Technical Requirements

These Technical Requirements (TR) define the ways in which you may or may not make use of the CNX services. This document will be regularly reviewed and revised in the light of operational experience to ensure maximum protection of service to CNX members.

Physical Configuration

  1. Ethernet interfaces attached to CNX ports shall be explicitly configured with duplex, speed and other configuration settings and shall not be auto-sensing.

MAC Layer

  1. Only specified ethertypes are allowed on the CNX VLANs. The policy is enforced with a VACL configured on the CNX switches.
  2. The following ethertypes are allowed:
    • 0x0800: IPv4
    • 0x0806: ARP
    • 0x86dd: IPv6
  3. Frames with any other ethertypes are dropped on CNX switch ingress.
  4. All frames of a service forwarded to an individual CNX port shall have the same source MAC address.

IP Layer

  1. Interfaces connected to CNX ports shall only use IP addresses and netmasks (prefix lengths) assigned to them by CNX. In particular:
    • IPv6 addresses (link & global scope) shall be explicitly configured and not auto-configured
    • IPv6 site-local addresses shall not be used
  2. Standard IP MTU size = 1500

Routing

  1. All exchange of routes across the CNX network shall be via BGP4(+).
  2. AS numbers used in BGP4(+) sessions across the CNX network shall not be from range reserved for private use.
  3. All routes advertised shall be aggregated as far as possible.
  4. IP address space assigned to CNX peering LAN shall not be advertised to other networks without explicit permission of CNX.
  5. All routes to be advertised in a peering session across CNX shall be registered in the APNIC or other public routing registry.

Forwarding

  1. Traffic shall only be forwarded to a CNX member when permission has been given by the receiving member either:
    • by advertising a route across the CNX network (directly or via the routeserver)
    • or explicitly in writing
  2. Traffic shall not be routinely exchanged between two CNX ports owned by the same CNX member.

CNX TR – May 2016

CNX configuration

global mac access list

mac access-list extended ix-protocols
 permit any any 0x800 0x0
 permit any any 0x806 0x0
 permit any any 0x86DD 0x0

per port configuration

mac access-group ix-protocols in

default switchport configuration

 
interface GigabitEthernet1/0/16
 switchport access vlan 500
 switchport mode access
 switchport nonegotiate
 switchport port-security violation protect
 switchport port-security mac-address sticky
 switchport port-security mac-address sticky 'Mac-address of Router' vlan access
 spanning-tree bpdufilter enable
 spanning-tree bpduguard enable
 no shutdown