Steering traffic with communities

Attach CNX large communities to routes exported to the route servers. They change route-server redistribution; they do not change the forwarding path of traffic already selected by another network.

Use the complete values in the large-community reference. CNX-specific standard and extended community equivalents are intentionally not documented.

Suppress a route globally

Attach 132213:0:0 to keep a route from being announced to any route-server client:

203.0.113.0/24  large community 132213:0:0

Add 132213:1:<PEER_ASN> to create an explicit exception for one peer.

Suppress a route toward one ASN

Attach:

132213:0:<PEER_ASN>

This affects route-server export to that ASN. It does not affect a bilateral session with the same network.

Limit domestic or non-domestic propagation

Use:

132213:0:65528  do not announce to domestic peers
132213:0:65529  do not announce to non-domestic peers

CNX classifies the announcing client and adds one of these received-route markers:

132213:65527:0  next hop and recipient are at the same CNX site
132213:65528:0  route received from a domestic participant
132213:65529:0  route received from a non-domestic participant

Treat the markers as CNX classification signals, not as geolocation of an end user or every network in the AS path.

To make an authorized export prefix domestic-only, attach 132213:0:65529 in the platform's outbound policy:

Cisco IOS XE: set large-community 132213:0:65529 additive
Junos OS:     then community add CNX-DOMESTIC-ONLY
Huawei VRP:   apply large-community 132213:0:65529 additive

On Junos, define CNX-DOMESTIC-ONLY with member large:132213:0:65529. Ensure the Cisco and Huawei neighbor configuration sends large communities. Complete examples are available in the platform configuration reference.

Request AS-path prepending

Use 132213:101:<PEER_ASN>, 132213:102:<PEER_ASN>, or 132213:103:<PEER_ASN> to prepend your announcing ASN one, two, or three times toward a selected ASN. Replace the peer ASN with 0 to apply the request to all route-server clients.

Prepending influences only networks whose policy considers the longer path. Local preference and other higher-priority attributes can override it.

Set MED on route-server export

The CNX helper policy supports five MED values:

132213:901:<TARGET>  MED 10
132213:902:<TARGET>  MED 20
132213:903:<TARGET>  MED 30
132213:904:<TARGET>  MED 40
132213:905:<TARGET>  MED 50

Set <TARGET> to a peer ASN or 0 for all route-server clients. Attach only one CNX MED community for a given target to avoid ambiguous intent.

MED is normally compared between paths from the same neighboring AS. Confirm that the receiving network's policy uses MED before depending on this control.

Add NO_EXPORT or NO_ADVERTISE for one peer

Use 132213:65281:<PEER_ASN> to make CNX add the well-known NO_EXPORT community to the copy sent to one peer. Use 132213:65282:<PEER_ASN> to add NO_ADVERTISE instead.

This is different from suppressing route-server export: CNX sends the route to the selected peer, and the well-known community instructs that peer how far it may propagate the route. Verify that the receiving platform honors the well-known community.

Verify the result

Check the advertised route on your router and then inspect it through the CNX looking glass from the intended recipient's perspective. Verify propagation, the resulting AS_PATH or MED, and the next hop. Do not infer success from the presence of a community on your outbound route alone.