> ## Documentation Index
> Fetch the complete documentation index at: https://docs.megaport.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Policies on Extreme IX

> This help topic describes the technical and security policies that member networks must follow when connecting to Extreme IX.

To preserve platform stability, prevent service degradation, and protect members against security threats, all member networks connected to Extreme IX must meet the following technical and port security requirements.

## Port security and Layer 2 traffic controls

* **MAC address authorization** -- Only one source MAC address is permitted per physical service port. Extreme IX drops traffic from any unapproved MAC address at the port level. For a VLAN interconnect service, one unique source MAC address is allowed per provisioned VLAN ID.
* **VLAN restrictions** -- Native VLAN 1 framing is not permitted on any interface connected to Extreme IX.
* **Prohibited L2 control protocols** -- Disable Spanning Tree Protocol (STP) on all member-facing interfaces connected to Extreme IX. Configure BPDU filtering on your router to prevent BPDU leakage.
* **Proxy ARP prohibition** -- Disable Proxy ARP on all router interfaces connected to the exchange.

## Traffic filtering and broadcast limits

* **Prohibited link-local protocols** -- Do not forward frames addressed to link-local multicast or broadcast destination protocols to Extreme IX ports, including:
  * Discovery protocols: CDP, EDP, LLDP
  * VLAN/trunking protocols: VTP, DTP
  * Router and control traffic: IRDP, ICMP redirects, BOOTP/DHCP
* **Allowed broadcast and multicast packets** -- Extreme IX blocks destination broadcast and multicast frames by default, except for broadcast ARP packets and multicast IPv6 Neighbor Discovery (ND) packets.
* **Broadcast rate limiting** -- Broadcast traffic forwarded from a member's port must not exceed 50 packets per second (pps) per physical interface.

## BGP and routing guidelines

* **Prefix announcement limits** -- The smallest IP address block you can advertise over Extreme IX is a `/24` (IPv4) or `/48` (IPv6).
* **Routing table policy** -- Do not advertise full internet routing tables. Advertise only your authorized local prefixes, DNS IP pools, and end-user IP pools.

## Technical references

For the complete technical specifications, see the [Extreme IX Technical Requirements page](https://extreme-ix.org/resources/technical-requirements).

## PeeringDB record

For step-by-step instructions on updating your network entry, setting your AS-SET, and linking your ports, see [PeeringDB Record](/ix/extreme-ix/peeringdb-record).
