IXP Manager - Pre-Configured

AWS Networking
Base
Hardened build
minimal ports, security patches applied at build time
Access
Unique credentials
generated on first boot, readable only by root
Verified
Boots working
services pass a health gate before release
Support
24/7, 365 days
by email and live chat, 24 hour response SLA

Overview

Launch a production-ready internet exchange platform in minutes instead of hours. IXP Manager pre-configured on AWS with unique credentials generated per instance and 24/7 expert support.

Why the cloudimg image

This image arrives installed, configured and hardened, so there is no manual setup before you can use it. It is built on a patched base, runs with credentials generated uniquely for your instance on first boot, and passes an automated health check before every release. Every deployment is backed by 24/7 support from cloudimg engineers.

Key features

  • Production-ready in minutes, not hours - the AMI ships with Apache, PHP 8.4, MySQL 8 and memcached pre-wired, the IXP Manager schema migrated and seeded, and an example exchange identity ready to replace. You land on a working sign-in page on first boot and can have your exchange configured the same day. Over 250 internet exchange points worldwide run IXP Manager in production.
  • Unique credentials generated per instance with no shared or default password in the image. On first boot the instance mints a fresh Laravel application key, database password, MySQL maintenance password and administrator password into a root-only file. Two-factor authentication is compulsory for administrators with no pre-baked enrolment, so the second factor is enrolled by you and belongs to you alone.
  • 24/7 expert support from cloudimg engineers with a one-hour average response for critical issues. Engineers assist with deployment, upgrades, route server and IRRDB filter configuration, TLS termination, PHP and MySQL performance tuning, and integration with AWS services including CloudFront, RDS, SES and CloudWatch.

See it running

Real screenshots taken while testing this image against its deployment guide.

IXP Manager - Pre-Configured screenshot 1 IXP Manager - Pre-Configured screenshot 2 IXP Manager - Pre-Configured screenshot 3 IXP Manager - Pre-Configured screenshot 4

Description

This is a repackaged open source software product wherein additional charges apply for cloudimg support services.

## IXP Manager - Run an Internet Exchange Point on AWS

IXP Manager is the open source platform that operates an Internet Exchange Point. Developed by INEX and in production at over 250 exchanges worldwide, it runs the day-to-day business of peering: onboarding members, allocating ports and addresses, generating device configuration, and publishing the statistics members care about.

This AMI removes the multi-hour manual installation that IXP Manager normally requires. Apache, PHP 8.4, MySQL 8 and memcached are already installed and wired together, the database schema is migrated and seeded with upstream reference data, and an example exchange identity is in place. The first page you reach is a working sign-in rather than an installer - you can replace that identity with your own exchange details in minutes.

## Get Started Quickly

Launch the AMI, retrieve your unique credentials from the root-only file, enrol your two-factor authenticator, and configure your exchange. A step-by-step guide covering first boot, two-factor enrolment, identity replacement and TLS is published at cloudimg.co.uk.

A 7-day free trial is enabled on this listing, so you can evaluate the image at no software charge before you commit.

## What IXP Manager Does

  • Member and peering port management, including the customer-facing self-service portal
  • IXP LAN, VLAN and IP address allocation across your peering fabric
  • Switch, patch panel and colocated equipment inventory
  • Route server, route collector and switch configuration generation from one source of truth
  • IRRDB-based prefix and AS-path filter generation from RIPE, RADB and other registries
  • Peering matrices, peer-to-peer traffic graphs and per-member statistics
  • IX-F member export for the peering databases that consume it

## Application Stack

  • IXP Manager 7.3.1 from the pinned upstream release, installed at /srv/ixpmanager
  • PHP 8.4 with OPcache and the intl, bcmath, snmp, rrd, ds, memcached and yaml extensions
  • Apache 2.4 with mod_php, clean URL rewriting and a hardened virtual host
  • MySQL 8.0 bound to localhost, on its own EBS volume at /var/lib/mysql
  • memcached for the application cache, bound to localhost
  • Composer, rrdtool, bgpq3 and the SNMP tooling used for graphing and switch polling
  • The upstream scheduler cron entry, so scheduled tasks run from first boot

## Secure First Boot

No usable credential ships in the image. On first boot a one-shot systemd service generates a fresh Laravel application key, database password, MySQL maintenance password and administrator password - all unique to that instance - written to a file readable only by root. Build-time secrets are overwritten during image preparation with random values that are generated, used once and discarded.

IXP Manager enforces two-factor authentication on administrator accounts with no enrolment baked into the image. The first sign-in requires the operator to enrol their own authenticator app before anything else is reachable. MySQL and memcached listen on the loopback interface only, and the web server refuses to serve the environment file. The image is TLS ready: attach a certificate through AWS Certificate Manager and a load balancer, or with Let's Encrypt directly, before exposing the portal to members, and restrict SSH to trusted address ranges.

## Production-Ready Storage Layout

The database tier and the application tier each get their own EBS volume, mounted by filesystem UUID, so either can be resized or snapshotted independently of the operating system disk.

## Compatible AWS Services

  • Amazon CloudFront and AWS Certificate Manager for TLS and global delivery
  • Amazon RDS for MySQL if you prefer a managed, Multi-AZ database tier
  • Amazon SES for notification mail IXP Manager sends to members
  • Amazon CloudWatch and AWS Systems Manager for monitoring and patching

## Evaluation Resources

  • Deployment guide at cloudimg.co.uk: first boot through production readiness
  • Sizing: up to 50 member ports on m5.large; 50-250 on m5.xlarge; 250+ benefit from Amazon RDS
  • Upstream reference at docs.ixpmanager.org: configuration, route server examples and the API

## Use Cases

  • Operating a new or growing internet exchange point
  • Automating route server and switch configuration from one database
  • Publishing traffic graphs, peering matrices and an IX-F export
  • Giving members a self-service portal for their ports and sessions

## Licensing and Support

IXP Manager is free and open source software published by INEX under the GNU General Public License version 2.0 - no licence fee, no key to enter. The cloudimg charge covers packaging, security patching, image maintenance and 24/7 expert support.

All product and company names are trademarks or registered trademarks of their respective holders. Use of them does not imply any affiliation with or endorsement by them.

Related technologies

internet exchange platformpeering managementroute server automationbgp configurationirrdb filteringix-f member exportpeering portalnetwork automationexchange point softwarepeering matrix