Summary

  • RFC 5286 does not turn an enabled feature into a universal backup. A neighbour qualifies as a loop-free alternate only for the destinations and failure assumptions whose strict distance tests it passes.
  • A credible protection record preserves the topology epoch, inequality operands, prefix origin, protection class, selection and installed state. “LFA enabled” is configuration evidence, not a coverage result.

Twenty is not less than twenty

Take an abstract router S, a destination D, and a candidate neighbour N. Suppose the frozen shortest-path calculation yields:

  • Distance_opt(N,D) = 20
  • Distance_opt(N,S) = 7
  • Distance_opt(S,D) = 13

RFC 5286's base loop-free condition asks whether:

Distance_opt(N,D) < Distance_opt(N,S) + Distance_opt(S,D)

Here the comparison is 20 < 20. It fails. The equality may look harmless on a slide, but the standard does not use “less than or equal”. With the information available to S, the candidate cannot be certified not to send traffic back towards S. The correct result is no LFA for that candidate and destination.

Now change one metric so the left-hand side becomes 19. The candidate passes under that new topology. Nothing about the physical identity of the neighbour changed. The proof changed because its operands changed. An LFA is therefore not an enduring label attached to a port or router. It is a derived result bound to a destination, metric graph, route calculation and anticipated failure.

Those numbers are a worked example, not a measurement from a named network. Their purpose is to expose the evidence boundary. A dashboard can truthfully display a green global setting and an empty candidate row at the same time. The setting says the software is allowed to compute and use alternates. The empty row says this graph did not supply one here.

The alternate is computed per destination

RFC 5286 uses precomputed alternate next hops to reduce packet loss while the distributed routing system converges. When the primary next hop fails, the calculating router can temporarily forward to a safe alternate until a new shortest-path calculation is installed. Computing the alternate does not replace or modify the ordinary primary SPF result.

The qualification is local and destination-specific. The same neighbour can pass for one prefix and fail for another. A topology change can change the answer. A multi-homed prefix can require attention to its several originators and advertised costs. An OSPF external route can add route-type and ASBR-selection rules. RFC 8518 updated the multi-homed-prefix treatment precisely because a single simplified view can lose valid alternatives or classify them badly.

That is why a useful coverage report needs a denominator. “Ninety-eight per cent protected” means little until it says whether it counts links, nodes, prefixes, primary next hops, destination classes or traffic volume. It also needs the failure model. Link protection is not node protection. Avoiding one local shared-risk group is not avoiding every correlated risk. A percentage produced before a metric or originator change is not necessarily current.

RFC 6571 examined how real service-provider topology shapes ordinary LFA applicability. RFC 7490 later added remote LFA because some topologies, notably rings, often do not offer a suitable physical neighbour. The existence of those later methods is evidence of the limit, not permission to report ordinary LFA coverage that was never computed.

Loop-free, downstream and node-protecting are different statements

The base inequality establishes loop freedom for the link-failure case it models. RFC 5286 also defines a stricter downstream condition:

Distance_opt(N,D) < Distance_opt(S,D)

A downstream path keeps every step closer to the destination according to the pre-failure topology. That can prevent a class of temporary loops when reality is worse than the failure assumed during calculation. It also reduces the set of qualifying alternates. Safety and coverage move in opposite directions here: a stricter candidate policy can avoid a loop by leaving traffic with no repair path.

Node protection adds another claim. A candidate may be loop-free with respect to S while its shortest route still passes through the primary neighbour E. In the equality case discussed by RFC 5286, N may have equal-cost paths, only some of which avoid E; S cannot force N to choose the safe one. The standard therefore does not allow an optimistic node-protection label merely because one safe equal-cost possibility exists.

Broadcast and NBMA links complicate the claim further. The pseudonode used by the link-state model matters, and a node-protecting alternate is not automatically link-protecting when S can reach that alternate over the same broadcast segment. Local shared-risk groups introduce another set of exclusions. A row saying only “candidate N passed” throws away the very classification an operator needs during failure.

The failure assumption must travel with the result. If a link-protecting alternate is activated for a node failure, or if two resources fail together when only one was modeled, packets can encounter a loop or be discarded. RFC 5286 does not promise that a proof for one failure set survives a larger one.

A feature flag is the first receipt, not the last

The evidence chain is longer than a configuration readback:

configured -> computed eligible -> selected -> installed -> activated -> forwarded -> converged -> observed outcome

Each arrow can break independently.

“Configured” says the calculation is permitted. “Computed eligible” should show the topology version, destination, candidate and successful inequalities. “Selected” records policy among candidates. “Installed” proves the backup next hop reached the forwarding plane. “Activated” binds a detector event to a state transition. “Forwarded” needs counters or a trace on the repair path. “Converged” shows the exceptional state was replaced by current routing. Any claim about reachability, a session or a service then needs evidence from that layer.

This article does not recommission the separate TI-LFA question of whether local repair proves service recovery. Its narrower point comes earlier. Before anyone can debate the outcome of a repair, the organisation must know whether an ordinary RFC 5286 alternate existed for the affected destination and failure at all.

Preserve the calculation, not just the verdict

A durable LFA record should include the calculating router, routing area or level, topology-database revision, calculation time, destination prefix, route type, originators, primary next hop and protected resource. For every candidate, retain the three base operands, the Boolean result, further downstream or node-protection tests, broadcast-pseudonode checks, relevant local-SRLG exclusions and the rejection reason.

Also record computation granularity. RFC 7916 distinguishes per-prefix from coarser operational approaches and places simulation, activation policy, troubleshooting and coverage monitoring in the management contract. A per-next-hop summary can conceal a prefix whose origin or route type changes the answer. A per-prefix result costs more state and computation, but it makes the exception visible.

The topology digest is not decorative. Without it, an auditor can recompute the formula against today's graph and obtain a different answer without knowing whether the original implementation was wrong or the network simply changed. A mathematical verdict whose operands and epoch were discarded is no longer reproducible evidence.

What the standard does not prove

RFC 5286 does not show that a named operator enabled LFA, that a product implemented it correctly, or that a real network achieved a particular coverage or convergence time. A failed inequality is not a defect; it can be the correct answer for the graph. A passed inequality does not prove selection or installation. An installed backup does not prove activation. A failure detector such as BFD can show a local detection event without proving any of those later states.

Nor do later remote-LFA, TI-LFA, Segment Routing or RSVP-TE mechanisms silently fill the gap. They have their own prerequisites and evidence. The honest status for an ordinary LFA candidate that fails the test is “no eligible alternate under this topology and policy”, not “protected by fast reroute” and not “the network will probably find another way”.