Segment Routing

IS-IS Micro-Loop Avoidance in OcNOS 6.3: Preventing Transient Forwarding Loops

In Layer 3 networks, IS-IS and OSPF prevent permanent loops by computing loop-free shortest paths. However, during network convergence, the brief period after a topology change while all routers are updating their forwarding tables, transient micro-loops can form. A micro-loop occurs when two adjacent routers have inconsistent forwarding tables: Router A has already updated its path to a destination, but Router B has not yet, causing packets to bounce between them until B converges.

While micro-loops are short-lived (typically milliseconds to seconds), they can saturate links and cause significant packet loss during high-traffic periods. OcNOS 6.3 introduces IS-IS micro-loop avoidance based on an ordered FIB update, the mechanism defined in RFC 6976, which sequences forwarding-table changes across the domain so no inconsistent state is ever exposed.

How Micro-Loops Form

IS-IS topology: R1 Source reaches R5 Destination via R1-R2-R3-R4-R5 (metric 10 each); dashed R3-R4 micro-loop that OcNOS 6.3 ordered FIB prevents.
Figure 1. Traffic from Source R1 to Destination R5 follows the primary IS-IS path R1 to R2 to R3 to R4 to R5, where every link has metric 10 and the direct R1 to R4 link is available but costs 40. During IS-IS convergence a transient micro-loop can form between an already converged and a not yet converged neighbor (shown here between R3 and R4). OcNOS 6.3 micro-loop avoidance uses ordered FIB updates to stop this loop from ever forming.

Ordered FIB: IS-IS Micro-Loop Avoidance in OcNOS 6.3

OcNOS 6.3 implements micro-loop avoidance as an ordered FIB (oFIB) process, following RFC 6976. The insight is that a micro-loop appears only when routers update their forwarding tables in the wrong order. If every router installs the new next-hop for a destination only after the router it now points to has already converged, no transient loop can ever form. OcNOS enforces exactly that ordering.

When a topology change is detected, each router computes both the reverse shortest-path tree (rSPT) and the shortest-path tree (SPT) for the affected prefixes and assigns every node a rank equal to its depth in hops within that tree. Rather than installing all new forwarding entries at once, the router installs them in ranked order, releasing each rank only after the preceding ranks have had time to complete. Routers closest to the change update first and routers further away follow, so an upstream router never redirects traffic toward a downstream router that has not yet converged.

The install time for each rank is governed by a simple relationship: T0 + H + (rank * MAX_FIB), where T0 is the arrival time of the triggering LSP, H is the configured hold-down time, and MAX_FIB is a network-wide constant representing the maximum time any router needs to update its FIB. Multiplying the rank by MAX_FIB staggers the ranks far enough apart that each level of the tree is guaranteed to finish before the next one begins.

The hold-down time and the FIB update constant are both configurable per level. The microloop-avoidance hold-timer option sets H and the microloop-avoidance max-fib option sets MAX_FIB, each accepting a value from 1 to 60 for level-1 or level-2. Once a level has walked through all ranks and its ordered FIB update is complete, its state machine reaches OFIB_STABLE, which you can confirm with the verification command below.

! OcNOS 6.3 IS-IS micro-loop avoidance configuration
!
router isis 1
 is-type level-1
 microloop-avoidance level-1
 microloop-avoidance level-2
 microloop-avoidance hold-timer <1-60> <level-1|level-2>  <=== Optional
 microloop-avoidance max-fib <1-60> <level-1|level-2>     <=== Optional
 net 49.0000.0000.0001.00
!

! Verification
PE1#sh isis microloop-avoidance detail
Tag 1: VRF : default
Level-1 status:
FSM State: OFIB_STABLE

Level-2 status:
FSM State: OFIB_STABLE

PE1#

Ordered FIB and TI-LFA Work Together

Ordered FIB micro-loop avoidance is a distinct mechanism from TI-LFA, and the two address different parts of a topology change. The table below summarizes the division of labor.

Mechanism Protects Against Activation
TI-LFA The failure event itself, using a pre-computed backup path BFD detection, <50ms
Ordered FIB micro-loop avoidance Transient loops while the domain reconverges Any topology change (link up or down)

These two mechanisms complement each other. TI-LFA provides the immediate backup path the instant a failure is detected, keeping traffic flowing on a pre-computed route. Ordered FIB then governs the convergence window that follows, sequencing every router's forwarding-table update so the network settles onto the new shortest paths without ever passing through an inconsistent, loop-prone state. Together they protect against both the failure event and the transient convergence artifacts that follow it.


IP Infusion Engineering Team

Partager