Summary
- RFC 9666 protects Level 2 scale by representing an Inside Area with one Proxy LSP, while making that hidden area responsible for the connectivity the abstraction advertises.
- Defensible operation must join per-router readiness, leader election, projection inputs, boundary filtering, outside and inside SPF, installed forwarding and end-to-end probes; no one stage inherits proof from another.
The outside network still had a route. Its link-state database showed one tidy proxy system connected to two edge routers. Nothing in that view exposed the failed spine inside the data center or the fact that the remaining internal path had not converged. The abstraction was coherent. The transit promise was not being kept.
That possibility is not an argument against RFC 9666. It is the cost the specification deliberately accepts to recover hierarchy. Conventional two-level IS-IS can summarize a Level 1 area when that area hangs from Level 2. A leaf-spine fabric is harder. If several leaves face Level 2 and traffic between those leaves crosses spines, ordinary shortest-path computation needs the transit topology. Copying the whole fabric into Level 2 can more than double the link-state database and erase the scaling benefit of the hierarchy.
Area Proxy offers a narrow alternative. The Inside Area continues to know its real topology. The Outside Area sees a synthetic system and a Proxy LSP. Outside Edge Routers form adjacencies to the Proxy System ID rather than to the physical identities of the Inside Edge Routers. Only the derived Proxy LSP escapes the boundary. The hidden area then owes the forwarding connectivity represented by that public object.
Readiness is unanimous before the identity is shared
Every Inside Router must be explicitly enabled and advertise the Area Proxy TLV in its Level 2 LSP. The Area Leader distributes the Proxy System ID only after it observes readiness from all Inside Routers. This is a useful minimum commitment: the shared abstraction is not meant to activate while part of the fabric still follows ordinary flooding rules.
But the advertisement remains a declaration of protocol readiness. It does not prove that an implementation installed the right filters, computed the right routes or programmed the forwarding plane. Inventory therefore matters. Operators need the expected Inside membership, each router's latest Area Proxy TLV, the leader's observation time and the exact event that made the common Proxy System ID active.
Candidate leaders should also agree on the Proxy System ID, hostname and projected configuration. Multiple proxy identities in one area are a misconfiguration. A stable identity across candidates is valuable, but it creates a second evidence problem: the same public node can be generated by different leaders from different moments and input sets.
The Proxy LSP is a projection, not a mirror
The leader builds the Proxy LSP from Inside state, especially the LSPs of Inside Edge Routers. LSPs from unreachable nodes must be excluded. Prefixes may be selected by lowest metric. Capabilities are frequently narrowed to what all nodes support; ranges become minima, MSD types become an intersection and overload in any node propagates outward. Segment Routing, SRv6, multi-topology and traffic-engineering data each have their own projection rules.
This means a checksum over the Proxy LSP proves the bytes of one derived object. It does not identify every raw LSP that entered the projection, every node excluded as unreachable, or every rule used to reduce several private claims into one public claim. Keep those inputs. A useful generation record contains the leader generation, Inside membership, source-LSP hashes, reachability judgment, selection decision and resulting sequence, lifetime and checksum.
Leader failure sharpens the distinction. RFC 9666 says a replacement candidate regenerates the Proxy LSP, while the failure appears outside merely as an update. Calm outside state is a product feature, not evidence that the internal handover was harmless. The interval between old-leader loss, new election, regenerated projection, route installation and successful probes is the operational event.
Two SPF realities must still produce one forwarding result
Outside Routers use the Proxy LSP and treat internal transit cost as zero because the topology is hidden. Inside Routers must flood but ignore that same LSP. They see the real fabric and compare inter-area metrics before intra-area metrics so their detailed view does not contradict the outside abstraction and form loops.
The two views are intentionally unequal. A monitoring system that merges them into one topology loses the very boundary the protocol depends on. Preserve an outside LSDB/SPF snapshot and an inside LSDB/SPF snapshot separately, then join them to FIB state at each boundary and to packet observations across each material ingress and egress pair.
The optional Area SID carries the same warning. Its advertisement tells the outside network that traffic can be directed to any Inside Edge Router. The claim becomes real only if the required edges consume the SID consistently and the selected internal path delivers the packet. A common SRGB start, minimum range and conservative capability intersection reduce ambiguity; they do not install hardware state.
The boundary has to hide exactly what the proxy replaces
An Inside Edge Router must wait until it learns the Proxy System ID before sending an outside Level 2 Hello, then source that Hello from the proxy identity. It must also prevent Inside LSPs and Inside references in CSNPs and PSNPs from escaping. A single leaked LSP can puncture the abstraction and give outside routers a mixed graph containing both the proxy and part of what it represents.
Filtering should therefore be tested as a negative invariant. Capture the boundary and prove that forbidden identities did not cross, rather than merely confirming that the Proxy LSP did. Authentication under RFC 5304 or RFC 5310 can protect the provenance and integrity of routing messages. It cannot prove that the projection was semantically right or the filter complete.
RFC 9666 is Experimental, covers IP traffic and leaves MPLS-based transit for future work. It also excludes a boundary LAN with multiple Inside Edge Routers. Those limits belong in the deployment record. The strongest adoption posture is not to inflate an elegant abstraction into universal authority. It is to preserve its narrow promise and test the hidden system that must make the promise true.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

