Configuring the IX port

Use the interface, VLAN, MTU, and IP assignments from your CNX connection record. The commands below describe the configuration shape; exact interface syntax depends on the router platform.

1. Configure the physical interface

Set the agreed speed and negotiation mode. If the service uses a link aggregation group, configure every member link with the same speed, MTU, and LACP settings before adding the routed service.

The platform examples deliberately place the IX service on a logical aggregate (Port-channel, ae, or Eth-Trunk), even when the initial handoff has only one physical member. Starting with a single-link LAG means a later capacity upgrade can add another CNX-provisioned member link without moving the VLAN, IP addresses, ACLs, or BGP sessions and without deliberately shutting down the logical IX interface.

CNX provisions LAG and MLAG only within a single site. At that site, CNX may terminate the member links on different access switches using MLAG. CNX does not offer and will not configure a LAG across CNX sites. A member connecting at multiple sites receives a separate attachment at each site.

A LAG is not required. A single physical interface is a valid configuration when no future bundle is planned. In that case, replace the aggregate name in the examples with the router's physical interface name and apply the same VLAN, addressing, MTU, and filtering configuration there. Coordinate any later change from a direct port to a LAG with CNX because moving the Layer-3 service may interrupt the connection.

Do not enable proxy ARP, IPv6 router advertisements, DHCP service, or Layer-2 discovery protocols toward the peering LAN unless CNX has explicitly requested them.

2. Configure the service VLAN

VLAN 500 is the default CNX peering VLAN. Use VLAN 500 for a tagged handoff unless the connection record supplied by CNX specifies another value.

  • For an untagged handoff, place the assigned addresses on the physical or aggregate interface.
  • For a tagged handoff, create an 802.1Q subinterface with the assigned VLAN ID and place the addresses there.

Apply the agreed MTU to every layer that carries the service. A subinterface cannot pass a larger packet than its parent interface.

3. Add the peering addresses

Configure both addresses supplied by CNX:

IPv4: <MEMBER_IPV4>/24
IPv6: <MEMBER_IPV6>/64

The shared peering networks are described in the route-server reference. Use only your assigned host addresses.

4. Apply an infrastructure ACL

Permit the control traffic required for your sessions and member services:

  • TCP/179 between your peering addresses and the route servers;
  • ICMP and ICMPv6 needed for diagnostics, path-MTU discovery, and IPv6 neighbour discovery;
  • TCP/3323 from your assigned IPv6 address to the CNX RPKI validators;
  • UDP/123 to the member time service; and
  • TCP/4460 when using NTS.

The member time service is available only over the CNX member peering network. NTP and NTS requests must use the CNX-assigned IPv6 peering address as their source; do not treat the service as reachable from other networks.

Do not apply a generic server-port ACL that blocks established BGP or required ICMPv6 messages.

5. Verify Layer 3

Confirm that the interface and VLAN are up, that neighbour discovery resolves the route-server addresses, and that sourced IPv4 and IPv6 pings reach the peering LAN.

Successful ping tests establish local Layer-3 reachability. They do not prove that BGP policy, route validation, or end-to-end forwarding is correct.

Platform snippets

Tagged handoffs have the following general form. Replace the placeholders and apply the CNX-supplied MTU to every relevant layer. The examples use a logical aggregate so the service can grow beyond one physical link. For a direct-port connection, substitute <PHYSICAL_INTERFACE> for Port-channel10, ae10, or Eth-Trunk10 respectively. Cross-site LAG is not a CNX service option.

The snippets use the default VLAN 500. If the member connection record assigns a different VLAN, replace 500 throughout the applicable example.

Cisco IOS XE

interface Port-channel10.500
 encapsulation dot1Q 500
 ip address <MEMBER_IPV4> 255.255.255.0
 ipv6 address <MEMBER_IPV6>/64

Junos OS

set interfaces ae10 unit 500 vlan-id 500
set interfaces ae10 unit 500 family inet address <MEMBER_IPV4>/24
set interfaces ae10 unit 500 family inet6 address <MEMBER_IPV6>/64

Huawei VRP

interface Eth-Trunk10.500
 dot1q termination vid 500
 ip address <MEMBER_IPV4> 255.255.255.0
 ipv6 enable
 ipv6 address <MEMBER_IPV6> 64

Continue with the complete Cisco IOS XE, Junos OS, or Huawei VRP configuration.