Summary
- RFC 2353 deliberately used UDP and IPv4 as a native data-link control beneath APPN/HPR, leaving recovery and sequencing to HPR’s Rapid Transport Protocol and outage detection to LDLC.
- An option to suppress liveness while a link was idle could make failure knowledge asymmetric: one node deactivated the link while the other retained it as active.
- A later activation could then be rejected as an unsupported parallel link, or new session activation could be sent on state the peer had already discarded. Recovery required explicit cross-checks, not faith in either local state.
At noon, two adjacent nodes agree that a link is active. The link becomes idle, and an optimization suppresses its periodic test traffic. A disruption occurs. One node discovers the break by another path and deactivates its local link instance. The other sees no packets and receives no outage notification, so its state remains active. By the time traffic returns, both machines are behaving consistently—and describing different pasts.
That is the most revealing sequence in RFC 2353, the May 1998 document for carrying Advanced Peer-to-Peer Networking and High Performance Routing across IP networks. The document was Informational, not an Internet Standard. It recorded an architecture that the APPN Implementers’ Workshop had moved to “Closed Pages” status in December 1997, meaning detailed enough for interoperable products within that process.
The design’s purpose was not simply to tunnel an older architecture. It treated IP as a native data-link control for HPR, retained APPN class-of-service and routing functions, and allowed an optional connection-network model that reduced the need to predefine every link. Its interesting choice was to avoid TCP.
UDP was a deliberate boundary
RFC 768 supplied a minimal datagram service: ports, length and checksum, without a connection whose teardown could notify an application. RFC 791 supplied the IPv4 datagram and routing layer. RFC 2353 accepted the consequences. Loss, duplication, delay, reordering and loss of connectivity had to be handled above UDP.
HPR already had machinery for that division. Its protocol called RTP—not the later IETF Real-time Transport Protocol—provided end-to-end selective retransmission, resequencing and adaptive rate-based flow and congestion control. LDLC, a logical data-link control component, handled link liveness and control exchanges. TCP’s recovery queues, timers and connection state would have duplicated functions and reduced scalability.
This was not a claim that UDP had become reliable. It was a claim that reliability belonged elsewhere. A UDP/IP observation could prove that a datagram was emitted or received. HPR RTP could prove recovery and ordering within its end-to-end scope. LDLC could test a link instance. None of those receipts, alone, established that both endpoints currently named the same link state.
Silence saved traffic by delaying shared knowledge
Because UDP provides no connection-outage notification, RFC 2353 required LDLC liveness on HPR/IP links. It described a default ten-second liveness period, a fifteen-second retry timer and three retries among the configured defaults. A successful test restarted the liveness clock.
The optional economy was attractive. If the link was idle, an implementation could stop sending liveness traffic, allowing underlying facilities to remain quiet or even deactivate temporarily. But an idle interval also removed the observation that kept neighbouring state aligned.
The RFC spells out two consequences. First, the node that knows of failure may later attempt reactivation. Its partner, still holding an active link between the same ports, can reject the request as an unsupported parallel link. Second, the unaware node may send data—including new session activation—over the link it still considers live. The node that already deactivated the instance may discard the traffic.
Neither side is necessarily corrupt. Each local record follows the events it observed. The fault lies in promoting either local record into proof of shared state.
The recovery rules were really evidence rules
RFC 2353 did not solve asymmetry by declaring one endpoint authoritative. When a node rejected activation as an unsupported parallel link, it should run liveness on relevant active links with the same IP-address pair and different service-access-point pairs. A stale entry could then be discovered rather than defended.
If an activation exchange arrived with the same IP and SAP pair as an active link, the receiver should deactivate the old instance and allow re-establishment, with a timer limiting harm from stray exchange-identification messages. A node should also try reactivation before acting on an LDLC-detected failure, helping when the remote side had detected failure earlier but the network had since recovered.
The detailed sense codes reinforced the boundary. Codes for unsupported parallel defined or dynamic links reported why the local activation path failed. They did not prove which endpoint first lost connectivity, whether a remote application had processed traffic or whether a session achieved its intended outcome.
Reliable traffic and a live link were different statements
The apparent paradox disappears once the layers are separated. HPR RTP could recover user traffic end to end while LDLC managed the logical link. A link test could succeed without proving that an APPN session had completed. A session activation failure could carry sense data without reconstructing the remote node’s entire timeline.
Security lived on yet another axis. RFC 2353 retained SNA session authentication and encryption, allowed IPsec for UDP traffic, and discussed firewall filters by address and port. Those controls could authenticate, protect or admit traffic. They did not reconcile two stale link-state machines.
The RFC Editor record and IETF history establish the document’s status and path. They do not prove a named deployment, current product behaviour or operational incident. RFC 1122 supplies host guidance cited in the design; it does not turn an IP address into a universal link identity.
Lu Heng’s running-code primacy provides a useful reading discipline. A local status has operational meaning only as far as the peer’s running behaviour will accept it. His minimum-initial-specification principle favours explicit, locally verifiable rules over a standing assertion of truth. The essay on reality layers supplies the final separation: carriage, liveness, reliable transport, link activation and session outcome are adjacent realities, not synonyms.
RFC 2353’s lasting lesson is not that keepalives are always good. It is that reducing observation changes the time at which systems can agree. When silence is an optimization, recovery must treat local state as a hypothesis and ask the peer again.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

