SR-MPLS and IS-IS
Relate IGP advertisements and segment identifiers to the label stack observed on the data path.
Service provider · EVPN/VXLAN · MPLS
Decode control and data planes together, then localize whether the evidence points to underlay, overlay, routing control, encapsulation, MTU, or neighbor learning.
The synthetic provider corpus is in preparation. Protocol coverage varies by release and capture; confirm required decoders and evidence paths during evaluation.
Multi-vendor fault domains
A single service failure can cross several control and encapsulation layers. The investigation should preserve their timing and dependencies.
Relate IGP advertisements and segment identifiers to the label stack observed on the data path.
Compare both directions and expose where label overhead, popping, or path-MTU behavior diverges.
Separate VTEP underlay transport from EVPN control state and the encapsulated tenant exchange.
Tie invalid IP, UDP, or VXLAN lengths to the exact generated frames and affected forwarding behavior.
Follow TCP setup, TTL handling, BGP OPEN state, resets, and repeated session attempts as one sequence.
Connect ARP requests and replies with MAC/IP advertisement, suppression, flooding, and the return path.
Evidence-led workflow
Preserve the provider edge, core, VTEP, or peer observation point and the incident window.
Compare advertisements, sessions, labels, encapsulation, paths, and neighbor state against what crossed the wire.
Name the supported fault domain, rejected alternatives, exact packet evidence, visibility limits, and next capture or owner.