Junos OS complete example
This example uses set-format configuration. Replace every placeholder and confirm feature support on the exact platform and Junos release.
Member ASN: <YOUR_ASN>
Tagged VLAN: 500 (default)
IX aggregate: ae10
Member IPv4: <MEMBER_IPV4>/24
Member IPv6: <MEMBER_IPV6>/64
Authorized IPv4: 203.0.113.0/24
Authorized IPv6: 2001:db8:100::/48
Route-server ASN: 132213
The configuration intentionally includes every route server and validator. CNX may rotate an individual node out of service for routine maintenance without customer notification, so omitting endpoints removes the designed redundancy.
Port
This example uses ae10 from the first link so that another CNX-provisioned
physical link can later join the LAG without moving the Layer-3 service or
disabling the logical IX interface. A LAG is optional; for a direct-port
connection, replace ae10 with the physical interface name throughout the
configuration. CNX provisions LAG and MLAG only within a single site and will
not configure a LAG across CNX sites. A same-site MLAG may terminate on
different CNX access switches.
The commands use the default peering VLAN 500. Replace 500 throughout this
example if the CNX connection record assigns a different VLAN.
set interfaces ae10 mtu <MTU>
set interfaces ae10 unit 500 vlan-id 500
set interfaces ae10 unit 500 family inet address <MEMBER_IPV4>/24
set interfaces ae10 unit 500 family inet6 address <MEMBER_IPV6>/64
Use unit 0 without vlan-id for an untagged handoff.
Export only authorized domestic routes
set policy-options prefix-list CNX-OUT-V4 203.0.113.0/24
set policy-options prefix-list CNX-OUT-V6 2001:db8:100::/48
set policy-options community CNX-DOMESTIC-ONLY members large:132213:0:65529
set policy-options policy-statement CNX-EXPORT term ipv4 from family inet
set policy-options policy-statement CNX-EXPORT term ipv4 from prefix-list-filter CNX-OUT-V4 exact
set policy-options policy-statement CNX-EXPORT term ipv4 then community add CNX-DOMESTIC-ONLY
set policy-options policy-statement CNX-EXPORT term ipv4 then accept
set policy-options policy-statement CNX-EXPORT term ipv6 from family inet6
set policy-options policy-statement CNX-EXPORT term ipv6 from prefix-list-filter CNX-OUT-V6 exact
set policy-options policy-statement CNX-EXPORT term ipv6 then community add CNX-DOMESTIC-ONLY
set policy-options policy-statement CNX-EXPORT term ipv6 then accept
set policy-options policy-statement CNX-EXPORT term reject then reject
Delete the two community add actions if the routes should reach all route-
server participants.
RPKI validators and import policy
set routing-options validation group CNX-RPKI session 2001:df6:1441::d:7f48 port 3323
set routing-options validation group CNX-RPKI session 2001:df6:1441::d:7f48 local-address <MEMBER_IPV6>
set routing-options validation group CNX-RPKI session 2001:df6:1441::2:d027 port 3323
set routing-options validation group CNX-RPKI session 2001:df6:1441::2:d027 local-address <MEMBER_IPV6>
set routing-options validation group CNX-RPKI session 2001:df6:1441::6:1ba7 port 3323
set routing-options validation group CNX-RPKI session 2001:df6:1441::6:1ba7 local-address <MEMBER_IPV6>
set policy-options policy-statement CNX-IMPORT term rpki-invalid from protocol bgp
set policy-options policy-statement CNX-IMPORT term rpki-invalid from validation-database invalid
set policy-options policy-statement CNX-IMPORT term rpki-invalid then reject
set policy-options policy-statement CNX-IMPORT term continue then accept
The final accept represents the remainder of this minimal example. In a real
router, place the Invalid rejection before the existing peer, bogon, and local-
preference policy rather than bypassing it.
Route-server BGP, Add-Path, and ECMP
set routing-options autonomous-system <YOUR_ASN>
set protocols bgp group CNX-RS type external
set protocols bgp group CNX-RS peer-as 132213
set protocols bgp group CNX-RS import CNX-IMPORT
set protocols bgp group CNX-RS export CNX-EXPORT
set protocols bgp group CNX-RS family inet unicast add-path receive
set protocols bgp group CNX-RS family inet6 unicast add-path receive
set protocols bgp group CNX-RS multipath multiple-as
set protocols bgp group CNX-RS neighbor 103.7.144.1 local-address <MEMBER_IPV4>
set protocols bgp group CNX-RS neighbor 103.7.144.2 local-address <MEMBER_IPV4>
set protocols bgp group CNX-RS neighbor 103.7.144.3 local-address <MEMBER_IPV4>
set protocols bgp group CNX-RS neighbor 2001:de8:1d::1 local-address <MEMBER_IPV6>
set protocols bgp group CNX-RS neighbor 2001:de8:1d::2 local-address <MEMBER_IPV6>
set protocols bgp group CNX-RS neighbor 2001:de8:1d::3 local-address <MEMBER_IPV6>
Do not configure enforce-first-as on this group. If several equal BGP paths
reach the routing table but only one enters forwarding, add the forwarding-
table load-balancing policy appropriate for the installed platform and release.
NTP
The CNX member time service is available only over the CNX member peering network. The router must source requests from the IPv6 peering address assigned to your membership:
set system ntp source-address <MEMBER_IPV6>
set system ntp server 2001:df6:1440::123 preferNTS on supported Junos OS Evolved platforms
Native RFC 8915 support starts with Junos OS Evolved 24.2R1 on selected ACX,
QFX, and PTX platforms. After importing the verified CNX root certificate into
the CNX-ROOT CA profile:
set system ntp nts trusted-ca trusted-ca-profile CNX-ROOT
set system ntp server 2001:df6:1440::123 nts remote-identity hostname nts.cnx.net.kh
Confirm the exact model in Juniper Feature Explorer and validate the server chain before committing the NTS configuration.
Verification
show interfaces terse ae10.500
show bgp summary
show bgp neighbor 103.7.144.1
show bgp neighbor 2001:de8:1d::1
show validation session
show validation database brief
show route validation-state invalid
show ntp associations
Also inspect a suitable prefix for multiple retained BGP paths and multiple installed forwarding next hops.