Internet Exchange
CNX is a 100GE metro Layer-2 Internet exchange fabric spanning multiple data centres in Phnom Penh. The exchange fabric carries packets directly between connected networks. CNX route servers provide a control-plane service that distributes routes without forwarding member traffic.
Start with Getting started for the information to collect before configuring the port. Continue with Configuring the IX port and Configuring route-server BGP.
The route servers enforce route-origin validation and registry-derived route filters. Members retain control of local route selection and can influence route-server propagation with large BGP communities. Members may also establish bilateral BGP sessions directly with other participants.
CNX also supports private network interconnects (PNIs) between member ports across the Phnom Penh metro network.
Direct members can reach CNX's IPv6-only RPKI validators and member time service from their assigned IPv6 peering address.
How the exchange works
-
Control plane and data plane
How route-server BGP sessions remain separate from traffic forwarded across the exchange fabric.
-
Getting started at CNX
Collect connection details, publish routing data, and prepare routing policy before configuring the IX port.
Port and BGP
-
Configuring the IX port
Configure the physical handoff, VLAN, MTU, and assigned IPv4 and IPv6 peering addresses.
-
Configuring route-server BGP
Establish filtered IPv4 and IPv6 BGP sessions with every CNX route server.
-
Verifying and troubleshooting peering
Check the port, BGP capabilities, accepted routes, exported prefixes, and end-to-end forwarding.
-
Route-server service
CNX route-server ASN, peering addresses, session behavior, and supported capabilities.
Add-Path and ECMP
-
Add-Path and ECMP
Why receiving several BGP paths and forwarding over equal-cost next hops are separate router functions.
-
Enabling Add-Path and ECMP
Receive multiple paths from CNX route servers and install eligible next hops for equal-cost forwarding.
Traffic steering
-
Steering traffic with communities
Use CNX large communities to limit propagation, prepend paths, classify routes, and set export MED.
-
BGP large communities
Large communities accepted or attached by CNX for propagation, prepending, MED, classification, and diagnostics.
Routing security
-
Routing security at CNX
How IRR data, ROAs, AS-SETs, ROV, and future ASPA checks protect route exchange.
-
Publishing routing data
Publish IRR, AS-SET, PeeringDB, ROA, and ASPA data consumed by CNX routing policy.
-
Using the CNX RPKI validators
Connect an IX router to the IPv6-only CNX RTR service and apply route-origin validation.
-
Route validation policy
Checks applied to routes received by the CNX route servers.
-
How CNX builds route-server policy
How participant assignments and public routing datasets become generated route-server configuration.
Time service
-
Using the member time service
Synchronize a directly connected member router over the CNX IPv6 peering fabric.
Platform configurations
-
Router platform configurations
Complete CNX connection examples for Cisco IOS XE, Junos OS, and Huawei VRP routers.
-
Cisco IOS XE complete example
Complete IOS XE pattern for the CNX port, route-server BGP, Add-Path, ECMP, ROV, NTP, and domestic-only export.
-
Junos OS complete example
Complete Junos pattern for the CNX port, route-server BGP, Add-Path, ECMP, ROV, NTP or NTS, and domestic-only export.
-
Huawei VRP complete example
Complete Huawei VRP pattern for the CNX port, route-server BGP, Add-Path, ECMP, ROV, NTP, and domestic-only export.