Summary
- RFC 8029 sends an MPLS Echo request along the data path associated with a Target FEC Stack and asks the receiving label switching router to compare forwarding disposition with control-plane knowledge. The reply is evidence about that probe, FEC, responder and moment.
- Full ECMP coverage may be impossible, normally unused backup paths are outside the procedure, and the reply can return over ordinary IP or a separate control channel. Neither one success nor one silence proves the aggregate service.
- A defensible receipt joins probe inputs, actual path and return code, reply mode and return path, attempted and untested alternatives, sustained BFD state and a separate representative customer transaction.
A green line appears in the operations console. The MPLS ping returned. The tempting sentence is immediate: the service is up.
But the packet that came back was built for a narrower job. It carried a Target FEC Stack, a label context, a sequence number and a requested reply mode. It exercised one forwarding outcome selected by the fields in that packet. A router received it, evaluated a defined set of conditions and returned a code. Calling that event “the service” erases the most useful information the test produced.
RFC 8029, published in 2017, is the current consolidated specification for detecting MPLS data-plane failures. It names Kireeti Kompella first among six authors, alongside George Swallow, Carlos Pignataro, Nagendra Kumar, Sam Aldrin and Mach Chen. It obsoletes the original RFC 4379 and several updates. That attribution matters: Kompella is a documented contributor to collective IETF work, not the owner of every implementation or the operator of any network that uses it.
The FEC is the question the probe actually asks
Ordinary IP ping asks whether an IP endpoint can return an ICMP reply. LSP Ping needs to test a label-switched path even when the sender does not know the address of its far-end router. It therefore carries a description of the forwarding equivalence class whose path is in question. In simple cases that may be one LDP prefix or one RSVP session. A VPN or a service nested inside another tunnel can require a stack of FEC elements.
The request is forwarded by its MPLS label stack, not by its 127/8 destination address. That special destination is a safety device: if a broken LSP ejects the packet early, the diagnostic packet should not be forwarded as ordinary customer IP traffic. At the expected egress, the packet reaches the control plane and the router checks whether it really is an egress for the named FEC. In traceroute mode, successively larger TTL values bring transit routers into the test so the initiator can localise a mismatch.
This is strong evidence when its inputs survive. “Ping passed” is weak. “At 10:14:07 UTC, label stack X carrying Target FEC Stack Y reached LSR Z; Z returned code and subcode R for sequence S” is reviewable. The latter can be compared with the route and label state that existed then. The former cannot even say what question was asked.
The distinction is sharper for services that carry an MPLS payload. RFC 8029 explains that an extra label may be needed to expose breakage that a bare diagnostic packet would miss. A router could accept the simple echo yet be unable to carry the payload form used by an L2VPN or L3VPN. The test packet must represent the forwarding treatment being claimed. A synthetic packet that omits the decisive layer cannot lend its success to that layer.
One hash outcome is not all of ECMP
MPLS forwarding can present several next hops for one FEC. The selected path may depend on destination address, UDP source port, entropy labels, traffic class, payload interpretation or vendor-specific logic. LSP Ping gives the initiator fields it can vary and downstream mappings it can follow. It does not promise omniscience.
RFC 8029 is candid that proprietary distribution algorithms can make complete alternate-path coverage impractical. It says normally unused backup paths are not addressed by the procedure, and even composed attempts across several ECMP stages may fail to reach every possible combination. A successful echo therefore proves the path the packet selected, within the checks performed. It cannot make an untouched member healthy by association.
RFC 7882 illustrates the same operational danger through BFD: one session can remain up over one ECMP path while traffic assigned to another path is blackholed. The lesson is not that LSP Ping or BFD is defective. The lesson is that aggregation needs a denominator. A console should say “7 of 8 enumerated paths tested; one backup untested,” not “MPLS healthy.”
Coverage must also preserve packet class. A probe treated as IP may hash differently from a non-IP MPLS payload. A low-rate control packet may avoid loss that appears under representative traffic. A chosen traffic-class value may miss a queueing or policing defect affecting another class. The receipt needs the fields that influenced selection, and the conclusion must name the population to which the result applies.
The reply has its own route
The Echo Reply is not required to reverse the tested LSP. RFC 8029 provides multiple reply modes: no reply, a normal IPv4 or IPv6 UDP response, a UDP response using Router Alert, or an application-level control channel. RFC 7110 later defined a way to specify a return path because operators sometimes need a controlled reverse route rather than whatever ordinary IP forwarding chooses.
That separation resolves two common mistakes. First, a reply received through the management network does not prove the reverse customer path. Second, a missing reply does not necessarily prove that the forward probe failed. The egress might not support LSP Ping, a control-plane policer might discard the request, or the return path might be broken. RFC 8029 calls out false negatives from non-compliant routers and suggests probing beyond a silent transit node in traceroute mode.
The useful record therefore stores both legs without pretending they are symmetric. For the forward leg: label and FEC stack, TTL, selected downstream and validation result. For the return: requested mode, responder address, destination, transport, return-path constraint and arrival time. If the return is ordinary IP, say so. If no evidence of the reverse LSP was collected, leave that field unknown.
LSP Ping and BFD live on different clocks
An on-demand test can verify a forwarding relationship at one moment. Operators also need rapid, continuing detection. RFC 5884 combines the mechanisms by using LSP Ping to bootstrap a BFD session and to carry the information needed to bind that session to an MPLS LSP. BFD then exchanges packets at negotiated intervals to detect loss of continuity.
The two receipts should not be compressed. LSP Ping can explain FEC and path context; BFD can supply a time series of liveness under its session and path selection. A BFD session that stayed up for an hour does not retroactively prove every ECMP member, and an Echo Reply at noon does not guarantee continuity at 12:05. The operational conclusion needs an observation window.
Customer experience requires a third clock. A representative service transaction may include customer-edge interfaces, pseudowire state, MTU, payload size, class of service, encryption, DNS, transport and application behavior. It may need loss, delay and availability measured over the contractual interval. LSP Ping can localise an MPLS fault inside that chain; it cannot substitute for the chain.
A return code is an account, not a badge
RFC 8029 defines return codes and downstream mapping information so the initiator can understand whether the responder was an egress, whether labels and interfaces matched, and where forwarding diverged. Hierarchical or stitched tunnels can change the FEC stack along the way. Some tunnels may be hidden, including through a Nil FEC. The response is a structured account of what the node disclosed and checked, not a universal attestation.
Security reinforces that reading. The specification discusses denial of service, spoofing, replay, hijacking and disclosure of network state. Sender handles and sequence numbers help match a reply to an outstanding request; implementations can also check timestamps, rate-limit control-plane traffic and restrict accepted sources. Those controls increase confidence in the diagnostic exchange. They do not authenticate a customer application or turn the responding router into an independent auditor.
Heng Lu's agency lens is useful here. The standard authors define a shared diagnostic grammar. Implementers decide how faithfully to realise it. Operators choose probe parameters, coverage and escalation. Customer-service owners decide what outcome matters. None of those agents can silently lend its authority to the next. The standards author's name cannot certify an implementation; the router's reply cannot sign the customer's experience.
The minimum-specification principle also fits. Interoperability needs common message types, FEC encodings, return codes and procedures. It does not need a central institution to pronounce every service healthy. Local operators retain the decision because they know their tunnels, traffic classes, failure domains and obligations. Running code supplies evidence, but only within the experiment actually run.
Build a joined diagnostic receipt
Start with the question. Record initiator, time, target service hypothesis, LSP identifier, Target FEC Stack, label stack and whether the packet represents the real payload depth. Preserve TTL, ping or traceroute mode, traffic class, entropy label, destination and UDP fields that can affect ECMP.
Then record the observation. Name the responding LSR, return code and subcode, downstream mappings, interface and label results, FEC-stack changes, response time and raw request/reply hashes where available. Link each result to the exact sequence and configuration epoch.
Describe coverage rather than implying it. List enumerated next hops, field combinations attempted, paths observed, paths not reached, backup and detour state, unsupported nodes and rate limits. State whether the population is known or only sampled.
Keep the return leg separate. Store the requested and actual reply mode, return destination, control channel or IP route evidence, and any RFC 7110 return-path constraint. A received reply may validate the exchange while leaving reverse service behavior untested.
Add continuity and service outcomes as independent witnesses. Preserve BFD session identity, discriminator, interval, selected path, state transitions and window. Then attach a representative customer transaction with endpoints, payload, traffic class, performance measures and SLA interval. If one witness is absent, do not let another fill its field.
The final conclusion can then be exact: a named probe for a named FEC traversed an observed forward path and received a matched reply under stated conditions; specified alternatives were or were not exercised; continuity was observed for a stated window; a separate service transaction did or did not meet its objective. That sentence is longer than “ping succeeded.” It is also what makes the result safe to act on.
Sources
- RFC 8029 — Detecting MPLS Data-Plane Failures
- RFC 4379 — the original MPLS LSP Ping specification
- IETF Datatracker — Kireeti Kompella
- RFC 5884 — BFD for MPLS LSPs
- RFC 7110 — Return Path Specified LSP Ping
- RFC 7737 — Label Switched Path Ping and Traceroute Reply Mode Simplification
- RFC 7882 — Seamless BFD Use Case
- Heng Lu — Running-Code Primacy
- Heng Lu — Minimum Initial Specification
- Heng Lu — On the Agency Problem
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
