Summary

  • RFC 9521 identifies a Geneve BFD session differently during bootstrap and steady state: VNI and inner addresses find a session before the peer discriminator exists; afterwards the discriminator alone is authoritative for demultiplexing.
  • An Up result proves the scoped control exchange. It does not prove that every tenant flow shares its path or treatment, that compressed sessions cover every VAP pair, or that the overlay service delivered an application outcome.

Imagine two network-virtualization edges with ten virtual access points apiece. One cyan BFD exchange is green. The same dashboard also shows a tenant application as available. Between those two colours lies the whole evidence problem.

The control exchange may have traversed one underlay ECMP member while the application flow hashed onto another. It may have used a different queue, security policy or service chain. It may cover one VAP on each edge while the failing tenant pair is represented by another. Nothing in that scenario makes the BFD result false. It makes the service conclusion too large.

The session has two identities over time

RFC 9521 is unusually useful because it specifies the admission and demultiplexing details instead of leaving “BFD over a tunnel” as a slogan. A session originates and terminates at a Virtual Access Point, or VAP, on a Network Virtualization Edge. The VAP's ordinary payload decides whether the probe carries inner Ethernet/IP/UDP/BFD or inner IP/UDP/BFD. Both endpoints must use the same VNI and the same payload form.

Before the remote endpoint has supplied a usable discriminator, Your Discriminator is zero. In the Ethernet case, the receiver should locate the session through the VNI and the inner source and destination MAC and IP addresses. In the IP case, the VNI and inner source and destination IP addresses do the work. The inner UDP source port may assist. If the receiver cannot identify the session, it must drop the packet and should raise a management exception.

Once Your Discriminator is non-zero, the rule changes: that discriminator alone must demultiplex the session. This is not merely a parsing detail. A diagnostic record that retains only the final discriminator loses the bootstrap tuple that established what the discriminator was supposed to represent. Conversely, a record that retains only VNI and VAP addresses may miss discriminator reuse after restart. A defensible history joins both identities through the transition packet and a configuration generation.

A VNI is scope, not authority

The packet also carries crisp validation fields. The Geneve O bit is one, the C bit is zero, and Protocol Type distinguishes Ethernet, IPv4 and IPv6 payloads. The receiver checks the destination VAP mapping, UDP destination and TTL or Hop Limit. A failed validation never reaches BFD processing.

Those checks protect protocol scope. They do not prove that the sender owns a tenant, is authorised to represent a customer or may trigger a production change. Geneve itself has no inherent security mechanism; RFC 9521 recommends BFD authentication. Authentication can strengthen a packet-origin claim under configured keys. It still does not grant the BFD process authority to drain traffic, declare an SLA breach or close an incident. Those are separate decisions with separate principals.

The scale shortcut changes the observation surface

The most revealing paragraph in RFC 9521 is not a header diagram. It is the overload warning. If each of two NVEs owns N Ethernet VAPs, the pair could create N squared BFD sessions. The RFC recommends a control on the maximum and says N sessions may be enough when all N VAPs are covered.

That is sensible engineering, but it creates a governance question: what did “covered” mean in the deployed mapping? One probe per VAP can show that every access point participates in some exchange. It cannot silently become evidence that every possible VAP pair, tenant flow or policy combination was exercised. Compression is a declared sampling policy. The inventory, pair-selection rule and uncovered combinations belong beside the green session count.

Rate is another part of scope. RFC 9521 requires BFD for Geneve to operate inside a Traffic-Managed Controlled Environment unless BFD is genuinely congestion controlled. The operator must provision probe rates to avoid congestion and false failure detection. A Down transition without the rate configuration, queue state and packet-loss context cannot by itself name the broken component.

Build the receipt chain before the automation chain

The minimum operational ledger has seven joins:

  1. A mapping receipt records the two NVEs, VAPs, VNI, payload form and configuration generation.
  2. A bootstrap receipt preserves the zero-discriminator lookup tuple and every validation result.
  3. A transition receipt binds that tuple to the non-zero local and remote discriminators, including restart boundaries.
  4. A probe-treatment receipt records the outer flow, available ECMP or LAG selection evidence, timers, authentication and rate policy.
  5. A coverage receipt lists all VAPs, intended pairings, active sessions, compression rule and gaps.
  6. A reaction receipt records who consumed the state change, what action was authorised, and whether the FIB or policy actually changed.
  7. A service receipt observes representative tenant traffic and the application result over a stated window.

RFC 9521 standardises the middle of that chain. It does not pretend to own the beginning or the end. That restraint is the design lesson. Running code creates valuable evidence when the claim remains as narrow as the mechanism that produced it.

Sources