Availability, Downtime & Shared Risk
Nines converted into hours you can actually plan around — and a check on the assumption underneath every redundancy calculation, which is that the two paths fail independently.
Availability and downtime
A year is taken as 365 days. Editing either field updates the other, because they are the same statement said two ways — and “four nines” is much easier to agree to than “an hour of outage a year”.
From MTBF and MTTR
A protected service, and what its paths share
List what each path passes through. Give elements that share physical infrastructure the same risk tag — the duct, the bridge, the chamber, the power feed. Anything tagged on both sides is common to both paths however separate the routes look.
Primary path
Secondary path
Why the naive answer is so wrong
Parallel availability multiplies unavailabilities. Two paths that are each down for 0.1% of the year are both down for 0.1% of 0.1% — one part in a million — which is where the thousandfold improvement comes from. Every bit of that improvement is the word both, and both assumes the failures are unrelated.
A shared duct breaks that in the most direct way possible: when the digger goes through it, both paths are down at once, and the service is down for as long as the duct is. No amount of redundancy on either side of it changes that. The shared element sits in series with the whole arrangement, and it sets a ceiling the service can never rise above.
The size of the effect surprises people. Two 99.9% paths sharing a duct that is itself 99.95% available do not deliver six nines. They deliver a little under 99.95% — about four and a half hours a year rather than thirty seconds. The design looks identical on a diagram, and it is five hundred times worse.
What actually gets shared
Ducts and trenches are the obvious one and still the commonest, because two circuits ordered years apart from the same carrier often end up in the same subduct without anybody being told.
Bridges and structures concentrate risk geographically. Two routes that diverge by forty kilometres can still cross the same river on the same bridge.
Building entries and chambers defeat diversity at the last hundred metres. Diverse routes across a country that arrive through one riser are diverse right up to the point where it matters.
Power is the one that catches people who did the fibre survey properly. Two genuinely diverse fibres landing on equipment fed from one rectifier are one path with extra steps.
Geographic corridors are invisible on a logical diagram. Separate ducts along the same road are separate until the road is dug up.
What this does not do
It gives steady-state availability, which is a long-run average. It says nothing about whether a particular year will contain a bad month, and it does not model correlated weather, wear-out, maintenance windows, or the time a protection switch itself takes.
MTBF figures come from vendors and are estimates of a population, not a promise about your unit. MTTR is the one number you largely control, and halving it halves downtime exactly — which is usually cheaper than buying more redundancy.
Everything is calculated in your browser. Nothing about your network is uploaded.