Ethernet CFM 802.1ag: Service OAM Configuration Guide - 夜莺博客

Ethernet CFM 802.1ag: Service OAM Configuration Guide

A green link light, a converged spanning tree and a resolved ARP entry do not prove that a customer circuit is actually forwarding frames. Ethernet has no native mechanism to test a service end to end, and that is exactly the gap IEEE 802.1ag Connectivity Fault Management (CFM) fills. CFM adds in-band heartbeat messages, an Ethernet loopback ("ethernet ping") and a hop-by-hop linktrace that works at Layer 2 the way ICMP works at Layer 3. This guide explains the CFM hierarchy and then shows working configurations for Cisco IOS/IOS-XE and Junos EX/QFX devices, along with the verification commands you need when a service — not just a port — goes dark.

What CFM Actually Solves

Three fault-management protocols are defined by 802.1ag and extended by ITU-T Y.1731:

  • Continuity Check Messages (CCM) — periodic multicast heartbeats (Ethertype 0x8902, destination MAC 01:80:c2:00:00:32) used for proactive fault detection.
  • Loopback (LBM/LBR) — a unicast "ethernet ping" to a MEP or MIP for fault verification.
  • Linktrace (LTM/LTR) — a multicast trace that lists every maintenance point along the path for fault isolation.

Because CFM frames travel in-band with customer traffic and are forwarded as ordinary data by devices that do not understand them, the protocol works across third-party transport without any control-plane cooperation.

The CFM Hierarchy: MD, MA, MEP, MIP

Object Meaning Key detail
Maintenance Domain (MD) An administrative boundary — customer, provider or operator Level 0–7; the higher the level, the broader the scope. Domains may nest but never intersect.
Maintenance Association (MA) One service instance inside a domain Identified by MD name + short MA name (VLAN ID, VPN ID, integer or string).
MEP Maintenance association end point at the edge of the domain MEP ID 1–8191; up or down direction; sends and terminates CCMs.
MIP Maintenance intermediate point inside the domain Passive; replies only to loopback and linktrace.

Two design rules prevent most field failures: a port that carries a MIP at a lower level must not carry a maintenance point at a higher level, and the domain level must match exactly on both ends of a CCM relationship — a level mismatch makes MEPs invisible to each other while every interface still shows "up".

Configuring CFM on Cisco IOS and IOS-XE

Step 1 — enable CFM globally and define the domain

enable
configure terminal
ethernet cfm ieee
ethernet cfm global
ethernet cfm traceroute cache
ethernet cfm alarm notification all
ethernet cfm domain ISP-DOMAIN level 5
 service CUST-EVC vlan 2100 direction down
  continuity-check interval 10s
  continuity-check loss-threshold 3
 exit
exit

Step 2 — attach the MEP to the service instance or port

interface GigabitEthernet4/2
 service instance 2100 ethernet EVC-CUST
  encapsulation dot1q 2100
  cfm mep domain ISP-DOMAIN mpid 102
  cfm mep domain ISP-DOMAIN monitor loss counter
 exit
exit

On a plain access port, the same MEP can be bound directly to the interface with ethernet cfm mep domain <domain> mpid <id> service <ma-name>. Use direction down when the MEP should talk to the wire (typical for CE-to-PE handoff) and the default up direction when it must survive a spanning-tree blocked port.

Step 3 — configure MIPs on transit devices

ethernet cfm domain ISP-DOMAIN level 5
 service CUST-EVC vlan 2100
  mip auto-create

Step 4 — verify

show ethernet cfm maintenance-points local
show ethernet cfm maintenance-points remote
show ethernet cfm errors
show ethernet cfm domain brief
ethernet cfm loopback 0011.2233.4455 domain ISP-DOMAIN mpid 201 source mpid 102
ethernet cfm linktrace 0011.2233.4455 domain ISP-DOMAIN mpid 201

The remote MEP table is the one that matters operationally: if the remote MEP never appears, CCM is not being received — check the MA name, VLAN and — most often — the maintenance level. If it appears and then flaps, look at show ethernet cfm errors for cross-connect, unexpected-MEP and level-mismatch counters.

Configuring CFM on Junos EX and QFX Switches

set protocols oam ethernet connectivity-fault-management maintenance-domain ISP-DOMAIN level 5
set protocols oam ethernet connectivity-fault-management maintenance-domain ISP-DOMAIN maintenance-association CUST-EVC continuity-check interval 10s
set protocols oam ethernet connectivity-fault-management maintenance-domain ISP-DOMAIN maintenance-association CUST-EVC continuity-check hold-interval 10
set protocols oam ethernet connectivity-fault-management maintenance-domain ISP-DOMAIN maintenance-association CUST-EVC mep 102 interface ge-0/0/10.2100
set protocols oam ethernet connectivity-fault-management maintenance-domain ISP-DOMAIN maintenance-association CUST-EVC mep 102 direction down
set protocols oam ethernet connectivity-fault-management maintenance-domain ISP-DOMAIN maintenance-association CUST-EVC mep 102 auto-discovery
set protocols oam ethernet connectivity-fault-management maintenance-domain ISP-DOMAIN maintenance-association CUST-EVC mep 102 remote-mep 201 action-profile LOC-ALARM
show oam ethernet connectivity-fault-management interfaces
show oam ethernet connectivity-fault-management mep-database
show oam ethernet connectivity-fault-management mip
show oam ethernet connectivity-fault-management statistics

On the MIP side, Junos switches support the MIP half function (MHF), which answers linktrace and loopback for a level without creating a full MIP on every VLAN — useful on large L2 fabrics where every access port should be visible to operator-level CFM.

Adding Y.1731 Performance Monitoring

Once continuity is proven, Y.1731 adds on-demand and proactive measurement. Cisco IOS IP SLA provides the Ethernet-specific probes:

ip sla 10
 ethernet y1731 delay DMM domain ISP-DOMAIN evc EVC-CUST mpid 201 cos 5 source mpid 102
  frame interval 100
  aggregate interval 300
 exit
ip sla schedule 10 start-time now life forever
show ip sla statistics 10

Delay (DMM/DMR), loss (LMM/LMR) and synthetic loss (SLM/SLR) results give you the numbers that matter for SLA reporting: two-way frame delay, delay variation and frame loss ratio per COS.

Field Pitfalls Worth Memorising

  • Level mismatch — the single most common cause of "CFM is configured but nothing works". Same domain name is not enough; the level must match.
  • CCM interval too aggressive — 3.3 ms or 10 ms intervals are unsuitable on congested or CPU-protected links; use 1 s or 10 s for wide-area transport.
  • Blocked ports — a down MEP stops seeing the wire when STP blocks the port; an up MEP keeps running through the relay function.
  • Cross-check enablement — configure expected remote MEPs and run ethernet cfm mep crosscheck enable level <n> vlan <id> so that a missing endpoint raises an alarm instead of silently staying "up".

Verification Checklist Before You Close the Ticket

  1. Local MEP up, correct interface and direction.
  2. Remote MEP present with the expected MEP ID and MAC.
  3. Zero cross-connect and unexpected-MEP errors after 3× the CCM interval.
  4. Loopback success and linktrace listing every expected MIP.
  5. Alarm notification verified by experimentally shutting the far end.

Used this way, CFM turns "the customer says the circuit is down" into a precise answer — the failure is between MEP 102 and MEP 201, at hop 3, with no ambiguity about which carrier owns it. For L2 protection and interface-level error forensics, see our notes on STP protection mechanisms and reading Junos interface error counters.

原文链接:https://www.cisco.com/c/en/us/support/docs/asynchronous-transfer-mode-atm/operation-administration-maintenance-oam/117457-technote-cfm-00.html