Describes how multipath Bidirectional Forwarding Detection (BFD) sessions can be hosted on user-specified line cards per VRF, and explains the impact on operational resiliency and tenant isolation in multi-tenant networks.
A host multipath BFD session is a BFD session control mechanism that:
-
enables assignment of multipath BFD monitoring sessions to specific line cards per VRF,
-
enhances tenant isolation by preventing session overlap across VRFs sharing the same destination address, and
-
improves operational resiliency and manageability for multi-tenant and managed service provider environments.
This feature is relevant when multiple tenants share network hardware but require independent operational domains, as is common in large managed service provider deployments.
Session hosting attributes and platform requirements
| Feature Name |
Release |
Description |
|---|---|---|
| VRF-specific BFD multipath location assignment |
Release 26.2.1 |
This feature allows you to pin BFD MP sessions to specific LCs by associating a destination IP and VRF with a physical location. When configured, the system automatically migrates matching sessions to the designated LC. This prevents collateral service disruption for unrelated tenants by ensuring that an LC reload only impacts sessions pinned to that specific hardware. |
In the default configuration, multipath BFD sessions are hosted only by destination address. When multiple VRFs use the same BFD destination, sessions may overlap, reducing isolation.
The main attributes of per-VRF line card BFD session hosting include:
-
Session granularity: Assigns BFD sessions per VRF per line card.
-
Tenant isolation: Prevents operational dependencies among VRFs sharing hardware and BFD sessions.
-
Resiliency: Limits the impact of hardware events to affected VRFs only.
-
Management flexibility: Supports per-customer or per-service resource planning and scaling.
-
Session support: Applies to both multi-hop and single-hop BFD multipath sessions
Comparison of BFD session hosting behavior:
| Attribute |
Default hosting |
Per-VRF and line card hosting |
|---|---|---|
| Session placement |
Based on destination address only |
Based on destination and VRF; explicitly assignable to line cards |
| Tenant/session isolation |
Possible session overlap across VRFs or tenants |
Strict isolation per VRF and line card |
| Operational resiliency |
Single line card failure impacts all sessions sharing destination |
Line card failure impacts sessions for assigned VRF only |
Map different VRFs to distinct line cards to maximize tenant isolation and improve service reliability, particularly in shared infrastructure environments.