Configuring the IX port
Use the interface, VLAN, MTU, and IP assignments from your CNX connection record. The commands below describe the configuration shape; exact interface syntax depends on the router platform.
1. Configure the physical interface
Set the agreed speed and negotiation mode. If the service uses a link aggregation group, configure every member link with the same speed, MTU, and LACP settings before adding the routed service.
The platform examples deliberately place the IX service on a logical aggregate
(Port-channel, ae, or Eth-Trunk), even when the initial handoff has only
one physical member. Starting with a single-link LAG means a later capacity
upgrade can add another CNX-provisioned member link without moving the VLAN,
IP addresses, ACLs, or BGP sessions and without deliberately shutting down the
logical IX interface.
CNX provisions LAG and MLAG only within a single site. At that site, CNX may terminate the member links on different access switches using MLAG. CNX does not offer and will not configure a LAG across CNX sites. A member connecting at multiple sites receives a separate attachment at each site.
A LAG is not required. A single physical interface is a valid configuration when no future bundle is planned. In that case, replace the aggregate name in the examples with the router's physical interface name and apply the same VLAN, addressing, MTU, and filtering configuration there. Coordinate any later change from a direct port to a LAG with CNX because moving the Layer-3 service may interrupt the connection.
Do not enable proxy ARP, IPv6 router advertisements, DHCP service, or Layer-2 discovery protocols toward the peering LAN unless CNX has explicitly requested them.
2. Configure the service VLAN
VLAN 500 is the default CNX peering VLAN. Use VLAN 500 for a tagged handoff unless the connection record supplied by CNX specifies another value.
- For an untagged handoff, place the assigned addresses on the physical or aggregate interface.
- For a tagged handoff, create an 802.1Q subinterface with the assigned VLAN ID and place the addresses there.
Apply the agreed MTU to every layer that carries the service. A subinterface cannot pass a larger packet than its parent interface.
3. Add the peering addresses
Configure both addresses supplied by CNX:
IPv4: <MEMBER_IPV4>/24
IPv6: <MEMBER_IPV6>/64
The shared peering networks are described in the route-server reference. Use only your assigned host addresses.
4. Apply an infrastructure ACL
Permit the control traffic required for your sessions and member services:
- TCP/179 between your peering addresses and the route servers;
- ICMP and ICMPv6 needed for diagnostics, path-MTU discovery, and IPv6 neighbour discovery;
- TCP/3323 from your assigned IPv6 address to the CNX RPKI validators;
- UDP/123 to the member time service; and
- TCP/4460 when using NTS.
The member time service is available only over the CNX member peering network. NTP and NTS requests must use the CNX-assigned IPv6 peering address as their source; do not treat the service as reachable from other networks.
Do not apply a generic server-port ACL that blocks established BGP or required ICMPv6 messages.
5. Verify Layer 3
Confirm that the interface and VLAN are up, that neighbour discovery resolves the route-server addresses, and that sourced IPv4 and IPv6 pings reach the peering LAN.
Successful ping tests establish local Layer-3 reachability. They do not prove that BGP policy, route validation, or end-to-end forwarding is correct.
Platform snippets
Tagged handoffs have the following general form. Replace the placeholders and
apply the CNX-supplied MTU to every relevant layer. The examples use a logical
aggregate so the service can grow beyond one physical link. For a direct-port
connection, substitute <PHYSICAL_INTERFACE> for Port-channel10, ae10, or
Eth-Trunk10 respectively. Cross-site LAG is not a CNX service option.
The snippets use the default VLAN 500. If the member connection record assigns
a different VLAN, replace 500 throughout the applicable example.
Cisco IOS XE
interface Port-channel10.500
encapsulation dot1Q 500
ip address <MEMBER_IPV4> 255.255.255.0
ipv6 address <MEMBER_IPV6>/64Junos OS
set interfaces ae10 unit 500 vlan-id 500
set interfaces ae10 unit 500 family inet address <MEMBER_IPV4>/24
set interfaces ae10 unit 500 family inet6 address <MEMBER_IPV6>/64Huawei VRP
interface Eth-Trunk10.500
dot1q termination vid 500
ip address <MEMBER_IPV4> 255.255.255.0
ipv6 enable
ipv6 address <MEMBER_IPV6> 64
Continue with the complete Cisco IOS XE, Junos OS, or Huawei VRP configuration.