**Session Date/Time:** 20 Jul 2026 07:00 # [NMOP](../wg/nmop.html) ## Summary The NMOP (Network Management Operations) Working Group met at IETF 126 to discuss its active drafts, recent hackathon developments, and the path forward for its core initiatives. Key highlights included progress on the YANG-Push to Message Broker integration, Network Incident and Anomaly Management suites, and a structured discussion on the modeling approaches for SIMAP (Service-to-Infrastructure Mapping). The working group reached a clear path forward on SIMAP modeling via a formal session poll, opting to support both RFC 8345-based and RFC 8795-based approaches depending on the specific operational use cases. Additionally, opportunities for collaboration between NMOP and the Network Management Research Group (NMRG) were explored. --- ## Key Discussion Points ### 1. Administration and Document Status * **Slides**: [Chairs slides](https://datatracker.ietf.org/meeting/126/materials/slides-126-nmop-sessa-1-chairs-slides-05) * **Presenters**: Reshad Rahman, Benoit Claise * **Discussion**: * The chairs welcomed the new working group secretaries, Lucia Cabanillas and Jefferson Campos Nobre, and thanked outgoing secretary Thomas Graf for his long service. * The working group celebrated its first RFC publication: RFC 9594 (Terminology). The SIMAP concept draft has cleared AD review and is awaiting directorate reviews before moving to the IESG. * Reshad Rahman reviewed document dependencies, noting that some NMOP documents have normative references to drafts in NetConf, NetMod, and OPSAWG. However, `draft-ietf-nmop-rfc3535-20years-later` has no external normative dependencies and can progress independently. * The chairs noted that they plan to run Working Group Last Call (WGLC) for the message broker documents as a suite, though they will hold them before submission to the IESG until their external normative dependencies advance. * Chong Feng raised a question about whether NMOP will serve as the primary venue for discussing AI agents. Benoit Claise clarified that Session 2 would address AI-related drafts and discuss how AI work can be scoped as practical, code-backed experiments in NMOP. ### 2. YANG-Push to Message Broker Integration & Hackathon Update * **Slides**: [YANG-Push to Message Broker Integration Status Update and Hackathon](https://datatracker.ietf.org/meeting/126/materials/slides-126-nmop-sessa-2-yang-push-to-message-broker-integration-status-update-and-hackathon-01) * **Presenter**: Thomas Graf * **Discussion**: * Thomas Graf reported updates on `draft-ietf-nmop-yang-message-broker-integration` (revisions 12 and 13), which finalized the security and operational considerations sections and added details on schema registry deviations for producers/consumers. * Thomas Graf proposed that `draft-ietf-nmop-yang-message-broker-integration` and `draft-ietf-nmop-message-broker-telemetry-message` are stable and ready for WGLC. He recommended that `draft-ietf-nmop-yang-message-broker-message-key` follow later as it was adopted more recently and is still evolving. * During the IETF 126 hackathon, progress was made on end-to-end testing, covering features like CBOR named identifiers, IETF/IEEE subscriptions, and Sienna Blue Planet workflow engine tests. ### 3. YANG Message Keys for Message Broker Integration * **Slides**: [YANG Message Keys for Message Broker Integration](https://datatracker.ietf.org/meeting/126/materials/slides-126-nmop-yang-message-broker-message-key-00) * **Presenter**: Ahmed Elhassany * **Discussion**: * Ahmed Elhassany presented updates to `draft-ietf-nmop-yang-message-broker-message-key`, highlighting a refined three-phase algorithm to extract keys from subscriptions (normalization to XPath, key template derivation, and key value extraction) to avoid head-of-line blocking. * The draft also outlines a deterministic, collision-free topic derivation algorithm designed to fit within Kafka’s 249-character limit using module prefixes. * Rob Wilton noted that YANG prefixes are not guaranteed to be globally unique. Ahmed Elhassany acknowledged this and explained that the algorithm uses hashing as a fallback to resolve collisions, preferring to keep topic names human-friendly while relying on schema registries for precise metadata lookup. * A CLI-based Rust implementation is now available on GitHub for testing. ### 4. YANG Data Model for Network Incident Management * **Slides**: [YANG Data Model for Network Incident Management](https://datatracker.ietf.org/meeting/126/materials/slides-126-nmop-yang-data-model-for-network-incident-management-01) * **Presenter**: Chen Li * **Discussion**: * Chen Li updated the group on `draft-ietf-nmop-network-incident-yang`. Major improvements include alignment with RFC 9594, adding an Operational Considerations section, and mapping parameters to `draft-ietf-nmop-network-anomaly-architecture` using the RFC 8969 layer architecture. * The model now allows generating incidents without knowing the source initially (by relaxing the minimum element constraints). * Reshad Rahman questioned the key structure, asking why a compound key (name, type, and incident ID) is used instead of making the unique 64-bit `incident-number` the sole key. Chen Li explained that the compound key is used for the YANG datastore, whereas the single `incident-number` is optimized for RPCs and notifications to improve processing performance. Reshad Rahman agreed to review the details offline. ### 5. Network Anomaly Detection Framework * **Slides**: [An Architecture for a Network Anomaly Detection Framework](https://datatracker.ietf.org/meeting/126/materials/slides-126-nmop-sessa-an-architecture-for-a-network-anomaly-detection-framework-00) * **Presenter**: Thomas Graf * **Discussion**: * Thomas Graf presented updates to the anomaly detection suite: `draft-ietf-nmop-network-anomaly-architecture`, `draft-ietf-nmop-network-anomaly-semantics`, and `draft-ietf-nmop-network-anomaly-lifecycle`. * For the architecture, references to SIMAP and Knowledge Graph documents were changed from normative to informative. * For semantics, the draft simplified prefixes/abstracts, added instance data examples, and introduced a temporary `ietf-network-anomaly-service-topology` module until permanent service models are defined. * For the lifecycle draft, the transition between validation and refinement was clarified, and topic/subject name constraints were aligned with the message broker naming work. * Thomas Graf requested an early YANG doctors review for these drafts. Benoit Claise suggested utilizing the same YANG doctor who reviews the message broker suite to maintain continuity. ### 6. SIMAP Modeling Base Discussion & Decision * **Slides**: * [SIMAP Modelling based on RFC8345 with some extensions](https://datatracker.ietf.org/meeting/126/materials/slides-126-nmop-simap-modelling-based-on-rfc8345-with-some-extensions-00) (Presenter: Olga Havel) * [Applicability of RFC8795 YANG data model to SIMAP](https://datatracker.ietf.org/meeting/126/materials/slides-126-nmop-sessa-7-applicability-of-rfc8795-yang-data-model-to-simap-00) (Presenter: Italo Busi) * [SIMAP YANG discussions and decision](https://datatracker.ietf.org/meeting/126/materials/slides-126-nmop-sessa-8-simap-yang-discussions-and-decision-02) (Presenter: Reshad Rahman) * **Discussion**: * The working group discussed the data model base for Service-to-Infrastructure Mapping (SIMAP). Two distinct paths were analyzed: * **RFC 8345 approach (Olga Havel)**: Establishes a generic, technology-agnostic multi-layer topology base, representing everything via simple nodes, termination points, and supporting links. Supported by Dan Voyer and Nigel Davis. * **RFC 8795 approach (Italo Busi)**: Leverages the Traffic Engineering (TE) topology model, advocating for profiling/pruning the larger, pre-existing TE model to avoid duplicate models for shared attributes like bandwidth and latency. Dieter Beller supported using existing models. * Rob Wilton raised a caution regarding the use of "deviations" to profile models, pointing out that YANG deviations are intended to describe platform-specific non-conformance rather than defining new standard specifications. * Reshad Rahman presented **Option 4**, which proposes adopting both approaches: using the RFC 8345-based generic model for non-TE use cases (such as L2VPN, L3VPN, and basic navigation) and the RFC 8795-based model for traffic-engineered or optical layers. This acknowledges some overlap in navigation but respects different operator priorities. * Nigel Davis commented that model overlap is common in the industry and should be managed with clear migration paths rather than avoided entirely. ### 7. NMRG and NMOP Collaboration Opportunities * **Slides**: [Network Management Research Group (NMRG) and Network Management Operations (NMOP) Working Group - Collaboration Opportunities](https://datatracker.ietf.org/meeting/126/materials/slides-126-nmop-sessa-network-management-research-group-nmrg-and-network-management-operations-nmop-working-group-collaboration-opportunities-00) * **Presenter**: Jefferson Campos Nobre * **Discussion**: * Jefferson Campos Nobre (co-chair of NMRG) presented opportunities to bridge the gap between long-term research (IRTF) and short-term operational standardization (IETF/NMOP) on topics like Intent-Based Networking, AI in network management, and Digital Twins. * Rob Wilton pointed out that NMOP focuses on operator concerns in a 1-to-2-year time horizon, whereas NMRG targets a 5-year outlook. * Thomas Graf and Diego Lopez suggested that NMOP should use the hackathons to implement and validate research concepts coming out of NMRG, creating a continuous feedback loop. ### 8. BMP YANG Model for Network Telemetry Messages * **Slides**: [BMP YANG Model for Network Telemetry Messages](https://datatracker.ietf.org/meeting/126/materials/slides-126-nmop-bmp-yang-model-for-network-telemetry-messages-00) * **Presenter**: Camilo Cardona * **Discussion**: * Camilo Cardona presented progress on representing BMP messages in a YANG schema to feed into the message broker architecture. The draft now directly imports BGP models from IDR and models BMP TLVs (including path marking). * A topic split was proposed: a real-time topic for state changes and statistics, and a compacted topic for the current state of the Adj-RIB-In. * To preserve message order while optimizing distribution, a distinction was introduced between the message key (for compaction) and a partition key (using the router hostname, ensuring all data from a single node goes to the same broker partition). * Mahesh Jethanandani advised checking with GROW and IDR working groups to confirm agreement before proceeding with a working group adoption call in NMOP. Thomas Graf noted that GROW was supportive of NMOP progressing this work. ### 9. Distributed Authorization Policy Sharing Model * **Slides**: [Model for distributed authorization policy sharing](https://datatracker.ietf.org/meeting/126/materials/slides-126-nmop-sessa-model-for-distributed-authorization-policy-sharing-01) * **Presenter**: Lucia Cabanillas * **Discussion**: * Lucia Cabanillas presented a framework to manage and share authorization policies across domains using YANG. The policy logic is written in Policy-as-Code languages (such as Rego/OPA) while YANG distributes the policy and its metadata. * Key updates include changing the policy language field to an `identityref` (allowing extensible support for new languages), adding metadata leaves (`author`, `owner`, `origin`, and `area` to route policies to correct PDP instances), and dropping the `version` leaf to handle versioning via git repositories. * A successful multi-domain demo was executed during the hackathon. * Mahesh Jethanandani asked if there was any overlap with other policy or authorization working groups in the IETF. Lucia Cabanillas clarified that the framework is generic and designed to remain agnostic of the underlying policy engine, with no known direct overlaps. --- ## Decisions and Action Items ### Decisions * **SIMAP Modeling Direction**: The WG formally decided to proceed with **Option 4**, which supports both the RFC 8345-based generic model and the RFC 8795-based TE model depending on the operational use cases. ### Action Items * **YANG Message Broker Suite**: * Chairs to initiate Working Group Last Call for `draft-ietf-nmop-yang-message-broker-integration` and `draft-ietf-nmop-message-broker-telemetry-message`. * Authors of `draft-ietf-nmop-yang-message-broker-message-key` to continue refining the draft based on hackathon feedback before requesting WGLC. * **Network Incident & Anomaly Detection**: * Chen Li to resolve outstanding github issues regarding the unique identifier keying mechanism (`incident-number` vs compound keys) in `draft-ietf-nmop-network-incident-yang`. * Chairs to request an early YANG doctor review for `draft-ietf-nmop-network-incident-yang` and the anomaly detection drafts (`draft-ietf-nmop-network-anomaly-architecture`, `draft-ietf-nmop-network-anomaly-semantics`, `draft-ietf-nmop-network-anomaly-lifecycle`). * **BMP Telemetry Model**: * Chairs to coordinate with the GROW and IDR working group chairs to ensure consensus before launching a Working Group Adoption Call for the BMP YANG model. --- ## Session Polls ### Poll 1: Test Poll * **Question**: Test poll * **Result**: yes: 0, no: 0, no_opinion: 0 (total: 3) ### Poll 2: SIMAP Modeling Approach Decision * **Question**: Does the WG agree to go with Option 4 (both approaches)? * **Result**: **yes: 39**, no: 9, no_opinion: 3 (total: 96) --- **Session Date/Time:** 23 Jul 2026 09:30 # [NMOP](../wg/nmop.html) ## Summary The NMOP Working Group met for a one-hour session to discuss network management operations, recent network incidents, and the applicability of artificial intelligence (AI) and machine learning (ML) frameworks to network management. Key topics included: * An operational analysis of a recent BGP routing loop incident at Swisscom and how generative AI was used to parse the telemetry data. * A coordination status update on the upcoming AIOps side meeting and proposed Wiki guidelines for AI/ML work within the IETF. * Several presentations on AI-assisted network management agents, northbound task interfaces, knowledge graphs, and automated protocol testing. --- ## Key Discussion Points ### 1. Administration and Agenda Bash **Presenters:** Benoît Claise, Rachid Medbouhi **Slides:** [Chairs slides](https://datatracker.ietf.org/meeting/126/materials/slides-126-nmop-sessa-1-chairs-slides-05) * **WG Scope & Experiments:** Benoît Claise opened the session by outlining the scope of NMOP, which focuses on operational deployment issues of existing network management technologies. He emphasized that NMOP’s strength lies in concrete, time-bounded experiments (such as the network anomaly framework defined in `draft-ietf-nmop-network-anomaly-architecture`). * **Adoption Criteria:** The chairs expressed caution regarding "working group shopping" (introducing drafts that failed to gain traction elsewhere without clean integration) and emphasized that new work must demonstrate active commitment, implementation at hackathons, and fit the working group’s DNA. * **Agent Observability:** Ying Zhen raised a question about whether "agent observability and intervention control" (discussed in a Wednesday side meeting) fits within the NMOP charter. Benoît Claise noted that suitability is evaluated against the slide criteria and would be discussed further in the context of the AIOps side meeting. --- ### 2. Swisscom Network Incident & Generative AI Analysis **Presenter:** Thomas Graf Thomas Graf shared an operational analysis of a BGP routing loop incident that occurred at Swisscom on July 2, 2024, and demonstrated how large language models (LLMs) can be combined with structured network semantics to analyze telemetry. * **Incident Details:** An early morning configuration change introducing additional VRF peerings on an Inter-AS Option A peering led to a BGP routing loop across 42 L3VPNs. This resulted in excessive BGP route withdrawals and high CPU utilization on BGP processes across four main network platforms. * **Telemetry & Semantics Correlation:** The anomaly was detected in real-time by a system leveraging concepts from: * `draft-ietf-nmop-network-anomaly-architecture` (architecture framework) * `draft-ietf-nmop-network-anomaly-semantics` (symptom ontology and metadata annotations) * `draft-ietf-nmop-network-anomaly-lifecycle` (refinement of the detection process) * `draft-ietf-nmop-yang-message-broker-integration` & `draft-ietf-nmop-yang-message-broker-message-key` (for high-efficiency telemetry delivery) * `draft-ietf-nmop-message-broker-telemetry-message` (converting BMP to YANG) * **Generative AI Experimentation:** Swisscom connected their time-series telemetry database to a Qwen 3.5 LLM agent. Using prompt engineering, the LLM successfully identified the looped prefixes, fluctuating Site of Origin (SOO) attributes, and affected VPNs. It also proved capable of connecting BGP instabilities to CPU utilization anomalies. * **Discussion & Chat Highlights:** * **Root Cause & Prevention:** Pierre Francois noted that CE behavior can be unpredictable and suggested avoiding AS_Path rewrites where possible, letting customers use `allowas-in`. Thomas Graf agreed and suggested utilizing "digital twins" to verify configuration changes before deployment. * **LLM Capabilities:** Joe Clarke shared that frontier models like Claude Sonnet/Opus show solid mid-tier engineering capabilities, but open-weight models often hallucinate BGP operational concepts without deep context. * **YANG Semantics vs. Format:** Thomas Graf asked if closer alignment between JSON Schema (via the new IETF JSON Schema WG) and YANG Schema would improve LLM agent performance. Joe Clarke and Pierre Francois responded that format is secondary to content; the key is defining meaningful descriptions in YANG data nodes that can map cleanly into schema parameters. * **Testing:** Dan Voyer asked if a benchmark exists to validate agent configurations. --- ### 3. AIOps Side Meeting & Wiki Guidelines **Presenter:** Mahesh Jethanandani (AD) **Slides:** [AIOps Side Meeting](https://datatracker.ietf.org/meeting/126/materials/slides-126-nmop-aiops-side-meeting-04) Mahesh Jethanandani detailed the logistical setup and goals for the upcoming community side meeting on AIOps. * **The Problem:** Many AI/ML management drafts have been presented across different WGs (working group shopping) without a single home. * **Wiki Guidance:** The AD has established Wiki guidelines outlining in-scope categories. Out-of-scope items include standalone AI/ML algorithm specifications, standalone gap analyses, and external framework alignments (which should be handled via liaisons). * **Next Steps:** If the community desires standardizing these elements, they can either (1) propose a new WG with a specific charter directly to the IESG, or (2) request a formal BoF. Mahesh urged participants to focus on defining a clear problem statement and charter text. --- ### 4. AI-Based Network Management Agent (NMA) & Interfaces **Presenter:** Xing Zhao X Xing Zhao presented updates to the NMA drafts, detailing architectural terminology and proposed interfaces. * **Terminology Update:** An NMA is defined as a network management entity translating user intents or preset goals into closed-loop management tasks, characterized by semi-autonomous or autonomous processing. * **Interface Taxonomy:** The architecture defines four interface types: 1. `A2U` (Agent-to-User: non-agent upper systems) 2. `A2A` (Agent-to-Agent) 3. `A2C` (Agent-to-Controller) 4. `A2N` (Agent-to-Network Device) * **A2U YANG Data Model:** Xing Zhao introduced a new individual draft defining the A2U interface, providing capability discovery, intent submission, and status checks. The model supports natural language and structured intents while reusing existing models like `draft-ietf-nmop-network-incident-yang`. A RESTCONF-based prototype was validated at the IETF Hackathon. * **Discussion:** * Joe Clarke expressed skepticism that agent developers would want to embed RESTCONF, calling it too heavyweight for what these agents do. He suggested that while YANG is useful for description, RESTCONF might be too restrictive. * Diego Lopez questioned the strict distinction between "users" and "other agents/controllers" in the northbound interface. Xing Zhao clarified that this is a pragmatic separation to allow operators to integrate existing non-agent OSS systems immediately without waiting for complex Agent-to-Agent protocol standards. * Bo Wu asked whether the A2U interface belongs in NMOP or the proposed new AIOps WG. Mahesh Jethanandani deferred this to the side meeting discussions. --- ### 5. Northbound Task Interface Problem Statement **Presenter:** Bo Wu Bo Wu outlined the operational gaps in how upper-layer systems interact with AI-driven NMAs. * **Gaps Identified:** Traditional Fault Management (FM) systems use slow, step-by-step queries to diagnose issues. An NMA simplifies this by taking a single intent goal and producing structured feedback. * **Use Cases:** Bo Wu presented two operational scenarios: L3VPN performance issues and cross-domain hardware faults (e.g., base station to access router). Gaps remain in formalizing task inputs/outputs, authorizing automated remediations, and capability discovery. --- ### 6. AI-Assisted Network Protocol Testing **Presenter:** Yunzhe Liu Yunzhe Liu proposed a framework to automate specification-driven protocol testing using AI. * **Framework Stages:** The framework proposes six stages: protocol representation, scope scoping, test case generation, artifact generation, execution, and refinement. * **Feedback:** The chairs and participants (including Boris Khasanov in Meetecho) pointed out that protocol testing is outside the charter of NMOP and suggested that the draft is better suited for the Benchmarking Methodology Working Group (BMWG) or the Research Group RASPRG. --- ### 7. Gateway for Network Knowledge Graph & Operational Requirements **Presenter:** Mingxi Wu Mingxi Wu delivered two presentations on knowledge graph interaction and data constraints. * **Knowledge Graph Gateway:** Interacting with network knowledge graphs currently requires specialized query knowledge (Cypher or SPARQL). The draft proposes a three-layer gateway architecture to translate natural language intents into low-level graph queries. * **Data Constraints for Agents:** Feeding raw, high-volume telemetry to AI agents incurs high token costs, bandwidth issues, and reasoning errors. The draft suggests shifting telemetry from "data for humans" to compact "state of evidence" artifacts containing payloads, context, and accountability metrics. This approach achieved high compression ratios during local testing. --- ## Decisions and Action Items * **Out of Scope Work:** The chairs determined that the AI-assisted network protocol testing framework presented by Yunzhe Liu is out of scope for NMOP. The authors are directed to present this work in BMWG or RASPRG. * **AIOps Coordination:** No immediate adoption decisions were made for the presented AI/NMA drafts. The disposition of these drafts is deferred to the outcomes of the AIOps Side Meeting. --- ## Next Steps 1. **AIOps Side Meeting:** Mahesh Jethanandani will lead the community side meeting to discuss whether to charter a new Working Group or request a BoF for AI/ML network management topics. 2. **Experimental Boundaries:** For drafts remaining in NMOP (such as the A2U interface proposal by Xing Zhao), the chairs and AD will evaluate if they can be framed as self-contained operational experiments, separating standard YANG model definitions from experimental validation.