BGP large communities

CNX documents large communities as its route-server control interface. In the tables below, <PEER_ASN> is the ASN of the route-server client affected by the control. <TARGET> is either a peer ASN or 0 for all clients.

Propagation controls

ActionLarge community
Do not announce to any route-server client132213:0:0
Announce to one peer as an exception to the previous control132213:1:<PEER_ASN>
Do not announce to one peer132213:0:<PEER_ASN>
Do not announce to domestic peers132213:0:65528
Do not announce to non-domestic peers132213:0:65529

The per-peer exception is meaningful when used with 132213:0:0.

AS-path prepend controls

ActionOne peerAll peers
Prepend announcing ASN once132213:101:<PEER_ASN>132213:101:0
Prepend announcing ASN twice132213:102:<PEER_ASN>132213:102:0
Prepend announcing ASN three times132213:103:<PEER_ASN>132213:103:0

Per-export MED controls

MED applied by CNXLarge community
10132213:901:<TARGET>
20132213:902:<TARGET>
30132213:903:<TARGET>
40132213:904:<TARGET>
50132213:905:<TARGET>

Use one MED community per target. CNX removes communities in its internal 132213:900-999:* control range before export.

Add a well-known community on export

Action toward one peerLarge community received by CNX
Add NO_EXPORT to the route exported to that peer132213:65281:<PEER_ASN>
Add NO_ADVERTISE to the route exported to that peer132213:65282:<PEER_ASN>

These controls cause CNX to add the corresponding well-known community to the copy exported to the selected route-server client. They do not affect a bilateral session.

Communities CNX attaches

Location and participant class

MeaningLarge community
Recipient and route next hop are at the same CNX site132213:65527:0
Route received from a domestic participant132213:65528:0
Route received from a non-domestic participant132213:65529:0

CNX removes member-supplied copies of these markers before applying its own classification.

Registry and origin-validation state

MeaningLarge community
Prefix is present in the member's derived IRR set132213:64512:11
Prefix is not present in the member's derived IRR set132213:64512:10
Origin is present in the member's derived AS-SET132213:64512:21
Origin is not present in the member's derived AS-SET132213:64512:20
Prefix was validated using a covering ROA as a route object132213:64512:31
Prefix was validated using the Registro.br dataset132213:64512:61
Route was accepted through an explicit whitelist132213:64512:41
ROV Valid132213:1000:1
ROV NotFound/Unknown132213:1000:2
ROV not performed132213:1000:3
ROV Invalid132213:1000:4

RPKI Invalid routes are rejected rather than exported as ordinary usable routes. Validation and reject markers are primarily useful through route-server diagnostics and the looking glass.

Reject-reason communities

Rejected routes are tagged 132213:65520:<REASON> in route-server diagnostic views.

ReasonMeaning
0Generic rejection
1Invalid AS-path length
2Bogon prefix
3Globally blacklisted prefix
4Invalid address family
5Invalid next hop
6Invalid left-most ASN
7Invalid ASN in the AS path
8Transit-free ASN found in an invalid AS-path position
9Origin ASN not authorized by the member's AS-SET
10IPv6 prefix outside global unicast space
11Prefix in the member-specific blacklist
12Prefix not authorized by the derived IRR set
13Invalid prefix length
14RPKI Invalid route
15Route-server ASN found where policy forbids it
16ASPA Invalid AS path; reserved for ASPA enforcement
65535Unknown or hook-defined rejection

Diagnostic views may also carry 132213:65499:<ANNOUNCING_ASN> to identify the member ASN from which a rejected route was received. These diagnostic markers are not steering controls.

Well-known communities

CNX honors the standard GRACEFUL_SHUTDOWN community 65535:0 by lowering route-server local preference to zero. The generated policy also recognizes the RFC 7999 BLACKHOLE community 65535:666; blackhole routes are propagated unchanged with NO_EXPORT. Acceptance by another member remains subject to that member's policy.