Steering traffic with communities
Attach CNX large communities to routes exported to the route servers. They change route-server redistribution; they do not change the forwarding path of traffic already selected by another network.
Use the complete values in the large-community reference. CNX-specific standard and extended community equivalents are intentionally not documented.
Suppress a route globally
Attach 132213:0:0 to keep a route from being announced to any route-server
client:
203.0.113.0/24 large community 132213:0:0
Add 132213:1:<PEER_ASN> to create an explicit exception for one peer.
Suppress a route toward one ASN
Attach:
132213:0:<PEER_ASN>
This affects route-server export to that ASN. It does not affect a bilateral session with the same network.
Limit domestic or non-domestic propagation
Use:
132213:0:65528 do not announce to domestic peers
132213:0:65529 do not announce to non-domestic peers
CNX classifies the announcing client and adds one of these received-route markers:
132213:65527:0 next hop and recipient are at the same CNX site
132213:65528:0 route received from a domestic participant
132213:65529:0 route received from a non-domestic participant
Treat the markers as CNX classification signals, not as geolocation of an end user or every network in the AS path.
To make an authorized export prefix domestic-only, attach
132213:0:65529 in the platform's outbound policy:
Cisco IOS XE: set large-community 132213:0:65529 additive
Junos OS: then community add CNX-DOMESTIC-ONLY
Huawei VRP: apply large-community 132213:0:65529 additive
On Junos, define CNX-DOMESTIC-ONLY with member
large:132213:0:65529. Ensure the Cisco and Huawei neighbor configuration
sends large communities. Complete examples are available in the
platform configuration reference.
Request AS-path prepending
Use 132213:101:<PEER_ASN>, 132213:102:<PEER_ASN>, or
132213:103:<PEER_ASN> to prepend your announcing ASN one, two, or three times
toward a selected ASN. Replace the peer ASN with 0 to apply the request to
all route-server clients.
Prepending influences only networks whose policy considers the longer path. Local preference and other higher-priority attributes can override it.
Set MED on route-server export
The CNX helper policy supports five MED values:
132213:901:<TARGET> MED 10
132213:902:<TARGET> MED 20
132213:903:<TARGET> MED 30
132213:904:<TARGET> MED 40
132213:905:<TARGET> MED 50
Set <TARGET> to a peer ASN or 0 for all route-server clients. Attach only
one CNX MED community for a given target to avoid ambiguous intent.
MED is normally compared between paths from the same neighboring AS. Confirm that the receiving network's policy uses MED before depending on this control.
Add NO_EXPORT or NO_ADVERTISE for one peer
Use 132213:65281:<PEER_ASN> to make CNX add the well-known NO_EXPORT
community to the copy sent to one peer. Use 132213:65282:<PEER_ASN> to add
NO_ADVERTISE instead.
This is different from suppressing route-server export: CNX sends the route to the selected peer, and the well-known community instructs that peer how far it may propagate the route. Verify that the receiving platform honors the well-known community.
Verify the result
Check the advertised route on your router and then inspect it through the CNX
looking glass from the intended recipient's perspective. Verify propagation,
the resulting AS_PATH or MED, and the next hop. Do not infer success from the
presence of a community on your outbound route alone.