Summary
- RFC 10014 recommends retiring “in-band OAM” and “out-of-band OAM” as dependable descriptions. It replaces the shortcut with three axes: active/passive/hybrid participation, path congruence and forwarding treatment.
- A dedicated probe may traverse the same nodes and links as a service flow yet use a different queue, priority, scheduler, shaping policy or protection treatment. Its result can be valid evidence of the path and still be invalid evidence of the customer's experience.
- Leaders need an OAM evidence contract that binds each result to the exact stream, epoch, direction, layer, maintenance domain, packet or counter semantics, path and treatment assumptions, decision threshold, corrective authority and independently verified service outcome.
The network map made the incident look impossible. A premium application class had recurring bursts of delay, but the active assurance session stayed green. The probe entered at the same edge, left at the same edge and crossed the same interior nodes. Every change board was shown the diagram. The provider's contract called the mechanism “in-band OAM.” The incident was closed as an application problem.
The diagram omitted the queue. The test packets carried a control codepoint and received privileged scheduling; the customer packets entered a congested service queue. Both paths were topologically congruent. Their treatment was not. The probe proved a bounded forwarding fact and was then promoted into proof of a different proposition.
RFC 10014, Guidelines for Characterizing the Term “OAM”, was published in June 2026 as an IETF Best Current Practice. Its subject appears linguistic, but its consequence is operational: words decide which evidence may close an incident, satisfy a contract, trigger automation or deny a customer credit. The document recommends avoiding “in-band” and “out-of-band” for OAM because packet networks provide several different things a measurement may be inside or outside. Precision is not cosmetic when a green status carries authority.
One adjective concealed three questions
“In-band” began in radio and telephony, where a band or channel was a physical idea. Packet networks have no single equivalent. In different RFCs and products, the term has meant that measurement information rides inside a production packet, that a dedicated test packet follows the production path, or that test and user packets receive equivalent forwarding treatment. Those meanings may coincide, but they do not have to.
RFC 10014 therefore offers three independent criteria.
The first asks how the method participates in traffic. Active OAM generates dedicated OAM packets. Passive OAM observes one or more existing data streams without generating dedicated packets or modifying the observed packets. Hybrid OAM combines active and passive elements. In-Data-Packet OAM is a narrower hybrid case: OAM information is carried in the very packets that carry the data traffic.
The second asks where OAM information travels. Path-congruent OAM follows the exact same forwarding path—the same nodes and links—as the traffic of interest. Non-path-congruent OAM is not guaranteed to do so. This is a topological statement. RFC 10014 explicitly warns that it says nothing about how packets are treated inside queues on those nodes.
The third asks how dedicated OAM packets are treated. Equal-forwarding-treatment OAM receives the same QoS treatment as user data, including relevant queuing, scheduling and shaping. Different-forwarding-treatment OAM may not. The word “same path” cannot answer that question.
These criteria do not form one ladder from weak to strong. They describe different mechanics. Passive observation has no dedicated probe packet whose path or queue can be classified. An in-data-packet method naturally shares the path and treatment of those selected packets, but its sample may represent only a chosen subset. An active method may be deliberately prioritized because rapid fault detection is its purpose. The right classification depends on the claim, not on a desire to give every tool the strongest label.
Path congruence is not fate sharing
RFC 10014 uses Virtual Circuit Connectivity Verification as the decisive counterexample. VCCV was historically described as “in-band” because its messages follow the same pseudowire path as user data. Under the new vocabulary it is active and path-congruent, yet it can receive different forwarding treatment. The path is shared; queue fate may not be.
The distinction is equally visible in Bidirectional Forwarding Detection. BFD is designed for rapid failure detection, and its control packets may receive the highest priority. That is sensible for liveness. It also means a healthy BFD session cannot, by itself, establish that ordinary packets escaped delay, loss or shaping lower in the scheduler. A liveness proposition does not become a performance proposition merely because both are displayed in the same dashboard.
When OAM traffic shares both the exact topology and forwarding treatment of the data traffic, RFC 10014 uses the stronger idea of fate sharing. Even then, the boundary must remain explicit. Equal queue treatment does not give a synthetic packet the payload size distribution, burst behavior, encryption state, transport history, application timeout or business semantics of the real workload. It narrows a network uncertainty; it does not close every layer above it.
This is why the sentence “the OAM was green” is incomplete. Green for which packet population? Which direction? Which traffic class? Which forwarding epoch? Which layer and maintenance domain? Which proposition—continuity, reachability, path, loss, delay or application completion? A result without those qualifiers is a status symbol detached from its evidentiary object.
The packet population changes the proposition
Different OAM families show why a common label cannot carry the details.
An MPLS echo request is active OAM. Its constructed packet tests a Forwarding Equivalence Class and expects particular data-plane behavior and a return. Packet construction, TTL, entropy, label stack and return path can affect what is learned. The result may be excellent evidence for the selected FEC while saying less about another entropy outcome or the experience of a large production flow.
MPLS loss and delay measurement introduces another split. Inferred loss measurement counts specially generated test messages. Direct loss measurement carries counters derived from user traffic in OAM messages. Both can be active in transport and yet differ in what population grounds the loss calculation; the latter is hybrid because an active message transports a passive observation of data packets.
RFC 9197 places IOAM information within selected data packets. Under RFC 10014, that is in-data-packet, path-congruent and equal-treatment for those packets. It is strong evidence about their path and treatment inside the IOAM domain. It is not evidence that every packet was selected, that collection was complete, that the application consumed the payload or that telemetry insertion and export were authorized in every domain.
RFC 9341 uses Alternate Marking to divide production traffic into blocks and derive loss or delay from markings and counters. Its strength is precisely that it measures real traffic. Its interpretation still depends on flow definition, observation points, block boundaries, counter behavior, clocks and the treatment of reordering. “Hybrid” describes the method family; it does not remove its measurement contract.
The lesson is not that synthetic tests are inferior. Active packets give controllable timing, known construction and coverage when user traffic is absent. Passive methods preserve production behavior but may lack visibility into causes. Hybrid methods can connect the two. Each gains authority only when its packet population matches the proposition being decided.
Layers and maintenance domains create a second blind spot
RFC 7276 describes OAM as a family of tools for detecting, isolating and reporting failures and monitoring performance. It also emphasizes that packet networks are layered. A provider may operate MPLS OAM between two provider edges while a customer measures IP service between customer edges. Both results can be correct and still disagree because they observe different endpoints, encapsulations and responsibilities.
The maintenance domain matters for governance as much as mechanics. A carrier can prove continuity within its core while an access link, customer edge, overlay, encryption gateway or application remains impaired. Conversely, a customer test may fail because of its local environment while the provider domain is sound. Neither party should be permitted to use a result outside its declared boundary as a universal verdict.
Direction also matters. Congruent forward and return paths cannot be assumed in a routed network. A request that reaches the far endpoint and a response that returns successfully may traverse different nodes, queues and policy. A single round-trip number can combine two unknown one-way distributions. Incident evidence must preserve the tested direction rather than letting a convenient aggregate erase it.
Finally, time creates an epoch boundary. Equal path and treatment at 10:00 do not prove equality after a traffic-engineering update, queue-map change, protection switch or rolling software deployment at 10:05. The configuration, topology and policy versions belong beside the result. Without them, an honest observation can be reused after the reality it described has ended.
OAM is not one function and green is not one authority
RFC 6291 standardized the expansion Operations, Administration, and Maintenance and explained the breadth hidden in the acronym. Operations keeps networks and services running and finds problems. Administration tracks resources and their use. Maintenance supports repair, upgrade and preventive or corrective action. Provisioning is related but separately defined.
A tool that performs continuity checking is not thereby an inventory, a maintenance decision, a repair authority and an outcome verifier. Yet product language often compresses all of these roles into an “OAM platform.” That compression encourages a subtle transfer of power: because the tool observed a signal, its policy engine is allowed to decide what the signal means; because it decided, its controller is allowed to reroute or withdraw; because the action completed, the incident is declared resolved.
Each transition needs its own owner. The measurement system owns the integrity of the observation. The service owner decides whether the result supports the claimed service condition. The automation owner defines thresholds, suppression and blast radius. The change authority decides whether an action is permitted. The outcome owner verifies that the affected user or workload recovered. A shared console may display all five, but one green icon cannot merge them.
The minimum evidence contract
Every consequential OAM result should carry a machine-readable claim record.
Begin with identity: service, tenant or aggregate; source and destination; direction; traffic class; protocol layer; maintenance domain; stream, FEC or packet-selection rule; configuration and forwarding epoch. Record whether the method is active, passive, hybrid or in-data-packet. For dedicated OAM packets, state whether path congruence and equal forwarding treatment are guaranteed by mechanism and configuration, merely expected, sampled, or known to be false.
Then preserve measurement semantics: packet construction, size and rate; marked population; counters and wrap behavior; clock source and synchronization quality; observation points; aggregation interval; loss and delay formula; sampling; threshold; confidence; missing-data policy and suppression. “Zero loss” without its denominator and window is not a stable fact.
Add provenance: implementation and policy version, collector identity, authentication and integrity result, configuration hash, time source, controller that received the event and rule that transformed it. Do not flatten a device counter, a signed export and a correlation engine's inference into the same evidence class.
Finally, separate decision and effect. Record which action the observation was allowed to trigger, the object and blast radius, idempotency key, approvals or exception, rollback condition, commit result and independent service verification. If a protection switch succeeds technically while application transactions keep failing, the automation completed but the incident did not.
This record is deliberately narrower than “full observability.” Its purpose is to prevent a measurement from acquiring authority it never earned.
Security begins with false equivalence
RFC 10014's security section is one sentence in substance: precise, unambiguous terminology improves security. The operational consequences are larger than the wording suggests.
An attacker or faulty component can exploit an assurance gap without forging the probe itself. If privileged OAM packets bypass congestion, an overload can remain invisible to the health gate. If an IOAM collector accepts data outside the intended domain, topology and operational metadata may cross trust boundaries. If a controller acts on a stale stream-to-policy binding, authentic measurements can trigger the wrong change. If a vendor maps “in-band” to one axis while procurement assumed all three, both sides can comply with their own interpretation and leave the customer unprotected.
Authentication is therefore necessary but insufficient. A cryptographically authentic observation can still concern the wrong stream, epoch, queue or maintenance domain. Security review must test semantic binding as rigorously as source identity.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
