Summary
- RFC 9634 requires active OAM traffic to be associated with the monitored DetNet IP flow so that the test packet follows the relevant path and receives the same forwarding treatment.
- BFD, STAMP and ICMP packets differ from application packets. A selected UDP source port may influence ECMP or LAG hashing, but heterogeneous equipment can still make inconsistent path decisions.
- A defensible receipt joins the production-flow selector, probe association, chosen path, shaping and policing treatment, reserved resources, service-layer history, measurement scope and application outcome.
The test packet returned before its timer expired. The application packet crossed its deadline on another member of the bundle.
The dashboard can show both as one green service only by discarding the fact that they travelled under different conditions.
RFC 9634 discusses the use of existing IP Operations, Administration and Maintenance protocols in Deterministic Networking networks with an IP data plane. Its examples include ICMP, Bidirectional Forwarding Detection and the Simple Two-way Active Measurement Protocol. These are familiar tools. The difficult question is unfamiliar because DetNet makes it unavoidable: when does a specially constructed OAM packet have authority to speak for an application flow?
The answer is not “when the endpoints match”. The test packet must be associated with the DetNet flow closely enough to traverse the relevant path and receive the same forwarding treatment. That requirement is the centre of the operational contract.
The probe is a different packet
A DetNet IP flow can be identified by an ordered match over provisioned fields. The set may include IP protocol, source and destination addresses, source and destination ports and DSCP. The exact set depends on the deployed classifier and path-selection machinery.
BFD and STAMP use UDP and assigned destination ports. ICMP is a network-layer protocol. Their headers cannot simply copy an arbitrary application packet. If the production classifier includes a field that the OAM protocol necessarily changes, the operator needs an explicit association rule rather than an assertion that the packets are “basically the same”.
RFC 9634 gives a bounded example. If both path selection and DetNet treatment use a three-tuple of source address, destination address and DSCP, OAM traffic sharing that three-tuple can receive the monitored flow's treatment. The example does not establish that every network uses that tuple. It tells the operator to expose the actual rule.
The receipt therefore starts with two selectors. One identifies the production flow. The other identifies the test session. Between them sits a mapping whose inputs, scope, owner and configuration epoch must be auditable.
A source port can steer a hash, not certify it
Multipath turns association into an experiment. In an ECMP fabric or Link Aggregation Group, a device may hash packet-header fields to select a member. When the OAM protocol has a fixed UDP destination port, choosing the UDP source port judiciously may help the probe land in the same bucket as the production flow.
“May help” is the correct authority. RFC 9634 notes that this technique assumes forwarding equipment makes consistent hashing decisions, an assumption that might not hold in a heterogeneous environment. One vendor may include a field another ignores. A software revision may change the hash seed. A resilient-hashing transition may preserve some members while remapping others. The return direction may use another topology and another rule.
A controller can calculate a source port from its model and still be wrong about the running path. To close that gap, the record needs the packet headers actually sent, the relevant hash or association configuration, the selected interfaces or members observed at the required nodes, the time window and any topology or membership change during it.
A successful reply proves the test exchange happened. It does not retroactively prove which bundle member carried the production packet.
Same road is still not the same journey
Path equivalence is necessary but incomplete. RFC 9634 also requires the OAM packet to receive the same treatment: shaping, filtering, policing and access to pre-allocated resources must match the monitored DetNet packet.
Two packets can cross the same routers and links while entering different queues. A probe can be admitted by an exception ACL, marked into another priority, exempted from a policer or carried outside the reservation whose exhaustion matters to the application. Low-volume probes can avoid the very burst conditions they are meant to test.
This is why “ping worked” is not merely a weak measurement. Without treatment equivalence, it is a measurement of another service. Even STAMP's precise timestamps answer the wrong question if the test stream did not compete for the same resources or traverse the same service functions.
The equivalence record must name the queue and classification rules, filters, policers, shapers, resource binding and forwarding sub-layer generation. If Packet Replication, Elimination and Ordering Functions matter, the test must also cross the intended service-layer history. A single surviving probe cannot describe which copies of the application traffic existed, were eliminated or arrived late.
Encapsulation trades mapping work for visibility
RFC 9634 describes IP-in-UDP as one way to reduce the operational work of mapping several IP OAM protocols. The tunnel is associated with the monitored flow, and test packets ride inside it. The simplification has a boundary: the DetNet domain appears as a single IP link. Ordinary traceroute cannot expose the transit DetNet IP nodes, so a modified procedure may be needed.
That is a governance choice as well as a technical one. A tunnel can improve consistency at the classification surface while removing some evidence needed for localization. The operator should record what became easier to prove and what became opaque.
DetNet-in-UDP can carry an associated channel and service identifier through the DetNet forwarding and service sub-layers, including PREOF-capable processing. GRE-in-UDP can map a tunnel to the flow and carry Y.1731/G.8013 continuity, loss and delay functions. These mechanisms make a stronger association possible; their presence is not the resulting measurement.
Interworking adds another seam. A service may cross IP, MPLS and Time-Sensitive Networking domains. Peering and tunnelling models preserve different OAM boundaries. Evidence from one domain cannot silently become an end-to-end receipt unless the interworking rule joins the domains and preserves the treatment claim.
The measurement needs its own contract
After association comes measurement. The record must identify direction, observation points, interval, packet population, sampling, sequence semantics, clock relationship, duplicate and late-packet treatment, and counter discontinuities.
BFD can detect continuity failure according to its session state machine. STAMP can support delay and loss observations under its test contract. ICMP can detect and localize certain failures. Each result retains the scope of the packets and mechanisms that produced it. Absence of a detected defect does not prove that every production packet met a deadline.
The configured DetNet flow in RFC 9633 can help name the association. It cannot supply the observed equivalence. A YANG reference is the plan; packet and node evidence establish whether the plan executed. This is the difference between a model that coordinates work and a receipt that closes a claim.
What the operator should preserve
The first part is the production-flow identity: exact classifier, direction, service and forwarding sub-layer references, traffic profile and configuration generation. The second is the OAM session: protocol, packet headers, source-port selection, authentication or access controls, interval and intended observation points.
The third is the association proof. It records why the test maps to the production flow, which path or member each used, and whether the rule remained stable. The fourth records treatment: queues, filters, policers, shapers, reservations and service-layer functions.
The fifth is the result: raw observations, clock basis, packet population, loss and delay computation, discontinuity handling and uncertainty. The sixth belongs to the service or application owner: whether the evidence was sufficient, what business deadline was at stake, and whether the rollout was accepted, limited, rolled back or waived.
This separation follows Heng Lu's minimum-specification and running-code discipline. A shared association contract is useful because it lets different implementations coordinate. It remains honest only when symbolic mapping cannot overrule the path, treatment and application evidence produced by the running system.
Sources
- Heng Lu — Minimum Initial Specification
- Heng Lu — Running-Code Primacy
- Heng Lu — Reality Layers
- IETF Datatracker — RFC 9634 history
- RFC 9634 information page
- RFC 9634 — DetNet IP OAM
- RFC 9634 canonical text
- RFC 9634 canonical XML
- RFC 9634 errata search
- RFC 8655 — DetNet Architecture
- RFC 8939 — DetNet IP Data Plane
- RFC 9551 — DetNet OAM Framework
- RFC 9633 — DetNet YANG Data Model
- RFC 5880 — Bidirectional Forwarding Detection
- RFC 5883 — Multihop BFD
- RFC 8762 — STAMP
- RFC 7799 — Active and Passive Metrics
- RFC 9546 — DetNet MPLS OAM
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

