Summary
- RFC 5240 puts observed election state and writable Candidate-BSR/Candidate-RP configuration in one MIB. A reader may learn topology; a writer may alter control-plane inputs.
- A local elected flag, timer or notification is a receipt from one device and zone. It does not prove domain-wide convergence, RP use or healthy multicast delivery.
One schema, two kinds of power
The PIM Bootstrap Router mechanism distributes the information routers need to map multicast groups to rendezvous points. RFC 5240 makes parts of that mechanism manageable through SNMP. Its four tables look orderly: Candidate-RP configuration, the elected BSR's RP set, Candidate-BSR configuration and learned elected-BSR state.
The apparent symmetry is operationally dangerous. Some columns are observations. Others are read-create. The same management endpoint can answer “who won?” and accept a change to who is likely to win next.
That distinction belongs in every audit record. A GET is evidence of what one agent returned at one time. A SET is an attempt to change configuration. A successful SET response is not yet evidence that an election changed, that Bootstrap messages propagated or that receivers installed the intended mapping. When a dashboard flattens those stages, a control action can masquerade as measurement.
Candidate is not elected; elected is not converged
RFC 5240 separates the local Candidate-BSR table from the elected-BSR table. The candidate row holds the address, election priority and RP hash-mask length the router will advertise for a zone. A read-only Boolean reports whether that local candidate is currently elected. A bootstrap timer reports when the local router will next originate a Bootstrap message—and is explicitly zero when the router is not elected.
Zero therefore does not, by itself, mean that a scheduler stalled. TRUE does not establish that every router in the domain has selected the same BSR. It states the local agent's condition.
The learned elected-BSR row adds address, priority, hash-mask length and minimum expiry time. That is stronger evidence about the router's present belief, but still not a domain-wide verdict. Proving convergence requires observations from independent routers or packets from the distribution path. Proving service requires a further step: the RP mapping must influence joins and actual multicast traffic.
The writable path can redirect authority
RFC 5240's security section is unusually direct. Creating a Candidate-BSR with a high priority, or raising the priority of an existing one, can take over the elected function and disrupt service. Candidate-RP priority has the opposite numeric sense: a lower value is better. A created or modified Candidate-RP can cause routers to select it for a group prefix.
These are not generic warnings about “management risk.” They identify the blast radius of specific columns. An automation identity allowed to write them can change election and mapping inputs. A compromised identity can do the same. The correct permission boundary is therefore not “has SNMP access.” It is whether a principal may read topology, receive notifications, create rows, change addresses, change priorities, change hash parameters or delete configuration.
SNMPv3 authentication and privacy matter because the values are sensitive in both directions. Read access can reveal elected and candidate routers. Write access can redirect control. Encrypting the transport without constraining principals still leaves the agency problem intact.
The RP-set table is a staging area, not proof of forwarding
On the elected BSR, the RP-set table contains group-to-RP mappings learned from Candidate-RP advertisements or created locally. The elected BSR applies local policy and may include some or all of them in Bootstrap messages.
That “some or all” is the missing edge in many dashboards. A row can exist without being selected for dissemination. A Bootstrap message can contain a mapping without every router receiving it. A router can learn the mapping without using the expected RP for a particular group. And an installed mapping does not prove traffic arrived.
The evidence chain should retain the table row, policy version, emitted message, receiver observation, installed mapping and data-plane result separately. Each link answers a different question. No link should borrow certainty from the one before it.
Notifications report transitions, not consensus
The optional diagnostics group defines notifications for a Candidate-BSR winning and an elected BSR losing. They are useful because they timestamp a local state transition. They are insufficient because notification support is optional, delivery may fail, access control may filter recipients and only the relevant elected device should emit them.
Silence is ambiguous. It may mean no change, no implementation, no subscription, no permission or a lost notification. A trap is also not a quorum. It proves that one agent emitted a report with particular objects. The claim “the domain changed leader” still needs independent state or packet evidence.
Indexes are part of the fact
The tables are keyed by address type, address, prefix length and zone. RFC 5240 warns that group-prefix bits beyond the declared prefix length must be zero because otherwise they identify a different row. Zone indexes join to the IP Multicast MIB. IPv4, IPv6 and scoped forms cannot be collapsed without losing meaning.
Evidence pipelines often retain the value but discard the index. That converts precise local records into ambiguous global claims. Preserve device identity, zone, address family, normalized prefix, collection time and object semantics. Without them, even an exact value cannot be attributed correctly.
RFC 5240 does not report an exploit, outage or vendor behavior. It supplies the schema and states its security consequences. Lu Heng's running-code test supplies the discipline: call something true only when attributable observations support it. The table is evidence when read with scope. It becomes authority when a principal can mutate it. Governance begins by refusing to confuse the two.
Sources
- RFC 5240, plain text, information record and Datatracker
- RFC 5059, information record and Datatracker
- RFC 4601, information record, RFC 5060, information record, RFC 5132 and information record
- RFC 3410, RFC 3414, RFC 3415, RFC 2578, RFC 2579, RFC 2580 and RFC 4001
- Lu Heng: Reality, Not Advocacy, Running-Code Primacy and The Agency Problem
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
