Summary
- The head-end requests protection and owns the unmodified FAST_REROUTE constraints. The PLR selects or computes an eligible backup and activates it locally; the merge point rejoins the protected LSP.
- A one-to-one detour gives each protected LSP separate backup state. A facility bypass can serve several eligible LSPs, normally using label stacking, but creates shared capacity and shared-fate dependencies.
- RFC 8796 adds summary-FRR signaling intended to reduce message exchange and scaling pressure for facility backup. RFC 9705 adds refresh-independent state, capability, adjacency and teardown procedures. Neither update proves universal implementation support.
What the protocol authorizes
RFC 4090 applies to explicitly routed RSVP-TE LSPs, not dynamically changing unicast IGP LSPs. The head-end LER inserts the FAST_REROUTE object; downstream LSRs must not change it. Its constraints include setup and holding priority, requested bandwidth or bandwidth estimate, hop limit, requested protection method, and link-attribute or affinity filters. The head-end can request local protection, label recording, node protection and bandwidth protection.
Setup priority governs whether a session may obtain resources by preempting another session; holding priority governs whether its reservation may itself be preempted. An unavailable bandwidth request can produce a PathErr unless eligible lower-priority reservations can be preempted. These are resource-authority rules, not evidence that a backup is available.
The PLR is the local actor. When it detects a protected link or node failure, it redirects data and control traffic onto the selected backup. Detection is an input; it does not grant the detector authority to invent a repair. The PLR must stay within the eligible protection request and available forwarding state. A local-protection-available indication requires an available backup path and necessary forwarding state, as clarified by verified Errata 4203. When repair is active, the PLR marks local-protection-in-use and should notify the head-end with a PathErr.
The merge point has a different job: it removes the bypass context where applicable and returns traffic to the protected LSP. In a facility bypass, the PLR applies the protected-LSP label and pushes the bypass label; the merge point removes that context. The merge point does not become the head-end, and the PLR does not globally reoptimize the LSP.
Two backup economics
A one-to-one detour is specific to one protected LSP. It can express precise constraints, but per-LSP tunnels, labels, signaling and reservation state scale with the number of LSPs. A facility bypass protects multiple eligible LSPs sharing a facility and merge point. It can reduce repeated constructs, but capacity must cover the relevant traffic and compatibility conditions. Its label stack is efficient only if the forwarding and merge behavior are correct. Analysis: this is a trade between per-LSP state and a larger shared dependency; one bypass failure or stale state can affect a broader set of protected LSPs.
Requested bandwidth, node-versus-link protection, affinity and hop limits determine eligibility rather than guaranteeing it.
RFC 8796's summary-FRR signaling is a scaling update for facility backup: it is intended to reduce PLR/merge-point message exchange and control-plane latency pressure when many LSPs share a bypass. RFC 9705 updates facility protection so state maintenance and stale-state cleanup need not depend on short periodic refresh timeouts, adding explicit capability, adjacency and teardown procedures. Support, interoperability and operational behavior remain implementation questions.
Reversion and evidence
RFC 4090 distinguishes global reversion, in which the head-end uses a broader view to reoptimize affected TE LSPs, from optional local reversion at the PLR. It recommends global revertive mode and warns that local reversion can add disruption during resource flapping. A PathErr tells the head-end to act; it does not make the temporary local path the new end-to-end design.
Analysis: beneficiaries include latency-sensitive and loss-sensitive services, and operators seeking continuity without waiting for network-wide propagation and computation. The price is reserved or preemptible capacity, label and signaling state, cleanup work, test coverage and coupling between LSPs sharing a bypass. A counterfactual without pre-established repair is longer exposure while the head-end or routing system converges, potentially with more packet loss. The opposite risk is fast diversion onto stale state, an exhausted reservation or a path that no longer satisfies the original assumption.
Facts above are attributed to the cited RFCs and verified errata. The leadership implications are analysis, not deployment evidence. There are no allegations in this standards brief. Unknowns include operator or vendor adoption, topology, detection quality, capacity margins, measured repair times, customer outcomes, simultaneous-failure behavior, flapping behavior and mixed-version interoperability. The normative target is “tens of milliseconds” for the stated one-to-one redirection goal; it is not a measured universal result.
Verification fixtures
- Authority fixture: originate an explicitly routed RSVP-TE LSP with FAST_REROUTE, label recording, node protection, bandwidth, setup/holding priorities, hop limit and affinity filters. Confirm the object is inserted by the head-end and unchanged downstream.
- Availability fixture: inspect the PLR before failure. Confirm local-protection-available is asserted only when an eligible backup and forwarding state exist; test the RFC 4090 Errata 4203 interpretation.
- Failure fixture: withdraw a protected link, then a protected node. Capture PLR label operations, local-protection-in-use, traffic redirection and the PathErr toward the head-end. Confirm detection triggers selection of a signaled backup rather than authorizing a new end-to-end path.
- Method fixture: compare one-to-one and facility backup. For facility protection, verify the protected-LSP label plus bypass label stack at the PLR and removal of bypass context at the merge point.
- Resource fixture: request bandwidth under competing setup and holding priorities. Verify preemption and PathErr behavior; test both link and node protection and an affinity mismatch.
- Lifecycle fixture: force global reversion, optional local reversion and repeated flaps. Observe disruption and cleanup. Separately test RFC 8796 summary signaling and RFC 9705 capability, adjacency and refresh-independent teardown only where an implementation claims support.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

