Cisco IOS XE complete example
This is a configuration pattern for a current IOS XE release. Replace every placeholder and check feature availability on the exact router and software train before applying it.
Member ASN: <YOUR_ASN>
Tagged VLAN: 500 (default)
IX interface: Port-channel10.500
Member IPv4: <MEMBER_IPV4>/24
Member IPv6: <MEMBER_IPV6>
Authorized IPv4: 203.0.113.0/24
Authorized IPv6: 2001:db8:100::/48
Route-server ASN: 132213
The example prefixes are documentation resources. Substitute prefixes that your ASN is authorized to originate.
The configuration intentionally includes every route server and validator. CNX may rotate an individual node out of service for routine maintenance without customer notification, so omitting endpoints removes the designed redundancy.
Port
This example uses Port-channel10 from the first link so that another
CNX-provisioned physical link can later join the LAG without moving the
Layer-3 service or shutting down the logical IX interface. A LAG is optional;
for a direct-port connection, replace Port-channel10 with the physical
interface name throughout the configuration. CNX provisions LAG and MLAG only
within a single site and will not configure a LAG across CNX sites. A
same-site MLAG may terminate on different CNX access switches.
The commands use the default peering VLAN 500. Replace 500 throughout this
example if the CNX connection record assigns a different VLAN.
interface Port-channel10.500
description CNX Internet Exchange
encapsulation dot1Q 500
ip address <MEMBER_IPV4> 255.255.255.0
ipv6 address <MEMBER_IPV6>/64
no ip redirects
no ipv6 redirects
For an untagged handoff, put the addresses on the physical or aggregate interface. Apply the CNX-supplied MTU consistently to the parent and subinterface.
Export only authorized domestic routes
This example announces two exact prefixes and attaches
132213:0:65529, which tells the CNX route servers not to export them to
non-domestic participants.
ip prefix-list CNX-OUT-V4 seq 10 permit 203.0.113.0/24
ipv6 prefix-list CNX-OUT-V6 seq 10 permit 2001:db8:100::/48
route-map CNX-EXPORT-V4 permit 10
match ip address prefix-list CNX-OUT-V4
set large-community 132213:0:65529 additive
route-map CNX-EXPORT-V4 deny 100
route-map CNX-EXPORT-V6 permit 10
match ipv6 address prefix-list CNX-OUT-V6
set large-community 132213:0:65529 additive
route-map CNX-EXPORT-V6 deny 100
Remove the set large-community lines if the routes should reach every route-
server participant.
Prefer accepted CNX routes
Apply ROV and the router's other inbound safety filters before assigning the CNX preference. The final permit term prefers accepted CNX routes over paid transit.
route-map CNX-IMPORT deny 10
match rpki invalid
route-map CNX-IMPORT permit 100
set local-preference 300
Adjust 300 to fit the router's existing local-preference hierarchy. Merge
these terms with existing bogon, leak, and peer-policy filters rather than
replacing them.
Route-server BGP, Add-Path, and ECMP
router bgp <YOUR_ASN>
no bgp enforce-first-as
bgp bestpath as-path multipath-relax
bgp always-compare-med
neighbor CNX-RS4 peer-group
neighbor CNX-RS4 remote-as 132213
neighbor 103.7.144.1 peer-group CNX-RS4
neighbor 103.7.144.2 peer-group CNX-RS4
neighbor 103.7.144.3 peer-group CNX-RS4
neighbor CNX-RS6 peer-group
neighbor CNX-RS6 remote-as 132213
neighbor 2001:de8:1d::1 peer-group CNX-RS6
neighbor 2001:de8:1d::2 peer-group CNX-RS6
neighbor 2001:de8:1d::3 peer-group CNX-RS6
address-family ipv4 unicast
neighbor CNX-RS4 activate
neighbor CNX-RS4 route-map CNX-IMPORT in
neighbor CNX-RS4 route-map CNX-EXPORT-V4 out
neighbor CNX-RS4 send-community both
neighbor CNX-RS4 additional-paths receive
maximum-paths eibgp 8
exit-address-family
address-family ipv6 unicast
neighbor CNX-RS6 activate
neighbor CNX-RS6 route-map CNX-IMPORT in
neighbor CNX-RS6 route-map CNX-EXPORT-V6 out
neighbor CNX-RS6 send-community both
neighbor CNX-RS6 additional-paths receive
maximum-paths eibgp 8
exit-address-family
Some IOS XE trains use address-family-wide bgp additional-paths receive
instead of the neighbor form. Confirm the negotiated capability after the
session restarts. Disabling first-AS enforcement is required because the
transparent route servers do not insert AS132213 into the redistributed
AS_PATH.
RPKI validators and ROV
Configure all three CNX RTR endpoints. The directly connected route normally
causes the sessions to use <MEMBER_IPV6>; verify the actual source address
because the IOS XE command does not provide a source-address argument.
router bgp <YOUR_ASN>
bgp rpki server tcp 2001:df6:1441::d:7f48 port 3323 refresh 600
bgp rpki server tcp 2001:df6:1441::2:d027 port 3323 refresh 600
bgp rpki server tcp 2001:df6:1441::6:1ba7 port 3323 refresh 600
Do not configure bgp bestpath prefix-validate allow-invalid. The explicit
route map rejects Invalid routes and permits Valid and NotFound routes to
continue through the import policy defined above. Keep the Invalid rejection
ahead of the preference and the router's remaining import-policy terms.
NTP
IOS XE has no verified native RFC 8915 client configuration for this guide. The CNX member time service is available only over the CNX member peering network. Use direct IPv6 NTP and source it from the CNX-facing interface; this must produce the IPv6 peering address assigned to your membership:
ntp server 2001:df6:1440::123 source Port-channel10.500 preferVerification
show interfaces Port-channel10.500
show bgp ipv4 unicast summary
show bgp ipv6 unicast summary
show bgp ipv4 unicast neighbors 103.7.144.1
show bgp ipv6 unicast neighbors 2001:de8:1d::1
show ip bgp rpki servers
show ntp associations
Verify advertised routes separately for every route server, confirm Add-Path receive negotiation, inspect the forwarding table for multiple next hops, and confirm that the RTR connections use the assigned CNX IPv6 source.