Summary

  • RFC 5305 distributes link attributes for traffic engineering, but its maximum reservable and unreserved bandwidth values may exceed physical bandwidth for oversubscription, while unreserved capacity is represented separately for eight setup priorities.
  • A usable proof chain must distinguish advertisement origin and age, decoder support, topology acceptance, constraint calculation, admission, committed reservation, installed forwarding state, packet observation and service outcome.

A database of offers, not a warehouse receipt

RFC 5305 extended IS-IS so that a router could describe more than a neighbor and a narrow metric. TLV 22 carries an extended reachability record: neighbor identity, a wider default metric and sub-TLVs for properties such as administrative group, interface and neighbor address, maximum bandwidth, maximum reservable bandwidth, unreserved bandwidth and a separate traffic-engineering metric. TLV 134 provides a stable traffic-engineering router ID. TLV 135 expands IPv4 reachability and carries the up/down control needed when prefixes move through the IS-IS hierarchy.

The result resembles a resource catalogue. That resemblance is useful and dangerous. The fields tell a path-computation process what the originating router is advertising. They do not, by themselves, show that a head end admitted a request, that a reservation protocol committed capacity, that a label-switched path was installed, that the data plane followed it, or that an application received a service.

This is not a criticism of the RFC. The standard defines a shared representation. A representation must be legible before any later system can make a decision. The mistake begins when an organization promotes that representation into evidence of the later decision.

“Maximum” can be larger than the link

Sub-TLV 9 describes maximum link bandwidth in the advertised direction. Its 32-bit IEEE floating-point value is expressed in bytes—not bits—per second. It is a directional encoded attribute, not a measurement trace.

Sub-TLV 10 describes maximum reservable link bandwidth. RFC 5305 says explicitly that, for oversubscription, this value can be greater than the bandwidth of the link. Sub-TLV 11 does the same for unreserved bandwidth. The word maximum therefore cannot be read as a physical promise. It names the upper bound used by a reservation policy, and that policy may intentionally sell or admit more logical capacity than the medium can simultaneously deliver.

Unreserved bandwidth is not one number. The sub-TLV holds eight numbers, corresponding to setup priorities 0 through 7. Preemption and reservation policy make the answer dependent on who is asking and at what priority. A dashboard that collapses those eight values into a single green gauge destroys the decision context. A value available to one setup priority need not be available to another, and an admitted lower-priority path may later yield to a higher-priority request.

The RFC further advises that rapid changes in unreserved values should not cause rapid LSP generation. This protects control-plane stability. It also means that the distributed view may lag local changes by design. A correctly encoded, correctly flooded value can be both authentic and no longer decisive by the time two head ends compete for it.

Color and metric are instructions, not observations

Administrative Group sub-TLV 3 is a 32-bit mask assigned by the network administrator. Its bits are often called colors or resource classes. The field does not discover a physical property. It publishes a classification chosen by an authority. A constraint such as “avoid this color” works only if the assignment, its meaning and the path-computation policy agree.

The TE default metric is also administratively assigned. It can present a differently weighted topology to a TE SPF calculation. When it is absent, the calculation falls back to the normal default metric from the extended reachability record. Two calculations can therefore operate on the same adjacency while optimizing different declared costs.

RFC 5305 also reserves a special meaning for the maximum 24-bit link metric: the link must not be considered during normal SPF, even though it may remain advertised for another purpose such as traffic engineering. Database presence is not calculation eligibility. The same visible link can belong to one analytical surface and be excluded from another.

Those distinctions matter during incident review. A path that differs from an operator's expectation may reflect a color assignment, a TE metric, a fallback to the normal metric, a maximum-metric exclusion or a stale attribute. “The link was in IS-IS” is not enough to identify which choice the path engine was authorized to make.

An address in a sub-TLV is not a route

RFC 5305 requires TE-capable implementations to include the interface-address sub-TLV, and on point-to-point adjacencies the neighbor-address sub-TLV. Yet it also commands implementations not to inject /32 routes for those addresses into routing or forwarding tables. Mixed support could otherwise create loops.

The TE router ID receives the same warning. It is a stable reference for a router and can help correlate OSPF and IS-IS topology, but its presence must not manufacture a /32 forwarding entry.

These prohibitions expose the architecture cleanly. A protocol can carry a name so that a controller can refer to an interface, neighbor or router without asserting that the name is currently reachable through the data plane. Reference, topology, routing and forwarding are different records.

Sub-TLV extensibility adds another boundary. An unknown sub-TLV is ignored and skipped. A receiver may accept the containing TLV while understanding only part of its attribute vocabulary. Packet acceptance, parser support and use in the calculation must therefore be tested separately.

Flooding solves distribution, not simultaneity

Link-state flooding gives participating routers a method to distribute state. It does not make every copy simultaneous. Origination time, LSP propagation, throttling, database installation, path calculation and reservation attempts occur on different clocks.

Consider two head ends that see the same unreserved value and both decide that a request fits. RFC 5305 supplies the advertised input. It does not serialize their decisions or commit the resource. A separate admission and reservation mechanism must resolve the race. After that decision, the updated available value may take time to enter and cross the flooding domain.

Authentication does not close this gap. RFC 5305 points to the general IS-IS security considerations associated with RFC 5304. A receiver may establish that an LSP was accepted under an authentication policy. That is valuable provenance evidence. It does not prove that the originator's administrative value matches physical capacity, that the value is fresh enough for this request, or that any later admission succeeded.

RFC 5303's three-way handshake similarly strengthens evidence about a point-to-point adjacency. It does not certify every attribute that will later be flooded through the adjacency. A live, reciprocal control-plane relationship can carry an old, misunderstood or policy-relative resource statement.

What RFC 5305 does—and does not—establish

RFC 5305 was published in 2008 as a Standards Track successor to the Informational RFC 3784. It defines encodings and rules. It expressly leaves migration mechanisms and procedures out of scope. Its security section says the document raises no new IS-IS security issues and refers readers to the protocol's general protection.

Later RFCs expanded the family: GMPLS attributes, inter-AS TE, performance metrics and application-specific link attributes. They help show how durable the extensible representation became. They do not turn an attribute registry into an operational audit trail.

This article does not claim that a particular network oversubscribes, advertises stale values, misuses colors, loses reservations or routes traffic contrary to policy. Proving any of those propositions would require implementation and configuration evidence, timestamped LSPs, topology-database snapshots, admission logs, reservation state, forwarding entries, packet observations and service measurements.

The narrower conclusion is firm. A TE advertisement is a signed or unsigned statement in a distributed control plane. It may be precise, policy-authorized and useful. It is still upstream of commitment.

Sources