Summary

  • RFC 9656 augments the traffic-engineering topology model with microwave carriers, aggregate radio links, rlt-mode, nominal bandwidth, configured frequencies and selected operational observations.
  • The model can describe which higher-layer link depends on which microwave radio link, but a valid snapshot does not prove current transmission, protection switching, interference control, usable throughput or service delivery.
  • A defensible operating receipt joins the model revision and authority to constituent-carrier configuration, observed RF state, aggregation behavior, dependency realization and a separately measured service outcome.

The route that was right on paper

Imagine a controller that sees 800 megabits of nominal microwave bandwidth and chooses that link for a service. The topology is internally consistent. The supporting-link reference is correct. The configured channel is present. Yet rain, interference or a changed modulation state has reduced usable capacity by the time traffic arrives.

The error is not necessarily in the model. The error is the sentence made from it. “The model exposes 800 megabits” describes a named field under a named revision. “The service has 800 megabits now” is a measurement claim about a running system.

RFC 9656 gives those statements a better chance of staying separate. Its ietf-microwave-topology module augments the technology-independent traffic-engineering topology of RFC 8795, which builds on the network model in RFC 8345. The result is a shared representation of microwave infrastructure without pretending that every consumer has become a radio.

Carrier, radio link and service are different objects

A carrier is one over-the-air link, normally identified by transmit and receive frequencies. A radio link combines one or more carriers for bonding or protection and carries higher-layer traffic. The higher-layer link can then point back through a supporting-link dependency to the microwave radio link beneath it.

That hierarchy prevents two common compressions. First, the status of one carrier is not automatically the status of the aggregate. Second, the existence of the aggregate is not automatically the performance of the service that depends on it.

Microwave point-to-point radio links operate at Layers 0 and 1. RFC 9656 does not model switching across a chain of microwave radio links. Higher-layer switching occurs after termination. A controller that draws one long logical path from several dependencies is performing an additional inference. Its graph may be useful and correct, but it needs the constituent identities and time windows that make the inference auditable.

Configuration and observation do not share authority

The model makes the difference visible in its leaves. tx-frequency and channel-separation are writable carrier configuration. actual-rx-frequency, actual-tx-cm, actual-snir and actual-transmitted-level are read-only operational observations. mw-bandwidth is read-only nominal bandwidth.

These fields answer different questions. A configured transmit frequency records intended behavior. An actual receive frequency records what the device reports observing. Actual SNIR describes a radio condition at some time. Nominal bandwidth describes a design characteristic, not a throughput test. A complete audit keeps the writer, reader, device, revision and timestamp attached to each statement.

The earlier microwave model in RFC 8561 supplies the types and interface foundation. RFC 9656 adds the topology relationship needed by controllers. Neither document causes the air interface to obey the database. Running state still has to answer.

rlt-mode names composition, not successful protection

The rlt-mode structure records how many carriers are bonded and how many are protecting. It is tempting to translate “one protecting carrier” into “the service is protected.” That crosses several missing receipts.

Administrative and operational status apply to the microwave carriers, not to the aggregate radio link. The radio link is enabled and disabled through its constituents. A declared protection count therefore identifies intended composition. It does not show that the standby carrier was usable, that a trigger occurred, that traffic switched, that the switchover stayed inside its objective or that the higher-layer service survived.

The evidence chain needs the carrier set and configuration epoch, each carrier's operational state, the protection decision, the transition timestamps, traffic counters and the service-level observation. Without that chain, “protected” is a topology adjective rather than an incident conclusion.

The controller boundary is also a freshness boundary

RFC 9656 anticipates exchange between a physical network controller and a multi-domain service coordinator in the architecture described by RFC 8453. The PNC may know the radio details; the MDSC may use abstracted bandwidth and dependencies to compute a service path.

Abstraction is necessary. It is not timeless. The receiving controller should retain the producing authority, model revision, collection time, validity interval and update result. Otherwise, an old but syntactically valid graph can outrank fresher carrier evidence. A successful API read proves delivery of a representation, not simultaneity with the air interface.

Heng Lu's reality-layers discipline is practical here: schema, configured state, device observation, controller inference and service outcome must not borrow one another's authority. Minimum Initial Specification explains why a shared minimum model can coordinate independent systems without pretending to centralize every decision. Running-code primacy demands the observed result after the shared vocabulary has done its work.

Security is control over physical consequences

The RFC's security considerations are not generic management boilerplate. Unauthorized changes to rlt-mode, tx-frequency or channel-separation can change radio behavior, create invalid configuration or stop operation. NETCONF, RESTCONF and NACM provide transport and access-control mechanisms. They do not decide whether a particular change was justified.

A durable change receipt records the actor, authorization policy, request bytes, prior model revision, accepted configuration, device result, resulting operational leaves and service impact. The IANA YANG Module Names registry establishes the module's public identity. It cannot certify that any operator deployed it safely or that a particular radio link is carrying traffic.

The receipt the model makes possible

Start with the topology identity: network, node, termination point, carrier and radio-link identifiers. Add the module revision and controller epoch. Record the writable intent for frequency, separation and composition. Then capture the device's actual frequencies, coding/modulation, SNIR, transmitted level and per-carrier operational status with timestamps.

For an aggregate, preserve which carriers participated, whether they were bonded or protecting, and the observed transition state. For a dependent higher-layer link, preserve the exact supporting-link identity and its validity interval. Finally, measure usable throughput, loss, latency and application outcome on traffic whose time and path can be correlated with the radio evidence.

RFC 9656 supplies the grammar that lets these records meet. The strongest conclusion is not “the topology is the network.” It is “this representation, under this authority and epoch, can be compared with these running observations and this service result.”

Sources