Summary
- RFC 1226 mapped one AX.25 frame to one IP datagram, omitted HDLC flags and zero-stuffing, retained the 16-bit CRC-CCITT frame check sequence, and assigned protocol number 93.
- The IP datagram supplied a new outer boundary. What survived inside it was a selected frame representation, not a recording of every bit that had crossed—or would cross—a radio link.
- A protocol-93 packet can establish bytes at an IP observation point. It cannot alone establish RF transmission, station identity, successful reassembly, delivery or action.
A frame arrived without its old punctuation
RFC 1226 is unusually short. Published in May 1991, it describes an Experimental way to carry AX.25 amateur packet-radio link-layer frames inside IP. The RFC Editor record now places it in the Legacy stream, and the Datatracker record says plainly that it has no IETF endorsement or formal standing in the standards process. It is a narrow representation rule, not evidence that a network deployed it.
The central mapping fits in one sentence: each AX.25 frame is encapsulated in one IP datagram. Yet “encapsulated” did not mean that every transmitted bit was copied. HDLC flags marked frame boundaries on the serial link, and zero-stuffing kept the flag pattern from appearing accidentally in the content stream. RFC 1226 omitted both. An IP datagram already had a length and a beginning and end, so reproducing the old delimiters inside the new container would have duplicated a job the outer layer was performing.
The specification kept something else: the 16-bit CRC-CCITT frame check sequence, normally generated by HDLC transmission hardware. In every other respect, it said, the AX.25 frame was carried unaltered. The tunnel representation was therefore selective. It removed one layer's boundary machinery, retained its check value, and preserved the remaining frame bytes.
That distinction matters to evidence. A captured protocol-93 datagram can support a bounded statement: at this IP observation point, a payload appeared in the form RFC 1226 assigned to an AX.25 frame. It cannot reconstruct the omitted flags or zero-stuffing. It cannot show that an antenna radiated anything, that a receiver detected RF energy, that a modem accepted the frame, or that the retained FCS was generated by the device someone later names.
A checksum can travel farther than the event it once checked
The FCS looks like the most physical survivor. That makes it tempting to treat its presence as a witness to a radio hop. The inference does not hold. A check sequence is a value in the encapsulated bytes. It may have been copied from a received frame, generated before a future transmission, recomputed in software or supplied by another source. RFC 1226 defines how to carry it; it does not authenticate its maker or narrate its history.
Even a correct FCS would answer only a constrained comparison over a defined sequence of bits. It would not identify a licensed operator, authorize a station, prove that the payload described reality, or show that a later consumer acted. Those require station records, capture context, trusted endpoint identity, decapsulation logs and operational evidence that the RFC never supplies.
The memo is explicit that security issues are not discussed. Protocol number 93 is therefore a dispatch label, not an identity credential. The current IANA Protocol Numbers registry still lists decimal 93 as AX.25 Frames and explains that IPv4's Protocol field identifies the next-level protocol. Registration prevents numerical collision. It does not validate the bytes behind the number or the party that sent them.
One frame did not always mean one packet on the path
RFC 1226 expected an AX.25 frame normally to stay within 330 octets, making IP fragmentation unnecessary in the ordinary case it contemplated. It nevertheless allowed experiments with larger frames and directed them to standard IP fragmentation and reassembly.
That caveat splits another apparently simple record. At the encapsulation interface there is one AX.25 frame and one IP datagram. On a path with a smaller packet-size limit, RFC 791 permits the datagram to become several fragments. RFC 1122 requires Internet hosts to support reassembly. A sensor in the middle may therefore observe only a fragment; a destination may receive an incomplete set; the reconstructed datagram may never reach an AX.25 consumer.
“One frame per datagram” is a construction rule, not a delivery receipt. Proof of the intended inner unit requires reassembly evidence at the destination. Proof of delivery requires a later hand-off. Proof of operational effect requires a still later observation.
The useful artifact is the boundary map
RFC 1226 leaves a compact map of which layer owned which fact. HDLC owned the serial delimiters and bit-stuffing. The encapsulator owned their removal and the construction of an IP payload. IPv4 owned the outer length, protocol classification, routing and possible fragmentation. The destination owned reassembly. A decapsulator owned the recovery of the selected AX.25 representation. None of these records could silently borrow the authority of the others.
This is why the memo remains useful even without deployment claims. It shows that “unaltered” is always scoped. The frame was unaltered in all other respects after two named framing mechanisms had been removed. Good operational history must preserve the exception, the observation point and the layer. Otherwise a tunnel packet becomes a fictional transcript of a physical event it was never designed to certify.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
