Summary
- RFC 5287 discourages the parallel PW Status TLV while a TDM interworking function is operational because data- and control-plane indications can contend. In-band control-word status is the ordinary witness; the TLV becomes the fallback when the IWF itself fails but PWE3 signalling survives.
- A durable incident record must preserve the reporter, its own health, raw status bits, direction, generation and action. Merging both channels into one
pseudowire_upfield removes the information needed to decide which observation was entitled to speak.
The green session outlived the reporter
Imagine a fault timeline with three facts. The LDP session is established. The label binding remains present. The TDM interworking function has stopped producing a trustworthy stream. A control-plane dashboard can remain green through all three. That colour is not necessarily wrong: the signalling process and its adjacency may indeed be alive. It is wrong only when promoted into a conclusion about the data-plane reporter or the emulated circuit.
RFC 5287 defines the setup extensions for TDM pseudowires. It uses the PWE3 LDP machinery of RFC 4447, now replaced by RFC 8077, to agree PW type, labels and interface parameters. TDM endpoints must agree on the type; all TDM encapsulations use a control word; payload size, bit-rate, AAL mode, RTP use, timestamp frequency, signalling behavior and other options are checked according to the selected service. A cleared control bit is an Illegal C-Bit, not a harmless default.
Those checks matter, but they establish compatibility for setup. They do not say that the attachment circuit is healthy now, that packets are arriving, that a jitter buffer is stable, that a clock has been recovered or that an application accepts the reconstructed service. RFC 5287's status rule becomes valuable precisely because it keeps setup and observation separate.
SAToP, CESoPSN and TDMoIP carry status in the TDM pseudowire control word. The fields describe attachment-circuit and packet-network conditions in band. PWE3 can also report related states through a PW Status TLV transported by the control protocol. At first glance, two reports appear better than one. The standard identifies the harder problem: two partly overlapping reporters with different paths, clocks and failure dependencies can create contention rather than confirmation.
Authority follows the failure boundary
RFC 5287's ordinary rule is narrow. As long as the TDM pseudowire interworking function is operational, use of the PW Status TLV is not recommended. The stated reason is to avoid contention between status indications reported by the data and control planes. The document does not say that a control plane is universally inferior. It says the in-band reporter is the relevant witness while the function that creates and interprets that stream remains able to report.
The exception reveals the architecture. If the TDM IWF itself fails while the PWE3 control plane remains operational, the signalling PE should send a PW Status TLV with all five listed fault bits set: pseudowire not forwarding; local attachment-circuit ingress receive fault; local attachment-circuit egress transmit fault; local PSN-facing ingress receive fault; and local PSN-facing egress transmit fault.
That is a fallback, not a claim that every component independently developed five simultaneous defects. The ordinary reporter has lost authority because its own function failed. The surviving control plane communicates a conservative failure envelope. An automation system that counts each bit as a separately observed physical fault would manufacture evidence the RFC did not provide.
The reverse error is just as serious. If the IWF works and the in-band control word reports a fault, a stale or slower TLV must not silently override it merely because the management system finds LDP easier to ingest. Reporter convenience is not reporter authority. A normalized state needs the dependency that justifies the choice.
reporter -> reporter health -> raw indication -> reconciliation rule -> action -> observed result
Every arrow needs a record. Without the reporter-health step, reconciliation becomes a fixed preference rather than a conditional decision. Without the raw indication, no one can later determine whether an alarm was suppressed, delayed, broadened or overwritten.
“Not recommended” leaves an operator obligation
RFC 5287 uses NOT RECOMMENDED, not MUST NOT. An implementation can expose both paths. That flexibility does not make the conflict disappear; it transfers responsibility to the operator and the consuming software. The system must define what happens when the control word and TLV differ, how long each value remains current, how an IWF failure is detected, and whether clearing a fault requires evidence from the same reporter that raised it.
Time is part of the meaning. A TLV received before a label change may refer to an older PW generation. An in-band indication may stop because the packet stream stopped, not because the condition cleared. Silence from a failed reporter is not green. A recovered LDP adjacency can replay a current control-plane state while the jitter buffer is still acquiring. A data stream can resume before the CE application signalling pair is restored. One timestamp attached to a merged status cannot represent all of those transitions.
Keep source time where available, receive time, FEC and label generation, PW identity, local and remote PE, direction, raw bits and reporter health. Record whether the value was superseded, suppressed or used to trigger teardown. A dashboard may still show one operational state, but the projection must remain reversible into the observations that produced it.
The paired pseudowire is another proof against green leftovers
RFC 5287 also defines a paired construction for basic CESoPSN NxDS0 service with CE application signalling on a separate pseudowire. The data PW and signalling PW must use the same service type, setup method and matching interface parameters, except for complementary role bits. With the PWId FEC, the data member uses an even identifier and the signalling member the next odd identifier. With the generalized FEC, correct association is implementation-specific.
The operational rule is stronger than “warn if incomplete”. If one member establishes and the other does not, or if either fails later, the established member must be torn down. The remaining transport object is not a degraded but valid composite service. Its continued presence would be a misleading fragment.
This rule has a direct monitoring consequence. Inventory must model the pair, not infer service health from either member. A clean data packet stream without CE signalling can be wrong for the promised service. A signalling member without data cannot deliver the bearer channel. The teardown command is an action receipt, not proof that both members disappeared everywhere or that the customer circuit recovered after a later retry.
The paired rule is not the thesis of the earlier multi-segment pseudowire Article. Here it illustrates the same evidence discipline as reporter selection: a visible control object can survive beyond the validity of the function it is being used to represent. RFC 5287 refuses that ambiguity by defining the association and teardown behavior.
Liveness is not status, and status is not outcome
The evidence chain should remain explicit:
configured -> label negotiated -> parameters compatible -> pair complete -> reporter healthy -> status observed -> action executed -> packets forwarded -> timing recovered -> circuit outcome observed
An LDP session proves a signalling relationship, not current attachment health. A label mapping proves a binding, not packet delivery. Compatible parameters prove the endpoints agreed on the checked representation, not that physical circuits actually match every external assumption. A healthy in-band status reporter can report a fault; reporter health is not service health. A PW Status fallback can communicate IWF loss; it does not prove the remote PE received or acted on the notification.
VCCV and BFD add connectivity evidence. OAM mapping can carry defects between technologies. Preferential-forwarding status can influence path choice. None of these automatically replaces TDM control-word semantics or an independent circuit result. They answer different questions and can fail independently.
Nor does a clear status prove timing quality. Packet delivery can coexist with excessive delay variation, a buffer problem or poor clock recovery. This article does not repeat the retained RFC 5143 thesis about header correctness versus circuit continuity. Its earlier question is who supplied the state on which an operator or automated system acted.
Preserve contradiction as evidence
When two channels disagree, the cheapest database model keeps one Boolean and an updated_at. The latest writer wins. That design erases the incident.
A useful ledger keeps both observations and the reconciliation. For each report, retain the object generation, raw value, semantic version, reporter, path, direction, local source time, receive time and reporter-health assessment. For the decision, retain the precedence rule, reason, expiry, owner and action. For the result, retain readback from the affected forwarding object plus packet, timing and CE observations appropriate to the claim.
Contradiction is not data dirt to be cleaned. It can reveal a dead IWF, a stale control update, a mismatched PW generation, a broken association or a management adapter that mapped distinct bits into one label. Deleting one side because it is inconvenient makes the dashboard calmer and the infrastructure less knowable.
No source in this package shows a named operator suffering this failure or quantifies its frequency. The issue is a standards-defined possibility. A responsible Article can explain the mechanism and the evidence needed to detect it without inventing an outage.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
