Summary

  • In RFC 5251 shuffling mode, an ingress PE replaces customer port identifiers in the RSVP Session and Sender Template with provider identifiers; the egress PE reverses that translation.
  • A CE can therefore observe one continuous session without proving which PIT version, internal port mapping, provider path, cross-connect or data-plane outcome supported it.

One session, more than one namespace

A customer edge asks to connect one customer port to another. It names both ends in its own addressing realm. The request reaches the provider edge, crosses a network whose internal identifiers the customer need not see, and emerges at the far edge carrying customer identifiers again. To the two CEs, the result can look like one point-to-point LSP.

RFC 5251 calls the mechanism “shuffling.” At the ingress PE, the Session and Sender Template objects are rewritten from CPIs—Customer Port Identifiers—to PPIs—Provider Port Identifiers. At the egress PE, the PPIs are mapped back to CPIs. The protocol preserves the customer's session abstraction by changing the names underneath it twice.

This is not sleight of hand. It is how two addressing realms remain independent. The mistake is to treat the unchanged customer view as proof that nothing material changed inside it. The session can remain logically whole while every audit question about endpoint mapping, provider resources and observed continuity remains open.

CPI, VPN-PPI and PPI do different jobs

RFC 5251 does not define one universal port name. A CPI identifies the customer side. A PPI identifies the provider side. A VPN-PPI gives the PE port an identifier in the L1VPN customer's addressing realm. The provider controls PPI assignment; L1VPN administrators control addresses used for CPIs and VPN-PPIs.

An unnumbered PPI and VPN-PPI may use the same port index as a convenience. That numeric equality does not merge their authority. They are interpreted in different realms. A logging system that stores only “port 17” without recording whether it meant CPI, VPN-PPI or PPI discards the context needed to reconstruct the translation.

The same discipline applies to control channels. CE and PE control-channel addresses must be unique within an L1VPN, but they need not be unique across different L1VPNs. The channel therefore needs an unambiguous association with its VPN. An address alone cannot be promoted into a globally unique identity.

RFC 5251 makes that separation useful. Provider operation can remain independent of customer addressing, and provider addresses can remain hidden. But independence creates a translation boundary. Every translation needs the table, version and VPN context that made it valid at that moment.

The PIT is the hinge

Each provider edge maintains a VPN-specific Port Information Table. It contains CPI-to-PPI tuples and, for local ports, VPN-PPI information. Provisioning can populate it; discovery can contribute local or remote information. RFC 5195 and RFC 5252 define BGP- and OSPF-based discovery choices.

Those discovery mechanisms matter as provenance, but they are not the central event in shuffling. Once a request arrives, the ingress PE selects a PIT for the L1VPN and resolves the target CPI to a PPI. It then replaces the customer values in the signaling objects. At the far side, another PIT lookup performs the reverse translation.

The session receipt does not contain a proof that both lookups used the intended generation of state. If a row was stale, misprovisioned or associated with the wrong operational context, syntactically correct rewriting could still enact the wrong mapping. RFC 5251's security section therefore keeps management and configuration protection important and recommends considering data-plane verification against accidental misconfiguration.

That recommendation is not an admission that the protocol lacks value. It identifies the correct evidence boundary. Signaling proves a signaling transition. A CE-to-CE data-plane test observes whether the resulting connection reaches the expected far end.

Shuffling preserves an abstraction, not a trace

After ingress replacement, signaling inside the provider network carries PPIs, not CPIs. At egress, the reverse mapping restores customer-facing names. The RFC says shuffling must apply to all RSVP-TE messages at the PE edges when this option is used. A partial implementation would create inconsistent session state.

The customer sees a single LSP with a virtual link between the PEs. The provider sees the PE-to-PE segment in detail. The PEs may filter provider topology from the information sent back to the CEs. Under the overlay rules, Notification and Record Route objects can be removed or edited at the edge.

Topology hiding is a legitimate service boundary. Customers are not automatically entitled to the provider's internal map. Yet an audit cannot infer the hidden map from the clean customer abstraction. “One session” does not mean one internal RSVP session, one physical hop, one optical channel or one immutable path.

RFC 5251 also permits stitched or nested operation instead of shuffling. A compatible PE-to-PE session can be established or an existing LSP or forwarding adjacency associated with the customer request. RFC 5150 and RFC 4206 govern those constructions. They may produce a similar customer-facing service while generating different internal receipts.

For operations, the mode is therefore material evidence. A trouble ticket that records only the CE session identifier cannot tell whether the provider shuffled one session, stitched segments or nested the service in a hierarchy.

Acceptance is not cross-connect proof

The CE originates a request with its local CPI and a target CPI. The ingress PE finds the corresponding provider endpoint. The request ultimately reaches the target CE still carrying the originator's CPI, and the LSP is established if the target accepts.

That sequence contains several bounded decisions. The origin CE selected a target from those it knew. Provider policy constrained which port-to-port topologies were allowed. The PE mapped the names. The target CE accepted the request. None of those acts, alone, observes that the intended physical cross-connect was programmed or that traffic traversed it.

A Path or Resv receipt belongs to the control plane. Resource reservation, label or wavelength programming, protection state, physical continuity and carried customer traffic are later layers. Even a data-plane continuity test proves only what it actually sends and receives; SLA performance and application outcome need their own observations.

The distinction becomes especially important when a customer supplies an Explicit Route Object. The ingress PE may reject it. Without an ERO, the PE calculates the provider path; with the permitted loose form, the PE still computes and inserts the internal path. The customer request constrains the service without becoming authoritative over every provider hop.

Preserve both sides of the translation

An evidence record should begin with the L1VPN context, control channel and original source and target CPIs. It should then preserve the exact PIT version, row provenance, resolved PPIs and ingress rewrite. At the far edge, it should record the reverse PIT lookup, restored CPIs and target acceptance. RSVP state, resource programming, data-plane verification and observed service belong on later rungs.

No normalized “session up” field can replace that chain. If the mapping history is discarded, the same visible CE session may be impossible to explain after provisioning changes. If internal topology is intentionally hidden from the customer, the provider still needs protected internal evidence capable of correlating the hidden segment with the customer abstraction.

Lu Heng's reality-layer discipline applies directly. A name in one realm is not the same fact as a name in another. A successful translation is not the same fact as a correct physical connection. A continuous customer abstraction is not the same fact as a continuous service. Running systems remain accountable when each boundary records exactly what it transformed and what it actually observed.

Sources