Summary

  • RFC 9574 lets a low-performance EVPN leaf send one broadcast or multicast copy to an assisted replicator, avoiding repeated copies over the same first-hop links without requiring PIM in the core.
  • A Replicator-AR route advertises eligibility, not installed forwarding state. The RFC recommends a configurable activation timer, default three seconds, while ordinary ingress replication remains active.
  • Safe activation requires evidence that the leaf route reached the chosen replicator, selective membership and flooding lists were programmed, all participants use a compatible mode, and data-plane canaries reach the intended receivers without duplicates.

The route arrived before the machine was ready

At 09:00:00, a leaf receives a new Replicator-AR route. The BGP path is feasible. The assisted-replication address is known. A control-plane dashboard turns green.

RFC 9574 nevertheless recommends that the leaf wait. For three seconds by default, it should continue ordinary ingress replication. The reason is precise: the new or rebooted replicator needs time to receive the leaf's Regular-IR route and program the leaf before the leaf sends broadcast or multicast traffic through it.

That interval is the article's central fact. It is not a ceremonial hold-down. It is a protocol-level acknowledgement that route discovery and forwarding readiness are different events. The leaf knows whom it could select before it knows that the selected node has learned enough to replicate correctly.

Optimization moves replication; it does not remove state

Ordinary ingress replication keeps multicast state out of the underlay. Its cost is duplication: an ingress NVE may send several copies of the same frame across the same physical link. A PIM tree sends one copy through that portion of the fabric, but fabric routers then hold multicast state.

Assisted Replication offers a third placement. A low-performance AR-LEAF sends one broadcast or multicast copy to an AR-REPLICATOR. The replicator fans it out toward remote leaves, other replicators and local attachment circuits. The state and bandwidth burden have moved toward selected devices; they have not disappeared.

Unknown unicast stays on the known-unicast path under the AR procedures. Pruned flooding-list flags can separately suppress destinations that do not want BM or unknown-unicast traffic. That separation matters: a claim about assisted broadcast/multicast replication cannot be generalized to every kind of BUM traffic.

Two addresses are two instructions

The Replicator-AR route carries an AR-IP. Traffic sent to that address asks the receiver to apply assisted-replication behavior and potentially forward from one overlay tunnel to others. A Regular-IR route uses the IR-IP. Traffic arriving there follows ordinary ingress-replication behavior and is not fanned back into overlay tunnels.

The addresses are therefore data-plane instructions, not mere locators. In the single-IP variant, distinct VNIs carry the same distinction. Source address, destination address, VNI and selective-set membership decide whether the packet is replicated onward, delivered locally or prevented from returning to its origin.

A route inspector can confirm that the advertised values exist. It cannot confirm that the correct branch ran for a real packet. That requires forwarding-table readback and a data-plane observation.

The fallback path is part of the design

A non-selective leaf may know zero, one or several replicators and make its own local selection. Different leaves need not choose the same node. If every known replicator is down, former replicators cease advertising that role, or none was ever discovered, the leaf must return to regular ingress replication.

Selective mode is more constrained. Each leaf selects one replicator per broadcast domain and sends a Leaf A-D route targeted to it. The replicator builds a selective leaf set from those requests. If the active replicator fails, the leaf selects another, issues a new Leaf A-D update and is advised to use ordinary ingress replication during another activation interval.

This is not a failure of the optimization. It is the continuity mechanism that keeps eligibility changes from being mistaken for immediately complete state transfer. Operational readiness includes proof that the fallback is still programmed and within the weak leaf's performance envelope.

Three seconds is a default, not evidence

RFC 9574 says the activation timer should be configurable and should account for the time required for the leaf's Regular-IR route to reach the replicator and be programmed. The default is three seconds. The selective join-wait timer also defaults to three seconds, but serves a different purpose: it lets a leaf collect candidate Replicator-AR routes before sending its Leaf A-D choice.

Neither timer observes completion. One delays activation; the other delays selection signaling. A quiet timer expiry does not prove BGP propagation, route-target import, leaf-set update, forwarding-list installation or hardware programming. Three seconds can be conservative in one fabric and insufficient in another.

Leadership should therefore treat the defaults as safe starting coordinates. Measured propagation and programming distributions, including reboot and control-plane pressure, should determine the operating value. The acceptance receipt is an observed state transition, not the passage of wall time.

Selective and non-selective modes cannot be blended casually

Selective replicators advertise the L flag and build sets containing only leaves that requested their service. If any replicator advertises L=0, the other replicators must fall back to non-selective behavior. All leaves in one broadcast domain are expected to be configured consistently; selective and non-selective leaves should not coexist.

The consequence is concrete. A non-selective leaf can send traffic to a selective replicator, yet that replicator may omit other leaves that are not in its selective set. This is not solved by the packet being syntactically correct or the route being present. Mode consistency is part of reachability.

The RFC also distinguishes route withdrawal from finished convergence. Withdrawing a selective Replicator-AR route causes the corresponding Leaf A-D route to be withdrawn. That removes control-plane intent. It does not by itself prove that stale lists drained everywhere or that the fallback carried every packet during the transition.

Security language must remain bounded

RFC 9574 explains that concentrating BM traffic on a replicator creates exposure: an attack or performance failure at that node can affect delivery, incorrect forwarding logic can create loops, mode mismatch can create duplication, and careless pruning can suppress required traffic. It also describes source-address preservation needed for split-horizon behavior and the uRPF trade-off that follows.

These are design risks, not reports of a named exploit or outage. The standard does not establish that a particular vendor mishandles the timer, that a three-second window caused loss, or that a tenant experienced a loop. The defensible claim is that the protocol creates observable transition points and explicitly retains a fallback because capability advertisement alone is insufficient.

Sources

Sources