Cisco IOS XE complete example

This is a configuration pattern for a current IOS XE release. Replace every placeholder and check feature availability on the exact router and software train before applying it.

Member ASN:          <YOUR_ASN>
Tagged VLAN:         500 (default)
IX interface:        Port-channel10.500
Member IPv4:         <MEMBER_IPV4>/24
Member IPv6:         <MEMBER_IPV6>
Authorized IPv4:     203.0.113.0/24
Authorized IPv6:     2001:db8:100::/48
Route-server ASN:    132213

The example prefixes are documentation resources. Substitute prefixes that your ASN is authorized to originate.

The configuration intentionally includes every route server and validator. CNX may rotate an individual node out of service for routine maintenance without customer notification, so omitting endpoints removes the designed redundancy.

Port

This example uses Port-channel10 from the first link so that another CNX-provisioned physical link can later join the LAG without moving the Layer-3 service or shutting down the logical IX interface. A LAG is optional; for a direct-port connection, replace Port-channel10 with the physical interface name throughout the configuration. CNX provisions LAG and MLAG only within a single site and will not configure a LAG across CNX sites. A same-site MLAG may terminate on different CNX access switches.

The commands use the default peering VLAN 500. Replace 500 throughout this example if the CNX connection record assigns a different VLAN.

interface Port-channel10.500
 description CNX Internet Exchange
 encapsulation dot1Q 500
 ip address <MEMBER_IPV4> 255.255.255.0
 ipv6 address <MEMBER_IPV6>/64
 no ip redirects
 no ipv6 redirects

For an untagged handoff, put the addresses on the physical or aggregate interface. Apply the CNX-supplied MTU consistently to the parent and subinterface.

Export only authorized domestic routes

This example announces two exact prefixes and attaches 132213:0:65529, which tells the CNX route servers not to export them to non-domestic participants.

ip prefix-list CNX-OUT-V4 seq 10 permit 203.0.113.0/24
ipv6 prefix-list CNX-OUT-V6 seq 10 permit 2001:db8:100::/48

route-map CNX-EXPORT-V4 permit 10
 match ip address prefix-list CNX-OUT-V4
 set large-community 132213:0:65529 additive
route-map CNX-EXPORT-V4 deny 100

route-map CNX-EXPORT-V6 permit 10
 match ipv6 address prefix-list CNX-OUT-V6
 set large-community 132213:0:65529 additive
route-map CNX-EXPORT-V6 deny 100

Remove the set large-community lines if the routes should reach every route- server participant.

Prefer accepted CNX routes

Apply ROV and the router's other inbound safety filters before assigning the CNX preference. The final permit term prefers accepted CNX routes over paid transit.

route-map CNX-IMPORT deny 10
 match rpki invalid
route-map CNX-IMPORT permit 100
 set local-preference 300

Adjust 300 to fit the router's existing local-preference hierarchy. Merge these terms with existing bogon, leak, and peer-policy filters rather than replacing them.

Route-server BGP, Add-Path, and ECMP

router bgp <YOUR_ASN>
 no bgp enforce-first-as
 bgp bestpath as-path multipath-relax
 bgp always-compare-med

 neighbor CNX-RS4 peer-group
 neighbor CNX-RS4 remote-as 132213
 neighbor 103.7.144.1 peer-group CNX-RS4
 neighbor 103.7.144.2 peer-group CNX-RS4
 neighbor 103.7.144.3 peer-group CNX-RS4

 neighbor CNX-RS6 peer-group
 neighbor CNX-RS6 remote-as 132213
 neighbor 2001:de8:1d::1 peer-group CNX-RS6
 neighbor 2001:de8:1d::2 peer-group CNX-RS6
 neighbor 2001:de8:1d::3 peer-group CNX-RS6

 address-family ipv4 unicast
  neighbor CNX-RS4 activate
  neighbor CNX-RS4 route-map CNX-IMPORT in
  neighbor CNX-RS4 route-map CNX-EXPORT-V4 out
  neighbor CNX-RS4 send-community both
  neighbor CNX-RS4 additional-paths receive
  maximum-paths eibgp 8
 exit-address-family

 address-family ipv6 unicast
  neighbor CNX-RS6 activate
  neighbor CNX-RS6 route-map CNX-IMPORT in
  neighbor CNX-RS6 route-map CNX-EXPORT-V6 out
  neighbor CNX-RS6 send-community both
  neighbor CNX-RS6 additional-paths receive
  maximum-paths eibgp 8
 exit-address-family

Some IOS XE trains use address-family-wide bgp additional-paths receive instead of the neighbor form. Confirm the negotiated capability after the session restarts. Disabling first-AS enforcement is required because the transparent route servers do not insert AS132213 into the redistributed AS_PATH.

RPKI validators and ROV

Configure all three CNX RTR endpoints. The directly connected route normally causes the sessions to use <MEMBER_IPV6>; verify the actual source address because the IOS XE command does not provide a source-address argument.

router bgp <YOUR_ASN>
 bgp rpki server tcp 2001:df6:1441::d:7f48 port 3323 refresh 600
 bgp rpki server tcp 2001:df6:1441::2:d027 port 3323 refresh 600
 bgp rpki server tcp 2001:df6:1441::6:1ba7 port 3323 refresh 600

Do not configure bgp bestpath prefix-validate allow-invalid. The explicit route map rejects Invalid routes and permits Valid and NotFound routes to continue through the import policy defined above. Keep the Invalid rejection ahead of the preference and the router's remaining import-policy terms.

NTP

IOS XE has no verified native RFC 8915 client configuration for this guide. The CNX member time service is available only over the CNX member peering network. Use direct IPv6 NTP and source it from the CNX-facing interface; this must produce the IPv6 peering address assigned to your membership:

ntp server 2001:df6:1440::123 source Port-channel10.500 prefer

Verification

show interfaces Port-channel10.500
show bgp ipv4 unicast summary
show bgp ipv6 unicast summary
show bgp ipv4 unicast neighbors 103.7.144.1
show bgp ipv6 unicast neighbors 2001:de8:1d::1
show ip bgp rpki servers
show ntp associations

Verify advertised routes separately for every route server, confirm Add-Path receive negotiation, inspect the forwarding table for multiple next hops, and confirm that the RTR connections use the assigned CNX IPv6 source.

Vendor references