RSVP – OAM BFD
1. Intro
We can configure OAM BFD for LSPs to detect LSP data plane faults.
To bootstrap the OAM BFD session, there is an initial exchange of MPLS Ping packets (Echo Request/Reply) between the ingress and egress routers, that is using UDP port 3503.
After the initial MPLS Ping exchange, the routers will exchange BFD control packets using UDP port 3784.
The Ingress router will always use source Loopback address and destination 127.0.0.1, for both Ping and BFD packets.
The Egress router will always use the Loopbacks for both source and destination, for both Ping and BFD packets.
2. OAM BFD simple configuration
### The topology is not really that important.
### There is an LSP from R1 to R7:
root@R1# run show rsvp session ingress
Ingress RSVP: 1 sessions
To From State Rt Style Labelin Labelout LSPname
17.0.0.7 17.0.0.1 Up 0 1 FF - 303152 R1-to-R7
Total 1 displayed, Up 1, Down 0
### We will activate OAM BFD for this LSP:
set protocols mpls label-switched-path R1-to-R7 to 17.0.0.7
set protocols mpls label-switched-path R1-to-R7 oam bfd-liveness-detection minimum-interval 300
### Note: It is probably a good idea to configure a more forgiving 300 ms instead of the default 50 ms.
### After about 1 minute, the BFD is established between R1 and R7:
root@R1# run show mpls lsp ingress extensive name R1-to-R7
Ingress LSP: 2 sessions
17.0.0.7
From: 17.0.0.1, State: Up, ActiveRoute: 0, LSPname: R1-to-R7, LSPid: 40
ActivePath: (primary)
LSPtype: Static Configured, Penultimate hop popping
LoadBalance: Random
Follow destination IGP metric
Encoding type: Packet, Switching type: Packet, GPID: IPv4
LSP Self-ping Status : Enabled
*Primary State: Up
Priorities: 7 0
OptimizeTimer: 30
SmartOptimizeTimer: 180
Flap Count: 0
MBB Count: 0
Reoptimization in 15 second(s).
Computed ERO (S [L] denotes strict [loose] hops): (CSPF metric: 3000)
17.1.3.3 S 17.3.6.6 S 17.6.7.7 S
Received RRO (ProtectionFlag 1=Available 2=InUse 4=B/W 8=Node 10=SoftPreempt 20=Node-ID):
17.1.3.3(Label=303152) 17.3.6.6(Label=302880) 17.6.7.7(Label=3)
OAM state : BFD session up LSP-ping up
10 Jul 31 05:39:07.302 CSPF: computation result ignored, new path no benefit
9 Jul 31 05:38:39.163 Selected as active path
8 Jul 31 05:38:39.162 Self-ping ended successfully
7 Jul 31 05:38:38.656 Up
6 Jul 31 05:38:38.656 Self-ping started
5 Jul 31 05:38:38.656 Self-ping enqueued
4 Jul 31 05:38:38.656 Record Route: 17.1.3.3(Label=303152) 17.3.6.6(Label=302880) 17.6.7.7(Label=3)
3 Jul 31 05:38:38.621 LSP-ID: 1 created
2 Jul 31 05:38:38.621 Originate Call
1 Jul 31 05:38:38.621 CSPF: computation result accepted 17.1.3.3 17.3.6.6 17.6.7.7
Created: Fri Jul 31 05:38:38 2026
Total 1 displayed, Up 1, Down 0
### We can also see the BFD session:
root@R1# run show bfd session extensive
Detect Transmit
Address State Interface Time Interval Multiplier
127.0.0.1 Up ge-0/0/2.0 0.900 0.300 3
Client RSVP-OAM, TX interval 0.300, RX interval 0.300
Session up time 01:17:36
Local diagnostic None, remote diagnostic None
Remote state Up, version 1
Session type: Multi hop BFD
Min async interval 0.300, min slow interval 1.000
Adaptive async TX interval 0.300, RX interval 0.300
Local min TX interval 0.300, minimum RX interval 0.300, multiplier 3
Remote min TX interval 0.050, min RX interval 0.050, multiplier 3
Local discriminator 16, remote discriminator 16
Echo TX interval 0.000, echo detection interval 0.000
Echo mode disabled/inactive
LSP-Name R1-to-R7
Session ID: 0
1 sessions, 1 clients
Cumulative transmit rate 3.3 pps, cumulative receive rate 3.3 pps
### And some logs for the same:
Jul 31 07:39:57 R1 bfdd[19335]: BFDD_TRAP_STATE_UP: local discriminator: 17, new state: up
Jul 31 07:39:57 R1 rpd[19435]: RPD_MPLS_PATH_BFD_UP: BFD session for MPLS path came up on LSP R1-to-R7
### With Wireshark captures we can see the initial MPLS PING exchange:
### Notice the ingress router is encapsulating the packet with MPLS labels.
### Also notice the Destination address is 127.0.0.1 and port number is 3505.
Frame 200: Packet, 118 bytes on wire (944 bits), 118 bytes captured (944 bits)
Ethernet II, Src: 56:04:0d:00:5f:c7 (56:04:0d:00:5f:c7), Dst: 56:04:0d:00:0c:37 (56:04:0d:00:0c:37)
MultiProtocol Label Switching Header, Label: 302880, Exp: 6, S: 1, TTL: 254
Internet Protocol Version 4, Src: 17.0.0.1, Dst: 127.0.0.1
User Datagram Protocol, Src Port: 55467, Dst Port: 3503
Multiprotocol Label Switching Echo
Version: 1
Global Flags: 0x0001
0000 0000 0000 0... = Reserved: 0x0000
.... .... .... ...1 = Validate FEC Stack: True
.... .... .... ..0. = Respond only if TTL expired: False
.... .... .... .0.. = Validate Reverse Path: False
Message Type: MPLS Echo Request (1)
Reply Mode: Reply via an IPv4/IPv6 UDP packet (2)
Return Code: No return code (0)
Return Subcode: 0
Sender's Handle: 0x10017941
Sequence Number: 0
Timestamp Sent: Jul 31, 2026 14:39:50.721470999 UTC
Timestamp Received: Jan 1, 1970 00:00:00.000000000 UTC
Target FEC Stack
Type: Target FEC Stack (1)
Length: 24
FEC Element 1: RSVP IPv4 Session Query
Type: RSVP IPv4 Session Query (3)
Length: 20
IPv4 Tunnel endpoint address: 17.0.0.7
Must Be Zero: 0
Tunnel ID: 31041
Extended Tunnel ID: 0x11000001
IPv4 Tunnel sender address: 17.0.0.1
Must Be Zero: 0
LSP ID: 1
BFD Discriminator TLV
Type: BFD Discriminator TLV (15)
Length: 4
BFD Discriminator: 0x00000011
### Notice the MPLS PING Reply has no MPLS labels:
Frame 201: Packet, 74 bytes on wire (592 bits), 74 bytes captured (592 bits)
Ethernet II, Src: 56:04:0d:00:0c:37 (56:04:0d:00:0c:37), Dst: 56:04:0d:00:5f:c7 (56:04:0d:00:5f:c7)
Internet Protocol Version 4, Src: 17.0.0.7, Dst: 17.0.0.1
User Datagram Protocol, Src Port: 3503, Dst Port: 55467
Multiprotocol Label Switching Echo
Version: 1
Global Flags: 0x0001
0000 0000 0000 0... = Reserved: 0x0000
.... .... .... ...1 = Validate FEC Stack: True
.... .... .... ..0. = Respond only if TTL expired: False
.... .... .... .0.. = Validate Reverse Path: False
Message Type: MPLS Echo Reply (2)
Reply Mode: Reply via an IPv4/IPv6 UDP packet (2)
Return Code: Replying router is an egress for the FEC at stack depth RSC (3)
Return Subcode: 1
Sender's Handle: 0x10017941
Sequence Number: 0
Timestamp Sent: Jul 31, 2026 14:39:50.721470999 UTC
Timestamp Received: Jul 31, 2026 14:39:50.724317999 UTC
### And the BFD CONTROL Packets, Ingress to Egress:
Frame 245: Packet, 74 bytes on wire (592 bits), 74 bytes captured (592 bits)
Ethernet II, Src: 56:04:0d:00:5f:c7 (56:04:0d:00:5f:c7), Dst: 56:04:0d:00:0c:37 (56:04:0d:00:0c:37)
MultiProtocol Label Switching Header, Label: 302880, Exp: 6, S: 1, TTL: 254
Internet Protocol Version 4, Src: 17.0.0.1, Dst: 127.0.0.1
User Datagram Protocol, Src Port: 49152, Dst Port: 3784
BFD Control message
001. .... = Protocol Version: 1
...0 0000 = Diagnostic Code: No Diagnostic (0x00)
11.. .... = Session State: Up (0x3)
Message Flags: 0xc0
Detect Time Multiplier: 3 (= 900 ms Detection time)
Message Length: 24 bytes
My Discriminator: 0x00000011
Your Discriminator: 0x00000011
Desired Min TX Interval: 300 ms (300000 us)
Required Min RX Interval: 300 ms (300000 us)
Required Min Echo Interval: 0 ms (0 us)
### BFD CONTROL, EGRESS to Ingress
Frame 246: Packet, 66 bytes on wire (528 bits), 66 bytes captured (528 bits)
Ethernet II, Src: 56:04:0d:00:0c:37 (56:04:0d:00:0c:37), Dst: 56:04:0d:00:5f:c7 (56:04:0d:00:5f:c7)
Internet Protocol Version 4, Src: 17.0.0.7, Dst: 17.0.0.1
User Datagram Protocol, Src Port: 49152, Dst Port: 3784
BFD Control message
001. .... = Protocol Version: 1
...0 0000 = Diagnostic Code: No Diagnostic (0x00)
11.. .... = Session State: Up (0x3)
Message Flags: 0xc0
Detect Time Multiplier: 3 (= 150 ms Detection time)
Message Length: 24 bytes
My Discriminator: 0x00000011
Your Discriminator: 0x00000011
Desired Min TX Interval: 50 ms (50000 us)
Required Min RX Interval: 50 ms (50000 us)
Required Min Echo Interval: 0 ms (0 us)
2. RE Filter
This was simple enough. But in a production environment we will have RE Filters on Loopback0.
Let’s add an RE-PROTECT Filter on our Loopback interface, where we will also have to permit the UPD ports used by OAM BFD.
### Create a FW filter:
root@R1# show | display set | match RE-PROTECT
set interfaces lo0 unit 0 family inet filter input RE-PROTECT
set firewall family inet filter RE-PROTECT term SSH from protocol tcp
set firewall family inet filter RE-PROTECT term SSH from port ssh
set firewall family inet filter RE-PROTECT term SSH then accept
set firewall family inet filter RE-PROTECT term OSPF from protocol ospf
set firewall family inet filter RE-PROTECT term OSPF then accept
set firewall family inet filter RE-PROTECT term RSVP from protocol rsvp
set firewall family inet filter RE-PROTECT term RSVP then accept
set firewall family inet filter RE-PROTECT term DENY then reject
### But BFD session is not allowed yet, so it is down:
root@R1# run show mpls lsp ingress extensive
Ingress LSP: 1 sessions
17.0.0.7
From: 17.0.0.1, State: Up, ActiveRoute: 0, LSPname: R1-to-R7, LSPid: 40
ActivePath: (primary)
LSPtype: Static Configured, Penultimate hop popping
LoadBalance: Random
Follow destination IGP metric
Encoding type: Packet, Switching type: Packet, GPID: IPv4
LSP Self-ping Status : Enabled
*Primary State: Up
Priorities: 7 0
OptimizeTimer: 30
SmartOptimizeTimer: 180
Flap Count: 0
MBB Count: 0
Reoptimization in 12 second(s).
Computed ERO (S [L] denotes strict [loose] hops): (CSPF metric: 3000)
17.1.3.3 S 17.3.6.6 S 17.6.7.7 S
Received RRO (ProtectionFlag 1=Available 2=InUse 4=B/W 8=Node 10=SoftPreempt 20=Node-ID):
17.1.3.3(Label=303152) 17.3.6.6(Label=302880) 17.6.7.7(Label=3)
OAM state : BFD session not up LSP-ping up
13 Aug 3 06:49:22.642 BFD session down on path[2 times, first Aug 3 06:38:50.818]
12 Aug 3 06:37:17.454 LSP ping failure on path
11 Aug 3 06:33:31.778 BFD session down on path
10 Jul 31 08:32:41.387 CSPF: computation result ignored, new path no benefit[4 times, first Jul 31 05:39:07.302]
9 Jul 31 05:38:39.163 Selected as active path
8 Jul 31 05:38:39.162 Self-ping ended successfully
7 Jul 31 05:38:38.656 Up
6 Jul 31 05:38:38.656 Self-ping started
5 Jul 31 05:38:38.656 Self-ping enqueued
4 Jul 31 05:38:38.656 Record Route: 17.1.3.3(Label=303152) 17.3.6.6(Label=302880) 17.6.7.7(Label=3)
3 Jul 31 05:38:38.621 LSP-ID: 1 created
2 Jul 31 05:38:38.621 Originate Call
1 Jul 31 05:38:38.621 CSPF: computation result accepted 17.1.3.3 17.3.6.6 17.6.7.7
Created: Fri Jul 31 05:38:38 2026
Total 1 displayed, Up 1, Down 0
root@R1# run show bfd session
0 sessions, 0 clients
Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
### Let's add port 3504:
root@R1# show | compare
[edit firewall family inet filter RE-PROTECT]
term RSVP { ... }
+ term BFD {
+ from {
+ protocol udp;
+ port 3503;
+ }
+ then accept;
+ }
term DENY { ... }
[edit]
root@R1# commit
commit complete
### Junos is trying to bring up the BFD session, but not succesfuly:
root@R1# run show bfd session
Detect Transmit
Address State Interface Time Interval Multiplier
127.0.0.1 Down ge-0/0/2.0 0.000 1.000 3
1 sessions, 1 clients
Cumulative transmit rate 1.0 pps, cumulative receive rate 0.0 pps
### We must also allow port 3784:
root@R1# show | compare
[edit firewall family inet filter RE-PROTECT term BFD from]
- port 3503;
+ port [ 3503 3784 ];
[edit]
root@R1# commit
commit complete
### Now the BFD session is UP:
root@R1# run show bfd session
Detect Transmit
Address State Interface Time Interval Multiplier
127.0.0.1 Up ge-0/0/2.0 0.900 0.300 3
1 sessions, 1 clients
Cumulative transmit rate 3.3 pps, cumulative receive rate 3.3 pps
root@R1# run show mpls lsp ingress extensive
Ingress LSP: 1 sessions
17.0.0.7
From: 17.0.0.1, State: Up, ActiveRoute: 0, LSPname: R1-to-R7, LSPid: 40
ActivePath: (primary)
LSPtype: Static Configured, Penultimate hop popping
LoadBalance: Random
Follow destination IGP metric
Encoding type: Packet, Switching type: Packet, GPID: IPv4
LSP Self-ping Status : Enabled
*Primary State: Up
Priorities: 7 0
OptimizeTimer: 30
SmartOptimizeTimer: 180
Flap Count: 0
MBB Count: 0
Reoptimization in 2 second(s).
Computed ERO (S [L] denotes strict [loose] hops): (CSPF metric: 3000)
17.1.3.3 S 17.3.6.6 S 17.6.7.7 S
Received RRO (ProtectionFlag 1=Available 2=InUse 4=B/W 8=Node 10=SoftPreempt 20=Node-ID):
17.1.3.3(Label=303152) 17.3.6.6(Label=302880) 17.6.7.7(Label=3)
OAM state : BFD session up LSP-ping up
13 Aug 3 06:49:22.642 BFD session down on path[2 times, first Aug 3 06:38:50.818]
12 Aug 3 06:37:17.454 LSP ping failure on path
11 Aug 3 06:33:31.778 BFD session down on path
10 Jul 31 08:32:41.387 CSPF: computation result ignored, new path no benefit[4 times, first Jul 31 05:39:07.302]
9 Jul 31 05:38:39.163 Selected as active path
8 Jul 31 05:38:39.162 Self-ping ended successfully
7 Jul 31 05:38:38.656 Up
6 Jul 31 05:38:38.656 Self-ping started
5 Jul 31 05:38:38.656 Self-ping enqueued
4 Jul 31 05:38:38.656 Record Route: 17.1.3.3(Label=303152) 17.3.6.6(Label=302880) 17.6.7.7(Label=3)
3 Jul 31 05:38:38.621 LSP-ID: 1 created
2 Jul 31 05:38:38.621 Originate Call
1 Jul 31 05:38:38.621 CSPF: computation result accepted 17.1.3.3 17.3.6.6 17.6.7.7
Created: Fri Jul 31 05:38:38 2026
Total 1 displayed, Up 1, Down 0
### The lesson here is that we need both 3504 and 3784 for OAM BFD.
External Resources: