Port security and Layer 2 traffic controls
- MAC address authorization — Only one source MAC address is permitted per physical service port. Extreme IX drops traffic from any unapproved MAC address at the port level. For a VLAN interconnect service, one unique source MAC address is allowed per provisioned VLAN ID.
- VLAN restrictions — Native VLAN 1 framing is not permitted on any interface connected to Extreme IX.
- Prohibited L2 control protocols — Disable Spanning Tree Protocol (STP) on all member-facing interfaces connected to Extreme IX. Configure BPDU filtering on your router to prevent BPDU leakage.
- Proxy ARP prohibition — Disable Proxy ARP on all router interfaces connected to the exchange.
Traffic filtering and broadcast limits
- Prohibited link-local protocols — Do not forward frames addressed to link-local multicast or broadcast destination protocols to Extreme IX ports, including:
- Discovery protocols: CDP, EDP, LLDP
- VLAN/trunking protocols: VTP, DTP
- Router and control traffic: IRDP, ICMP redirects, BOOTP/DHCP
- Allowed broadcast and multicast packets — Extreme IX blocks destination broadcast and multicast frames by default, except for broadcast ARP packets and multicast IPv6 Neighbor Discovery (ND) packets.
- Broadcast rate limiting — Broadcast traffic forwarded from a member’s port must not exceed 50 packets per second (pps) per physical interface.
BGP and routing guidelines
- Prefix announcement limits — The smallest IP address block you can advertise over Extreme IX is a
/24(IPv4) or/48(IPv6). - Routing table policy — Do not advertise full internet routing tables. Advertise only your authorized local prefixes, DNS IP pools, and end-user IP pools.