Summary

  • RFC 3919 gave RMON-2 agents shared names for IPv6 and MPLS decoding paths, but it did not turn those names into a description of every service carried inside them.
  • The sharpest limit is written into the MPLS entries themselves: unicast and multicast can be distinguished at the entry layer, while their children are “not systematically identifiable.”

Remote monitoring depends on a deceptively small question: what kind of packet can a probe say it understands? RMON-2's protocol directory answered with an inventory. It listed protocol types a particular agent could monitor, so management software could relate counters and host or conversation tables to a named encapsulation. The directory was not a universal packet census, and it did not make the probe learn a new decoder merely because a manager added a row. RFC 2021 calls this limited extensibility: software must already know the relevant demultiplexing logic before configuration can extend a level above it.

RFC 3919, published as an Informational memo in October 2004, supplied additional identifier macros for IPv6 and Multi-Protocol Label Switching. Its modest purpose was interoperability among RMON-2 agents: if implementations described common packet paths in different ways, management tools could not reliably compare their protocol-specific views. The memo explicitly says an RMON-2 implementation can conform without these identifiers. They were useful shared vocabulary, not a new conformance test or a claim that every probe supported them. (RFC 3919; RFC Editor record)

The contrast inside the document matters. For IPv6, a child can be selected by the one-octet Protocol field. The identifier can therefore follow a known demultiplexing value: the document names ICMPv6 as protocol 58 and shows UDP reached through native IPv6 as a different path from UDP inside IPv6-in-IPv4 tunnelling. ether2.ip6.udp and ether2.ip.ipip6.udp are not interchangeable labels. A path describes how the parser got to the transport protocol, not just the final word “UDP.”

For MPLS, RFC 3919 draws a shorter branch. It names mplsu and mplsm, distinguishing unicast from multicast with the corresponding link-layer values—EtherType 0x8847 and 0x8848—and lists encodings for other link types. Then both entries stop: children of MPLS are not systematically identifiable. That line is not a claim that MPLS never carries IP or that packets behind labels cannot be decoded. It says this identifier set does not define a generally usable child tree beneath those MPLS descriptors. (RFC 3032)

That limit prevents a directory label from overpromising. A probe may know an outer framing or a particular MPLS entry without exposing a stable, shared name for every payload or service behind a label stack. A route label is not itself a protocol-family declaration; its interpretation belongs to other mechanisms and context. RFC 3919 does not attempt to infer that context from a label or promise that two agents assign the same local row number.

The distinction between a protocol name and an index is equally important. RFC 2895 defines the encoded protocolDirID and parameter strings, while counting tables use protocolDirLocalIndex. RFC 2021 says this integer is meaningful only within one SNMP entity. It is a local handle into that agent's directory, not an identifier that can be copied into another probe's data and assumed to mean the same thing. Interoperability comes from shared descriptor rules and careful interpretation, not from pretending every implementation has the same local numbering.

RFC 3919 is therefore a small but revealing boundary document. Where IPv6 exposes a standardized next-header value, the identifier vocabulary can describe a deeper parser path. Where MPLS's children do not have a comparable systematic mapping in this framework, the vocabulary stops at the outer entry. A capability inventory can help a manager ask better questions; it cannot establish that a probe actually saw a packet, decoded it correctly, counted it over a given interval, or recognized the business service a label happened to carry. Those claims need observation records and additional evidence, not a longer name in a table.

Sources