Summary
- RFC 1074 described a Level-2-only subset of ANSI IS-IS for the 1988 NSFNET backbone. Its IS-IS and ES-IS control PDUs travelled inside IP as protocol 85, while IPv4 addresses and autonomous-system-derived administrative domains were fitted into NSAP-shaped fields.
- An EGP reachability announcement did not enter the interior system unchanged. An NSS checked it against the Routing Policy Data Base, converted the accepted network and advertising domain into an address prefix, attached a policy-derived cost, and advertised that state in an End System PDU.
The new NSFNET backbone in RFC 1074 joined thirteen sites across the continental United States. Permanent point-to-point links ran at T1 speed, 1.544 Mbit/s, with logical links able to consume a fraction or all of that capacity. At each site, a Nodal Switching Subsystem combined IBM RT/PC processors, a modified 4.3BSD kernel and packet-switching duties. For routing, each NSS appeared as one node.
That hardware is easy to file under “early router history.” The control design is more revealing. Between NSS nodes, NSFNET used an adaptation of the emerging ANSI Intermediate System to Intermediate System protocol. At the edge, it spoke the Exterior Gateway Protocol to regional networks. Between those systems sat a policy database and a deliberate change of representation.
RFC 1074 therefore documents neither a clean OSI network nor a clean TCP/IP stack. It records an operational backbone borrowing a link-state grammar from one protocol family, transporting it through another, and translating exterior claims into interior facts only after administrative review.
The subset mattered as much as the protocol name
ANSI IS-IS described two routing levels: Level 1 within an area and Level 2 between areas. NSFNET implemented only Level 2. Of the possible subnetwork-specific modes, it used general-topology permanent point-to-point links. This was not every feature of the emerging standard deployed under a new badge. It was a selected control mechanism fitted to one backbone.
The placement on the stack was equally specific. In the ISO framework, IS-IS operated directly above the data-link layer. NSFNET put the IS-IS and ES-IS PDUs on top of IP and assigned protocol number 85 to that traffic. The protocol discriminator inside a PDU separated the two control families. The IANA Protocol Numbers registry still labels 85 NSFNET-IGP.
That registry entry proves that a number was assigned. It does not prove present deployment, historic conformance at every node, or successful route installation in any individual incident. Even in 1988, receiving a protocol-85 datagram established only that a control envelope reached an IP endpoint. Its contents still had to parse, enter a link-state database, survive computation and affect a forwarding table.
RFC 1074 relied on IP fragmentation and reassembly rather than defining another fragmentation mechanism for its IS-IS environment. The authors judged an IS-IS PDU unlikely to exceed IP's maximum size inside this backbone. The decision shows how thoroughly the borrowed control protocol was made to inhabit the local IP system: even the limit and failure point for a large control message belonged to its carrier.
Four Internet bytes acquired an ISO-shaped sleeve
The addressing mismatch could not be ignored. ANSI IS-IS expected Network Service Access Point addresses. NSFNET possessed Internet network numbers, IPv4 addresses and autonomous-system identities. The implementation made those facts fit the expected fields instead of pretending they were already the same thing.
Its nine-byte Domain Specific Part began with two bytes for an administrative domain, followed by two empty bytes, four bytes for an IP address and one more empty byte. The Initial Domain Part was unused. A six-byte router identifier similarly used two empty bytes followed by the router's four-byte IP address. A Network Entity Title was produced from the constructed NSAP form.
Empty fields are part of the historical evidence. They show that the designers were mapping between structures, not discovering a natural identity. An IPv4 address did not become an OSI address by metaphysical agreement; it became a value placed at a known offset in a control protocol that expected a different grammar.
For NSFNET routing, each Autonomous System was treated as a separate Administrative Domain. That equation served this implementation. It should not be promoted into a universal definition. The mapping had operational value because an EGP peer's AS and the network it announced could be carried together through the backbone's link-state machinery.
The exterior claim crossed a policy checkpoint
The boundary problem becomes clearer in RFC 1092. EGP assumed an engineered spanning-tree world. NSFNET was becoming meshed and contained “backdoor” routes between regionals. The same network could be advertised through more than one regional, while the base protocol had no generally accepted metric interpretation that established a primary representative. Nor did EGP alone stop one regional from claiming somebody else's network at distance zero.
NSFNET's response was not to flood received EGP packets through the core. Networks and regional operators made bilateral representation agreements. The Network Operations Center recorded them in a Routing Policy Data Base. An attaching NSS could compare an EGP claim with the permitted network, advertising autonomous system and chosen priority. A mismatch could produce an alarm; an unauthorized route could be ignored.
Only then did the representation change. RFC 1074 says that a network from an accepted EGP Network Reachability record and the administrative domain of its peer were encapsulated into an NSAP-shaped address prefix. That prefix entered the reachable-address portion of an End System PDU. Its cost came from the policy database maintained in the NSS.
So the interior link-state system did not merely repeat an exterior assertion. It originated a new control record whose content combined an observed claim with local authorization and cost. At another NSS, learned End System PDU information was processed and filtered before any corresponding reachability was sent to a mid-level EGP peer.
This distinction prevents a dangerous reading of routing evidence. A received EGP record proves what a peer asserted. A policy entry proves what operators intended to authorize. An originated ES PDU proves that some accepted and converted state entered the interior protocol. An SPF result and forwarding-table row are later facts. A packet that traversed the chosen exit is later still.
Policy shaped information, not every packet
RFC 1104 later described four controls at the NSFNET interface: peer checks based on source address, verification of the EGP autonomous-system identity, verification of the announced Internet network numbers, and metric control through the policy database. It reported that this implementation had been in place since July 1988.
The same memo drew an essential boundary. NSFNET's deployed model controlled the distribution of routing information at network or administrative-domain granularity. Once that information generated routing tables, ordinary packet switching did not need to consult the policy database for every packet. The design therefore imposed little data-plane cost, but it could not express end-user authorization and did not stop every malicious source-routed packet.
Policy was powerful precisely because it acted before a claim became shared topology. It was not omniscient. If the database was stale, if an attaching NSS held the wrong version, or if an authorized representative announced a broken path, the presence of a policy check did not guarantee delivery. Control-plane legitimacy and data-plane fitness remained different properties.
Later Integrated IS-IS was not a simple rename
The later RFC 1195 specified Integrated IS-IS for TCP/IP and dual IP/OSI environments. It added IP-specific information to the OSI link-state protocol, supported pure-IP, pure-OSI and dual domains, and described IP and OSI packets being forwarded as-is over underlying link services. Its purpose and wire model were broader than the NSFNET-specific implementation in RFC 1074.
The resemblance is historically important: both works refused the idea that one routing algorithm must belong forever to one network-layer family. The difference is just as important. RFC 1074 documents a selected Level 2 implementation, control PDUs carried over IP, and Internet facts made to resemble the fields expected by an ANSI/ISO design. RFC 1195 standardized explicit IP reachability extensions for integrated environments. Calling them the same protocol would erase the experimental translation work that the earlier backbone actually performed.
RFC 1222 offers the architectural result in retrospect. The first 56 Kbit/s NSFNET phase let backbone, regional and campus routing information mix more freely. The T1 phase strongly decoupled the backbone IGP from the IGPs of attached clients and used exterior routing across the boundary. Each administrative entity could choose its own internal method.
That separation explains RFC 1074 better than a contest between ISO and IP. The backbone did not demand that every regional adopt its IGP. It needed a controlled way to turn external reachability into internal topology while leaving each routing domain responsible for itself.
Sources and limits
RFC 904 supplies EGP's base grammar; it does not contain NSFNET's later representation policy. RFC 1093 places that policy and the IGP/EGP boundary in the wider routing architecture. RFCs 1074, 1092 and 1104 are implementation accounts written by participants. They specify intended behavior and record operating choices; they are not packet captures or availability measurements. RFC 1222 is a later first-party retrospective. RFC 1195 describes a subsequent standards-track design, not proof that RFC 1074 was wire-compatible with it. The IANA registry records number assignment, not traffic.
The narrow historical conclusion is strong enough. NSFNET made unlike control systems cooperate by naming the conversion points: IP carried the PDU; a shaped field carried the Internet address; EGP supplied an exterior claim; policy authorized and priced it; IS-IS distributed the resulting interior state. No single observation owned the whole route.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
