Huawei VRP complete example
VRP command availability and hierarchy vary across Huawei product families. This example follows current NetEngine-style VRP syntax; validate it against the exact model and release before committing it.
Member ASN: <YOUR_ASN>
Tagged VLAN: 500 (default)
IX interface: Eth-Trunk10.500
Member IPv4: <MEMBER_IPV4>/24
Member IPv6: <MEMBER_IPV6>/64
Authorized IPv4: 203.0.113.0/24
Authorized IPv6: 2001:db8:100::/48
Route-server ASN: 132213
The configuration intentionally includes every route server and validator. CNX may rotate an individual node out of service for routine maintenance without customer notification, so omitting endpoints removes the designed redundancy.
Port
This example uses Eth-Trunk10 from the first link so that another
CNX-provisioned physical link can later join the LAG without moving the
Layer-3 service or shutting down the logical IX interface. A LAG is optional;
for a direct-port connection, replace Eth-Trunk10 with the physical interface
name throughout the configuration. CNX provisions LAG and MLAG only within a
single site and will not configure a LAG across CNX sites. A same-site MLAG may
terminate on different CNX access switches.
The commands use the default peering VLAN 500. Replace 500 throughout this
example if the CNX connection record assigns a different VLAN.
interface Eth-Trunk10.500
description CNX Internet Exchange
dot1q termination vid 500
ip address <MEMBER_IPV4> 255.255.255.0
ipv6 enable
ipv6 address <MEMBER_IPV6> 64
mtu <MTU>
Some VRP platforms use a different VLAN encapsulation command. For an untagged handoff, configure the aggregate or physical interface directly.
Export only authorized domestic routes
ip ip-prefix CNX-OUT-V4 index 10 permit 203.0.113.0 24
ip ipv6-prefix CNX-OUT-V6 index 10 permit 2001:db8:100:: 48
route-policy CNX-EXPORT-V4 permit node 10
if-match ip-prefix CNX-OUT-V4
apply large-community 132213:0:65529 additive
route-policy CNX-EXPORT-V4 deny node 100
route-policy CNX-EXPORT-V6 permit node 10
if-match ipv6 address prefix-list CNX-OUT-V6
apply large-community 132213:0:65529 additive
route-policy CNX-EXPORT-V6 deny node 100
Remove the apply large-community actions if the routes should reach every
route-server participant.
RPKI validators and ROV
Configure each CNX validator as a separate RPKI session:
rpki
session 2001:df6:1441::d:7f48
tcp port 3323
connect-interface <MEMBER_IPV6>
quit
session 2001:df6:1441::2:d027
tcp port 3323
connect-interface <MEMBER_IPV6>
quit
session 2001:df6:1441::6:1ba7
tcp port 3323
connect-interface <MEMBER_IPV6>
quit
quit
commit
The official VRP command permits an IPv6 source address in
connect-interface. On products that require the interface name as well,
include the actual CNX-facing interface according to that release's command
reference.
Enable origin validation in both BGP address families. Omitting
allow-invalid keeps Invalid routes out of best-path selection:
bgp <YOUR_ASN>
ipv4-family unicast
prefix origin-validation enable
bestroute origin-as-validation
ipv6-family unicast
prefix origin-validation enable
bestroute origin-as-validation
commitRoute-server BGP, Add-Path, and ECMP
bgp <YOUR_ASN>
undo check-first-as
peer CNX-RS4 group
peer CNX-RS4 as-number 132213
peer 103.7.144.1 group CNX-RS4
peer 103.7.144.2 group CNX-RS4
peer 103.7.144.3 group CNX-RS4
peer CNX-RS6 group
peer CNX-RS6 as-number 132213
peer 2001:de8:1d::1 group CNX-RS6
peer 2001:de8:1d::2 group CNX-RS6
peer 2001:de8:1d::3 group CNX-RS6
ipv4-family unicast
peer CNX-RS4 enable
peer CNX-RS4 route-policy CNX-EXPORT-V4 export
peer CNX-RS4 advertise-large-community
peer CNX-RS4 capability-advertise add-path receive
maximum load-balancing ebgp 8
load-balancing as-path-relax
ipv6-family unicast
peer CNX-RS6 enable
peer CNX-RS6 route-policy CNX-EXPORT-V6 export
peer CNX-RS6 advertise-large-community
peer CNX-RS6 capability-advertise add-path receive
maximum load-balancing ebgp 8
load-balancing as-path-relax
commit
The transparent route servers do not insert AS132213 into the redistributed
AS_PATH, which is why first-AS checking is disabled for these sessions.
NTP
No verified native RFC 8915 NTS client configuration is available for this guide. The CNX member time service is available only over the CNX member peering network. Configure direct IPv6 NTP and source it from the CNX-facing interface; this must produce the IPv6 peering address assigned to your membership:
ntp-service unicast-server 2001:df6:1440::123
ntp-service server source-interface Eth-Trunk10.500
commit
Check the exact source-interface command semantics for the installed VRP
family; it must result in <MEMBER_IPV6> as the packet source.
Verification
display interface Eth-Trunk10.500
display bgp peer
display bgp routing-table
display rpki session 2001:df6:1441::d:7f48 verbose
display rpki table
display ntp-service sessions
Confirm the Add-Path receive capability, inspect a suitable prefix for several paths, and verify multiple installed forwarding next hops separately.