Huawei VRP complete example

VRP command availability and hierarchy vary across Huawei product families. This example follows current NetEngine-style VRP syntax; validate it against the exact model and release before committing it.

Member ASN:          <YOUR_ASN>
Tagged VLAN:         500 (default)
IX interface:        Eth-Trunk10.500
Member IPv4:         <MEMBER_IPV4>/24
Member IPv6:         <MEMBER_IPV6>/64
Authorized IPv4:     203.0.113.0/24
Authorized IPv6:     2001:db8:100::/48
Route-server ASN:    132213

The configuration intentionally includes every route server and validator. CNX may rotate an individual node out of service for routine maintenance without customer notification, so omitting endpoints removes the designed redundancy.

Port

This example uses Eth-Trunk10 from the first link so that another CNX-provisioned physical link can later join the LAG without moving the Layer-3 service or shutting down the logical IX interface. A LAG is optional; for a direct-port connection, replace Eth-Trunk10 with the physical interface name throughout the configuration. CNX provisions LAG and MLAG only within a single site and will not configure a LAG across CNX sites. A same-site MLAG may terminate on different CNX access switches.

The commands use the default peering VLAN 500. Replace 500 throughout this example if the CNX connection record assigns a different VLAN.

interface Eth-Trunk10.500
 description CNX Internet Exchange
 dot1q termination vid 500
 ip address <MEMBER_IPV4> 255.255.255.0
 ipv6 enable
 ipv6 address <MEMBER_IPV6> 64
 mtu <MTU>

Some VRP platforms use a different VLAN encapsulation command. For an untagged handoff, configure the aggregate or physical interface directly.

Export only authorized domestic routes

ip ip-prefix CNX-OUT-V4 index 10 permit 203.0.113.0 24
ip ipv6-prefix CNX-OUT-V6 index 10 permit 2001:db8:100:: 48

route-policy CNX-EXPORT-V4 permit node 10
 if-match ip-prefix CNX-OUT-V4
 apply large-community 132213:0:65529 additive
route-policy CNX-EXPORT-V4 deny node 100

route-policy CNX-EXPORT-V6 permit node 10
 if-match ipv6 address prefix-list CNX-OUT-V6
 apply large-community 132213:0:65529 additive
route-policy CNX-EXPORT-V6 deny node 100

Remove the apply large-community actions if the routes should reach every route-server participant.

RPKI validators and ROV

Configure each CNX validator as a separate RPKI session:

rpki
 session 2001:df6:1441::d:7f48
  tcp port 3323
  connect-interface <MEMBER_IPV6>
 quit
 session 2001:df6:1441::2:d027
  tcp port 3323
  connect-interface <MEMBER_IPV6>
 quit
 session 2001:df6:1441::6:1ba7
  tcp port 3323
  connect-interface <MEMBER_IPV6>
 quit
quit
commit

The official VRP command permits an IPv6 source address in connect-interface. On products that require the interface name as well, include the actual CNX-facing interface according to that release's command reference.

Enable origin validation in both BGP address families. Omitting allow-invalid keeps Invalid routes out of best-path selection:

bgp <YOUR_ASN>
 ipv4-family unicast
  prefix origin-validation enable
  bestroute origin-as-validation
 ipv6-family unicast
  prefix origin-validation enable
  bestroute origin-as-validation
commit

Route-server BGP, Add-Path, and ECMP

bgp <YOUR_ASN>
 undo check-first-as
 peer CNX-RS4 group
 peer CNX-RS4 as-number 132213
 peer 103.7.144.1 group CNX-RS4
 peer 103.7.144.2 group CNX-RS4
 peer 103.7.144.3 group CNX-RS4
 peer CNX-RS6 group
 peer CNX-RS6 as-number 132213
 peer 2001:de8:1d::1 group CNX-RS6
 peer 2001:de8:1d::2 group CNX-RS6
 peer 2001:de8:1d::3 group CNX-RS6

 ipv4-family unicast
  peer CNX-RS4 enable
  peer CNX-RS4 route-policy CNX-EXPORT-V4 export
  peer CNX-RS4 advertise-large-community
  peer CNX-RS4 capability-advertise add-path receive
  maximum load-balancing ebgp 8
  load-balancing as-path-relax

 ipv6-family unicast
  peer CNX-RS6 enable
  peer CNX-RS6 route-policy CNX-EXPORT-V6 export
  peer CNX-RS6 advertise-large-community
  peer CNX-RS6 capability-advertise add-path receive
  maximum load-balancing ebgp 8
  load-balancing as-path-relax
commit

The transparent route servers do not insert AS132213 into the redistributed AS_PATH, which is why first-AS checking is disabled for these sessions.

NTP

No verified native RFC 8915 NTS client configuration is available for this guide. The CNX member time service is available only over the CNX member peering network. Configure direct IPv6 NTP and source it from the CNX-facing interface; this must produce the IPv6 peering address assigned to your membership:

ntp-service unicast-server 2001:df6:1440::123
ntp-service server source-interface Eth-Trunk10.500
commit

Check the exact source-interface command semantics for the installed VRP family; it must result in <MEMBER_IPV6> as the packet source.

Verification

display interface Eth-Trunk10.500
display bgp peer
display bgp routing-table
display rpki session 2001:df6:1441::d:7f48 verbose
display rpki table
display ntp-service sessions

Confirm the Add-Path receive capability, inspect a suitable prefix for several paths, and verify multiple installed forwarding next hops separately.

Vendor references