Segment Routing

ISIS-SR with TI-LFA in OcNOS: Topology-Independent Fast Reroute

Part of IP Infusion's guide to Segment Routing.

Fast Reroute (FRR) is the network's ability to pre-compute backup paths and switch to them in under 50 milliseconds when a link or node fails, before routing protocols have had time to reconverge. TI-LFA (Topology-Independent Loop-Free Alternate) is the most advanced FRR mechanism available today, providing 100% protection coverage against single link, node, and SRLG failures across any topology, without the coverage gaps of classic LFA or Remote LFA.

FRR Evolution: LFA, RLFA, and TI-LFA

Mécanisme Comment ça marche Couverture Limitation
LFA Pre-computed neighbor that is not affected by the failure ~60 to 80% Topology-dependent; many failures have no LFA
RLFA LDP tunnel to remote repair node ~95% Requires LDP; repair node must be P-space
TI-LFA SR segment stack to any post-convergence path node 100% Requires Segment Routing (IS-IS or OSPF)

TI-LFA achieves this coverage by computing the post-convergence path (the path traffic would take after the network fully reconverges following the failure) and encoding it as an SR segment stack. This stack is pre-computed and pre-installed. When the failure occurs, the router immediately redirects traffic using the segment stack, with no need for signaling.

TI-LFA Network Topology

IS-IS SR topology: seven OcNOS routers R1 to R7 with loopbacks 10.10.10.101 to 10.10.10.107 and node-SIDs 16101 to 16107. R2 is the Point of Local Repair and R6 the destination: the solid SPF primary path runs R2 to R4 to R6 at cost 65, and the dashed TI-LFA repair for an R2 to R4 failure runs R2, R1, R3, R5, R7, R6 with R1 as the PQ node. Each link is labelled with its IGP metric.
IS-IS Segment Routing with TI-LFA in OcNOS. Seven routers R1 to R7 carry loopbacks 10.10.10.101 to 10.10.10.107 and prefix node-SIDs 16101 to 16107. R2 is the Point of Local Repair and R6 the destination: R2 reaches R6 through R4 at a cost of 65 (45 + 20), shown solid. TI-LFA protects the R2 to R4 link, and the repair it pre-installs is the post-convergence path R2, R1, R3, R5, R7, R6, shown dashed, with R1 as the PQ node. IGP metrics are on the links: R1-R2 10, R1-R3 10, R2-R4 45, R3-R5 10, R4-R5 30, R4-R6 20, R5-R7 20, R6-R7 20. There is no R2-R3 link.

Configuring ISIS-SR with TI-LFA in OcNOS

! OcNOS -- IS-IS SR with TI-LFA
! Shown on R2, the Point of Local Repair (PLR) analyzed in this lab.
! Enable TI-LFA on every router in the IS-IS domain.
!
! ---- Prerequisite: IS-IS Segment Routing (from the ISIS-SR setup) ----
! segment-routing mpls is enabled under the IS-IS instance; the node
! SID is set on the loopback with prefix-sid index. R2's node SID label
! seen in the SR forwarding plane is 16102 (SRGB base 16000 + index 102).
!
router isis OCNOS
  is-type level-2-only
  segment-routing mpls
!
interface lo
  ip address 127.0.0.1/8
  ip address 10.10.10.102/32 secondary
  ip router isis OCNOS
  prefix-sid index 102
!
! ---- Core interfaces (IS-IS point-to-point) ----
! xe4.95  faces R1  (neighbor 10.10.12.1, metric 10)
! xe21.93 faces R4  (neighbor 10.10.24.4, metric 45)
interface xe4.95
  ip router isis OCNOS
  isis network point-to-point
  isis metric 10
!
interface xe21.93
  ip router isis OCNOS
  isis network point-to-point
  isis metric 45
!
! ---- Enable TI-LFA for IS-IS level-2, IPv4 ----
router isis OCNOS
  fast-reroute ti-lfa level-2 proto ipv4
  commit
!
! Note: the fast-reroute TI-LFA command must be enabled for the
! respective IS-IS levels on every router in the domain. Node protection
! is computed automatically when a valid PQ path exists (see below).

Verification Commands

These commands walk the case in the figure above: destination R6, reached through R4 at a cost of 65, with the R2 to R4 link protected. Which node becomes the PQ node depends on one value, the R1 to R3 metric, and it is worth changing it to watch the repair move. At the 10 shown above the PQ node is R1; raise it to 30 and the PQ node becomes R3; raise it to 100 and there is no common PQ node at all, so TI-LFA falls back to a disjoint P and Q pair. Note which command you need: isis metric is the narrow metric and OcNOS caps it at 63, so the first two cases are isis metric 10 et isis metric 30, while the third is isis wide-metric 100. One metric change and a re-run of the three commands below is the whole demonstration.

! OcNOS -- TI-LFA verification (run on R2, the PLR)
!
! Step 1: IS-IS topology and metrics
show isis topology
! Tag OCNOS:  VRF : default
! IS-IS paths to level-2 routers
! System Id     Metric   Next-Hop        Interface       SNPA
! R4            45       R4    xe21.93    e8c5.7a46.5c33
! R1            10       R1    xe4.95     e8c5.7aa0.a142
! R6            65       R4    xe21.93    e8c5.7a46.5c33

! Step 2: TI-LFA P-space / Q-space / PQ node for a destination (R6)
show isis tilfa pq | be Node: R6.00-00

! Step 3: Primary and TI-LFA backup path for a prefix (R6 = 10.10.10.106/32)
show ip isis route tilfa | be 10.10.10.106/32

! Step 4: MPLS forwarding-table (FTN): primary and backup on the source router
show mpls forwarding-table 10.10.10.106/32

! Step 5: MPLS ILM-table: primary and backup on the transit router
show mpls ilm-table 10.10.10.106/32
!
! What each of these prints on a real router is shown in the capture below.

The output below was captured on 2 October 2026 on R5, an OcNOS 7.0.1 router in IP Infusion's lab, running IS-IS level-2 with segment-routing mpls et fast-reroute ti-lfa level-2 proto ipv4 in a four-router core (R3, R4, R5 and R6). Router names, addresses and labels are that lab's, not the topology above. It follows one destination, R4 (4.4.4.4/32): the primary path leaves R5 on xe6.200, and the pre-installed repair goes through the PQ node R3 (3.3.3.3) on po35.200. Long tables are cut to the rows for that destination and its repair trunk.

R5-S9510-28DC#show isis tilfa pq

Tag 1: Level-2 Link State Database:

Node: R4-S9510-28DC.00-00
 Interface xe6.200
  PQ Node: R3-S9510-28DC.00-00 backup dist:10
  No PQ Node found on backup path (Node Protection)

Node: R6-S9510-30XC.00-00
 Interface po56.200
  PQ Node: R3-S9510-28DC.00-00 backup dist:10
  No PQ Node found on backup path (Node Protection)

R5-S9510-28DC#show ip isis route tilfa

Tag   : 1  VRF : default
Codes : L1 - IS-IS level-1, L2 - IS-IS level-2,
        C - Connected Routes, ia - IS-IS inter area

3.3.3.3/32
   Route type: L2, FTN-ix :3  ILM-ix :4784
   SR Incoming Label      : 17003
   Primary Path Nexthop   : 11.3.5.0, po35.200
     SR outgoing Label    : 3
     PQ node              : 44.4.4.4
     Backup outgoing Label: 17003
     Bypass_trunk id      : 2203
     Backup out interface : xe6.200
     Protection Type      : Link Protecting

   Trunk : 2202 :3.3.3.3_nh_492667080_ALG0   FTN-ix : 20 ref_cnt:8
   Number Of outgoing label : 1
    3
   Nexthop address : 11.3.5.0


4.4.4.4/32
   Route type: L2, FTN-ix :2  ILM-ix :4782
   SR Incoming Label      : 17004
   Primary Path Nexthop   : 11.4.5.4, xe6.200
     SR outgoing Label    : 3
     PQ node              : 3.3.3.3
     Backup outgoing Label: 17004
     Bypass_trunk id      : 2202
     Backup out interface : po35.200
     Protection Type      : Link Protecting

R5-S9510-28DC#show mpls forwarding-table

Codes: > - installed FTN, * - selected FTN, p - stale FTN, ! - using backup
       B - BGP FTN, K - CLI FTN, (t) - tunnel, P - SR Policy FTN, (b) - bypass,
       L - LDP FTN, R - RSVP-TE FTN, S - SNMP FTN, I - IGP-Shortcut,
       U - unknown FTN, O - SR-OSPF FTN, i - SR-ISIS FTN, k - SR-CLI FTN
       (m) - FTN mapped over multipath transport, (e) - FTN is ECMP

FTN-ECMP LDP: Enabled, SR: Disabled
Code    FEC                 FTN-ID    Nhlfe-ID  Tunnel-ID   Pri   Out-Label    Out-Intf    ELC       Nexthop         Algo-Num   UpTime
   i>   3.3.3.3/32          3         1447      -           -     -            -           -         -               0          2d15h10m
                                      1401      0           Yes   3            po35.200    No        11.3.5.0        -          -
                                      1544      -           No    17003        xe6.200     No        11.4.5.4        -          -
i(b)>   3.3.3.3/32          20        1401      2202        Yes   3            po35.200    No        11.3.5.0        0          2d15h08m
   i>   4.4.4.4/32          2         1463      -           -     -            -           -         -               0          02w3d08h
                                      1445      0           Yes   3            xe6.200     No        11.4.5.4        -          -
                                      1457      -           No    17004        po35.200    No        11.3.5.0        -          -

R5-S9510-28DC#show mpls ilm-table

Codes: > - installed ILM, * - selected ILM, p - stale ILM, ! - using backup
       K - CLI ILM, T - MPLS-TP, s - Stitched ILM
       S - SNMP, L - LDP, R - RSVP, C - CRLDP
       B - BGP , K - CLI , V - LDP_VC, I - IGP_SHORTCUT
       O - OSPF/OSPF6 SR, i - ISIS SR, k - SR CLI
       P - SR Policy,       U - unknown, UPStr - upstream

ILM-ECMP LDP: Enabled, SR: Disabled
Code    FEC/VRF/L2CKT    ILM-ID      In-Label    Out-Label   In-Intf    Out-Intf/VRF       Nexthop                 pri  Algo-Num  UpTime    UPStr peers
   i>   4.4.4.4/32         4782        17004       3           N/A        xe6.200          11.4.5.4                Yes  0         02w3d09h
                                       17004       17004       N/A        po35.200         11.3.5.0                No   -          -
! OcNOS -- Node protection vs link protection
!
! TI-LFA works out node protection by itself: show isis tilfa pq lists the
! node-protecting P nodes with no extra configuration, and on OcNOS 7.0.1
! "fast-reroute ti-lfa level-2 proto ipv4" takes no further keyword.
! The result is reported per prefix in the Protection Type field: a
! node-protecting backup avoids the next-hop router as well as the link,
! a link-protecting one avoids the link only.
!
! For each destination, the PQ computation gives the link-protecting PQ node,
! then the node-protecting one, or says that none was found:
show isis tilfa pq | be Node: R6.00-00
!
! The per-prefix route output reports the protection type and the repair
! (bypass) trunk that carries the pre-computed segment stack:
show ip isis route tilfa | be 10.10.10.106/32
!
! The repair trunk itself (label stack and nexthop) is listed under the
! PQ node's own prefix:
show ip isis route tilfa | be 10.10.10.101/32
!
! In the R5 capture above, every backup is Link Protecting and each node
! reports "No PQ Node found on backup path (Node Protection)", so that core
! offers link protection only. Trunk 2202 is the repair tunnel to the PQ
! node R3, listed under 3.3.3.3/32.

IP Infusion Engineering Team

Partager