocols do not hand over the desired value unchanged. An LLDP Port ID depends on its subtype and need not be a 32-bit number. LACP actor and partner port numbers are independently assigned 16-bit values. Mapping either representation to the neighbor's advertised L2 Bundle Member Link Local Identifier is product-specific work.
That produces a subtle failure mode. Every component fact may be authentic: LLDP really reported a port label, the router really stored a mapping, OSPF really authenticated the router's LSA, and BGP-LS really transported the attribute. Yet the join can still be wrong because the conversion table was stale, configured against the wrong port, or applied after cabling changed. Cryptographic carriage preserves the originator's statement; it does not retroactively validate the observation that generated it.
For leadership, this is a useful general rule. Secure transport authenticates who said something and protects what they said. It cannot by itself prove that the speaker's sensor, local database or earlier inference was correct.
Reciprocity catches disagreement, not every shared mistake
The proposed relation provides an important consistency check. If R1 says A→X, the controller should find R2 saying X→A. A mismatch can reveal misconfiguration, incorrect discovery or tampering with acquisition. Implementations are encouraged to expose validation mechanisms.
Reciprocity is not omniscience. Both routers can be configured with the same outdated pair. An implementation-specific discovery process can produce mutually consistent output from a stale inventory. Two advertisements may also come from different topology epochs during a change. A reciprocal match raises confidence in correlation; it does not prove the cable is presently attached, the member is forwarding, or a metric sample belongs to the same moment.
The evidence chain should remain explicit:
- the parent L3 link or bundle is advertised;
- each endpoint advertises non-zero local member identifiers;
- an acquisition system produces a remote mapping with source and age;
- OSPF or IS-IS authentically carries what the router created;
- BGP-LS exports it under the correct parent and member ordering;
- a consumer confirms reciprocal A→X and X→A without malformed or stale evidence;
- live interface state confirms the physical members are presently connected;
- fresh measurement identifies bandwidth, delay or loss for the intended pair; and
- the controller's action reaches the intended members and the forwarding outcome is observed.
The remote-ID extension strengthens the middle of this chain. It does not collapse the end into the middle.
Unknown must not be converted into absent
Revision 07 is careful about missing evidence. If a remote identifier is absent, the value was not learned or not advertised. The absence does not say that the neighbor lacks a corresponding member. This distinction matters during mixed deployment, when one endpoint implements the extension and the other does not.
Zero also has a narrow meaning: unknown. It is not a valid interface identifier. OSPF originators must not advertise zero and receivers treat it as absence. IS-IS can use zero only as a positional placeholder when other members in the same descriptor have known remote IDs. BGP-LS never exports the zero.
Malformed collections create a different state. In IS-IS, the count and order of remote IDs must match the enclosing member descriptors. A zero length, a length not divisible by four, or a count mismatch causes the whole remote-ID set for that descriptor to be treated as unknown. Guessing a partial positional join would be more dangerous than admitting uncertainty.
Duplicates receive deterministic treatment, not extra authority. OSPF and BGP-LS use the first occurrence and ignore later ones. IS-IS uses the first occurrence in the lowest-numbered LSP fragment. That rule produces stable parsing during transient conditions; it does not certify that the first value is operationally correct.
These states should stay separate in telemetry: unsupported, not learned, intentionally omitted, zero placeholder, malformed set, duplicate ignored, reciprocity mismatch, stale source and valid reciprocal pair. Compressing all of them into “no link” destroys exactly the information an operator needs.
Export does not move semantic responsibility to every intermediary
The BGP-LS roles reinforce the boundary. A Producer originates the new sub-TLV as an attribute of the Link NLRI for the parent L3 link. A Propagator does not perform the proposed semantic consistency checks. A Consumer performs reciprocity validation and decides how its application handles an error.
This division avoids pretending that a transport intermediary understands every topology-dependent claim. It also means a controller cannot treat arrival through BGP-LS as proof that somebody upstream already checked the mapping. The consumer that will steer traffic owns the last semantic review.
The advertised detail is sensitive. It exposes not merely the bundle but which individual members meet. The draft requires advertisement to be disabled by default and enabled on selected links. It also points back to trusted-domain isolation for BGP-LS. More visibility helps a controller; it can also help an outsider map physical topology.
Freshness belongs to the originator. A router must not keep advertising a remote identifier it knows is invalid and should withdraw or replace it when its source changes or ages out. The exact detection and age policy remain implementation matters. Operators therefore need provenance and time, not just the 32-bit number.
Last Call is not deployment
Datatracker records revision 07 as an active LSR Working Group document submitted for publication as a Proposed Standard. It entered IETF Last Call ending 13 October 2026, and IANA review is still needed. The text is dated 29 September 2026 and expires 2 April 2027. It is not an RFC.
The proposed OSPFv2, OSPFv3, IS-IS and BGP-LS sub-TLV types remain TBA. Nothing in the record proves assigned values, vendor implementation, operational deployment, accuracy rate or TE benefit. The mature claim is narrower: the draft specifies how to carry a bounded correlation assertion and where its trust boundary begins.
Sources
- Datatracker record for revision 07
- Exact revision 07 text
- RFC 9356: OSPF L2 bundle member attributes
- RFC 8668: IS-IS L2 bundle member attributes
- RFC 9085: BGP-LS L2 bundle member attributes
- RFC 9552: BGP-LS architecture
- RFC 4202: link local and remote identifiers
- RFC 8537: associated bidirectional LSPs
- RFC 9059: bidirectional forwarding paths
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
