Summary
- The IETF LSR working group's 29 September revision of its L2 bundle member remote-ID draft replaces an earlier recommendation to use an LLDP Port ID with a requirement for the exact non-zero 32-bit member identifier advertised by the neighbor. It is an Internet-Draft in IESG Last Call, not an RFC.
- The revision says LLDP and LACP may help discover which port is across the wire, but neither supplies that 32-bit routing identifier automatically. IGP authentication also does not attest the local discovery data from which a router formed the pairing.
A controller can have an authenticated and faithfully delivered topology advertisement that is still wrong about one physical member link. The 29 September version of Advertisement of Remote Interface Identifiers for Layer 2 Bundle Members makes that distinction central. It is intended to let routers advertise the remote identifiers of individual links inside an L2 bundle through OSPF or IS-IS and let a BGP-LS consumer correlate the two ends. This is useful where traffic engineering or failure analysis needs to know which member is actually connected to which, beyond the identity of the aggregate link.
The change from the 22 August -06 draft is not a new claim that such bundles exist. The older text recommended LLDP for acquiring the remote identifier and said a neighbor's LLDP Port ID should be used in the advertisement; it also mentioned LACP port identifiers as an alternative. The new -07 text withdraws that direct substitution. Each end assigns its own non-zero 32-bit L2 Bundle Member Link Local Identifier. A router advertising the remote ID for one member must use the exact value its neighbor advertises as that member's local ID. The two ends should therefore be checkable as a reciprocal pair, rather than merely as plausible port names.
This is a material engineering correction. An LLDP Port ID may be a different subtype and need not be a 32-bit number. LACP actor and partner port numbers are 16-bit values chosen independently at each end. Both protocols can help an implementation find the neighboring port, but the mapping from that observation to the neighbor's advertised member ID is implementation-specific. The draft now places acquisition of the exact value outside its own scope. It does not ban LLDP or LACP; it declines to certify a raw identifier copied from either one as the routing value.
Consider a hypothetical bundle with member A at one router and a neighbor's member X at the other. A discovery frame identifies a port, but the implementation confuses that port label with a different numeric member ID. The router then advertises a false A-to-X pairing. Routing-message authentication can prove which router emitted the message, not that the router's local discovery or configuration was correct. The draft's expanded security section describes this as a trust boundary and warns that a false mapping could mislead a traffic-engineering controller or failure-correlation system.
No actual outage or vendor defect is established by the draft.
The revision also prevents absence from becoming a false negative. A missing remote ID means the value was not learned or advertised; it does not mean the peer has no member. IS-IS may use zero as an unknown placeholder in an ordered member list, while BGP-LS exports that member without a remote-ID sub-TLV rather than exporting zero. Its propagator is not the semantic validator: the consumer does consistency checks and decides what an error means for its application. These distinctions matter during partial rollouts, when one end may support the extension and the other may not.
The Datatracker lists -07 as an active Internet-Draft in IESG Last Call until 13 October, intended for Proposed Standard status. It may still change. The existing requirement that advertisement be opt-in on specified links was already in -06; the new decision is about what an enabled advertisement can honestly claim. A controller that treats a discovered port name as proof of a reciprocal member ID is accepting an unverified translation precisely where it needs exact topology.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

