Route validation policy

CNX applies the following checks before redistributing a member route.

Session and next hop

  • The route must arrive over the configured participant session.
  • The left-most ASN must match the participant ASN.
  • The next hop must be an authorized peering address belonging to the same ASN.
  • The AS path must not contain private or invalid ASNs.
  • The AS path must contain no more than 32 ASNs.

Transit-free ASNs found away from the left-most position currently produce a warning rather than an automatic rejection.

Origin and prefix authorization

The origin ASN must be the participant ASN or a member of the participant's expanded AS-SET. The prefix must be present in the derived IRR route set. Longer prefixes covered by a route-set entry can be accepted only within the global prefix-length limits.

Where the origin is authorized but an IRR route object is missing, a matching RPKI ROA or supported registry dataset may provide prefix authorization. This does not bypass the independent ROV check.

RPKI origin validation

  • Valid routes continue through the remaining checks.
  • Invalid routes are rejected.
  • NotFound/Unknown routes can be accepted when the other authorization checks pass.

ASPA verification is currently disabled. Its presence in generated reject codes does not mean that the active route-server policy enforces it.

Prefix and volume limits

  • IPv4 prefixes must be between /8 and /24.
  • IPv6 prefixes must be within 2000::/3 and between /12 and /48.
  • Bogon, reserved, private, default, and CNX peering-LAN routes are rejected.
  • Member maximum-prefix limits come from explicit participant configuration or PeeringDB, with generated defaults where neither supplies a value.
  • Exceeding the maximum-prefix limit shuts down the session.

Community processing

CNX removes protected internal markers received from a participant, applies its own validation and classification markers, interprets supported steering communities, and removes internal control communities before export.

Only routes that pass every applicable check are eligible for redistribution.