Summary
- RFC 9801 requires a Private Line Emulation receiver to replace every lost or dropped packet payload with the same quantity of substitute data. All implementations must support
0xAA, alternating zeros and ones, as the default. - The filler helps maintain clock synchronization and valid 64B/66B sync headers while a holdover mechanism keeps time. It preserves cadence, not the remote customer's missing information.
- A defensible operating record separates received packets, sequence gaps, reordering decisions, replacement intervals, clock state, L/R indications, PLOS/DEG counters, native-service observations and customer outcomes.
The far-end port never stopped toggling. Its clock stayed inside tolerance. The line card did not emit an invalid 64B/66B sync header. Yet, for one interval, none of the bytes leaving that connector had crossed the packet network.
They were 0xAA.
That is not a defect invented for a cautionary tale. It is the default replacement pattern that RFC 9801 requires every Private Line Emulation implementation to support. When a PLE packet is lost—or arrives out of order at a receiver that does not reorder—the missing payload must be replaced with an equal amount of data. Alternating zeros and ones keep the clock moving and avoid invalid sync headers for 64B/66B services. The interworking function applies holdover while it emits the substitute.
The mechanism is sensible. A synchronous attachment circuit cannot pause politely while an IP or MPLS network waits for a late packet. Time continues. The receiver must put something on the wire. The governance error comes later, when “signal present”, “clock locked” or even “service up” is treated as proof that the original bit-stream arrived intact.
A private line is being emulated, not teleported
RFC 9801, published as a Proposed Standard in July 2025, carries bit-stream and structured-bit-stream services across a packet-switched network. The service may represent TDM, Ethernet physical-layer coding, Fibre Channel or OTN. The architecture sits inside the pseudowire framework described by RFC 3985: a provider-edge interworking function packetizes the customer-edge signal, sends fixed-size payloads over a virtual private wire service, and reconstructs the stream at the far edge.
The fixed size matters. During setup, both directions must agree on payload type and size, and the size remains unchanged for the life of the VPWS. Every implementation supports 1,024-byte payloads. A sequence number in the PLE control word increments for every packet, using the common control-word conventions of RFC 4385. It lets the receiver observe a gap. It does not reveal whether congestion, corruption, misrouting, an attack, a failed interface or excessive delay caused it.
An RTP header carries timing. PLE borrows timestamps and sequence conventions from RFC 3550, but explicitly does not import the whole RTP system: no RTCP, SRTP, header extensions or conferencing topology. For streams up to 200 Gbit/s, timestamps use a 125 MHz clock; faster streams use 250 MHz. The relative timing model follows RFC 4197: the difference between the attachment-circuit clock and a common network reference is transported so the far edge can recover cadence.
The timestamp is therefore an instruction for reconstruction, not a notarised copy of the payload. It helps answer when the receiver should emit. It does not answer what absent bytes originally were.
The sequence gap and the output byte are different facts
The receiver must have a de-jitter buffer. That buffer absorbs packet-delay variation and creates a decision window. An out-of-order packet may be reordered; if the implementation does not support reordering, it must be dropped. At that instant, a late but authentic payload and a packet that never arrived have the same output consequence: neither supplies bytes in time for the synchronous port.
RFC 9801 then requires replacement. The amount is exact because the output clock and fixed bit rate cannot stretch around the hole. The contents may be configured, but 0xAA support is mandatory. In binary, the byte is an alternating pattern. Its value is not a guess about customer data. It is chosen for electrical and coding continuity.
This produces a clean evidence ladder:
| Receipt | What it can establish |
|---|---|
| received packet and sequence number | a PLE payload arrived with this transport identity |
| observed sequence gap | one or more expected payload positions were absent at decision time |
| reordering decision | a late packet was restored or discarded under a stated policy |
| replacement interval | the output contained locally generated bytes for a stated duration |
| holdover and recovered clock | cadence was maintained within a stated timing observation |
| native maintenance signal | the reconstructed service exposed a bounded fault indication |
| customer observation | a named application experienced a measured result |
Collapsing these rows destroys the most important distinction. A trace of the customer-facing wire may truthfully show an uninterrupted stream. A packet capture of the provider network may truthfully show a loss. Neither contradicts the other: the interworking function bridged the missing interval with synthetic content.
Alarm bits report conditions; they do not restore history
The PLE control word carries two small but important assertions. The L bit says the sending provider edge knows that the carried payload is invalid because the local attachment circuit has a fault. The downstream edge must produce suitable replacement data and may inject the native service's fault signal. The R bit tells the peer that the receiving interworking function is experiencing PSN packet loss or a backward server-layer fault indication.
Those bits preserve direction and scope. L is evidence from the attachment-circuit side of the sender. R is a report from the receiving side about packet-network loss or another backward fault. Neither contains the missing payload; neither proves the far customer equipment interpreted the maintenance signal; neither identifies root cause.
The state machine adds thresholds. A run of missing packets for a configurable interval—one millisecond by default—declares Packet Loss Of Signal, or PLOS. A configurable excessive-loss condition across consecutive one-second windows declares degradation, or DEG; the described defaults are 15% across seven intervals. A threshold crossing is not the same object as the first lost packet. It is a later classification made with configured policy and a clock.
RFC 9801 also defines ES-PLE, SES-PLE and UAS-PLE accounting. A second with at least one lost packet, PLOS or DEG is errored. A second with more than 15% loss, PLOS or DEG is severely errored. Consecutive severely errored seconds lead to unavailability under configurable rules, with ten seconds as the default entry and exit run. These counters are valuable, but the RFC keeps attachment-circuit monitoring service-specific and outside its scope. A PLE counter is not automatically a Fibre Channel transaction failure, an Ethernet frame loss count or a customer outage duration.
Buffering buys tolerance by spending time
When a VPWS comes up, the receiver does not immediately stream buffered payload to the attachment circuit. It remains in an intermediate state and continues sending the proper downstream fault indication until enough data has accumulated. RFC 9801 notes a typical starting point of half the de-jitter buffer. That leaves room for delay to move in either direction.
The policy is an explicit trade: a larger buffer tolerates more packet-delay variation but adds latency and delays the moment at which loss becomes operationally visible. A smaller buffer shortens delay but converts more late packets into drops and replacement. “No underrun” can therefore be purchased with more waiting; “low latency” can be purchased with less tolerance. Neither setting proves the service met its customer's requirement.
Older circuit-emulation specifications such as RFC 4553, RFC 5086 and RFC 4842 explain why RTP-shaped timing and replacement behavior recur across synchronous emulation. RFC 9801 generalises the service surface to much faster and more varied bit streams. That makes the audit question more important, not less: which interval was received, which was manufactured, and which downstream observer could tell the difference?
A constant-bit-rate stream cannot yield to congestion
PLE is inelastic. The customer-side bit rate does not slow because a router is congested. RFC 9801 therefore says it cannot behave in the TCP-friendly manner discussed by RFC 2914. The packet network must provide sufficiently low loss and jitter through QoS, traffic engineering, admission control or capacity. The exact method is outside the specification.
Replacement data can soften the physical consequence of a brief loss, but it cannot make the traffic congestion-responsive. Nor can it prove that reserved capacity existed. The output may look orderly precisely because the edge absorbed the disorder. Capacity evidence belongs to the packet network; reconstructed-circuit evidence belongs to the interworking function; application evidence belongs to the user of the line.
The same separation applies to security. RFC 9801 assumes an isolated, trusted MPLS or SRv6 network and inherits pseudowire security considerations from RFC 5920. An attacker able to inject, delay, reorder or discard packets can force degradation beyond the de-jitter buffer, a risk class elaborated by RFC 9055. PTP-derived synchronization has its own delay-manipulation and clock threats, documented in RFC 7384. A stable recovered clock is therefore an observed timing property, not proof of an authenticated payload path.
The RFC Editor's information record, errata record and the IETF's document history describe the specification's publication state. The IANA pseudowire registry records allocated protocol values. None is an implementation receipt. Likewise, RFC 8214 defines EVPN-VPWS control concepts, while RFC 9801 explicitly leaves its PLE signalling extensions outside scope.
The TXT and XML forms of RFC 9801 and its canonical XML make the normative mechanism inspectable. They still cannot say whether a particular line replaced one byte or a billion.
The operating principle is simple: continuity is a service action; fidelity is an evidence claim. When the service action fabricates the only possible safe output, the evidence system must remember that it did so.
Sources
- https://www.rfc-editor.org/rfc/rfc9801.html
- https://www.rfc-editor.org/rfc/rfc9801.txt
- https://www.rfc-editor.org/rfc/rfc9801.xml
- https://www.rfc-editor.org/info/rfc9801/
- https://www.rfc-editor.org/errata/rfc9801
- https://datatracker.ietf.org/doc/rfc9801/history/
- https://www.rfc-editor.org/rfc/rfc3985.html
- https://www.rfc-editor.org/rfc/rfc4385.html
- https://www.rfc-editor.org/rfc/rfc3550.html
- https://www.rfc-editor.org/rfc/rfc4197.html
- https://www.rfc-editor.org/rfc/rfc4553.html
- https://www.rfc-editor.org/rfc/rfc5086.html
- https://www.rfc-editor.org/rfc/rfc4842.html
- https://www.rfc-editor.org/rfc/rfc2914.html
- https://www.rfc-editor.org/rfc/rfc9055.html
- https://www.rfc-editor.org/rfc/rfc5920.html
- https://www.rfc-editor.org/rfc/rfc7384.html
- https://www.rfc-editor.org/rfc/rfc8214.html
- https://www.iana.org/assignments/pwe3-parameters/pwe3-parameters.xhtml
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
