<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp   "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">

 <!ENTITY I-D.ietf-mpls-stamp-pw SYSTEM
    "https://xml2rfc.tools.ietf.org/public/rfc/bibxml3/reference.I-D.ietf-mpls-stamp-pw.xml">
 <!ENTITY I-D.ietf-ippm-stamp-yang SYSTEM
    "https://xml2rfc.tools.ietf.org/public/rfc/bibxml3/reference.I-D.ietf-ippm-stamp-yang.xml">
  <!ENTITY RFC768 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.768.xml">
  <!ENTITY RFC2119 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.2119.xml">
  <!ENTITY RFC2681 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.2681.xml">
  <!ENTITY RFC3031 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.3031.xml">
  <!ENTITY RFC4026 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.4026.xml">
  <!ENTITY RFC3032 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.3032.xml">
  <!ENTITY RFC5462 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.5462.xml">
  <!ENTITY RFC6234 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.6234.xml">
  <!ENTITY RFC6056 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.6056.xml">
  <!ENTITY RFC6335 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.6335.xml">
  <!ENTITY RFC8174 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.8174.xml">
  <!ENTITY RFC8762 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.8762.xml">
  <!ENTITY RFC8972 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.8972.xml">
  <!ENTITY RFC9503 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.9503.xml">
  <!ENTITY RFC5905 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.5905.xml">
  <!ENTITY RFC6790 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.6790.xml">
  <!ENTITY RFC8029 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.8029.xml">
  <!ENTITY RFC8085 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.8085.xml">
  <!ENTITY RFC8402 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.8402.xml">
  <!ENTITY RFC8403 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.8403.xml">
  <!ENTITY RFC9256 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.9256.xml">
  <!ENTITY RFC9350 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.9350.xml">
  <!ENTITY RFC9545 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.9545.xml">
  <!ENTITY RFC9780 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.9780.xml">
  <!ENTITY RFC9994 SYSTEM "https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.9994.xml">

]>
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" submissionType="IETF" docName="draft-ietf-spring-stamp-srpm-mpls-08" category="info" ipr="trust200902" obsoletes="" updates="" xml:lang="en" sortRefs="false" consensus="yes" symRefs="true" tocInclude="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.12.0 -->
  <!-- Generated by id2xml 1.5.0 on 2020-02-06T01:41:26Z -->
    <front>
    <title abbrev="STAMP for Segment Routing over MPLS">Performance Measurement Using Simple Two-Way Active Measurement Protocol (STAMP) for Segment Routing over the MPLS Data Plane</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-spring-stamp-srpm-mpls-08"/>
    <author fullname="Rakesh Gandhi" initials="R." role="editor" surname="Gandhi">
      <organization>Cisco Systems, Inc.</organization>
      <address>
        <postal>
          <street>Canada</street>
        </postal>
        <email>rgandhi@cisco.com</email>
      </address>
    </author>
    <author fullname="Clarence Filsfils" initials="C." surname="Filsfils">
      <organization>Cisco Systems, Inc.</organization>
      <address>
        <email>cfilsfil@cisco.com</email>
      </address>
    </author>
    <author fullname="Bart Janssens" initials="B." surname="Janssens">
      <organization>Colt</organization>
      <address>
        <email>Bart.Janssens@colt.net</email>
      </address>
    </author>
    <author fullname="Mach(Guoyi) Chen" initials="M." surname="Chen">
      <organization>Individual</organization>
      <address>
        <email>mach.chen@outlook.com</email>
      </address>
    </author>
    <author fullname="Richard Foote" initials="R." surname="Foote">
      <organization>Nokia</organization>
      <address>
        <email>footer.foote@nokia.com</email>
      </address>
    </author>

   <date year="2026"/>
    <workgroup>SPRING Working Group</workgroup>
    <abstract>
      <t>
   Segment Routing (SR) can be used to steer packets through a
   network employing source routing.  SR can be applied to both MPLS
   (SR-MPLS) and IPv6 (SRv6) data planes.

   This document describes the procedures for performance measurement in SR-MPLS networks using the
   Simple Two-Way Active Measurement Protocol (STAMP), as specified in RFC 8762,
   along with its optional extensions specified in RFC 8972 and further augmented in RFC 9503.

   The procedures described in this document are used for SR-MPLS paths (including Segment Lists of SR-MPLS Policies, SR-MPLS 
   IGP best paths, and SR-MPLS IGP Flexible Algorithm (Flex-Algo) paths), as well as Layer-3 and Layer-2 services carried over the
   SR-MPLS paths.
   </t>
    </abstract>
  </front>
  <middle>
    <section anchor="sect-1" numbered="true" toc="default">
      <name>Introduction</name>
   <t>
   Segment Routing (SR) <xref target="RFC8402" format="default"/> can be used to steer packets through a
   network employing source routing.  SR can be applied to both MPLS
   (SR-MPLS) and IPv6 (SRv6) data planes.

   SR can take advantage of Equal-Cost Multipath (ECMP) between source and transit nodes,
   between transit nodes, and between transit and destination nodes. SR
   Policies, as defined in <xref target="RFC9256" format="default"/>, are used
   to steer traffic through specific user-defined paths using a list of segments.
   </t>

   <t>
   A comprehensive SR performance measurement toolset is an
   essential requirement for measuring network performance and providing 
   Service Level Agreements (SLAs).
   </t>

   <t>
   The Simple Two-Way Active Measurement Protocol (STAMP), as specified in <xref target="RFC8762" format="default"/>, provides
   the capability to measure various performance metrics in IP networks
   without the use of a control channel to pre-signal session parameters.
   <xref target="RFC8972" format="default"/> specifies optional extensions in the form of Type-Length-Value (TLV) objects for STAMP, and
   <xref target="RFC9503" format="default"/> further augments that framework
   to define STAMP extensions for SR networks.
   </t>

   <t>
  This document describes the procedures for performance measurement in SR-MPLS networks, using
  STAMP as specified in <xref target="RFC8762" format="default"/>, along with its
  optional extensions specified in <xref target="RFC8972" format="default"/>
  and augmented in <xref target="RFC9503" format="default"/>.
  The procedures described in this document are used for SR-MPLS paths <xref target="RFC8402" format="default"/>
  (including Segment Lists of SR-MPLS Policies <xref target="RFC9256" format="default"/>,
  SR-MPLS IGP best paths, and SR-MPLS IGP Flexible Algorithm (Flex-Algo) paths <xref target="RFC9350" format="default"/>),
  as well as Layer-3 (L3) and Layer-2 (L2) services carried over the SR-MPLS paths.
   </t>

   <t>
  STAMP requires protocol support on the Session-Reflector to process the received test packets.
  As a result, the received test packets need to be punted from the fast path in the data plane for control-plane processing,
  and return test packets need to be generated. This limits the frequency of STAMP test packets
  and the ability to provide shorter measurement intervals. 
  </t>
  <t>
  This document defines new mechanisms to
  enhance the procedures for performance measurement using STAMP, improve scalability by supporting a larger
  number of STAMP sessions, and shorten the measurement interval for SR-MPLS paths by defining three new
  measurement modes: one-way, loopback, and loopback with Timestamp and Forward (TSF). The new measurement
  modes, loopback and loopback with TSF, take advantage of source routing.
   </t>

   <t>
   The procedure for performance measurement of MPLS LSPs using the measurement modes defined in this document is outside the scope of this document.
   </t>

    </section>

    <section anchor="sect-2" numbered="true" toc="default">
      <name>Conventions Used in This Document</name>
      <section anchor="sect-2.1" numbered="true" toc="default">
        <name>Requirements Language</name>

       <t>
    The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL
    NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED",
    "MAY", and "OPTIONAL" in this document are to be interpreted as
    described in BCP 14 <xref target="RFC2119" format="default"/> <xref target="RFC8174" format="default"/>
    when, and only when, they appear in all capitals, as shown here.
   </t>

      </section>

      <section anchor="sect-2.2" numbered="true" toc="default">
        <name>Abbreviations</name>
        <table anchor="abbreviations" align="center">
          <name>Abbreviations</name>
          <thead>
            <tr>
              <th align="left">Abbreviation</th>
              <th align="left">Expansion</th>
              <th align="left">Reference</th>
            </tr>
          </thead>
          <tbody>
            <tr><td>BoS</td><td>Bottom of Stack</td><td><xref target="RFC9994" format="default"/></td></tr>
            <tr><td>ECMP</td><td>Equal-Cost Multipath</td><td><xref target="RFC6790" format="default"/></td></tr>
            <tr><td>HMAC</td><td>Hashed Message Authentication Code</td><td><xref target="RFC6234" format="default"/></td></tr>
            <tr><td>L2VPN</td><td>Layer-2 Virtual Private Network</td><td><xref target="RFC4026" format="default"/></td></tr>
            <tr><td>L3VPN</td><td>Layer-3 Virtual Private Network</td><td><xref target="RFC4026" format="default"/></td></tr>
            <tr><td>LSE</td><td>Label Stack Entry</td><td><xref target="RFC9994" format="default"/></td></tr>
            <tr><td>MBZ</td><td>Must Be Zero</td><td><xref target="RFC8762" format="default"/></td></tr>
            <tr><td>MNA</td><td>MPLS Network Action</td><td><xref target="RFC9994" format="default"/></td></tr>
            <tr><td>MPLS</td><td>Multiprotocol Label Switching</td><td><xref target="RFC3032" format="default"/></td></tr>
            <tr><td>NTP</td><td>Network Time Protocol</td><td><xref target="RFC5905" format="default"/></td></tr>
            <tr><td>PHP</td><td>Penultimate Hop Popping</td><td><xref target="RFC3031" format="default"/></td></tr>
            <tr><td>PSID</td><td>Path Segment Identifier</td><td><xref target="RFC9545" format="default"/></td></tr>
            <tr><td>PTP</td><td>Precision Time Protocol</td><td><xref target="IEEE.1588" format="default"/></td></tr>
            <tr><td>S bit</td><td>Bottom of Stack bit</td><td><xref target="RFC3032" format="default"/></td></tr>
            <tr><td>SHA</td><td>Secure Hash Algorithms</td><td><xref target="RFC6234" format="default"/></td></tr>
            <tr><td>SID</td><td>Segment Identifier</td><td><xref target="RFC8402" format="default"/></td></tr>
            <tr><td>SR</td><td>Segment Routing</td><td><xref target="RFC8402" format="default"/></td></tr>
            <tr><td>SR-MPLS</td><td>Segment Routing with MPLS data plane</td><td><xref target="RFC8402" format="default"/></td></tr>
            <tr><td>SSID</td><td>STAMP Session Identifier</td><td><xref target="RFC8972" format="default"/></td></tr>
            <tr><td>STAMP</td><td>Simple Two-Way Active Measurement Protocol</td><td><xref target="RFC8762" format="default"/></td></tr>
            <tr><td>TC</td><td>Traffic Class</td><td><xref target="RFC5462" format="default"/></td></tr>
            <tr><td>TLV</td><td>Type-Length-Value</td><td><xref target="RFC8972" format="default"/></td></tr>
            <tr><td>TSF</td><td>Timestamp and Forward</td><td>This document</td></tr>
            <tr><td>TTL</td><td>Time to Live</td><td><xref target="RFC3032" format="default"/></td></tr>
            <tr><td>VPN</td><td>Virtual Private Network</td><td><xref target="RFC4026" format="default"/></td></tr>
          </tbody>
        </table>
      </section>

    </section>

    <section anchor="sect-3" numbered="true" toc="default">
      <name>Overview</name>

    <t>
    For performance measurement in SR-MPLS networks, the STAMP Session-Sender and Session-Reflector use the STAMP test packets specified in <xref target="RFC8762" format="default"/>, along with optional extensions specified in <xref target="RFC8972" format="default"/>. The STAMP test packets are encapsulated using an IP/UDP header, as specified in <xref target="RFC8762" format="default"/>. In this document, the STAMP test packets using the IP/UDP header are used for SR-MPLS networks, where the STAMP test packets are further encapsulated with an MPLS header.
    </t>

    <t>
    STAMP test packets are transmitted in one of the following performance measurement modes in SR-MPLS networks where processing on Session-Reflector varies:
    </t>

    <ol>
        <li><t>Two-Way measurement:</t>
      <t>Session-Reflector generates and transmits Session-Reflector test packets (see <xref target="sect-4.1" format="default"/>).</t></li>
      <li><t>One-Way measurement:</t>
          <t>Session-Reflector does not generate and transmit Session-Reflector test packets (see <xref target="sect-4.2" format="default"/>).</t></li>
      <li><t>Loopback measurement:</t>
          <t>Session-Reflector does not perform STAMP processing (see <xref target="sect-4.3" format="default"/>).</t></li>
      <li><t>Loopback measurement with TSF:</t>
          <t>Session-Reflector writes the receive timestamp in fast path but does not perform STAMP processing (see <xref target="sect-4.4" format="default"/>).</t></li>
    </ol>

    <t>
    Note that the two-way measurement mode is described as part of the STAMP process in <xref target="RFC8762" format="default"/> and is further described for SR-MPLS networks in this document. The other measurement modes are new, specific to SR-MPLS networks, and are not defined in <xref target="RFC8762" format="default"/>.
    </t>

    <t>
    STAMP test packets are transmitted on the same path as the data traffic flow under measurement to measure the delay and packet loss experienced by the data traffic flow, using the same MPLS encapsulation. 
    </t>

    <ul spacing="normal">
    <li> <t>STAMP test packets are transmitted on various transport data paths in the network to measure the delay and packet loss experienced by the traffic forwarded on those paths. 
    </t>
    </li>
    <li> <t>STAMP test packets are transmitted over L3 and L2 services in the network to measure the delay and packet loss experienced by the traffic carried by those services.
    </t>
    </li>
    </ul>

    <t>
    Typically, STAMP Session-Reflector test packets are transmitted along an IP path between the Session-Reflector and Session-Sender. Matching the forward-direction path and return path for STAMP test packets, even for directly connected nodes, is not guaranteed. In SR-MPLS networks, the same path (i.e., the same set of links and nodes) between the Session-Sender and Session-Reflector may be desired for the STAMP test packets in both directions, for example, in an ECMP environment. This is achieved as follows:
    </t>

    <ul spacing="normal">
    <li><t>In two-way measurement mode:</t>
    <t>The optional STAMP extensions for SR-MPL networks, as specified in <xref target="RFC9503" format="default"/>, are used. The STAMP Session-Reflector uses the return path parameters for the Session-Reflector test packet from the STAMP extensions in the received Session-Sender test packet, as specified in <xref target="RFC9503" format="default"/>.
    </t>
    </li>
    <li><t>In loopback and loopback with TSF measurement modes: </t> 
    <t>Both the forward direction path and the return path are added in the MPLS encapsulation of the Session-Sender test packets using source routing.</t>
    </li>
    </ul>

    <t>
    The performance measurement procedures defined in this document are used to measure both delay and packet loss in SR-MPLS networks based on the transmission and reception of STAMP test packets. The optional STAMP extensions, as defined in <xref target="RFC8972" format="default"/>, are used for direct measurement in SR-MPLS networks.
    </t>


    </section>


    <section anchor="sect-4" numbered="true" toc="default">
      <name>Measurement Modes</name>

<t>
In <xref target="modes-reference-topology-two-way" format="default"/> to <xref target="modes-loopback-mode-with-tsf" format="default"/>, the nodes S1 and R1 may be connected via an SR-MPLS path <xref target="RFC8402" format="default"/>.  
</t>

<t>
The SR-MPLS path may be a Segment List of an SR-MPLS Policy <xref target="RFC9256" format="default"/> on node S1 (referred to as the "head-end") with node R1 as the destination (referred to as the "endpoint"), an SR-MPLS IGP best path, or an SR-MPLS IGP Flex-Algo path <xref target="RFC9350" format="default"/>. Additionally, an L3 or L2 VPN service may be carried over the SR-MPLS path between nodes S1 and R1.
</t>

      <section anchor="sect-4.1" numbered="true" toc="default">
        <name>Two-Way Measurement Mode</name>

<t>
As shown in <xref target="modes-reference-topology-two-way" format="default"/>, in the reference topology for two-way measurement mode, the STAMP Session-Sender S1 initiates a Session-Sender test packet, and the STAMP Session-Reflector R1 generates and transmits a Session-Reflector test packet. The Session-Reflector test packets are transmitted to the Session-Sender S1 on the same path (i.e., the same set of links and nodes) or on a different path in the reverse direction from the path taken towards the Session-Reflector R1.
</t>

          <figure anchor="modes-reference-topology-two-way">
          <name>Reference Topology for Two-Way Measurement Mode</name>
          <artwork name="" type="" align="left" alt=""><![CDATA[
                       T1                T2
                      /                   \
             +-------+     Test Packet     +-------+
             |       | - - - - - - - - - ->|       |
             |   S1  |=====================|   R1  |
             |       |<- - - - - - - - - - |       |
             +-------+  Reply Test Packet  +-------+
                      \                   /
                       T4                T3

       STAMP Session-Sender          STAMP Session-Reflector
]]></artwork>
        </figure>

    <t>
T1 is a transmit timestamp, and T4 is a receive timestamp added by node S1. T2 is a receive timestamp, and T3 is a transmit timestamp added by node R1. All four timestamps are used by the Session-Sender to measure the two-way delay metric as ((T4 - T1) - (T3 - T2)). Timestamps T1 and T2 are used by the Session-Sender to measure the one-way delay metric as (T2 - T1), also referred to as the near-end (forward direction) delay metric. Note that the delay value (T4 - T3), measured by the Session-Sender, is referred to as the far-end (backward direction) one-way delay metric.
The "two-way delay" is the sum of the one-way delays in each direction and reflects the delay of the bidirectional path, irrespective of processing delays within the Session-Reflector.  
</t>

<t>
The computation of the one-way delay metric requires the clocks on the Session-Sender and Session-Reflector to be synchronized using either PTPv2 or NTPv4.
</t> 
 
      </section>

      <section anchor="sect-4.2" numbered="true" toc="default">
        <name>One-Way Measurement Mode</name>

<t>
As shown in <xref target="modes-reference-topology-one-way" format="default"/>, in the reference topology for one-way measurement mode, the STAMP Session-Sender S1 initiates a Session-Sender test packet. The STAMP Session-Reflector does not transmit Session-Reflector test packets upon receiving the Session-Sender test packets.
</t>


          <figure anchor="modes-reference-topology-one-way">
          <name>Reference Topology for One-Way Measurement Mode</name>
          <artwork name="" type="" align="left" alt=""><![CDATA[
                       T1                T2
                      /                   \
             +-------+     Test Packet     +-------+
             |       | - - - - - - - - - ->|       |
             |   S1  |=====================|   R1  |
             |       |                     |       |
             +-------+                     +-------+

       STAMP Session-Sender          STAMP Session-Reflector
  ]]></artwork>
        </figure>

<t>
T1 is a transmit timestamp added by node S1, and T2 is a receive timestamp added by node R1. Timestamps T1 and T2 are used by the Session-Reflector to measure the one-way delay metric as (T2 - T1).
</t>

<t>
The computation of the one-way delay metric requires the clocks on the Session-Sender and Session-Reflector to be synchronized using either PTPv2 or NTPv4.
</t>


      </section>

      <section anchor="sect-4.3" numbered="true" toc="default">
        <name>Loopback Measurement Mode</name>

<t>
As shown in <xref target="modes-reference-topology-for-loopback" format="default"/>, in the reference topology for loopback measurement mode, the STAMP Session-Sender S1 initiates a Session-Sender test packet to measure the loopback delay using source routing. At the STAMP Session-Reflector, the received STAMP test packets remain in the fast path in the data plane and are simply forwarded. In other words, the Session-Reflector does not perform STAMP functions or generate Session-Reflector test packets.
</t>

          <figure anchor="modes-reference-topology-for-loopback">
          <name>Reference Topology for Loopback Measurement Mode</name>
          <artwork name="" type="" align="left" alt=""><![CDATA[
                       T1 
                      /  
             +-------+     Test Packet     +-------+
             |       | - - - - - - - - - - |       |
             |   S1  |====================||   R1  |
             |       |<- - - - - - - - - - |       |
             +-------+  Return Test Packet +-------+
                      \                     
                       T4

       STAMP Session-Sender          STAMP Session-Reflector
                                           (Loopback, Forward)
]]></artwork>
            </figure>


<t>
The Session-Sender retrieves timestamp T1 from the received Session-Sender test packet and collects the receive timestamp T4 locally. The loopback delay is measured as (T4 - T1). This delay includes STAMP test packet processing on the Session-Reflector in data plane. The processing delay includes only the time required to forward the test packet from the incoming interface to the outgoing interface in the data plane. The Session-Reflector does not timestamp the test packets and therefore does not require timestamping capability.
The loopback delay is the round-trip delay as specified in <xref target="RFC2681" format="default"/>.
</t>

      </section>

      <section anchor="sect-4.4" numbered="true" toc="default">
        <name>Loopback Measurement Mode with TSF</name>

<t>
As shown in <xref target="modes-loopback-mode-with-tsf" format="default"/>, in the reference topology for "loopback measurement mode with TSF", the STAMP Session-Sender S1 initiates a Session-Sender test packet in loopback measurement mode using source routing. The TSF mechanism is used to optimize the operation of punting the test packet from the fast path in the data plane for control-plane processing and generating the return test packet on the STAMP Session-Reflector, as writing timestamp is implemented in the fast path in the data plane. This helps achieve a higher number of STAMP sessions and faster measurement intervals.
</t>

              <figure anchor="modes-loopback-mode-with-tsf">
          <name>Reference Topology for Loopback Measurement Mode with TSF</name>
          <artwork name="" type="" align="left" alt=""><![CDATA[
                       T1                T2
                      /                   \
             +-------+     Test Packet     +-------+
             |       | - - - - - - - - - - |       |
             |   S1  |====================||   R1  |
             |       |<- - - - - - - - - - |       |
             +-------+  Return Test Packet +-------+
                      \                    
                       T4

       STAMP Session-Sender          STAMP Session-Reflector
                                           (Loopback, TSF)
 ]]></artwork>
        </figure>

<t>
The Session-Sender adds the transmit timestamp (T1) to the payload of the Session-Sender test packet. The Session-Reflector writes the receive timestamp (T2) in the received STAMP test packet in the fast path in the data plane, without punting the test packet from the fast path in the data plane for control-plane STAMP processing.
</t>

<t>
The Session-Sender retrieves timestamps T1 and T2 from the received Session-Sender test packet and collects receive timestamp T4 locally. Timestamps T1 and T2 are used by the Session-Sender to measure the one-way delay metric as (T2 - T1). Timestamps T1 and T4 are used by the Session-Sender to measure the loopback delay metric as (T4 - T1).
</t>

      </section>

    </section>

    <section anchor="sect-5" numbered="true" toc="default">
      <name>STAMP Reference Model</name>

        <t>
  The STAMP Reference Model, along with some typical measurement 
  parameters, as defined in <xref target="RFC8972" format="default"/> for a STAMP session, is shown in <xref target="ure-reference-model" format="default"/>. 
    </t>

        <figure anchor="ure-reference-model">
          <name>STAMP Reference Model</name>
          <artwork name="" type="" align="left" alt=""><![CDATA[
                            +------------+
                            |    SDN     |
                            | Controller |
                            +------------+
                                 /  \
  Performance Measurement Mode  /    \         Stateful or Stateless 
  Destination UDP Port         /      \        Destination UDP Port
  Authentication Mode         /        \       Authentication Mode
      Keychain               /          \          Keychain
  Timestamp Format          /            \      Timestamp Format 
  SSID                     /              \     SSID (Stateful) 
  Metric Types            /                \  
                         v                  v
                     +-------+          +-------+
                     |       |  STAMP   |       |
                     |   S1  |==========|   R1  |
                     |       |  Session |       |
                     +-------+          +-------+

               STAMP Session-Sender  STAMP Session-Reflector
]]></artwork>
        </figure>

<t>
The procedure defined in <xref target="RFC8972" format="default"/> uses the two-way measurement mode.
</t>

    <t>
    The base STAMP test packet payloads specified in <xref target="RFC8972" format="default"/> are transported using an IP/UDP header and a destination UDP port <xref target="RFC6335" format="default"/>, selected as specified in <xref target="RFC8762" section="4.1" format="default"/>.
    The same destination port can be used for STAMP sessions for links, SR-MPLS paths, and L3 and L2 services carried over the SR-MPLS paths.
    </t>

<t>The source UDP port is selected by the Session-Sender. The same or different source UDP ports may be used for different STAMP sessions.</t>

<t>
The Session-Sender and Session-Reflector IP addresses for a STAMP session are provisioned on both endpoints of the session.
</t>

<t>Session-Reflector mode can be either Stateful or Stateless, as specified in <xref target="RFC8762" section="4" format="default"/>. Stateless Session-Reflector mode is applicable only in two-way measurement mode.</t>

<t>
The SSID in the STAMP test packets <xref target="RFC8972" format="default"/> must be set to a non-zero value in both directions.
The SSID in a STAMP test packet, along with the local configuration for the performance measurement mode, is used to identify STAMP sessions.
</t>

<t>
When authentication mode is enabled for STAMP sessions, the matching Authentication Type (e.g., HMAC-SHA-256) and Keychain must be configured on both the Session-Sender and Session-Reflector <xref target="RFC8762" format="default"/>.
</t>

<t>Examples of timestamp formats include 64-bit truncated Precision Time Protocol (PTPv2) <xref target="IEEE.1588" format="default"/> and 64-bit Network Time Protocol (NTPv4) <xref target="RFC5905" format="default"/>. By default, the Session-Reflector replies using the same timestamp format as received in the Session-Sender test packet, as indicated by the "Z" flag in the Error Estimate field, as specified in <xref target="RFC8762" format="default"/>. This behavior depends on the Session-Reflector's capability.</t>

<t>Examples of delay metrics are one-way delay, two-way delay, near-end delay (forward direction), and far-end delay (backward direction), as specified in <xref target="RFC8762" format="default"/>.</t>

<t>Examples of packet loss metric types are round-trip packet loss, near-end packet loss (forward direction), and far-end packet loss (backward direction), as specified in <xref target="RFC8762" format="default"/>.</t>

<t>
The IPv4 TTL, MPLS TTL, and IPv6 Hop Limit fields follow the specification in
<xref target="I-D.ietf-mpls-stamp-pw" format="default"/>.
</t>

<t>
The Flow Label field in the IPv6 header of the Session-Sender test packets is set to the value used by the data packets for
the IPv6 traffic flow being measured by the Session-Sender.
The Session-Reflector sets the Flow Label in its test packet to the value received in the Session-Sender test packet,
subject to local policy.
</t>

<t>A Software-Defined Networking (SDN) controller can be used for the configuration and management of STAMP sessions, as specified in <xref target="RFC8762" format="default"/>. The controller can also receive streaming telemetry of operational data. The YANG data model for STAMP, defined in <xref target="I-D.ietf-ippm-stamp-yang" format="default"/>, can be used to configure Session-Senders and Session-Reflectors and to stream telemetry of operational data.</t>

    <section anchor="sect-5.1" numbered="true" toc="default">
        <name>STAMP for One-Way Measurement Mode</name>
<t>
In one-way measurement mode, the Stateful mode of the Session-Reflector is used.
</t>
<t>
The SSID field in the received Session-Sender test packets <xref target="RFC8972" format="default"/> at the Session-Reflector, along with the local configuration, is used to identify the STAMP sessions that use one-way measurement mode on the Stateful Session-Reflector.
</t>

<t>
A different destination UDP port can be selected for one-way measurement mode than the one used by the Session-Reflector for two-way measurement mode.
When the same Session-Reflector UDP port is selected for one-way measurement mode, the Session-Sender requests, in the test packets, that the Session-Reflector not transmit Session-Reflector test packets. To achieve this, it uses the "No Reply Requested" flag in the Control Code Sub-TLV within the Return Path TLV defined in <xref target="RFC9503" format="default"/>.
</t>

    </section>

        <section anchor="sect-5.2" numbered="true" toc="default">
          <name>STAMP for Loopback Measurement Mode</name>

<t>
The Session-Reflector does not perform the STAMP process. Instead, its loopback function simply processes the IPv6/SRH header, ignoring the UDP header, to forward the test packet back to the Session-Sender without any STAMP modification.
</t>

<t>
The Session-Sender sets the destination UDP port to the UDP port it uses to receive return Session-Reflector test packets (other than UDP port 862, which is used by the Session-Reflector). The same UDP port is used as both the destination and source UDP port in the Session-Sender test packets.
</t>

<t>
At the Session-Sender, the "Session-Sender Sequence Number", the "Session-Sender Timestamp", the "Session-Sender Error Estimate", and the "Session-Sender TTL" fields <xref target="RFC8762" format="default"/> are all set to zero in the transmitted Session-Sender test packets and are ignored in the received test packets.
</t>
        </section>

            <section anchor="sect-5.3" numbered="true" toc="default">
          <name>STAMP for Loopback Measurement Mode with TSF</name>
<t>
The loopback measurement mode with TSF for the authenticated mode Session-Reflector test packet defined in Figure 4 of <xref target="RFC8972" section="3" format="default"/> requires recomputation of the HMAC key after writing the timestamp in the packet on the Session-Reflector. 
</t>
        </section>

              <section anchor="sect-5.4" numbered="true" toc="default">
        <name>Measurement Mode Comparison for STAMP</name>
        <table anchor="measurement-mode-comparison" align="center">
          <name>Measurement Mode Comparison for STAMP</name>
          <thead>
            <tr>
              <th align="left">Mode</th>
              <th align="left">Reflector</th>
              <th align="left">Timestamp</th>
              <th align="left">Clock Sync</th>
              <th align="left">Loss Metrics Applicable</th>
              <th align="left">Direct</th>
              <th align="left">Reference</th>
            </tr>
          </thead>
          <tbody>
          <tr><td>Two-Way</td><td>Stateful or Stateless</td><td>T1/T2/T3/T4</td><td>N1, N2</td><td>One-Way, Round-trip</td><td>Yes</td><td><xref target="RFC8762" format="default"/></td></tr>
            <tr><td>One-Way</td><td>Stateful</td><td>T1/T2</td><td>N1</td><td>One-Way</td><td>Yes</td><td>This document</td></tr>
            <tr><td>Loopback</td><td>N/A</td><td>T1/T4</td><td>N3</td><td>Round-trip</td><td>No</td><td>This document</td></tr>
            <tr><td>Loopback with TSF</td><td>N/A</td><td>T1/T2/T4</td><td>N1, N3</td><td>Round-trip</td><td>No</td><td>This document</td></tr>
          </tbody>
        </table>

    <t>
    N1: One-way delay metric computation requires clock synchronization.
    </t>
    <t>
    N2: Two-way delay metric computation does not require clock synchronization.
    </t>
    <t>
    N3: Loopback delay metric computation does not require clock synchronization.
    </t>

      </section>


    </section>
    

    <section anchor="sect-6" numbered="true" toc="default">
      <name>Encapsulations for Two-Way Measurement Mode</name>


    <section anchor="sect-6.1" numbered="true" toc="default">
        <name>Session-Sender Test Packet</name>
   <t>
  The content of a Session-Sender test packet is shown in <xref target="ure-dm-sender-test-packet" format="default"/>.
  The Session-Sender test packet payload, as defined in
  <xref target="RFC8972" section="3" format="default"/>,
  is transmitted with an IP header and a UDP header <xref target="RFC768" format="default"/>.
   </t>

        <figure anchor="ure-dm-sender-test-packet">
          <name>Content of Session-Sender Test Packet</name>
          <artwork name="" type="" align="left" alt=""><![CDATA[
 +---------------------------------------------------------------+
 | IP Header                                                     |
 .  Source IP Address = Session-Sender IP Address                .
 .  Destination IP Address = Session-Reflector IP Address        .
 .  IPv4 Protocol or IPv6 Next-header = 17 (UDP)                 .
 .                                                               .
 +---------------------------------------------------------------+
 | UDP Header                                                    |
 .  Source Port = Selected by Session-Sender                     .
 .  Destination Port = User-configured Destination Port Or 862   .
 .                                                               .
 +---------------------------------------------------------------+
 | Payload = Test Packet as specified in Figure 1 and Figure 3   |
 .           in Section 3 of RFC 8972                            .
 .                                                               .
 +---------------------------------------------------------------+
]]></artwork>
        </figure>

   </section>


<section anchor="sect-6.2" numbered="true" toc="default">
            <name>Session-Sender Test Packet for SR-MPLS Data Plane</name>

<section anchor="sect-6.2.1" numbered="true" toc="default">
            <name>Session-Sender Test Packet for SR-MPLS Paths</name>

<t>
An SR-MPLS Policy Candidate-Path contains one or more Segment Lists (i.e., a stack of MPLS labels) <xref target="RFC9256" format="default"/>.
For delay measurement of an SR-MPLS Policy, the Session-Sender test packets are transmitted for every Segment List of the Candidate-Path of the SR-MPLS Policy, by creating a separate STAMP session for each Segment List.
</t>

<t>
Each SR-MPLS Segment List contains a list of 32-bit Label Stack Entries (LSEs), where each LSE includes a 20-bit label value, an 8-bit Time to Live (TTL) field, a 3-bit Traffic Class (TC) field, and a 1-bit Bottom of Stack (BoS) field <xref target="RFC3032" format="default"/>.
</t>

<t>
The content of a Session-Sender test packet for an SR-MPLS path, using the SR-MPLS encapsulation of the data traffic transmitted over the path, is shown in <xref target="ure-test-packet-for-sr-mpls-policy" format="default"/>.
</t>

            <figure anchor="ure-test-packet-for-sr-mpls-policy">
              <name>Content of Session-Sender Test Packet for SR-MPLS Path</name>
              <artwork name="" type="" align="left" alt=""><![CDATA[
 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Label(1) (Top of Stack)    | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 .                                                               .
 .                                                               .
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Label(n)                   | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Test Packet as shown in Figure 6                   |
 .                                                               .
 +---------------------------------------------------------------+
]]></artwork>
            </figure>

<t>
An IP header is added that contains the head-end node address of the SR-MPLS Policy as the Source Address. 
There are two cases for the SR-MPLS Policy endpoints, as described below.
</t>

<ol>
    <li>
    <t>The endpoint address of the SR-MPLS Policy is used as the Destination Address in the IP header when it is specified and is not the null endpoint.</t>
    <t>In the case of Penultimate Hop Popping (PHP), the MPLS header is removed by the penultimate node. In this case, the specified Destination Address in the IP header ensures that the test packets reach the Session-Reflector at the SR-MPLS Policy endpoint.</t>
    </li>
    <li>
    <t>For an SR-MPLS Policy with Color-Only Destination Steering, where the endpoint is an unspecified address (the null endpoint is 0.0.0.0 for IPv4, as defined in <xref target="RFC9256" section="8.8.1" format="default"/>), a loopback address from the range 127/8 for IPv4 is used as the Destination Address in the IPv4 header.
    </t> 
    <t>
For IPv6 traffic, the IPv6 address of the Session-Sender is used as the Source Address, and an IPv6 address from the Dummy IPv6 Prefix 100:0:0:1::/64 block <xref target="RFC9780" format="default"/> <xref target="IANA-IPv6-REG" format="default"/> is used as the Destination Address in the IPv6 header.
    </t> 
    <t>
    In this case, the Session-Sender ensures that the Session-Sender test packets using the Segment List reach the Session-Reflector at the SR-MPLS Policy endpoint (for example, by adding the Prefix SID label of the SR-MPLS Policy endpoint to the Segment List). 
    </t>
    <t>
    In addition, the Session-Sender test packets may carry the "Destination Node IPv4 or IPv6 Address" STAMP TLV as defined in <xref target="RFC9503" format="default"/> to identify the intended Session-Reflector address.
    </t>
    </li>
</ol>

<t>
Each IGP Flex-Algo path in SR-MPLS networks <xref target="RFC9350" format="default"/> has Prefix SID labels advertised by the nodes. For delay measurement of SR-MPLS IGP Flex-Algo paths, the Session-Sender test packets carry the Flex-Algo Prefix SID labels of the Session-Sender and Session-Reflector in the MPLS header for that IGP Flex-Algo path under measurement.
</t>

<t>
Similarly, each IGP best path in SR-MPLS networks <xref target="RFC9350" format="default"/> has Prefix SID labels advertised by the nodes. For delay measurement of SR-MPLS IGP best paths, the Session-Sender test packets carry the IGP Prefix SID labels of the Session-Sender and Session-Reflector in the MPLS header for that IGP best path under measurement.
</t>

    </section>

    <section anchor="sect-6.2.2" numbered="true" toc="default">
          <name>Session-Sender Test Packet for Layer-3 Services over SR-MPLS Path</name>

<t>
For delay measurement of the L3 service carried over an SR-MPLS path, the SR-MPLS label stack of the data packets transmitted over the L3 service, including the L3 Virtual Private Network (L3VPN) label (advertised by the Session-Reflector), is used to encapsulate the Session-Sender test packets, as shown in <xref target="ure-test-packet-for-sr-l3-mpls" format="default"/>.
</t>

            <figure anchor="ure-test-packet-for-sr-l3-mpls">
              <name>Content of Session-Sender Test Packet for L3 Service over SR-MPLS Path</name>
              <artwork name="" type="" align="left" alt=""><![CDATA[
 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Label(1) (Top of Stack)    | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 .                                                               .
 .                                                               .
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            L3VPN Label                | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Test Packet as shown in Figure 6                   |
 .            Destination IP Address in L3VPN table              .
 .            Source IP Address in L3VPN table-reverse direction .
 .                                                               .
 +---------------------------------------------------------------+
]]></artwork>
            </figure>

<t>
An IP header, as shown in <xref target="ure-dm-sender-test-packet" format="default"/>, is added to the Session-Sender test packets after the MPLS header. The Destination Address in the IP header is reachable via the IP table lookup associated with the L3VPN label added for the L3 service on the Session-Reflector. The Source Address in the IP header of the Session-Sender test packets is reachable via the IP table lookup associated with the L3 service in the reverse direction.
</t>

      </section>

    <section anchor="sect-6.2.3" numbered="true" toc="default">
          <name>Session-Sender Test Packet for Layer-2 Services over SR-MPLS Path</name>

<t>
For delay measurement of the L2 service carried over an SR-MPLS path, the SR-MPLS label stack of the data packets transmitted over the L2 service, including the L2 Virtual Private Network (L2VPN) label (advertised by the Session-Reflector), is used to encapsulate the Session-Sender test packets, as shown in <xref target="ure-test-packet-for-sr-l2-mpls" format="default"/>.
</t>

     <figure anchor="ure-test-packet-for-sr-l2-mpls">
              <name>Content of Session-Sender Test Packet for L2 Service over SR-MPLS Path</name>
              <artwork name="" type="" align="left" alt=""><![CDATA[
 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Label(1) (Top of Stack)    | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 .                                                               .
 .                                                               .
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            L2VPN Label                | TC  |1|      TTL=1    |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Test Packet as shown in Figure 6                   |
 .                                                               .
 +---------------------------------------------------------------+
]]></artwork>
            </figure>

<t>
The L2VPN label is added with a TTL value of 1 to punt the Session-Sender STAMP test packet from the fast path in the data plane for control-plane processing on the Session-Reflector when using the Type 3 exception specified in <xref target="I-D.ietf-mpls-stamp-pw" format="default"/>.
</t>

<t>
An IP header, as shown in <xref target="ure-dm-sender-test-packet" format="default"/>, is added to the Session-Sender test packets after the MPLS header. This header contains the Session-Sender Address as the Source Address and the Session-Reflector Address as the Destination Address.
</t>

      </section>
      </section>


  <section anchor="sect-6.3" numbered="true" toc="default">
          <name>Session-Reflector Test Packet</name>

<t>
In two-way measurement mode, the Session-Reflector test packets are transmitted on the same SR-MPLS path (i.e., the same set of links and nodes) in the reverse direction to the Session-Sender to perform accurate two-way delay measurement.
</t>

<t>
The Session-Reflector decapsulates the MPLS header, if present, from the received Session-Sender test packets.
The Session-Reflector test packet is generated using the information from the received IP/UDP header of the Session-Sender test packet, as shown in <xref target="ure-test-reply-packet" format="default"/>.
</t>

        <figure anchor="ure-test-reply-packet">
          <name>Content of Session-Reflector Test Packet</name>
          <artwork name="" type="" align="left" alt=""><![CDATA[
 +---------------------------------------------------------------+
 | IP Header                                                     |
 .  Source IP Address                                            .
 .     = Session-Reflector IP Address                            .
 .  Destination IP Address                                       .
 .     = Source IP Address from Session-Sender Test Packet       .
 .  IPv4 Protocol or IPv6 Next-header = 17 (UDP)                 .
 .                                                               .
 +---------------------------------------------------------------+
 | UDP Header                                                    |
 .  Source Port = Selected by Session-Reflector                  .
 .  Destination Port                                             .
 .     = Source Port from Session-Sender Test Packet             .
 .                                                               .
 +---------------------------------------------------------------+
 | Payload = Test Packet as specified in Figure 2 and Figure 4   |
 .           in Section 3 of RFC 8972                            .
 .                                                               .
 +---------------------------------------------------------------+
]]></artwork>
        </figure>

<t>
The payload contains the Session-Reflector test packet defined in <xref target="RFC8972" section="3" format="default"/>.
</t>

<t>
For SR-MPLS paths, the Session-Sender uses
the Segment List sub-TLV in the Return Path TLV defined in <xref target="RFC9503" format="default"/>
to request that the Session-Reflector transmit the Session-Reflector test packet on a specific SR-MPLS return path.
</t>

<t>
Examples of specific SR-MPLS return paths include:
</t>

<ul>
  <li>The reverse SR-MPLS path associated with the forward direction SR-MPLS path.</li>
  <li>The Binding SID label of the reverse SR-MPLS Policy.</li>
  <li>The Prefix SID of the Session-Sender.</li>
</ul>

<t>
For SR-MPLS IGP Flex-Algo paths, the Session-Sender uses
the Segment List sub-TLV in the Return Path TLV defined in <xref target="RFC9503" format="default"/>
to request that the Session-Reflector transmit the Session-Reflector test packet on the same SR-MPLS IGP Flex-Algo path in the reverse direction.
</t>

        </section>
     </section>

         <section anchor="sect-7" numbered="true" toc="default">
      <name>Encapsulations for One-Way Measurement Mode</name>

<t>
In one-way measurement mode, for links, SR-MPLS paths, and L3 and L2 services carried over the SR-MPLS paths, the Session-Sender test packets with encapsulations as defined in <xref target="sect-6" format="default"/> for STAMP sessions, are transmitted.
As no Session-Reflector test packets are transmitted, the encapsulation for them defined in <xref target="sect-6" format="default"/> does not apply.
</t>

        </section>

        <section anchor="sect-8" numbered="true" toc="default">
          <name>Encapsulations for Loopback Measurement Mode</name>

<t>
In loopback measuement mode for SR-MPLS paths, and L3 and L2 services carried over the SR-MPLS paths, the Session-Sender test packets with encapsulations as defined <xref target="sect-6" format="default"/> for STAMP sessions, are transmitted. An IP header is added for the return path in the Session-Sender test packets, setting the Destination Address equal to the Session-Sender address, as shown in <xref target="ure-dm-sender-test-packet-lb-return" format="default"/>, to return the test packets to the Session-Sender.
</t>

        <figure anchor="ure-dm-sender-test-packet-lb-return">
          <name>Content of Session-Sender Return Test Packet in Loopback Measurement Mode</name>
          <artwork name="" type="" align="left" alt=""><![CDATA[
 +---------------------------------------------------------------+
 | IP Header (Return Path)                                       |
 .  Source IP Address = Session-Sender IP Address                .
 .  Destination IP Address = Session-Sender IP Address           .
 .  IPv4 Protocol or IPv6 Next-header = 17 (UDP)                 .
 .                                                               .
 +---------------------------------------------------------------+
 | UDP Header                                                    |
 .  Source Port = Selected by Session-Sender                     .
 .  Destination Port = Source Port                               .
 .                                                               .
 +---------------------------------------------------------------+
 | Payload = Test Packet as specified in Figure 1 and Figure 3   |
 .           in Section 3 of RFC 8972                            .
 .                                                               .
 +---------------------------------------------------------------+
]]></artwork>
        </figure>


  <section anchor="sect-8.1" numbered="true" toc="default">
       <name>Loopback Measurement Mode for SR-MPLS Paths</name>

<t>
In loopback measurement mode for SR-MPLS paths, the Session-Sender test packet carries either the Segment List of the forward direction path only or both the forward direction and return paths in the MPLS header, as specified in <xref target="RFC8403" format="default"/>, as shown in <xref target="ure-dm-sender-test-packet-lb-mpls" format="default"/>.
</t>

         <figure anchor="ure-dm-sender-test-packet-lb-mpls">
          <name>Content of Session-Sender Test Packet in Loopback Measurement Mode for SR-MPLS Path</name>
          <artwork name="" type="" align="left" alt=""><![CDATA[
 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Label(1) (Top of Stack)    | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 .                                                               .
 .                                                               .
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Label(n)                   | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Return Path Label(1)       | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 .                                                               .
 .                                                               .
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Return Path Label(n)       | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Test Packet as shown in Figure 11 (Return Path)    |
 .                                                               .
 +---------------------------------------------------------------+

       Example 1: Encapsulation Using SR-MPLS Return Path

 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Label(1) (Top of Stack)    | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 .                                                               .
 .                                                               .
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Label(n)                   | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Test Packet as shown in Figure 11 (Return Path)    |
 .                                                               .
 +---------------------------------------------------------------+

       Example 2: Encapsulation Using IP Return Path
]]></artwork>
        </figure>

<t>
In the case of an SR-MPLS Policy using PHP, the Session-Sender ensures that the STAMP test packets reach the SR-MPLS Policy endpoint, for example, by adding the Prefix SID label of the SR-MPLS Policy endpoint to the Segment List of the forward direction path.
</t>

<t>
The IP header for the return path is added to the Session-Sender test packets, and the Destination Address is set to the Session-Sender address in the IP header.
</t>

  <section anchor="sect-8.1.1" numbered="true" toc="default">
       <name>SR-MPLS Return Path</name>

<t>
The Session-Sender test packets, in the SR-MPLS label stack, carry the return path in addition to the forward direction path, as shown in Example 1 of <xref target="ure-dm-sender-test-packet-lb-mpls" format="default"/>. Examples of specific SR-MPLS return paths include:
</t>

<ul>
  <li>The SR-MPLS label stack of the Segment List of the associated reverse Candidate-Path.</li>
  <li>The Binding SID label of the reverse SR-MPLS Policy.</li>
  <li>The SR-MPLS Prefix SID label of the Session-Sender.</li>
</ul>

<t>
For SR-MPLS IGP Flex-Algo paths, the Session-Sender test packets carry the SR-MPLS Prefix SID label of the Session-Sender on the same SR-MPLS IGP Flex-Algo path in the reverse direction.
</t>

<t>
The Binding SID label of the reverse SR-MPLS Policy can be configured on the Session-Sender using, for example, an SDN controller.
</t>

   </section>

  <section anchor="sect-8.1.2" numbered="true" toc="default">
       <name>IP Return Path</name>

<t>
The Session-Sender test packets, in the MPLS header, carry only the SR-MPLS label stack of the forward direction path, as shown in Example 2 of <xref target="ure-dm-sender-test-packet-lb-mpls" format="default"/>.
</t>

<t>
The Session-Reflector decapsulates the MPLS header and forwards the test packet using the IP header back to the Session-Sender.
</t>

   </section>
   </section>

      <section anchor="sect-8.2" numbered="true" toc="default">
         <name>Loopback Measurement Mode for Layer-3 Services over SR-MPLS Path</name>

<t>
In loopback measurement mode for the L3 service carried over an SR-MPLS path, the SR-MPLS label stack of the data packets transmitted over the L3 service is used to encapsulate the Session-Sender test packets, as shown in <xref target="ure-dm-sender-test-packet-lb-l3-mpls" format="default"/>.
</t>

         <figure anchor="ure-dm-sender-test-packet-lb-l3-mpls">
          <name>Content of Session-Sender Test Packet in Loopback Measurement Mode for L3 Service over SR-MPLS Path</name>
      <artwork name="" type="" align="left" alt=""><![CDATA[
 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Label(1) (Top of Stack)    | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 .                                                               .
 .                                                               .
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Label(n)                   | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Return Path Label(1)       | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 .                                                               .
 .                                                               .
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            L3VPN Label (Return Path)  | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Test Packet as shown in Figure 11 (Return Path)    |
 .            Source and Destination IP Address in L3VPN table   .
 .                                                               .
 +---------------------------------------------------------------+

       Example 1: Encapsulation Using SR-MPLS Return Path


 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Label(1) (Top of Stack)    | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 .                                                               .
 .                                                               .
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            L3VPN Label (Forward Path) | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Test Packet as shown in Figure 11 (Return Path)    |
 .            Source and Destination IP Address in L3VPN table   .
 .                                                               .
 +---------------------------------------------------------------+

       Example 2: Encapsulation Using IP Return Path
]]></artwork>
        </figure>

<t>
The IP header for the return path of the Session-Sender test packets is added, setting the Destination Address to the Session-Sender address. The Destination Address added in the IP header for the return path must be reachable via the IP table lookup associated with the L3VPN label added to the test packets.
</t>

  <section anchor="sect-8.2.1" numbered="true" toc="default">
       <name>SR-MPLS Return Path</name>

<t>
The SR-MPLS label stack for the forward direction L3 service, excluding the L3VPN label advertised by the Session-Reflector, is added to the Session-Sender test packets.
</t>

<t>
In addition, the SR-MPLS label stack for the reverse direction L3 service, including its L3VPN label advertised by the Session-Sender, is added to the Session-Sender test packets.
 </t>

  </section>

  <section anchor="sect-8.2.2" numbered="true" toc="default">
        <name>IP Return Path</name>

<t>
The SR-MPLS label stack, including the L3VPN label (advertised by the Session-Reflector) for the forward direction L3 service, is added to the Session-Sender test packets.
</t>

<t>
The Session-Reflector decapsulates the MPLS header and forwards the Session-Sender test packet back to the Session-Sender using the IP header, after adding SR-MPLS encapsulation for the reverse direction L3 service.
</t>

   </section>

   </section>

    <section anchor="sect-8.3" numbered="true" toc="default">
       <name>Loopback Measurement Mode for Layer-2 Services over SR-MPLS Path</name>

<t>
In loopback measurement mode for the L2 service carried over an SR-MPLS path, the SR-MPLS label stack of the data packets transmitted over the L2 service is used to encapsulate the Session-Sender test packets, as shown in <xref target="ure-dm-sender-test-packet-lb-l2-mpls" format="default"/>.
</t>


         <figure anchor="ure-dm-sender-test-packet-lb-l2-mpls">
          <name>Content of Session-Sender Test Packet in Loopback Measurement Mode for L2 Service over SR-MPLS Path</name>
          <artwork name="" type="" align="left" alt=""><![CDATA[
 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Label(1) (Top of Stack)    | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 .                                                               .
 .                                                               .
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Label(n)                   | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Return Path Label(1)       | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 .                                                               .
 .                                                               .
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            L2VPN Label (Return Path)  | TC  |1|      TTL=1    |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Test Packet as shown in Figure 11 (Return Path)    |
 .                                                               .
 +---------------------------------------------------------------+

              Encapsulation Using SR-MPLS Return Path
]]></artwork>
        </figure>

   <t>
The IP header for the return path is added to the Session-Sender test packets, and the Destination Address is set to the Session-Sender address.
</t>

  <section anchor="sect-8.3.1" numbered="true" toc="default">
        <name>SR-MPLS Return Path</name>

<t>
The SR-MPLS label stack for the forward direction L2 service, excluding the L2VPN label advertised by the Session-Reflector, is added to the Session-Sender test packets.
</t>

<t>
In addition, the SR-MPLS label stack for the reverse direction L2 service, including its L2VPN label advertised by the Session-Sender, is added to the Session-Sender test packets with a TTL value of 1 to punt STAMP test packets from the fast path in the data plane for control-plane processing on the Session-Sender when using the Type 3 exception specified in <xref target="I-D.ietf-mpls-stamp-pw" format="default"/>.
</t>


   </section>

  <section anchor="sect-8.3.2" numbered="true" toc="default">
        <name>IP Return Path</name>
    <t>
    The STAMP test packets that do not use the SR-MPLS return path are not supported.
    </t>

   </section>
   </section>


   </section>

    <section anchor="sect-9" numbered="true" toc="default">
      <name>Encapsulations for Loopback Measurement Mode with TSF</name>

      <t>
      The encapsulations for loopback measurement mode with TSF is defined for SR-MPLS paths and does not support L3 and L2 services carried over the SR-MPLS paths.
      </t>


<section anchor="sect-9.1" toc="default" numbered="true">
    <name>STAMP TSF Network Actions</name>

<t>
The MPLS Network Action (MNA) Sub-Stack is specified in <xref target="RFC9994" format="default"/>.

This document defines two MPLS Network Action opcodes for TSF:
</t>

<ul>
  <li>STAMP TSF with PTPv2 (opcode TBA1): A 64-bit PTPv2 timestamp written at a begin offset of 16 bytes from the start of the STAMP test packet payload.</li>
  <li>STAMP TSF with NTPv4 (opcode TBA2): A 64-bit NTPv4 timestamp written at a begin offset of 16 bytes from the start of the STAMP test packet payload.</li>
  <li>Format: The LSE Format B or the LSE Format C <xref target="RFC9994" format="default"/> can carry either TSF opcode.</li>
  <li><t>Scope: The Ingress-to-Egress (I2E), Hop-by-Hop, and Select (IHS) field <xref target="RFC9994" format="default"/>.</t>
          <t>Must be set to "Select" when the return path is SR-MPLS (see <xref target="sect-8.1.1" format="default"/>) because the node that writes the timestamp pops the top label but does not remove the MPLS header.</t>
  <t>Must be set to "I2E" when the return path is IP/UDP (see <xref target="sect-8.1.2" format="default"/>) because the node that writes the timestamp removes the MPLS header and forwards the packet using the IP header.</t></li>
  <li>Ancillary Data: Set to 0.</li>
  <li>Interactions: The TSF opcodes do not interact with other network action opcodes.</li>
  <li>The U bit, Network Action Sub-Stack Length (NASL), and Network Action Length (NAL) are set as defined in <xref target="RFC9994" format="default"/>.</li>
</ul>

<t>
The timestamp is written in the "Receive Timestamp" field <xref target="RFC8972" format="default"/>, located at a begin offset of 16 bytes from the start of the STAMP test packet payload, as shown in the Session-Reflector test packet in Figure 2 of <xref target="RFC8972" section="3" format="default"/>.
</t>

<t>
In the Session-Sender test packets for SR-MPLS paths in loopback measurement mode with TSF, the MNA Sub-Stack with applicable TSF opcode is added to the MPLS header, as shown in <xref target="ure-test-packet-header-for-sr-mpls-with-timestamp-label" format="default"/>. 
</t>

        <figure anchor="ure-test-packet-header-for-sr-mpls-with-timestamp-label">
          <name>Content of Session-Sender Test Packet in Loopback Measurement Mode with TSF Network Action in Format-B LSE for SR-MPLS Paths</name>
          <artwork name="" type="" align="left" alt=""><![CDATA[
 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Label(1) (Top of Stack)    | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 .                                                               .
 .                                                               .
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Label(n)                   | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            MNA Label                  | TC  |S|      TTL      |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |  7-bit TBA1 |  13-bit (value 0x0)     |R|IHS|S|  NASL |U| NAL |
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 .                                                               .
 .                                                               .
 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
 |            Test Packet as shown in Figure 11 (Return Path)    |
 .                                                               .
 +---------------------------------------------------------------+
  ]]></artwork>
        </figure>

<t>
The SR-MPLS label stack of the return path can be added after the MNA Sub-Stack to receive the return test packet on a specific path, as described in the loopback measurement mode for SR-MPLS paths in this document. 
</t>

<t>
When a Session-Reflector receives a STAMP test packet with an MNA Sub-Stack containing opcode TBA1 or TBA2, it writes the timestamp in the STAMP test packet payload, pops the MNA Sub-Stack (after completing any other network actions), and forwards the test packet as defined in the loopback measurement mode for SR-MPLS paths. 
</t>

        <section anchor="sect-9.1.1" toc="default" numbered="true">
          <name>TSF Network Action Node Capability</name>

<t>
The Session-Sender needs to know if the Session-Reflector is capable of processing applicable opcode TBA1 or TBA2, to avoid dropping the test packets. This capability can be locally configured on the Session-Sender or signaled. Signaling extensions for this capability exchange are outside the scope of this document.
</t>

        </section>
    </section>

    </section>

    <section anchor="sect-10" numbered="true" toc="default">
      <name>Packet Loss Measurement in SR-MPLS Networks</name>

<t>
The procedure described for two-way measurement mode supports inferred measurements of round-trip, near-end (forward direction), and far-end (backward direction) packet loss. However, this provides only an approximate view of data packet loss.
</t>

<t>
The loopback measurement mode and loopback measurement mode with TSF, defined in this document, allow only round-trip packet loss measurement.
</t>

<t>
Note that the packet loss measurement does not require the clocks on the Session-Sender and Session-Reflector to be synchronized using either PTPv2 or NTPv4.
</t>

    </section>

    <section anchor="sect-11" numbered="true" toc="default">
      <name>Direct Measurement in SR-MPLS Networks</name>

 <t>
The STAMP "Direct Measurement" TLV (Type 5), defined in <xref target="RFC8972" format="default"/>, is used for data packet loss measurement. To collect direct-measurement counters for data packet flows, STAMP test packets containing this TLV are transmitted using the two-way measurement-mode procedure. The procedure collects Session-Sender transmit counters and Session-Reflector receive and transmit counters.
</t>

<t>
The receive data traffic can be measured as follows:
</t>

<ul>
<li>
The Path Segment Identifier (PSID) <xref target="RFC9545" format="default"/> of an SR-MPLS Policy (for the Segment List or for the Candidate-Path) 
may be carried in the data packets to measure received data traffic (for the receive packet counter) on the associated SR-MPLS path when the egress node supports PSID processing.
</li>

<li>
In the case of L3 and L2 services in SR-MPLS networks, the associated SR-MPLS service labels are used to measure received data traffic (for the receive packet counters) on the Session-Reflector.
</li>
</ul>

<t>
In loopback measurement mode and loopback measurement mode with TSF, direct measurement is not applicable.
</t>

    </section>

    <section anchor="sect-12" numbered="true" toc="default">
      <name>ECMP Measurement in SR-MPLS Networks</name>

<t>
The Segment List of an SR-MPLS path can have ECMP paths between the source and transit nodes, between transit nodes, and between transit and destination nodes, due to, for example:
</t>

      <ul>
        <li>Use of a node SID <xref target="RFC8402" format="default"/>.</li>

        <li>Use of an Anycast SID <xref target="RFC8402" format="default"/>, which can result in ECMP paths via transit nodes that are part of that anycast group.</li>
      </ul>

<t>
The STAMP test packets are transmitted to traverse different ECMP paths to measure the delay of each ECMP path of a Segment List, and can use the following mechanisms:
</t>

<ul>
  <li>Different entropy label values <xref target="RFC6790" format="default"/> are used in the Session-Sender and Session-Reflector test packets to take advantage of the hashing function in the forwarding plane and influence the ECMP path taken by the packets.</li>

  <li>Different Destination Address values from the IPv4 range 127/8 are used in the Session-Sender and Session-Reflector test packets to traverse different IPv4 ECMP paths, as described in <xref target="RFC8029" section="2.1" format="default"/>. In this case, the Session-Sender test packets may carry the "Destination Node IPv4 or IPv6 Address" STAMP TLV, as defined in <xref target="RFC9503" format="default"/>, to identify the intended Session-Reflector IP address.</li>
</ul>

<t>
The considerations for loss measurement for different ECMP paths of an SR-MPLS path are outside the scope of this document.
</t>

    </section>

    <section anchor="sect-14" numbered="true" toc="default">
      <name>Implementation Status</name>
    <t>
    Editorial note: Please remove this section prior to publication.
    </t>

    <section anchor="sect-14.1" numbered="true" toc="default">
      <name>Cisco Implementation</name>

    <t>
    The following Cisco routing platforms running IOS-XR operating system have participated in
    interoperability testing for one-way, two-way, and loopback measurement modes for SR-MPLS:
    </t>

    <t>
    *  Cisco 8000 (based on Cisco Silicon One ASIC)
      </t>

    <t>
    *  Cisco ASR9904 with Lightspeed linecard and Tomahawk linecard
      </t>

    <t>
    *  Cisco NCS5500 (based on Broadcom Jericho1 ASIC)
      </t>

    <t>
    *  Cisco NCS5700 (based on Broadcom Jericho2 ASIC)
      </t>

    </section>

    </section>

    <section anchor="sect-15" numbered="true" toc="default">
      <name>Operational and Manageability Considerations</name>

<t>
The operational considerations specified in <xref target="RFC8762" section="5"/> also apply to the procedures specified in this document.
Further, the operation and management considerations for performance measurement based on STAMP specified in <xref target="RFC8762" section="3"/>
also apply to the procedures specified in this document.
The manageability considerations described in <xref target="RFC8402" section="9" format="default"/> apply to this specification.
</t>

    
<t>
When a destination UDP port number other than the default port 862 is used, the same
network-impact study and agreement requirements specified in <xref target="RFC8762" section="4.1"/> apply.
</t>

<t>
The operational considerations specified in <xref target="RFC9994" format="default"/> are also applicable to the procedures described in this document.
</t>

<t>
Various statistics for one-way (near-end, far-end), two-way, and loopback delay metrics (such as average delay, minimum delay, maximum delay, and delay variance) as well as for one-way (near-end, far-end) or round-trip packet loss metrics (such as percentage loss and consecutive packets lost) and the STAMP session state changes can be computed using the performance measurement procedures described in this document.  Operator alerts are generated for anomaly detection when delay or loss metrics cross user-configured thresholds or when the STAMP session state changes.
</t>

<t>
When STAMP sessions are created for the Segment Lists of the SR-MPLS Policies, the scalability regarding the number of STAMP sessions needs to be carefully considered.
</t>

<t>
The operational considerations specified in <xref target="I-D.ietf-mpls-stamp-pw" format="default"/> apply when selecting a routable or non-routable IP address as a destination address.
</t>

<section anchor="sect-15.1" numbered="true" toc="default">
  <name>STAMP Session State Notification</name>

<t>
The threshold-based notification for delay and packet loss metrics is generated only
when the metrics change significantly. For unambiguous
monitoring, the controller needs to distinguish whether the STAMP session is active
but delay and packet loss metrics did not cross the thresholds, or whether the STAMP session
has failed and is not transmitting or receiving test packets.
</t>

<t>
The STAMP session state monitoring allows the node to determine whether the performance measurement test is active, idle, or failed.
</t>

<t>
The failed state of the STAMP session also indicates the connectivity failure
of the SR-MPLS path or of the L3/L2 service carried over the SR-MPLS path, where the STAMP session was active.
</t>

<t>
In all measurement modes, the STAMP session state is notified as idle when the Session-Sender is not transmitting test packets.
</t>

<t>
In two-way measurement mode, loopback measurement mode, and loopback measurement mode with TSF, STAMP session state is notified on Session-Sender as follows:
</t>

<ul>
  <li>The STAMP session state is initially notified as active on the Session-Sender when the Session-Sender is transmitting test packets and at least one Session-Reflector test packet has been received.</li>
  <li>The STAMP session state is notified as failed when N consecutive Session-Reflector test packets are not received at the Session-Sender after the STAMP session state is notified as active, where N (the consecutive packet loss count) is a locally provisioned value.</li>
</ul>

<t>
Similarly, in one-way measurement mode, STAMP session state is notified on Session-Reflector as follows:
</t>

<ul>
  <li>The STAMP session state is initially notified as active on the Session-Reflector once one or more Session-Sender test packets are received.</li>
  <li>The STAMP session state is notified as failed when N consecutive Session-Sender test packets are not received at the Session-Reflector after the STAMP session state is notified as active, where N (the consecutive packet loss count) is a locally provisioned value.</li>
</ul>

</section>

<section anchor="sect-15.2" numbered="true" toc="default">
  <name>Operational Considerations for TSF</name>

<t>
The TSF network action processing depends on the applicable TSF opcode and the corresponding timestamp format capability. Operators should verify Session-Reflector support for the applicable TSF opcode before enabling STAMP sessions with the TSF network action.
</t>

<t>
Implementations should maintain per-network-action counters for the following TSF Network Action events:
</t>

<ul>
  <li>Packets with TSF Network Action received.</li>
  <li>Packets with TSF Network Action invocations.</li>
  <li>Packets with TSF Network Action dropped because the action was unknown.</li>
  <li>Packets with TSF Network Action forwarded when the action was unknown.</li>
  <li>Packets with TSF Network Action dropped because of malformed packet.</li>
  <li>Packets with TSF Network Action timestamp write failures.</li>
</ul>

<t>
Successful and failed TSF network action invocations should be distinguishable. Notifications for sustained failures, malformed packets, or excessive packets with the TSF network action should be rate-limited.
</t>

</section>

    </section>

    <section anchor="sect-16" numbered="true" toc="default">
      <name>Security Considerations</name>
<t>
The security considerations specified in <xref target="RFC8762" format="default"/>, <xref target="RFC8972" format="default"/>, and <xref target="RFC9503" format="default"/> also apply to the procedures described in this document.
</t>

<t>
The measures specified in <xref target="RFC8762" section="7"/> to mitigate attacks also apply.
</t>

<t>
The security considerations specified in <xref target="RFC9994" format="default"/> and <xref target="I-D.ietf-mpls-stamp-pw" format="default"/> are also applicable to the procedures described in this document.
</t>

<t>
The use of HMAC-SHA-256 in authenticated mode protects the data integrity of the STAMP test packets. The message integrity protection using HMAC, as specified in <xref target="RFC8762" section="4.4" format="default"/>, can be used with the procedures described in this document.
</t>

<t>The source UDP port number should be selected using a randomized allocation method as specified in
  <xref target="RFC6056"/> to provide protection against off-path attacks, as recommended in <xref target="RFC8085"/>.</t>

<t>
Furthermore, SSIDs <xref target="RFC8972"/> should not be assigned predictably. To avoid predictability, implementations can use a cryptographically secure pseudorandom number generator
  <xref target="NIST-CSPRNG" format="default"/>.</t>


<t>
The procedures defined in this document are intended for deployment in a single network administrative domain. As such, the Session-Sender address, Session-Reflector address, and the forward direction and return paths are provisioned by the operator for the STAMP session. It is assumed that the operator has verified the integrity of the forward direction and return paths of the STAMP test packets.
</t>

   <t>
  Implementations can mitigate attacks by performing basic validation
  checks on Session-Reflector test packets received at the Session-Sender, such as verifying that
  timestamp T2 is later than timestamp T1 (when the Session-Sender and Session-Reflector clocks are synchronized) 
  in the STAMP Reference Topology shown in <xref target="modes-reference-topology-two-way"/>.  The minimal state
  associated with this protocol also limits the extent of measurement
  disruption that can be caused by a corrupt or invalid test packet to a
  single test cycle.</t>


<t>
STAMP test packets received through a transport path or a service context must be processed only in that context. This document does not provide a mechanism for cross-service OAM interactions.
</t>

<section anchor="sect-16.1" numbered="true" toc="default">
  <name>Security Considerations for TSF</name>

<t>
The TSF network action uses the IANA-assigned opcodes TBA1 and TBA2 with timestamp formats and begin offsets. 
Their processing therefore needs to be restricted to trusted nodes and trusted STAMP sessions.
An attacker that can inject packets with the TSF network action could cause unauthorized data-plane timestamping or influence measured paths.
Network operators need to filter MPLS packets carrying the TSF Network Action at administrative-domain boundaries and are expected to restrict the action to Session-Reflector nodes that support the applicable TSF opcode.
</t>

<t>
The Session-Reflector writes the timestamp specified by opcode TBA1 or TBA2 in the STAMP test packet payload. Implementations need to validate the MNA Sub-Stack, opcode, timestamp format, and available payload length before writing the timestamp. Bounds checking is required to prevent malformed packets from causing memory corruption, packet corruption, or denial-of-service conditions. Any malformed packet with the TSF network action needs to be dropped.
</t>

</section>

    </section>
    <section anchor="sect-17" numbered="true" toc="default">
      <name>IANA Considerations</name>
      <t>
    IANA is requested to assign code points from the Network Action Opcodes registry
    created in <xref target="RFC9994" format="default"/> as specified in <xref target="tsf-network-action-opcodes" format="default"/>.
    </t>

    <table anchor="tsf-network-action-opcodes" align="center">
      <name>Network Action Opcodes</name>
      <thead>
        <tr>
          <th align="left">Opcode</th>
          <th align="left">Description</th>
          <th align="left">In-Stack Only, Post-Stack Only, In-Stack and Post-Stack</th>
          <th align="left">Reference</th>
        </tr>
      </thead>
      <tbody>
        <tr>
          <td align="left">TBA1</td>
          <td align="left">STAMP TSF with PTPv2</td>
          <td align="left">In-Stack Only</td>
          <td align="left">This document</td>
        </tr>
        <tr>
          <td align="left">TBA2</td>
          <td align="left">STAMP TSF with NTPv4</td>
          <td align="left">In-Stack Only</td>
          <td align="left">This document</td>
        </tr>
      </tbody>
    </table>
    </section>
  </middle>
  <back>
    <references>
      <name>References</name>
      <references>
        <name>Normative References</name>

    &RFC768;
    &RFC2119;
    &RFC4026;
    &RFC6335;
    &RFC8174;
    &RFC8762;
    &RFC8972;
    &RFC9503;
    &RFC9994;
    &I-D.ietf-mpls-stamp-pw;

      </references>

      <references>
        <name>Informative References</name>

    &RFC3031;
    &RFC3032;
    &RFC2681;
    &RFC5462;
    &RFC5905;
    &RFC6056;
    &RFC6234;
    &RFC6790;
    &RFC8029;
    &RFC8085;
    &RFC8402;
    &RFC8403;
    &RFC9256;
    &RFC9350;
    &RFC9545;
    &RFC9780;

    &I-D.ietf-ippm-stamp-yang;

    <reference anchor="IEEE.1588">
          <front>
            <title>1588-2008 IEEE Standard for a Precision Clock Synchronization Protocol for Networked Measurement and Control Systems</title>
            <author>
              <organization>IEEE</organization>
            </author>
            <date month="March" year="2008"/>
          </front>
    </reference>

    <reference anchor="NIST-CSPRNG" target="https://csrc.nist.gov/pubs/sp/800/90/a/r1/final">
      <front>
        <title>Recommendation for Random Number Generation Using Deterministic Random Bit Generators, Revision 1</title>
        <author>
          <organization>National Institute of Standards and Technology</organization>
        </author>
        <date year="2015"/>
      </front>
      <seriesInfo name="NIST Special Publication" value="800-90A Revision 1"/>
    </reference>

    <reference anchor="IANA-IPv6-REG" target="https://www.iana.org/assignments/iana-ipv6-special-registry" quoteTitle="true">
      <front>
        <title>IANA IPv6 Special-Purpose Address Registry</title>
        <author>
          <organization>IANA</organization>
        </author>
      </front>
    </reference>

    </references>
    </references>

    <section numbered="false" anchor="acknowledgments" toc="default">
      <name>Acknowledgments</name>
      <t>
The authors would like to thank Ianik Semco and Thierry Couture for their discussions on the use cases for Performance Measurement in Segment Routing. The authors would also like to thank Greg Mirsky, Gyan Mishra, Xie Jingrong, Zafar Ali, Boris Hassanov, Ruediger Geib, Liyan Gong, Zhenqiang Li, Maria Matejka, William Hawkins, Mike Koldychev, and Bruno Decraene for reviewing this document and providing useful comments and suggestions. Additionally, Patrick Khordoc, Haowei Shi, Amila Tharaperiya Gamage, Pengyan Zhang, Ruby Lin, Senni Tan, and Radu Valceanu have helped improve the mechanisms described in this document. The authors would also like to thank Haoyu Song for the Shepherd's review and Alvaro Retana for the WG chair's review, which helped improve this document.
      </t>
    </section>

  <section numbered="false" anchor="contributors">
  <name>Contributors</name>

   <t>The following people have substantially contributed to this document:</t>

   <artwork><![CDATA[Daniel Voyer
Cisco Systems, Inc.
Email: davoyer@cisco.com

]]></artwork>

   <artwork><![CDATA[Navin Vaghamshi
Reliance
Email: Navin.Vaghamshi@ril.com

]]></artwork>

   <artwork><![CDATA[Moses Nagarajah
Individual
Email: mosesnehru@gmail.com

]]></artwork>

   <artwork><![CDATA[Amit Dhamija
Arrcus
India
Email: amitd@arrcus.com

]]></artwork>

    </section>

  </back>
</rfc>
