Summary

  • RFC 3395 added application verbs to RMON protocol identifiers, but a verb could describe a transaction spanning packets and directions rather than a command visible in the packet being counted.
  • Every packet still had to enter one complete leaf counter. When several verbs appeared, the probe had to choose one under its own policy, so the published number contained both traffic and implementation judgment.

Imagine two monitoring probes watching exactly the same link. They agree on every byte. They use the same registered names. They are both conforming. Yet one reports more of one application operation than the other. RFC 3395 contains the reason in a deceptively small sentence: if a packet contains multiple verb types, the agent must select one, and how it selects is implementation-specific.

Published in September 2002 on the Standards Track, RFC 3395 updated the Protocol Identifier Reference of RFC 2895. Its problem was practical. A monitor that stopped at “HTTP”, “SNMP” or “FTP” could distinguish protocols but not the operations within them, even though different operations could have very different costs and consequences. The document created a standard way to name those application transactions. It did not create a new MIB module or new managed object.

The inherited protocol directory already treated a packet as an encapsulation stack. Each layer contributed four octets to protocolDirID and one octet to protocolDirParameters. The full sequence identified a leaf: not merely Ethernet, IP or TCP in isolation, but the path through the layers that the monitor had recognized. RFC 3395 made an application verb one more layer in that sequence.

Its wire representation was compact. The verb layer occupied four octets: a reserved zero octet followed by a 24-bit unsigned enumeration in network byte order. The explicit enumeration range ran from 1 to 16,777,215, unique within a parent protocol and preferably assigned densely. A zero parameter octet accompanied the layer for structural conformance, although the verb itself did not use parameters.

Zero already meant something. Every application protocol implicitly possessed connect(0), the bucket for establishment and termination traffic that belonged to no other verb. The enumeration could not be reassigned. But the name was not a globally protected word: the HTTP example separately gave CONNECT an explicit connect(8). That distinction warned implementers not to infer semantics from a familiar string without also carrying its parent and number.

The macro named VERB-IDENTIFIER registered the parent, description, references and list of names and enumerations. Names were case-sensitive in the definition and unique within their parent. When a protocol supplied authoritative terms, the registry was supposed to preserve them. Registration made two products capable of printing the same label. It did not yet make them capable of reaching that label by the same evidence.

The crucial difficulty was time. Many protocol layers can be recognized from the packet in front of the parser. A verb may live across a conversation. An SNMP Response PDU does not say whether it answers a Get or GetNext request. To count the response under the right transaction, a probe must remember the preceding request moving in the other direction and correlate the pair. In RFC 3395's SNMP example, Response and Report are therefore not independent verbs; they inherit the request transaction.

TCP adds a different kind of memory. An application operation can be divided across several segments. The probe may have to follow the flow and reconstruct enough of its byte stream before classification becomes possible. If capture policy depends on the verb, the decision can arrive after the earliest relevant packets. Those packets must either have been pre-buffered or be lost from the supposedly operation-specific capture.

This is why “verb” did not mean one opcode, command token or PDU type. A transaction could involve several PDU types. It could even cross protocol-directory entries: FTP's control exchange and its separate data connection may belong to the same useful operation. The label represented a monitoring transaction chosen by a classifier, not a raw field copied from every packet.

RMON accounting nevertheless demanded a crisp output. Each packet was counted once under one complete leaf protocol encapsulation. Its full size increased that counter, not merely the few bytes occupied by the recognized application token. A monitor could not split one packet across several verb counters just because the packet carried more than one kind of operation.

RFC 3395 suggested several ways to break the tie: choose the first verb, the one occurring most often, the one occupying the most octets, or the one considered most interesting through knowledge of the protocol. It standardized none of them. Each rule answers a different question, so identical packet traces can yield different distributions without either implementation violating the document.

The examples made the abstraction concrete through FTP, POP3, SNMP, HTTP and SMTP. They also exposed how dangerous a bare label could be. A counter marked GET is not proof that a human intended a retrieval, that authorization succeeded, that the server returned useful content or that a complete payload was visible. It says that an agent, with some amount of context and some local policy, classified packets beneath that registered leaf.

The security discussion was similarly precise. Adding verb identifiers introduced no new MIB operations, but finer measurement could reveal which application operations a network was using. That operational detail might deserve more protection than a coarse protocol total. “No new operation” was not “no new information”.

Later, RFC 4502 replaced the RFC 2021 specification of the RMON-2 MIB. That lineage helps locate the measurement model, but it does not prove that products implemented RFC 3395, used the same reassembly policy or retained enough state under load. Standards status supplies a contract to test; it does not supply deployment evidence.

Lu Heng's Minimum Initial Specification principle fits the design's restraint. The RFC fixed the interoperable naming surface, binary layer, reserved default, capability rules and once-only accounting obligation. It left timeouts, buffers, stream reconstruction and multi-verb preference to local engineering because one initial rule could not safely embody every protocol and resource constraint.

Running-Code Primacy then changes how the counter should be trusted. Operators need the probe version, enabled decoders, state limits, loss statistics, reassembly behaviour and verb-selection policy alongside the number. Without those, comparison mistakes a common vocabulary for a common observation process.

RFC 3395's enduring lesson is not that monitoring was unreliable. It is that measurement acquired provenance before it acquired a value. The counter said GET only after a probe remembered, assembled and chose. The number was real, but its meaning lived partly inside the machine that produced it.

Sources