Summary

  • RFC 2023 put IPv6 behind two gates: PPP first had to reach its Network-Layer Protocol phase, and IPv6CP then had to reach Opened; control packets used 0x8057, while admitted IPv6 datagrams used 0x0057.
  • Interface-Token negotiation made the two 32-bit values different on that point-to-point link. It did not authenticate either peer or prove global uniqueness, address ownership, a usable route, packet receipt or application success.

There is a revealing oddity in the first standards-track specification for carrying IPv6 over PPP. One endpoint could ask for an Interface-Token of zero. Under RFC 2023, the peer answered with a non-zero suggestion—inside what the text called a Configure-Ack. Two years later, RFC 2472 changed that response to Configure-Nak, restoring the ordinary distinction between exact acceptance and a proposed replacement.

The correction matters because the names of PPP replies are not ceremony. They describe what evidence has been created. An Ack normally says that the latest request has been accepted. A Nak says that the request is not acceptable as written but supplies a value that might be. A Reject removes an option from the bargain. RFC 2023’s token mechanism used all three paths to solve one narrow problem: the two ends of one PPP link must not finish with the same 32-bit token.

That was all it solved.

A network protocol waited behind a link protocol

PPP did not treat a working carrier as permission to send every kind of packet. RFC 1661 divided the work into layers and phases. LCP established, configured and tested the data-link connection. Optional authentication could follow. Only then did PPP enter the Network-Layer Protocol phase, where a separate Network Control Protocol configured each network-layer protocol.

RFC 2023 inserted IPv6 into that architecture through IPv6CP. The control exchange had its own PPP Protocol value, hexadecimal 8057. IPv6 data had a different value, 0057. The distinction made the causal sequence visible on the wire: the control protocol negotiated the conditions; the data protocol used the resulting admission.

Two gates therefore had to be open before IPv6 could be communicated. PPP had to reach the Network-Layer Protocol phase, and IPv6CP had to reach Opened. An IPv6CP packet arriving too early was to be silently discarded. Under the general PPP rule, a supported network-layer packet arriving while its corresponding NCP was not open was also discarded.

These gates prevent a common interpretive error. LCP Opened did not mean “IPv6 ready.” It meant that the data-link configuration exchange had completed. The network phase allowed IPv6CP to negotiate; it did not complete that negotiation. IPv6CP Opened admitted IPv6 packets; it did not manufacture a route or transmit a datagram.

Two tentative numbers meet

RFC 2023’s Interface-Token option was Type 1, Length 6: a one-octet type, a one-octet length and a 32-bit token. Each implementation selected a tentative value for its own end. The RFC preferred a non-zero value drawn from several sources likely to differ even between similar machines. A link-layer address alone was explicitly not always sufficient. If no good source existed, the endpoint could request zero and ask the peer to help.

The receiver compared the token in the peer’s Configure-Request with the token in its own latest Configure-Request. Different, non-zero values were the easy case: the remote token was acknowledged. Equal, non-zero values revealed a collision: the receiver sent a Configure-Nak with a different non-zero suggestion. Equal zeros ended automatic negotiation through Configure-Reject; no default token could be assumed, and recovery was left unspecified.

The crossed-Nak case is the most subtle. Each side might propose to the other the same replacement. If the token received in a Nak differed from the last value the recipient had suggested to its peer, it could be placed into a new Configure-Request. If the values matched, another tentative token had to be chosen. The sequence could repeat, but the document expected independent choices to diverge quickly.

This is convergence without a registry. The peers do not consult a global authority. They compare local proposals, expose a collision, and try again. The result is scoped by the comparison that produced it: different values at the two ends of this link, in this negotiation.

Ack, Nak and Reject create different receipts

A Configure-Ack for a non-zero requested token records acceptance of that option in one directional exchange. It does not say that the opposite direction is complete. It does not say that the peer is who it claims to be. RFC 2023 did not discuss security, and Interface-Token was not an authentication protocol.

A Configure-Nak records a narrower fact: the current request is not the value on which the receiver is willing to converge, and another value is suggested. It is not evidence that the requester sent a revised packet, that the new token was acknowledged, or that IPv6CP later opened.

A Configure-Reject records the end of this option’s negotiation path. It may mean the receiver does not implement the option, or it may express the zero-against-zero failure described by RFC 2023. After a valid rejection, the next Configure-Request must omit Interface-Token. Rejection therefore cannot be read as evidence that a fallback token exists.

The zero case exposes why RFC 2472’s later edit was more than wording. RFC 2023 described an Ack containing a non-zero suggestion in response to a zero request. RFC 2472 changed that response to a Nak. The later document made the receipt match the event: the peer was proposing a replacement, not accepting the request unchanged. It also replaced the 32-bit token with a 64-bit Interface-Identifier. RFC 5072 later superseded RFC 2472, and today’s IANA registry cites RFC 5072 for IPv6CP. RFC 2023 must therefore be read as a historical design stage, not current configuration advice.

Compression was another directional promise

IPv6CP also carried a Type 2 IPv6-Compression-Protocol option. It signalled the ability to receive packets using a specified IPv6 compression protocol. Each end had to request the option separately for bidirectional compression, and the default was no compression.

That option reinforces the same evidence discipline. An accepted receive capability is not a compressed packet. A compressed packet is not successful decompression. Successful decompression is not route reachability or application delivery. The mechanism belongs in this article only because it shows that IPv6CP’s Opened state could summarize several negotiated conditions; the compression algorithms and their own state histories remain separate subjects.

Local uniqueness was not global identity

RFC 2023 said the token must be unique within the PPP link. That phrase supplies both the guarantee and its boundary. The final values distinguish the two ends of one point-to-point link. They are not allocations in a worldwide namespace. A random seed raises the probability of divergence; it does not issue a certificate.

A distinct token pair does not identify the human, organization, device or account behind either endpoint. It does not show that either endpoint was authorized to use the link. It does not establish ownership of the IPv6 address formed from the token. It does not prove that a route exists beyond the peer, that policy permits forwarding, or that the remote protocol stack remains alive.

Even an observed 0057 PPP frame proves only that one frame was classified as carrying one IPv6 packet at the observation point. To prove delivery, the observer needs later evidence: receipt at the intended endpoint, integrity checks, transport or application acknowledgement, and correlation strong enough to join those events. No state-machine label can silently supply those missing receipts.

RFC 2023’s durable lesson is therefore not that 32 bits were enough. They were soon replaced. The lesson is that a distributed protocol can solve a tightly bounded coordination problem by making disagreement visible and requiring another round. The tokens diverged. The link acquired a local addressing distinction. Everything larger—identity, authority, ownership, reachability and outcome—still required its own proof.

Sources