Summary
- RFC 2108 gave operators a common way to measure 10 and 100 Mb/s repeaters, search for observed source addresses and infer physical topology across multiple hubs.
- Its most important boundary was architectural: repeater ports remained physical-layer paths, while the separate management entity exposed counters and observations.
- A located address, a TopN ranking or a topology diagram was evidence from a stated window—not proof of ownership, packet understanding, root cause, authorization or restored service.
The apparent paradox in RFC 2108 is useful. The MIB can tell a manager that a particular source address was heard on a particular repeater port. Yet the document is equally explicit that a repeater has no MAC address as part of its repeating function and does no higher-level packet processing. It receives activity and bits, regenerates them and sends them onward. The address-aware answer belongs to the instrumentation around that function, not to a newly intelligent hub.
That distinction mattered in February 1997. The RFC Editor record describes RFC 2108 as the Proposed Standard that replaced RFC 1516 for IEEE 802.3 repeaters at 10 and 100 Mb/s. The earlier RFC 1516 had supplied the first Hub MIB. RFC 2108 was a functional superset: it added multiple-repeater support, management of 100BASE-T equipment, port TopN reports, active address search and a method for topology mapping. It also moved the module to the SMIv2 conventions specified by RFC 1902.
The result was not a packet analyser hidden in a hub. It was a better contract between instruments and managers.
Two kinds of interface
The cleanest proof is in RFC 2108's relationship to MIB-II. The MIB-II specification models network interfaces on a managed system. RFC 2108 says the relevant entries are the interfaces through which the management entity itself sends and receives management operations. A repeater port is not one of those interfaces. It is a physical connection over which repeated symbols pass.
So one box could present two very different surfaces. Its management processor had an addressable network interface and an SNMP agent. Its repeater ports had activity, error and partition state. The agent could inspect implementation instrumentation and publish an observation about a port without converting that port into a host-like endpoint. The separation is the reason the MIB can be expressive without rewriting the Ethernet architecture.
Counters became portable evidence
RFC 2108 aligned its principal counters with the management objects in IEEE 802.3 section 30.4. The IEEE text defined what should be measured and where; the MIB defined how a manager would retrieve it. An implementer could reuse one instrumentation layer rather than maintain an IEEE account and a contradictory SNMP account.
That made ordinary questions reproducible. How many readable frames had a port seen? How many octets? How many FCS or alignment errors, short events, runts, collisions, late events, excessive-length events, data-rate mismatches, automatic partitions, isolates or symbol errors? The standard did not turn any one number into a diagnosis. It made the number's meaning stable enough that a diagnosis could be argued.
TopN reporting sharpened the distinction. A manager selected a variable and a sampling interval. The agent measured the change during that interval and returned the ports with the greatest activity. “Top” therefore meant largest observed change in the chosen counter, inside the chosen window, among the included ports. It did not mean guilty, compromised, congested forever or even busiest outside that window.
The report carried its own fragility. Entries were not available while collection was still under way. Counter continuity could break if a port moved between repeater instances; the manager was expected to compare the port-last-change timestamp. A ranking without its interval, selected metric and configuration history was a screenshot with its legend removed.
Last seen is not attached now
Passive address tracking recorded the source address from the last readable frame observed on a port since monitoring began. That was operationally valuable. A technician facing a patch-panel maze could obtain a clue about which segment had recently carried a station's traffic.
But the object said “last observed,” not “owns this address,” “is still connected” or “is authorised here.” A laptop might have moved. A bridge might have relayed the frame. The address might have been reassigned or spoofed. No readable frame might yet have arrived. Even the table's address index could change without notice. RFC 2108 supplied a fact with a timestamp-shaped boundary; it did not supply identity.
Active address search made the experiment explicit. A management station placed a source MAC address in a search table and asked the agent to watch a repeater. The state could become single, multiple or none. Only a single observation yielded a meaningful group and port. Multiple sightings were not squeezed into a false unique location, and no sighting did not become a negative proof.
The search row also had an owner token and an expiry. That mechanism prevented two management stations from silently overwriting each other's experiment and allowed abandoned rows to be reclaimed. It was concurrency control for observers. It did not authenticate the endpoint being watched, confer permission to disconnect it or establish who controlled it.
A topology map was a reconstruction
The document's topology procedure combined two evidence systems. It used the repeater's address search to learn where source addresses could be heard, and a bridge or switch forwarding database to learn which addresses appeared behind switched ports. By recursively eliminating impossible placements, a manager could draw a representation of the physical topology.
The verb “draw” is tempting; “infer” is safer. The procedure depended on frames actually being emitted and read, forwarding databases being current, searches being timed coherently and the network not changing beneath the calculation. It could produce a highly useful map without producing metaphysical certainty. It could not establish that an endpoint was reachable now, that a failed counter caused an outage, that a manager had authority to intervene or that service had returned after intervention.
The intellectual achievement was precisely this refusal to collapse layers. RFC 2108 allowed management software to act on observations made near the physical layer while preserving the claim that packet meaning lived elsewhere.
A standard at the edge of an era
The IETF and IEEE later reviewed the Hub MIB's history in RFC 4441. It had gone through three iterations, and further evolution looked unlikely as repeaters receded from operational networks. That lifecycle did not make the measurement model disposable. Modern telemetry still faces the same temptation: because a control system can correlate identifiers, counters and topology, operators start talking as if the observed component itself knew the story.
The address-tracking work also carried a documented intellectual-property boundary. RFC 1988 records Hewlett-Packard's covenant concerning the patented technique. That legal history deserves its own treatment; here it is enough to note that technical observability and the right to implement it were separate questions.
Three later essays by Heng Lu help name the broader governance problem. “Minimum Initial Specification, Localized Future Decision” argues for narrow common rules that leave later decisions local. “On Reality Layers, Symbolic Power, and Why Clarity Feels So Hostile” warns against letting an administrative representation replace the thing represented. “Running Code Primary” returns authority to observable operation. RFC 2108 is an early, unusually concrete example: standardise the evidence surface; do not pretend the evidence has already decided its meaning.
Sources
- RFC 2108 — Definitions of Managed Objects for IEEE 802.3 Repeater Devices using SMIv2
- RFC Editor record for RFC 2108
- RFC 1516 — Definitions of Managed Objects for IEEE 802.3 Repeater Devices
- RFC 1213 — Management Information Base for TCP/IP-based internets: MIB-II
- RFC 1902 — Structure of Management Information for Version 2 of SNMP
- RFC 1988 — Conditional Grant of Rights to Specific Hewlett-Packard Patents
- RFC 4441 — The IEEE 802/IETF Relationship
- Minimum Initial Specification, Localized Future Decision
- On Reality Layers, Symbolic Power, and Why Clarity Feels So Hostile
- Running Code Primary
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
