| Internet-Draft | IOAM Using MPLS Network Actions | August 2026 |
| Gandhi, et al. | Expires 27 February 2027 | [Page] |
In situ Operations, Administration, and Maintenance (IOAM), defined in RFC 9197, collects operational and telemetry information in the packet using IOAM-Data-Fields while the packet traverses a path between two points in the network. Several IOAM Option-Types are available, for example, Pre-allocated Trace, Proof of Transit (POT), Edge-to-Edge (E2E), and Incremental Trace, that can be used to collect information for calculating various performance metrics. RFC 9326 defines the IOAM Direct Export (IOAM-DEX) Option-Type, which is used as a trigger for IOAM data to be directly exported or locally aggregated without being pushed into in-flight data packets.¶
MPLS Network Actions (MNA) mechanisms indicate actions to be performed on any combination of Label Switched Paths, MPLS packets, and the node itself, and to transport data needed for these actions. This document employs the MNA mechanisms to collect and transport the operational state and telemetry information using IOAM-Data-Fields as well as IOAM-DEX.¶
This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.¶
Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.¶
Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."¶
This Internet-Draft will expire on 27 February 2027.¶
Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved.¶
This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Revised BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Revised BSD License.¶
In situ Operations, Administration, and Maintenance (IOAM) [RFC9197] collects operational and telemetry information in the packet using IOAM-Data-Fields while the packet traverses a path between two points in the network. Several IOAM Option-Types are available, for example, Pre-allocated Trace, Proof of Transit (POT), Edge-to-Edge (E2E), and Incremental Trace, that can be used to collect information for calculating various performance metrics. Such mechanisms transport the collected information from an IOAM encapsulating node to an IOAM decapsulating node (both typically located at the edge of the IOAM domain within the data path).¶
IOAM Direct Export (IOAM-DEX) [RFC9326] is an IOAM Option-Type used as a trigger for IOAM data to be directly exported or locally aggregated without being pushed into in-flight data packets. The exporting method and format are outside the scope of [RFC9326].¶
MPLS Network Actions (MNA) mechanisms [RFC9789] indicate actions to be performed on any combination of Label Switched Paths, MPLS packets, and the node itself, and allow for the transport of data needed for these actions. [RFC9994] defines mechanisms for carrying a Network Action Sub-Stack (NAS) as part of the MPLS label stack, i.e., the In-Stack MNA solution. [I-D.ietf-mpls-mna-ps-hdr] defines mechanisms for carrying MNA and Ancillary Data (AD) below the MPLS label stack, i.e., as the Post-Stack MNA solution. [RFC9791] describes various use cases that can be realized using the MNA solution, including the IOAM and IOAM-DEX.¶
This document employs the MNA mechanisms to collect and transport the operational state and telemetry information using IOAM Option-Types, including Pre-allocated Trace, POT, and E2E, as well as IOAM-DEX. The mechanism for exporting the collected information for the IOAM-DEX Option-Type is outside the scope of this document. Also, transporting the Incremental Trace IOAM Option-Type is outside the scope of this document.¶
The terminology defined in [RFC9789], [RFC9994], and [I-D.ietf-mpls-mna-ps-hdr] is used in this document.¶
| Abbreviation | Meaning | Reference |
|---|---|---|
| AD | Ancillary Data | [RFC9613] |
| Blob | Binary Large Object | This document |
| BoS | Bottom of Stack | [RFC3032] |
| HbH | Hop-by-Hop | [RFC9789] |
| I2E | Ingress to Egress | [RFC9789] |
| E2E | Edge to Edge | [RFC9197] |
| IHS | I2E, HbH, or Select | [RFC9994] |
| IOAM | In situ Operations, Administration, and Maintenance | [RFC9197] |
| IOAM-DEX | IOAM Direct Export | [RFC9326] |
| IOAM-DEX-MNA-ISD | IOAM Direct Export as MPLS Network Action ISD | This document |
| ISD | In-Stack Data | [RFC9613] |
| LSE | Label Stack Entry | [RFC3032] |
| MNA | MPLS Network Action | [RFC9789] |
| MPLS | Multiprotocol Label Switching | [RFC3032] |
| NAI | Network Action Indicator | [RFC9613] |
| NAL | Network Action Length | [RFC9994] |
| NAS | Network Action Sub-Stack | [RFC9789] |
| NASL | Network Action Sub-Stack Length | [RFC9994] |
| OAM | Operations, Administration, and Maintenance | [RFC6291] |
| P bit | Post-Stack Data Presence bit | [I-D.ietf-mpls-mna-ps-hdr] |
| POT | Proof of Transit | [RFC9197] |
| RLD | Readable Label Depth | [RFC9789] and [I-D.ietf-mpls-mna-ps-hdr] |
| PFN | Post-Stack First Nibble | [RFC9790] |
| PSD | Post-Stack Data | [RFC9613] |
| PSMH | Post-Stack MPLS Header | [I-D.ietf-mpls-mna-ps-hdr] |
| S bit | Bottom of Stack bit | [RFC3032] |
| TC | Traffic Class | [RFC5462] |
| TTL | Time to Live | [RFC3032] |
| U bit | Unknown Network Action Handling bit | [RFC9994] |
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here.¶
Pre-allocated Trace, POT, and E2E IOAM Option-Types [RFC9197] use user packets to collect and transport the operational state and telemetry information. This document defines the Post-Stack MNA [I-D.ietf-mpls-mna-ps-hdr] solution for encapsulation of the Pre-allocated Trace, POT, and E2E IOAM Option-Types (see Section 4).¶
However, for some use cases, e.g., mobile backhaul, in which network resources are closely controlled, collecting and transporting telemetry information within a user packet may increase the complexity of network operations. In such environments, IOAM nodes can use IOAM-DEX, an IOAM Option-Type used as a trigger for IOAM data to be directly exported or locally aggregated without being pushed into in-flight data packets, as defined in [RFC9326]. IOAM-DEX collects the on-path telemetry information defined as IOAM data in [RFC9197]. In this document, encapsulations for IOAM-DEX are realized as In-Stack Data (see Section 5) and as Post-Stack Data (see Section 4).¶
The procedure defined in this document for carrying IOAM Option-Types using the MNA solution can be applied to user traffic packets and active measurement test packets. [I-D.gandhi-ippm-stamp-mpls-hdr] uses the mechanisms defined in this document to transport IOAM Option-Types using the MNA solution, with Simple Two-Way Active Measurement Protocol (STAMP) test packets for Hop-by-Hop (HbH) and E2E measurements. [I-D.ietf-ippm-on-path-active-measurements] also describes active measurement methods where the mechanisms defined in this document can carry IOAM Option-Types for on-path telemetry in MPLS networks.¶
The procedure defined utilizes the In-Stack MNA mechanisms [RFC9994] and Post-Stack MNA mechanisms [I-D.ietf-mpls-mna-ps-hdr] to transport IOAM Option-Types defined in Section 4 of [RFC9197] and IOAM-DEX Option-Type defined in Section 3.2 of [RFC9326]) as Post-Stack MNA in MPLS networks.¶
The presence of the associated Post-Stack MPLS Header (PSMH) is indicated by setting the P bit to 1 in the NAS as defined in [I-D.ietf-mpls-mna-ps-hdr]. An example of a NAS with a Format B LSE and the associated PSMH carrying IOAM and IOAM-DEX Option-Types is shown in Figure 1.¶
0 1 2 3 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ | MNA Label (value 4) | TC |S| TTL | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ | Opcode | 13-bit Data (Format B) |P|IHS|S| NASL |U| NAL | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ | Label | TC |1| TTL | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ ~ Post-Stack MPLS Header for IOAM and IOAM-DEX per Figure 2 ~ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ ~ Optional Payload + Padding ~ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
The fields in a NAS are defined as follows:¶
If both edge and intermediate nodes need to process the IOAM Option-Types, then the IHS scope MUST be set to "HbH, value 0x1". If only edge nodes need to process the IOAM Option-Types, then the IHS scope MUST be set to "I2E, value 0x0". The I2E scope allows skipping IOAM processing on the intermediate nodes, i.e., it avoids the need to parse all IOAM Option-Types to detect the one that requires HbH processing.¶
An example encoding of PSMH carrying IOAM and IOAM-DEX in Post-Stack MNA is shown in Figure 2.¶
0 1 2 3 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ | PFN |Reserve| PSMH-Len | Type = MNA Post-Stack Header | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ | MNA-PS-OP |R|R| PS-NAL | Block-Number |R|IOAM-Opt-Type| +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ ~ IOAM Option-Type and Data Space [RFC9197] [RFC9326] ~ ~ Beginning from Namespace-ID ~ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
The Post-Stack MPLS Base Header is added and contains the following fields as defined in [I-D.ietf-mpls-mna-ps-hdr].¶
The PSMH is added after the Post-Stack MPLS Base Header and contains the Post-Stack network action opcode for IOAM and IOAM-DEX, the length in 4-octet units, and the IOAM Option-Type with IOAM-Data-Fields in the Post-Stack ancillary data as shown in Figure 2 and contains the following fields:¶
MNA-PS-OP (7-bit): Set to Opcode TBA1 (network action opcode for IOAM and IOAM-DEX in PSD) for the IOAM Option-Type defined in [RFC9197], and the IOAM-DEX Option-Type defined in [RFC9326].¶
The U bit for this network action is set as specified in [I-D.ietf-mpls-mna-ps-hdr].¶
The IHS scope field for this network action is set to either I2E or HBH [I-D.ietf-mpls-mna-ps-hdr].¶
Block-Number (8-bit): The Block-Number is used for the alternate marking method [RFC9341] to aggregate the IOAM-Data-Fields collected in the data plane and to correlate IOAM-Data-Fields exported from different nodes along the packet path, e.g., to compute measurement metrics for each block of a data flow.¶
The following processing rules apply to the network action opcode TBA1.¶
An example of multiple Post-Stack Network Actions with the same IHS scope carrying different IOAM and IOAM-DEX Option-Types is shown in Figure 3.¶
0 1 2 3 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ | PFN |Reserve| PSMH-Len | Type = MNA Post-Stack Header | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ | MNA-PS-OP1 |R|R| PS-NAL1 | Block-Number |R|IOAM-Opt-Type| +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ ~ IOAM Option-Type and Data Space [RFC9197] [RFC9326] ~ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ | MNA-PS-OP2 |R|R| PS-NAL2 | Block-Number |R|IOAM-Opt-Type| +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ ~ IOAM Option-Type and Data Space [RFC9197] [RFC9326] ~ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ ~ Optional Payload + Padding ~ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
In this example, the PSMH carries the post-stack network action MNA-PS-OP1 with length PS-NAL1 and the post-stack network action MNA-PS-OP2 with length PS-NAL2, both for different Option-Types.¶
The network actions with I2E scope carry IOAM Option-Types that require processing on the encapsulating and egress nodes only.¶
The IOAM Option-Type carried can be the IOAM E2E Option-Type (value 3) defined in [RFC9197] or the IOAM-DEX Option-Type (value 4) defined in [RFC9326]. The network actions with I2E scope MUST NOT carry any IOAM Option-Type that requires IOAM processing on the intermediate nodes, as it will not be processed by them when the IHS scope is set to "I2E, value 0x0".¶
The IOAM and IOAM-DEX network action procedure with I2E scope is summarized as follows:¶
The network actions with HbH scope carry IOAM Option-Types that require processing at the intermediate and/or encapsulating and egress nodes.¶
The IOAM Option-Type carried can be Pre-allocated Trace (value 0), POT (value 2), or E2E (value 3) defined in [RFC9197], or the IOAM-DEX Option-Type (value 4) defined in [RFC9326].¶
Note that the network actions defined in this document do not support the IOAM Incremental Trace Option-Type (value 1), which requires HbH processing.¶
The IOAM and IOAM-DEX network action procedure with HbH scope is summarized as follows:¶
Both HbH and I2E scope network actions for IOAM and IOAM-DEX MAY be carried in the Post-Stack MNA in an MPLS packet. In this case, the PSMH carrying HbH-scoped network actions MUST be added after the BoS and before the PSMH carrying I2E-scoped network actions. This minimizes the Readable Label Depth (RLD) [I-D.ietf-mpls-mna-ps-hdr] required on intermediate nodes for processing IOAM and IOAM-DEX.¶
The procedure defined adopts the IOAM-DEX Option-Type format defined in [RFC9326] using MNA In-Stack Data (ISD) [RFC9994] to support direct export in MPLS networks.¶
To transport direct export of the operational state and telemetry information, the IOAM-DEX-MNA-ISD Binary Large Object (blob) is placed in a NAS according to the procedure defined in [RFC9994]. An example NAS with Format B LSE and Format D LSE to carry IOAM-DEX-MNA-ISD is shown in Figure 4.¶
0 1 2 3 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ | MNA Label (value 4) | TC |S| TTL | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ |Opcode = TBA2| 13-bit Data (Format B) |P|IHS|S| NASL |U| NAL | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ ~1| IOAM-DEX-MNA-ISD per Figure 5 (Format D) |S| ~ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
Here, the fields in a NAS are defined as follows:¶
By setting the IHS field [RFC9994], the IOAM-DEX-MNA-ISD can be configured to operate in HbH, I2E, or Select scopes [RFC9789] to collect the operational state and telemetry information.¶
The following processing rules apply to the network action opcode TBA2.¶
The following processing rules apply when carrying both the network action opcode TBA1 for the IOAM-DEX Option-Type in a PSMH and the network action opcode TBA2 in a NAS in an MPLS packet:¶
The IOAM-DEX-MNA-ISD blob in a NAS uses the Format D LSE Section 4.4 of [RFC9994], that maps to the IOAM-DEX Option-Type format [RFC9326]. In addition to the requirement to preserve the S bit, the most significant bit in Format D LSE is always set to 1, avoiding a possible mix-up of the LSE with one of the Base Special Purpose Labels [RFC9994]. The format of the IOAM-DEX-MNA-ISD blob in a NAS is shown in Figure 5.¶
0 1 2 3 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ |1| Namespace-ID | Reserved |S| Flags | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ |1| IOAM-Trace-Type-MNA |S|O|R| Ext-Flags | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ |1| Flow ID MNA (Optional) |S| Flow ID MNA | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ |1| Sequence Number MNA (Optional) |S| Seq Num MNA | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
Here, the fields are defined as follows:¶
IOAM-Trace-Type-MNA (22-bit): The IOAM-Trace-Type-MNA corresponds to the IOAM-Trace-Type field defined in Section 3.2 of [RFC9326].¶
O (1-bit): This is a one-bit flag identical to the interpretation of bit 22 of the IOAM-Trace-Type field as defined in Section 3.2 of [RFC9326], marked as "variable-length Opaque State Snapshot" per [RFC9197]; assigned code points are found in IANA's IOAM Trace-Type registry [IANA-IOAM-Trace-Type].¶
R (1-bit): This is a one-bit flag identical to the interpretation of bit 23 of the IOAM-Trace-Type field as defined in Section 3.2 of [RFC9326], marked as "reserved" per [RFC9197]; assigned code points are found in IANA's IOAM Trace-Type registry [IANA-IOAM-Trace-Type].¶
Ext-Flags (6-bit): The Ext-Flags field comprises six one-bit subfields. The allocation of the subfields in this field is according to the Extension-Flags field defined in Section 4.3 of [RFC9326].¶
In the IOAM-DEX Option-Type defined in [RFC9326], the IOAM-Trace-Type and Reserved fields together form the second 32-bit word, aligning the optional fields to 4-octet boundaries.¶
Flow ID MNA: An optional 4-octet field containing a 30-bit Flow ID (after removing leading 1 and S bits).¶
The semantics of the Flow ID MNA field are the same as those of the Flow ID field defined in Section 3.2 of [RFC9326], with the following two differences.¶
Sequence Number MNA: An optional 4-octet field containing a 30-bit sequence number (after removing leading 1 and S bits).¶
The semantics of the Sequence Number MNA field are the same as those of the Sequence Number field defined in Section 3.2 of [RFC9326], with the following two differences.¶
The length of the Ext-Flags field in the IOAM-DEX Option-Type in MNA is shorter by two one-bit fields compared to the length of the Extension-Flags field defined in Section 3.2 of [RFC9326]. In the 6-bit Ext-Flags field of the IOAM-DEX-MNA-ISD header, four flags have been mapped to those IANA assigned flags in the IOAM-DEX Option-Type, and two flags (corresponding to unassigned bits in the [RFC9326] Extension-Flags field) remain unassigned.¶
0 1 2 3 4 5
+-+-+-+-+-+-+
|F|Q|N|I|A|A|
+-+-+-+-+-+-+
Here, the Ext-Flags field is defined as follows:¶
The following behaviors for node capability apply:¶
The encapsulating node needs to know if the intermediate and egress nodes can support the IOAM and IOAM-DEX network actions. Information about the IOAM and IOAM-DEX capabilities of the nodes may be configured, collected through management protocols, or distributed by control protocols (such as advertising by routing protocols). The encapsulating node learns about the IOAM and IOAM-DEX capabilities of nodes using mechanisms that are out of scope for this document.¶
The encapsulating node needs to know about the path maximum transmission unit (MTU) for the nodes on the path [RFC3032]. Information about the path MTU of the nodes may be configured, collected through management protocols, or distributed by control protocols (such as MTU signaling for Label Distribution Protocol [RFC3988] and Path MTU Discovery for IPv6 [RFC8201]). The mechanisms to learn about the path MTU of nodes in the path are out of scope for this document.¶
The encapsulating node needs to know about the RLD of the nodes in the path as described in Section 2.3.1 of [RFC9789] and updated in [I-D.ietf-mpls-mna-ps-hdr], so that IOAM and IOAM-DEX Option-Types can be read by nodes in the path. Information about the RLD of the nodes may be configured, collected through management protocols, or distributed by control protocols (such as advertising by routing protocols). The mechanisms to learn about the RLD of nodes in the path are out of scope for this document.¶
The encapsulating node needs to ensure that the IOAM Option-Types and their IOAM-Data-Fields and IOAM-DEX data in a NAS and the associated PSMH are added within the RLD [I-D.ietf-mpls-mna-ps-hdr] of the downstream MNA-capable nodes so that they can process the IOAM-Data-Fields and IOAM-DEX data.¶
The following processing rules apply to nested MPLS encapsulation when adding a new MPLS encapsulation:¶
Operational considerations discussed in [RFC9994] and [I-D.ietf-mpls-mna-ps-hdr] apply to this document.¶
Management considerations discussed in [RFC9789], management and deployment considerations discussed in [RFC9197], and performance considerations discussed in Section 5 of [RFC9326] are also applicable here.¶
Further operational considerations include policies controlling the processing of the collected operational state and telemetry information, and their transport in MPLS networks. Additional considerations are described in Section 6 for deploying IOAM and IOAM-DEX in MPLS networks.¶
An implementation MAY collect the following counters:¶
Nodes MAY generate rate-limited notifications or alarms for significant operational events, such as sustained high rates of IOAM-related packet drops to alert operators to potential issues. Comprehensive logging of IOAM and IOAM-DEX network action processing details can aid in network diagnostics and post-mortem analysis.¶
The security considerations discussed in [RFC9197], [RFC9326], and [RFC9378] for IOAM and IOAM-DEX apply to this document.¶
The security considerations discussed in [RFC9341] for alternate marking and [RFC9630] for IOAM deployment apply to this document.¶
The security considerations discussed in [RFC9789], [RFC9994], and [I-D.ietf-mpls-mna-ps-hdr] for MNA apply to this document.¶
The usage of network actions defined in this document for IOAM and IOAM-DEX is intended for deployment in a single network administrative domain. As such, it assumes that the operator enabling the IOAM and IOAM-DEX operations has previously verified the integrity of the path that packets take. However, operators need to properly secure the IOAM and IOAM-DEX in the domain to avoid malicious configuration and use, which could include injecting malicious IOAM and IOAM-DEX packets into the domain.¶
IANA is requested to assign code points from its Network Action Opcodes registry (created in [RFC9994] and updated in [I-D.ietf-mpls-mna-ps-hdr]) as specified in Table 2.¶
| Opcode | Description | In-Stack Only, Post-Stack Only, In-Stack and Post-Stack | Reference |
|---|---|---|---|
| TBA1 | Network Action for IOAM and IOAM-DEX in PSD | Post-Stack Only | This document |
| TBA2 | Network Action for IOAM-DEX in ISD | In-Stack Only | This document |
As described in Section 5.5 of [RFC9994], the network actions in a NAS are processed in order starting from the top of the label stack. The PSMH Start Offset Network Action opcode TBA3 defined in [I-D.ietf-mpls-mna-ps-hdr] can be added to interleave Post-Stack Network Actions with In-Stack Network Actions to define processing order. The following example shows how to process the Post-Stack Network Action before some of the In-Stack Network Actions in a NAS.¶
0 1 2 3 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-- | MNA Label (value 4) | TC |0| TTL | | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ | | Opcode=L | Ancillary Data |1|IHS|0| NASL=3|U|NAL=0| | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ N | Opcode=1 | Flag-Based NAIs |0| NAIs |U|NAL=0| A +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ S | Opcode=TBA3 | 0 |0| 0 |U|NAL=0| | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ | | Opcode=M | Ancillary Data |1| AD |U|NAL=0| | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-- | PFN |Reserve| PSMH-Len | Type = MNA Post-Stack Header | | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ P |Opcode = TBA1|R|R| PS-NAL | Block-Number |R|IOAM-Opt-Type| S +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ M ~ IOAM Option-Type and Data Space [RFC9197] [RFC9326] ~ H ~ Beginning from Namespace-ID ~ | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-- ~ Optional Payload + Padding ~ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+--
In this example, shown in Figure 7, the network actions in the NAS are processed in the following order:¶
Note: Opcode TBA3 will be assigned by IANA as part of [I-D.ietf-mpls-mna-ps-hdr]. This example will be updated by the RFC editor with the IANA assigned value for TBA3 at the time of publication. This note is to be removed once TBA3 value is updated in this example.¶
The authors would like to thank Adrian Farrel and Xueyan Song for reviewing this document and providing review comments. The authors would also like to thank Patrick Khordoc, Sagar Soni, Shwetha Bhandari, Vengada Prasad Govindan, Tarek Saad, Stewart Bryant, Xiao Min, Jaganbabu Rajamanickam, Jie Dong, and Cheng Li for reviewing the early version of this document. The authors would also like to thank Mach Chen, Andrew Malis, Matthew Bocci, and Nick Delregno for the MPLS-RT expert review of the early version of this document. The authors also thank Matthew Bocci for the early Rtgdir review, Sheng Jiang for early Opsdir review, and Giuseppe Fioccola for the PerfMetrDir review, which helped improve this document.¶
The following people have substantially contributed to this document:¶
Zafar Ali Cisco Systems, Inc. Email: zali@cisco.com Frank Brockners Cisco Systems, Inc. Germany Email: fbrockne@cisco.com Loa Andersson Huawei Technologies Email: loa@pi.nu¶