Questions and answers

Short answers to what networks ask most. Each one links to the page with the detail.

About the exchange

What is an Internet exchange?
A place where networks connect to each other and exchange traffic directly, instead of sending it through a third network. How peering works
Is Maharlika IX an internet provider?
No. A port gives peering access, not internet transit. Port pricing
Who runs Maharlika IX?
Maharlika Connect Inc. It is responsible for the platform, the policies and the commercial terms. Governance
Who is connected?
The list of connected networks names every network with a session on the route servers, with its ASN, type and website. Connected networks
How much traffic does the exchange carry?
The traffic page shows the inbound traffic of the exchange as a whole, with the latest figures and the peak, over a day, a week and a month. Exchange traffic

Joining

Who can connect?
Any network with a public ASN can apply: internet service providers (ISPs), carriers, cable and broadband operators, content providers, cloud platforms, data centre operators, government and academic networks, banks and financial institutions, and enterprises. Requests are assessed against our technical requirements, network capability and the policies of the exchange. Request a port
How do I connect?
In three steps. Tell us about your network. Share your ASN, preferred location, port speed, and whether you’d like to use our route servers. Confirm your connection. We confirm the facility, port, and cross-connect details, then send your connection information and welcome guide. Connect and go live. Connect your port, establish your BGP sessions, and start exchanging traffic. Peering guide
What do I need before I go live?
A route or route6 object for every prefix you will announce, an AS-SET that lists your ASN and any customer ASNs, and a PeeringDB record that is up to date. Create RPKI ROAs for the same prefixes: a route with no ROA is accepted as not found; a route that is RPKI-invalid is rejected. Peering guide
Where can I connect?
Ports are available in Metro Manila, Bulacan and Rizal. Laguna and Cavite are planned. Locations
My network is outside these areas. Can I still connect?
Yes. Networks in the Visayas, Mindanao and other parts of Luzon connect over a transport link to one of the facilities. Email peering@maharlikaix.ph and we will advise on the nearest one. Locations
Can a network outside the Philippines connect?
Yes. Any network with a public ASN can apply, wherever it is. A network abroad connects over a transport link, such as an international circuit, to one of the facilities. This is often called remote peering. Maharlika IX works with its members and partner networks to extend access beyond its own locations, where that is technically and commercially feasible. Email peering@maharlikaix.ph and we will advise on the facility. Locations
What does a port cost?
The 1G community port is free for eligible networks. Paid ports are ₱25,000 per month for 10G, ₱45,000 for 25G and ₱100,000 for 100G. Port pricing
Who can have the free 1G port?
The free 1G port is for emerging and low-traffic networks with a public ASN of their own, such as small internet service providers, schools, research networks and government agencies. It is offered under the Maharlika Access Program and depends on technical qualification and port availability. Cross-connect, transport, colocation, setup fees and taxes are quoted separately. Tell us about your network in the request. Port pricing
What is not included in the port charge?
Cross-connect, transport, colocation, setup fees and taxes. They are quoted separately. Port pricing
Can I have more than one port?
Yes. For 2×100G or a link aggregation group, email peering@maharlikaix.ph. Port pricing

Peering

What is the MTU of the peering LAN?
1500 bytes. Jumbo frames are not supported. The peering LAN is delivered untagged on your port. Peering LAN policy
Do I have to use the route servers?
No. Peering with the route servers is optional. You can use them, peer directly with other members, or do both. How peering works
Do I have to peer with every member?
No. Members decide for themselves who they peer with. Bilateral sessions are agreed between the two networks involved. On the route servers your routes go to every peer unless you limit them with communities. BGP communities
Does traffic pass through the route servers?
No. The route servers pass routes between members. Traffic goes directly from one member to another across the peering LAN. How peering works
What is the ASN of the route servers?
AS9420, on both. The route servers are transparent: AS9420 does not appear in the AS path. Route server policy
Is IPv6 supported?
Yes. IPv4 and IPv6 run on the same port, and both route servers handle both. Port pricing
What may my port send?
IPv4, IPv6 and ARP, from one MAC address. Frames from other addresses are dropped at the port. Peering LAN policy
Where do I find my peering addresses and session details?
In the welcome guide that we email when the handoff is agreed. They are not published on this website. Peering guide
How do I control which members receive my routes?
With BGP communities. By default the route servers announce your routes to every peer. Control communities leave out specific peers, or announce to selected peers only. BGP communities

Filtering

How are routes filtered?
Both route servers check every announcement against RPKI and, where a member has an IRR filter, against its IRR data. Routes that fail are rejected. They also check the next hop, the AS path, bogons and prefix length. Route server policy
Which prefix lengths are accepted?
IPv4 from /8 to /24. IPv6 no longer than /48. A default route is rejected. A blackhole route is the one exception. Route server policy
Why was my route rejected?
The looking glass shows every route the route servers hold, including rejected routes and the reason. Common causes are a missing route object with no valid ROA, an origin that is not in your AS-SET, and an announcement that is RPKI-invalid. Looking glass
What happens to a route without a ROA?
It is treated as not found and accepted, subject to the other checks. A route that is RPKI-invalid is rejected. RPKI policy
I changed my IRR objects. When do the filters follow?
The filters are rebuilt from the IRR on a fixed schedule, so a change is normally live within 24 hours. Register a prefix at least 24 hours before you announce it for the first time. You do not need to ask for it. If a prefix is still rejected afterwards, the NOC can check your AS-SET expansion and tell you which prefixes are accepted. Email noc@maharlikaix.ph. IRR policy
Can I blackhole an address that is under attack?
Yes. Announce that one address, a /32 for IPv4 or a /128 for IPv6, inside a prefix that your IRR data covers, with the BLACKHOLE community (RFC 7999). Your IRR data must be current. The route servers mark the route NO_EXPORT, and each member decides in its own router whether to act on it. BGP communities

Operations and support

How do I report a fault?
Email noc@maharlikaix.ph, or telephone the NOC on +63 917 849 8949, 24 hours a day, every day. The status page shows the current state of each service. Network status
What should I do before maintenance on my router?
Tell the NOC beforehand. You can also signal graceful shutdown (RFC 8326), so that traffic moves away first. BGP communities
How do I report a security problem?
Email security@maharlikaix.ph. Report a security issue
Who do I ask about anything else?
Email info@maharlikaix.ph. Contact

Terms used on this site

ASN
Autonomous system number. The number that identifies a network in BGP.
AS-SET
An IRR object that lists the ASNs a network announces routes for: its own and those of its customers.
BGP
Border Gateway Protocol. Networks use it to tell each other which addresses they can reach.
BGP community
A tag on a route. Members use communities to tell the route servers what to do with a route. The route servers use them to record its state.
Bilateral peering
A BGP session set up directly between two members.
Blackholing
Asking peers to drop traffic to an address that is under attack.
Bogon
An address range that must not appear in the global routing table, such as private, reserved or documentation space.
Cross-connect
The cable inside a facility that joins your equipment to the exchange port.
Graceful shutdown
A signal that lowers the preference of your routes before planned maintenance, so that traffic moves away first.
Handoff
Where and how your network meets the exchange: the facility, the port, the optics and the cross-connect.
IRR
Internet Routing Registry. A set of databases in which networks record the prefixes they originate and the ASNs they announce routes for.
IXP Manager
The software Maharlika IX uses to manage members and ports. It publishes the member list and the traffic statistics, and builds the route server filters from the IRR.
Link aggregation group
Several ports joined to act as one link.
Looking glass
A public view of the routes the route servers hold, including rejected routes.
MANRS
Mutually Agreed Norms for Routing Security. A programme of actions that reduce routing incidents.
NOC
Network operations centre. The team that runs the exchange day to day.
Peering LAN
The shared network that member routers and the route servers connect to.
PeeringDB
A public database in which networks and exchanges record where they are present and who to contact about peering.
Private VLAN
A VLAN between the ports of two members, apart from the peering LAN.
ROA
Route Origin Authorisation. A signed record that says which ASN may originate a prefix.
Route object
An IRR record that says which ASN originates a prefix. For IPv6 it is a route6 object.
Route server
A server that passes routes between members, so that one session reaches many peers.
RPKI
Resource Public Key Infrastructure. The system that holds ROAs and lets a network check the origin of a route against them.
RTR
RPKI-to-Router. The protocol that carries the checked ROA data from a validator to a router or a route server.
Transit
A paid service in which one network carries the traffic of another to the rest of the internet.
Welcome guide
The document we email when the handoff is agreed. It has your peering addresses, VLAN and session details.