{"id":17,"date":"2025-03-13T06:58:54","date_gmt":"2025-03-13T06:58:54","guid":{"rendered":"https:\/\/fe.desnet.online\/apjii\/?page_id=17"},"modified":"2025-03-17T10:23:23","modified_gmt":"2025-03-17T03:23:23","slug":"allowed-traffic","status":"publish","type":"page","link":"https:\/\/fe.desnet.online\/apjii\/allowed-traffic\/","title":{"rendered":"Allowed Traffic"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"17\" class=\"elementor elementor-17\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-66d971f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"66d971f\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-b688c5c\" data-id=\"b688c5c\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2f93311 elementor-widget elementor-widget-heading\" data-id=\"2f93311\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Allowed Traffic Types on Unicast Peering LANs<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9e20eee elementor-widget elementor-widget-text-editor\" data-id=\"9e20eee\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>To ensure smooth operation of the IIX infrastructure we impose a set of restrictions on what kind of traffic is allowed on the peering fabric. This page gives a summary of those restrictions. For more info, including hints on how to configure equipment, please see the IIX Configuration Guide.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d4bb18e elementor-widget elementor-widget-heading\" data-id=\"d4bb18e\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">1. Physical Connection<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-23342f2 elementor-widget elementor-widget-text-editor\" data-id=\"23342f2\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Interface settings<br \/>1Gbase and 10Gbase Ethernet interfaces attached to IIX ports must be explicitly configured with speed, duplex other configuration settings, i.e. they should not be auto-sensing.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-df2388e elementor-widget elementor-widget-heading\" data-id=\"df2388e\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">2. MAC Layer<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c8a1696 elementor-widget elementor-widget-text-editor\" data-id=\"c8a1696\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>2.1 Ethernet framing<\/p><p>The IIX infrastructure is based on the Ethernet II (or \u201cDIX Ethernet\u201d) standard. This means that LLC\/SNAP encapsulation (802.2) is not permitted. For more information on the differences, see the Ethernet FAQ, question 4.1.2.2 Ethernet types.<\/p><p>Frames forwarded to Some Exchange ports must have one of the following ethertypes:<\/p><ul><li>0x0800 \u2013 IPv4<\/li><li>0x0806 \u2013 ARP<\/li><li>0x86dd \u2013 IPv6<\/li><\/ul><p>2.3 One MAC address per connection<br \/>Frames forwarded to an individual IIX port shall all have the same source MAC address.<\/p><p>2.4 No proxy ARP <br \/>Use of proxy ARP on the router\u2019s interface to the Exchange is not allowed.<\/p><p>2.5 Unicast only<br \/>Frames forwarded to IIX ports shall not be addressed to a multicast or broadcast MAC destination address except as follows:<\/p><ul><li>broadcast ARP packets<\/li><li>multicast ICMPv6 Neighbour Discovery packets. Please note that this does not include Router Solicitation or Advertisement packets.<\/li><\/ul><p>2.6 No link-local traffic <br \/>Traffic related to link-local protocols shall not be forwarded to IX ports. Link-local protocols include, but are not limited to, the following list:<\/p><ul><li>IRDP<\/li><li>ICMP redirects<\/li><li>IEEE 802 Spanning Tree<\/li><li>Vendor proprietary protocols. These include, but are not limited to:<ul><li>Discovery protocols: CDP, EDP, LLDP etc.<\/li><li>VLAN\/trunking protocols: VTP, DTP<\/li><li>Interior routing protocol broadcasts (e.g.OSPF, ISIS, IGRP, EIGRP)<\/li><li>BOOTP\/DHCP<\/li><li>PIM-SM<\/li><li>PIM-DM<\/li><li>DVMRP<\/li><li>ICMPv6 ND-RA<\/li><li>UDLD<\/li><li>L2 Keepalives<\/li><\/ul><\/li><\/ul><p>The following link-local protocols are exceptions and are allowed:<\/p><ul><li>ARP<\/li><li>IPv6 ND<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3b189e1 elementor-widget elementor-widget-heading\" data-id=\"3b189e1\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">3. IP Layer<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6db2fec elementor-widget elementor-widget-text-editor\" data-id=\"6db2fec\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>3.1 No directed broadcast<br \/>IP packets addressed to IIX peering LAN\u2019s directed broadcast address shall not be automatically forwarded to IIX ports. 3.2 no-export of IIX peering LAN<br \/>IP address space assigned to IIX Peering LANs must not be advertised to other networks without explicit permission of IIX.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-39d7450 elementor-widget elementor-widget-heading\" data-id=\"39d7450\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">4. Application layer (TCP\/IP model)<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-dd5e0f1 elementor-widget elementor-widget-text-editor\" data-id=\"dd5e0f1\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Using Application layer protocols to unleash malicious actions against other IIX customers over IIX infrastructure, is forbidden. IIX reserves the right to disable a customer\u2019s port in case of complaints of attacks\/abuse originating from such customers. The following list includes, but is not limited to:<\/p><ul><li>BGP hijacking<\/li><li>DNS amplification\/flood<\/li><li>HTTP flood<\/li><li>NTP amplification<\/li><li>UDP flood<\/li><li>ICMP flood<\/li><li>Simple Service Discovery Protocol (SSDP)<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Allowed Traffic Types on Unicast Peering LANs To ensure smooth operation of the IIX infrastructure we impose a set of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"site-sidebar-layout":"no-sidebar","site-content-layout":"","ast-site-content-layout":"full-width-container","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"class_list":["post-17","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/fe.desnet.online\/apjii\/wp-json\/wp\/v2\/pages\/17","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fe.desnet.online\/apjii\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/fe.desnet.online\/apjii\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/fe.desnet.online\/apjii\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fe.desnet.online\/apjii\/wp-json\/wp\/v2\/comments?post=17"}],"version-history":[{"count":10,"href":"https:\/\/fe.desnet.online\/apjii\/wp-json\/wp\/v2\/pages\/17\/revisions"}],"predecessor-version":[{"id":385,"href":"https:\/\/fe.desnet.online\/apjii\/wp-json\/wp\/v2\/pages\/17\/revisions\/385"}],"wp:attachment":[{"href":"https:\/\/fe.desnet.online\/apjii\/wp-json\/wp\/v2\/media?parent=17"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}