PacketSafari

Service provider · EVPN/VXLAN · MPLS

Troubleshoot the provider network. Prove the failing layer.

Decode control and data planes together, then localize whether the evidence points to underlay, overlay, routing control, encapsulation, MTU, or neighbor learning.

Validation focus

The synthetic provider corpus is in preparation. Protocol coverage varies by release and capture; confirm required decoders and evidence paths during evaluation.

Provider incident · shared packet record Evidence path active
Control and data planes
PE-1EVPN · IS-IS
PSR-MPLS
PE-2EVPN · IS-IS
EVPN / VXLAN overlay
Tenant A
PCAP
Tenant B
PacketSafari investigation
PacketSafariCore Enginecorrelates packet evidence across planes
ControlIS-IS · BGP EVPN
TransportMPLS · IP · UDP
OverlayVXLAN · ARP
Fault-domain verdict
UnderlayOverlayRouting controlEncapsulation / MTUNeighbor learning
Conclusion stays reviewableExact frames · decoded fields · capture limits
A service-provider topology sends IS-IS, BGP EVPN, MPLS, VXLAN, and ARP packet evidence into PacketSafari, which compares control and data planes and returns a reviewable fault-domain verdict.

Multi-vendor fault domains

Stop reading each protocol in isolation.

A single service failure can cross several control and encapsulation layers. The investigation should preserve their timing and dependencies.

SR-MPLS and IS-IS

Relate IGP advertisements and segment identifiers to the label stack observed on the data path.

MPLS label and MTU faults

Compare both directions and expose where label overhead, popping, or path-MTU behavior diverges.

EVPN/VXLAN reachability

Separate VTEP underlay transport from EVPN control state and the encapsulated tenant exchange.

Malformed VXLAN packets

Tie invalid IP, UDP, or VXLAN lengths to the exact generated frames and affected forwarding behavior.

BGP GTSM and OPEN churn

Follow TCP setup, TTL handling, BGP OPEN state, resets, and repeated session attempts as one sequence.

EVPN ARP-learning asymmetry

Connect ARP requests and replies with MAC/IP advertisement, suppression, flooding, and the return path.

Evidence-led workflow

Acquire once. Test competing explanations.

  1. Capture the relevant boundaries

    Preserve the provider edge, core, VTEP, or peer observation point and the incident window.

  2. Correlate control and forwarding evidence

    Compare advertisements, sessions, labels, encapsulation, paths, and neighbor state against what crossed the wire.

  3. Return a bounded conclusion

    Name the supported fault domain, rejected alternatives, exact packet evidence, visibility limits, and next capture or owner.