Summary
- A PSID is a local label from the egress SR Local Block. It is inserted after the last SR-path label and is processed and popped by the egress.
- RFC 9884 extends LSP Ping to verify PSID processing and the SR path context that the egress associates with it.
- The endpoint of the SR path is the responder. LSP Traceroute is outside this specification because transit nodes do not process the PSID.
The operational trap is subtle: a successful packet journey can say only that the label reached the expected place. It does not by itself establish that the egress mapped the label to the intended policy object. RFC 9884 addresses that missing identity check. The probe carries a Target FEC Stack sub-TLV describing the context expected at the responder.
There are six new forms, IPv4 and IPv6 versions of three scopes: policy (sub-types 49 and 52), candidate path (50 and 53), and segment list (51 and 54). Select the scope according to PSID use. If every segment list in a policy uses the PSID, use the policy form. If all lists belonging to one candidate path use it, use the candidate-path form. If only one or some lists use it, use the segment-list form; some-list validation requires multiple LSP Ping messages, each carrying one segment-list-associated sub-TLV.
The forms become progressively more specific. Policy validation matches headend, color, and endpoint. Candidate-path validation adds protocol origin, originator, and discriminator. Segment-list validation adds Segment-List-ID. Unsupported Protocol-Origin makes responder validation fail. Reserved fields are transmitted as zero and ignored on receipt. The six new sub-TLVs are not expected together: if more than one is present, only the first is processed.
A malformed Target FEC Stack sub-TLV produces return code 1. A PSID that cannot be mapped to the described context produces return code 10. Successful validation returns code 3 and FEC-Status 1. For reverse or reply-path use, the endpoint sends the sub-TLV and the headend validates it without setting a return code; invalid replies are dropped and the error should be logged or reported.
Theo March analysis: This is best treated as a control-plane-to-data-plane correlation signal, not a generic reachability signal. Dashboards should separate policy, candidate-path, and segment-list probes. Field-level mismatches and return code 10 can point to stale programming or an identity mismatch, while packet loss suggests a different investigation. RFC 9884 does not mandate a monitoring platform, retention policy, rollout plan, or dashboard schema, and a successful PSID check does not validate every transit segment.
Sources
Operator decision path: identify the PSID scope; choose the corresponding IPv4 or IPv6 form; construct the exact identity fields; send LSP Ping to the egress responder; read code 1, 10, or successful code 3/FEC-Status 1; then compare the returned identity with control-plane state before changing programming.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
