Date: Fri, 29 Mar 2024 01:25:25 +0200 (SAST) Message-ID: <981879648.4359.1711668325373@localhost> Subject: Exported From Confluence MIME-Version: 1.0 Content-Type: multipart/related; boundary="----=_Part_4358_1823610117.1711668325372" ------=_Part_4358_1823610117.1711668325372 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Content-Location: file:///C:/exported.html
To ensure that your connection to the INX is easy, as well as secure, we= have created a set of templates for the configuration of various types of = hardware in common use at the exchange point.
Although we do filter = specific types of Layer-2 frames, we still encourage peers to keep thei= r ports clean, and may insist on this before moving you out of quarantine.<= /p>
We recommend that you use a Layer 3 device to connect to the INXes= ; doing so, minimises your risk of creating any unnecessary loops. &n= bsp;Below are some configurations that should help if you connect directly = to a router (preferred)
interface = <INT> ip address 196.60.x.y 255.255.255.0 ipv6 address 2001:43f8:1fx::y/64 description PEERING:: *INX no ip redirects no ip proxy-arp no cdp enable no ip directed-broadcast no mop enable no keepalive=20 no udld mode aggressive ipv6 nd ra suppress
interface = <INT> description PEERING:: *INX mtu 9216 ipv4 address 196.60.x.y 255.255.255.0 ipv4 verify unicast source reachable-via any ipv4 unreachables disable ipv6 nd suppress-ra ipv6 nd dad attempts 0 ipv6 verify unicast source reachable-via any ipv6 address 2001:43f8:1fx::y/64 ipv6 unreachables disable load-interval 30
interfaces= { ge-0/0/0 { description "PEERING:: *INX=E2=80=9D; unit 0 { family inet { no-redirects; address 196.60.x.y/24; } family inet6 { address 2001:43f8:1fx::y/64 } } }
/interface= ethernet set ether1 comment=3D"PEERING:: *INX" /ip neighbor discovery set ether1 discover=3Dno /ip address add interface=3Dether1 address=3D196.60.x.y/24 /ipv6 address add interface=3Dether1 address=3D2001:43f8:1fx::y/64 advertis= e=3Dno /tool romon port disable numbers=3D<Interfacenumber of Ethernet>
In general it's always safest to connect to an Internet Exchange Point o= nto a layer-3 router port. However, we understand that sometimes this= is difficult to do. In cases where you need to connect your INX port= onto a switch, you will want to pay particular attention to making sure th= at the port that the IX cross-connect terminates on, has been secured. &nbs= p;Below are templates that should help you make a secure connection to the = INX.
vtp mode t= ransparent ! no spanning-tree vlan 9999 ! vlan 9999 name INX ! interface <INT> description PEERING:: *INX switchport mode access switchport access vlan 9999 spanning-tree bpdufilter enable no keepalive no cdp enable no lldp receive no lldp transmit no udld enable end