Summary

  • RFC 3355 mapped L2TP onto an ATM AAL5 virtual circuit, but required every L2TP PDU to fit within one AAL5 PDU; the bearer MTU therefore constrained the tunnel and every PPP session using it.
  • Encapsulation selection, VC setup, security and clearing remained bearer-layer facts. A negotiated envelope did not prove inner-session establishment or delivery, and a cleared SVC terminated the tunnel’s user sessions.

A tunnel promises distance from the medium beneath it. To the inner protocol, a remote endpoint can look as though it were attached by a simple link even when an intervening network performs switching, signaling and segmentation. That promise is useful because applications and sessions need not understand every carrier technology. It becomes dangerous when “hidden” is mistaken for “irrelevant.”

RFC 3355, published on the Standards Track in August 2002, specified L2TP over ATM Adaptation Layer 5. The base L2TP specification said that the tunnelling protocol was largely insulated from media details and required only packet-oriented point-to-point connectivity. An AAL5 virtual circuit could provide exactly that service between an L2TP Access Concentrator and an L2TP Network Server.

Yet the mapping had a physical-looking boundary in its logic: each L2TP PDU had to travel inside a single AAL5 PDU. It could not be divided across several AAL5 messages by this specification and then treated as one L2TP unit at the top. The maximum envelope offered by the VC therefore set the tunnel MTU, which in turn constrained the Maximum Receive Unit of every PPP connection sharing the tunnel.

This was not merely a number copied between configuration screens. One outside limit propagated inward through several abstractions. A service provider might present a virtual link; L2TP might present a tunnel; PPP might present individual sessions. Nevertheless, an oversized inner unit still had to fit through the same outer AAL5 message boundary. Hiding the bearer’s details did not manufacture extra space.

RFC 3355 required support for a PPP MRU of at least 1500 bytes. It also recommended a larger envelope capable of supporting an IP packet of at least 9180 bytes inside the PPP PDU. Those statements described implementation capability and design preference. They did not prove that a particular VC had negotiated or provisioned the necessary size, that an actual PPP peer had selected it, or that an application packet crossed without fragmentation or loss.

The distinction between capability and live evidence matters whenever a tunnel carries many sessions. A product may advertise a maximum. One PVC may be provisioned differently from another. An SVC may receive different parameters at setup. A PPP session may negotiate a smaller MRU. Traffic may include additional headers or follow a path with another constraint. “Supports 9180” is therefore not a receipt for one observed 9180-byte delivery.

The underlying AAL5 service was tightly characterized. L2TP treated it as a bit-synchronous, full-duplex, point-to-point link. The circuit could be permanent, established by provisioning, or switched, set up on demand. AAL5 message mode had to operate in non-assured mode without the corrupted-delivery option. At the boundary L2TP saw octets, not sub-octets.

These details made the abstraction possible, but also defined where it could fail. The service did not promise reliable delivery merely because it preserved message boundaries. A valid AAL5 length and CRC could bound one received PDU; it did not authenticate the sender, provide confidentiality, or prove that the inner L2TP control plane accepted the packet. Framing integrity was one reality layer, not the whole transaction.

Protocol identity also crossed the seam in two different ways. Under LLC encapsulation, each AAL5 PDU carried an LLC/SNAP header with an IANA identifier for L2TP. The envelope named what it contained. Under VC multiplexing, the header was absent; endpoints had already agreed that this virtual circuit carried L2TP. Meaning lived in the circuit’s provisioned or signaled context rather than in every PDU.

RFC 3355 required support for LLC-encapsulated L2TP on permanent circuits. LLC on switched circuits and VC-multiplexing on either circuit type were optional. PVC endpoints had to be configured for the same choice. Two boxes could each support L2TP and still fail to interpret the same bytes if their circuit context disagreed. Media independence did not remove the need for a shared naming convention at the boundary.

Switched virtual circuits moved that agreement into the ATM control plane. The caller used Broadband Lower Layer Information elements to offer LLC encapsulation, VC multiplexing, or both in preference order. If both were offered and the call was accepted, the called peer selected exactly one. If only an unsupported form was offered, the request had to be rejected.

Successful selection proved a bounded fact: for that connection setup, both sides had chosen a method for interpreting the AAL5 payload. It did not prove that the L2TP control connection later came up, that PPP sessions authenticated, that user packets fit, or that an application received them. The control plane had agreed on an envelope grammar; the contents still had their own lifecycle.

The reset rules make this dependency impossible to ignore. If an SVC-backed L2TP tunnel was reset under the base L2TP procedure, both ends had to clear the SVC. Every user session on that tunnel was terminated. Either end could later try to establish a new tunnel after a new client request, but the new attempt did not continue the old sessions invisibly.

Likewise, notification that the AAL5 SVC had been cleared required the implementation to tear down the L2TP tunnel and return its control connection to idle. The outer network had not merely removed an implementation detail; it had removed the packet-oriented link on which the inner state depended. Bearer failure propagated upward.

RFC 3355 deliberately left some reachability judgments to implementations. After setup failure, the caller could regard the destination as unreachable until later notice, but the conditions for entering and leaving that judgment were local decisions. When no sessions remained, either end could optionally clear an SVC. A status such as “unreachable” or “idle” therefore needed provenance: which layer reported it, what event produced it, and which state machine still existed?

Quality of service followed the same pattern. Different client qualities could be placed on multiple AAL5 connections between LAC and LNS. More ambitious inverse multiplexing of a tunnel across several virtual circuits was left for further study. L2TP itself imposed no ATM transmission rate or traffic descriptor. PVC parameters could be agreed by the parties; SVC parameters could be requested during setup. A requested traffic descriptor was configuration evidence, not proof of delivered performance.

Security could not be inherited from correct encapsulation either. RFC 3355 warned that attacks on the ATM transport might compromise the tunnel. It referred implementers to authentication headers, encrypted payloads and ATM-layer security services. A circuit carrying the right PID, a correct CRC and an accepted B-LLI choice could still lack confidentiality or adequate peer authentication.

The adjacent standards clarify without collapsing the layers. RFC 1661 supplied PPP and its MRU negotiation. RFC 2684 supplied the general LLC/SNAP and VC-multiplexed AAL5 forms. RFC 2364 placed PPP directly over AAL5, while RFC 3355 carried PPP sessions indirectly through L2TP. RFC 2331 described ATM signaling. RFC 2661 supplied the tunnel and session state that the AAL5 bearer could support or remove.

Other L2TP mappings demonstrate that the seam changed with the bearer. RFC 3070 mapped L2TP over Frame Relay, not AAL5; its details cannot be substituted for RFC 3355’s single-message envelope. RFC 3193 coordinated L2TP with IPsec and added separate security-state dependencies. RFC 4459 later treated tunnel MTU and fragmentation as a general layered problem. None of these documents proves a deployment or incident for RFC 3355.

The current IANA L2TP registry preserves assignments used for coordination. A registry entry proves that a value has a defined place. It does not prove that a box implemented it, a VC carried it, or a session survived it. This is the same evidence discipline that the mapping itself demands.

RFC 3355 is a compact lesson in abstraction. A good abstraction hides machinery so that higher layers can operate. It does not repeal the machinery’s finite resources or lifecycle. The L2TP tunnel could hide ATM’s signaling and cells from its PPP users. The AAL5 VC still decided how large one envelope could be, how its contents were identified, and what disappeared when the bearer was cleared.

Sources