Hello, I have reviewed this document as part of the security directorate’s ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. Summary: Has Nits I have no major concern. However I think that the Security considerations section could and should better leverage on [I-D.ietf-detnet-security] (currently it is mainly cited but that's all). Indeed, the [I-D.ietf-detnet-security] document is all about DetNet security, it introduces the problem in a clear manner, then it discusses with much detail both security risks and mitigation technics, providing high level synthesis tables, and sections 9.1 and 9.2 are even dedicated to IP and MPLS DetNet security. This is a MUST read document that provides valuable discussion (perhaps more than in the present document, sorry). I also think the [I-D.ietf-detnet-security] reference (""Deterministic Networking (DetNet) Security Considerations") should be a Normative Reference (it's currently in the Informative Reference list). Minor comments: - Section 4.1 uses the S-PE acronym when refering to the Relay Node, whereas S-PE is not expended in the Abbreviations list of section 2.2. Regards, Vincent