Summary
- RFC 5143 is a Historic specification for carrying SONET/SDH circuit signals over MPLS; new implementations must use standards-track RFC 4842 instead.
- Its 32-bit CEM header carries DBA and remote-defect flags, sequence state, a structure pointer, pointer-adjustment bits and ECC-6.
- ECC-6 protects the header, corrects a single-bit error and detects up to two-bit errors; it does not protect the circuit payload.
- A valid or repaired header cannot recreate a missing packet, reverse reordering, fill the jitter buffer or establish packet synchronization.
- The receiver decides packet loss at playout time, when it knows whether usable data arrived before the circuit needed it.
- Sequence numbers expose loss and misordering; implementations may reorder, but otherwise must drop misordered packets and substitute configured data.
- Loss of packet synchronization drives CEM-RDI toward the packet network and, for structured service, AIS-P toward the circuit side.
- Dynamic Bandwidth Allocation may intentionally remove payload while keeping packet cadence, so packet flow alone does not prove customer data exists.
- Clock recovery remains a separate function; valid headers do not prove frequency, phase, jitter or wander at the reconstructed interface.
- The legacy header could resemble IPv4 and invite payload-based ECMP, adding jitter and reordering that the correction code cannot solve.
- Security is no stronger than the packet network and may be weaker than native TDM; ECC is neither authentication nor provenance.
- Leadership should demand separate receipts for header integrity, packet order, buffer state, timing quality, alarm translation and actual circuit output.
A successful correction can precede an honest alarm
Imagine the receiving edge examining a CEM packet. One bit in the header has changed in flight. ECC-6 identifies and corrects it. The header is now internally coherent: its sequence number, structure pointer and control flags can be interpreted.
The packet expected immediately before it, however, never reached the playout edge. Or it arrived on another equal-cost path after its time slot had passed. The receiver cannot move a SONET/SDH clock backwards while it waits. It must output something now. A sequence of missing or empty packets crosses the configured threshold, packet synchronization is declared lost, and the circuit side receives AIS-P rather than valid customer payload.
Nothing contradictory happened. The correction code succeeded at the job assigned to it. The service failed a different test.
This is why RFC 5143 remains analytically useful despite its Historic status. It exposes an assurance error that modern systems repeat: promoting the strongest easily collected technical receipt into proof of a broader outcome. A repaired field becomes a “healthy packet”; a run of healthy packets becomes a “healthy pseudowire”; the pseudowire becomes a “continuous circuit”. Each promotion crosses an observation boundary.
The header is deliberately small
The CEM header is 32 bits. It records whether Dynamic Bandwidth Allocation is active, whether the far edge reports a defect, a ten-bit sequence number, a structure pointer, two pointer-adjustment or alarm bits, and the six ECC bits. The sequence number cycles from zero to 1023. The structure pointer helps a structured service locate the start of its synchronous payload envelope. N and P convey pointer movement in ordinary operation and contribute to alarm signalling.
These are coordination facts. They let two edges agree on how to interpret the next unit of work. They do not describe every state required to reproduce the service. The header does not contain a complete history of prior arrivals, the depth of the remote buffer, the quality of the recovered clock, the state of an attached customer's equipment or the business consequence of an alarm.
That narrowness is a virtue. A shared protocol should contain what independent implementations must share. Trouble begins when an inventory or monitoring layer treats the narrow record as if it were an operational twin of the circuit.
ECC-6 makes the boundary especially clear. Appendix B defines a check matrix over the 32-bit header. The receiver derives a syndrome, corrects a single-bit error and detects up to two-bit errors. The mechanism can even be disabled by provisioning, in which case the field is zero. Its object is unambiguous: the CEM header. It has no parity over the SONET/SDH payload and no power to manufacture bytes that never arrived.
Sequence is evidence, not repair
Sequence numbers tell the receiver what should have come next. They reveal a gap or an inversion, but detection is not restoration. RFC 5143 requires the de-packetizer to detect lost and misordered packets. It may reorder packets when its implementation and buffer permit. If it does not reorder them, it must drop the misordered packets. Missing or dropped payload is replaced by a programmable byte pattern.
That substitute protects the shape and cadence of the output. It does not retrospectively make the customer's data correct. An operator who counts only a continuously clocked interface can therefore miss the very evidence the interface is designed to contain: the circuit stayed electrically or optically present by emitting a maintenance or replacement pattern.
Packet synchronization adds state over time. A receiver begins out of synchronization. It acquires synchronization only after a configured run of packets with sequential numbers, and it loses synchronization after a configured run of missing or empty packets. A single well-formed header does not satisfy either condition.
The loss decision also waits until playout. Earlier, a packet that appears absent may merely be late. At the instant its bytes must be delivered, the receiver finally knows whether the packet is usable. That deadline is where network observation becomes service consequence. Arrival telemetry without the playout decision is incomplete; playout state without the original sequence evidence is difficult to diagnose.
The jitter buffer is part of the claim
Circuit emulation asks an irregular packet network to feed a regular circuit. The CEM jitter buffer absorbs variation and releases bytes at the required rate. Its depth is adjustable because path delay variation is not constant. Over the interval represented by the buffer, arrivals must on average balance fixed-rate playback.
The same number of received packets can produce different outcomes under different ordering, timing and buffer conditions. A late burst may overflow a shallow buffer. A quiet interval may underflow it. A packet can arrive, be counted by network telemetry and still be useless because its playout deadline has passed. Conversely, a deeper buffer may preserve the service at the cost of latency.
Buffer depth is therefore not an implementation footnote. It is part of the evidence needed to interpret whether packet carriage became circuit continuity. Reporting packets_received without packets_played, late_packets, buffer_underrun, buffer_overrun and synchronization state leaves the outcome undefined.
RFC 4842's later performance model makes the separation explicit. Missing or dropped packets form one class; buffer underflow, overflow and loss of packet synchronization form another. The distinction survives the replacement of RFC 5143 because it reflects the system, not an accidental field layout.
DBA preserves cadence while removing meaning
Dynamic Bandwidth Allocation is another trap for superficial health checks. During AIS-P or an unequipped SONET/SDH payload, the packetizer may suppress the circuit payload. It continues to send the headers and packet-network encapsulation. The packet rate remains equivalent to normal operation so that the far jitter buffer does not collapse and the receiver can distinguish intentional line conditioning from a packet-network failure.
A flow graph can therefore look steady while no customer payload is being transported. The steady cadence is useful—it keeps state stable and conveys an explicit condition—but its meaning is the opposite of ordinary service. DBA must be triggered from SONET/SDH overhead indications, not by guessing from a payload pattern. That rule preserves the provenance of the decision.
The leadership lesson is not to distrust the packet stream. It is to retain its semantics. stream_present, payload_present, maintenance_condition, packet_sync and valid_user_data_played are different fields. Compressing them into up=true makes an intentional safety mechanism look like a successful business outcome.
Time cannot be corrected by header parity
The output interface must regenerate the input service clock. RFC 5143 supports synchronous and asynchronous modes chosen by provisioning, with both ends configured consistently. Structured synchronous service can use pointer-adjustment information, and sequence numbers help prevent the same adjustment from being applied repeatedly after duplication or reordering.
That is not a universal clock proof. For asynchronous operation the receiver may use adaptive recovery; important details remain with the implementation. The replacement RFC likewise leaves adaptive algorithms outside the specification while requiring the result to respect the applicable SONET/SDH jitter and wander limits.
A perfectly decoded sequence can still be played with unacceptable frequency error or phase noise. A stable average packet rate can conceal short-term jitter. A clock algorithm can remain locked while the payload has been replaced by alarms. Timing assurance therefore needs measurements at the reconstructed interface, not an inference from header validity.
This is the deeper reason to keep future decisions local. The shared format supplies compatible observations. The implementation chooses buffer and recovery behaviour. The operator decides which timing limits and service objectives matter. None of those local choices should be smuggled into a universal claim attached to ECC success.
The legacy ECMP hazard shows why syntax is not path control
RFC 5143 also records a specific defect in the legacy encapsulation. Certain combinations of its first control bits can resemble the first nibble of IPv4. Equipment that guesses at packet type and hashes apparent payload fields for equal-cost multipath may then split packets belonging to one pseudowire across different paths. RFC 4928 explains how this can create jitter and reordering. RFC 4842's standards-track format avoids that violation.
Again, the header can arrive intact. ECC can pronounce it recoverable. The surrounding forwarding system may nevertheless have changed the order and timing on which circuit reconstruction depends. Integrity of a record is not authority over the path that carried it.
This is also why the article cannot be read as a deployment recommendation. RFC 5143 is Historic. The operationally responsible conclusion for a new implementation is to use RFC 4842. The enduring value of the older document is its transparent decomposition of the problem and the migration warning carried by its status.
Six receipts, not one green lamp
An assurance system for circuit emulation should preserve at least six distinct receipts.
First, header integrity: was the header valid, corrected, uncorrectable or sent without ECC? Second, packet continuity: were sequence gaps, duplicates or inversions observed, and were any inversions repaired? Third, buffer outcome: which packets were actually available at playout, and did underflow or overflow occur? Fourth, timing outcome: did the reconstructed clock meet required frequency, jitter and wander limits? Fifth, maintenance state: were AIS-P, CEM-RDI, unequipped payload or DBA active, and where was each condition first observed?
Sixth, service output: did valid customer data emerge, and did the attached system experience the intended continuity?
Each receipt can justify the next check. None can impersonate the rest.
The separation also improves incident response. A header-correction spike points toward one class of link or equipment problem. Ordered packets with buffer underflow point toward pacing or path-delay variation. Clean packet and buffer data with poor output timing points toward clock recovery. Regular DBA packets with AIS-P point toward a line condition, not transport silence. The same green/red composite hides all four diagnoses.
Sources
- RFC 5143, HTML
- RFC 5143, text
- RFC Editor record
- IETF Datatracker
- Document history
- RFC 5143 errata search
- IANA Pseudowire Name Spaces
- RFC 4842: Circuit Emulation over Packet
- RFC 4553: Structure-Agnostic TDM over Packet
- RFC 5086: Structure-Aware TDM Circuit Emulation
- RFC 4447: Pseudowire Setup and Maintenance Using LDP
- RFC 4385: Pseudowire Emulation Edge-to-Edge Control Word
- RFC 4928: Avoiding ECMP Treatment in MPLS Networks
- RFC 3985: Pseudowire Emulation Edge-to-Edge Architecture
- RFC 4023: Encapsulating MPLS in IP or GRE
- RFC 5085: Pseudowire Virtual Circuit Connectivity Verification
- RFC 6374: Packet Loss and Delay Measurement for MPLS
- Minimum Initial Specification, Localized Future Decision, and Voluntary Adoption
- On Reality Layers, Symbolic Power, and Why Clarity Feels So Hostile
- Running-Code Primacy
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
