# DynamicLink docs Source: https://docs.zayo.com/Home

DynamicLink Documentation

Zayo’s network, controlled by you.

DynamicLink gives you real-time control of your network services—activate, scale, and manage connectivity in seconds through a single, software-driven platform including an agentic AI network experience.

Ready to get started? Jump to our [Quick Start page](Welcome).

Welcome Introduction and quick start information Dash AI DashAI and the DynamicLink MCP server Ports Provision a port to access the Zayo network Internet Dedicated Internet Access and public IPs Ethernet Services Ethernet specifications and E-Line setup Cloud Links Connect to AWS, Azure, and other clouds Cloud Router Route traffic across cloud connections. Network Manage groups and network configuration. Services Configure firewall rules and services Insights Network and application observability Administration Manage users and account settings Videos Watch video guides and tutorials
# How to Configure NAT Rules Source: https://docs.zayo.com/Services/NAT A step-by-step guide to understanding and configuring Network Address Translation (NAT) in the DynamicLink portal. ## What is NAT (Network Address Translation)? **NAT (Network Address Translation)** is a method used to change the IP address of traffic as it passes through a routing device. Its primary use cases include enhancing security by hiding the original IP address of a packet and enabling translation between private and public IP addresses to conserve public IP address space. ### Key NAT Types * **SNAT (Source NAT)**: This is commonly used to allow multiple devices within a private network (like an office or home) to share a single public internet connection. It works by masking multiple internal private IP addresses behind one public IP address. * **1:1 NAT**: This translates one internal, private IP address to one external, public IP address. It is sometimes described as a DMZ (Demilitarized Zone) because it fully exposes an internal host to the outside network, making it directly reachable from the internet. *** ## How to Use NAT in the DynamicLink Portal To configure NAT rules in the DynamicLink portal, follow these steps: ### Step 1: Enable Address Translation (NAT) Service for the Tenant Before you can create NAT rules, the service must be enabled for the tenant. 1. Navigate to **Tenants** from the bottom menu. 2. Select the desired tenant from the list. 3. Click the **pencil icon** to edit the tenant settings. 4. Under "Select services for the tenant", ensure **Address Translation (NAT)** is enabled. ### Step 2: Add a NAT Rule Once the service is enabled, you can create the specific translation rules. 1. Navigate to the **Services** menu (bottom menu). 2. Select **My Services**. 3. Click on **Applications: NAT**. 4. Click the **+ Add** button to open the "Add NAT Rule" dialog. 5. In the dialog that appears, fill out the following fields: * **Type**: Select the NAT type from the drop-down list. DynamicLink supports **Source NAT**, **1:1 NAT**, and **Port Forwarding**. * **Name**: Give the NAT rule a descriptive name (e.g., `WebServer-1-to-1-NAT`). * **Description**: Provide a freeform text description explaining the rule's purpose. * **Inside**: * For **1:1 NAT**, enter the single internal IP address to translate from. * For **Source NAT**, enter the internal subnet to translate from (e.g., `192.168.1.0/24`). * **Outside**: Choose an interface to use. If the NAT rule is for internet access, select the interface provided for that purpose. Entering a single IP here is typically only used for 1:1 NAT applications. 6. Click **Add** to save the new NAT rule. ### Step 3: Edit or Delete a NAT Rule (Optional) You can easily manage your existing NAT rules. * **To Edit**: Hover the mouse over a NAT rule in the list, click the **pencil icon**, make the necessary changes, and then click **Edit** to save. * **To Delete**: Hover the mouse over the rule in the list, then click the **trashcan icon** to permanently remove it. # DDoS Protection Source: https://docs.zayo.com/Services/ddos # This guide provides you with the necessary information to understand, monitor, and manage DDoS protection on their assigned IPs and services using the NaaS Platform. The NaaS Platform offers real-time, automated mitigation to ensure service continuity during DDoS attacks. ## 1. Introduction The DynamicLink DDoS Protection service continuously monitors your internet-facing connections and automatically blocks large-scale DDoS attacks. As a user, you will interact with a user-friendly interface to view and manage your protection based on pre-defined rules set by the operator.   High-level overview of the DDoS Protection System   Figure 1: A high-level diagram showing how traffic is monitored and mitigated. ## 2. Access Requirements To effectively use the DDoS protection service, ensure you meet the following requirements: * **Valid tenant credentials:** Provided by your system administrator. * **Network familiarity:** Understanding of IP ranges and hosted services. * **Basic knowledge of common DDoS attack types.** ## 3. Key Concepts Familiarize yourself with these core concepts: * **Mitigation Status:** Indicates whether an IP is currently under protection. * **Thresholds:** Limits set by the system administrator that trigger mitigation. * **DUA (Device Under Attack):** Your IP currently being targeted by an attack. * **False Positive:** Legitimate traffic mistakenly flagged as an attacker. * **Per IP Visibility:** Each IP is tracked individually for accurate mitigation. ## 4. Enterprise Portal Overview The Portal is your central hub for monitoring protected services.   Tenant Portal Dashboard  Figure 2: The Tenant Portal Dashboard displaying real-time activity. * **Dashboard:** Displays real-time and historical DDoS activity, active threats, protected IPs, and mitigation activity. * **Traffic View:** Shows traffic trends per IP, both historical and real-time. * **Thresholds:** Can be reviewed and, if permitted, adjusted. * **Logs:** Available for download and review. * **Alerts:** Notify you of detected threats and mitigation actions. ## 5. Daily Operations Follow these steps for routine monitoring and management: ### 5.1. Monitor Traffic 1. Log in to the NaaS portal. 2. Open **Dashboard** ⇒ **Live View**. 3. Observe per IP trends and spikes. ### 5.2. Review Alerts 1. Navigate to **Alert** ⇒ **Recent Events**. 2. Filter by IP or timestamp. 3. Acknowledge resolved alerts. ### 5.3. Export Reports 1. Go to **Logs** ⇒ **Export**. 2. Select format: CSV, JSON. 3. Download for compliance use. ## 6. How to Use DDoS Protection As a tenant, you have a simplified view of DDoS protection. Most complex logic is handled by your provider, but you can manage basic settings. ### 6.1. Know Which Rules Apply to You * **Tenant Global Rules:** Always on and cannot be changed. * **Tenant Template Rules:** Can be enabled/disabled or switched to monitor mode if the option is provided. * **Tenant Specific Rules:** Custom rules unique to your organization. ### 6.2. Manage Your Rules 1. Go to NaaS portal ⇒ **Services** ⇒ **DDoS display screen**. 2. View the available rules, each with a name and description. 3. If a rule has options:    - You may enable or disable it.    - You may switch it to monitor mode to observe attacks without blocking.    - You may apply the rule to specific IPs or subnets in your network. ## 7. DDoS Statistics Access detailed DDoS statistics to monitor and analyze attack trends. ### 7.1. Accessing DDoS Statistics 1. Log in to the NaaS portal. 2. Go to the left navigation panel ⇒ Click on **Service**. 3. Select **DDoS**. 4. The statistics dashboard will be displayed.   DDoS Statistics Dashboard   Figure 5: The main DDoS statistics dashboard. ### 7.2. Top Summary Section * **Status:** Real-time indicator (e.g., "No Attack" - green means no attack detected). * **Attack in last 7 days:** Displays total mitigated traffic (in GB) and peak mitigation rate (in Mbps). * **Target & Mitigation Rate:** Shows mitigation success rate (%) and unique attack targets over the past 7 days. * **DDoS Status Summary:** Breakdown of current system status (Active Mitigation, Monitor Only, Disabled). * **Last Attack:** Timestamp of the most recent detected attack. ### 7.3. Dashboard Tabs & Filter * **Tab (General/Attack Details):**   - **General:** Summary view of traffic, attack patterns, and mitigated flows.   - **Attack Details:** Detailed session breakdown. * **Filter Panel:** Apply filters by fields like Rule Name, DIA Name, Target IP. * **CSV:** Export DDoS attack data for offline analysis. ### 7.4. Graph and Charts * **Total Incoming and Mitigation Traffic (Top Graph):**   - Green area: Successfully mitigated traffic.   - Red Line: Unblocked attack traffic that passed through.   - Blue Line: Total incoming traffic.   - Use this to compare actual threats and mitigation effectiveness. * **Observed Traffic by Traffic Name:** Traffic classification by protocol or service (e.g., DNS, ICMP, UDP Flood). Helps identify the nature of attack or abnormal traffic flow. * **Observed Traffic By Rule Name:** Shows what traffic was flagged by which DDoS rule (e.g., ICMP\_Flood, TCP\_SYN). Useful for reviewing rule effectiveness. ### 7.5. Visualization Panels (Right Side) * **Attack per IP (Bar Chart):** Horizontal bar showing targeted IP addresses and attack volume per IP. * **Observed Traffic By Rule (Pie Chart):** Breakdown of mitigated traffic by DDoS rule type.   Attack per IP Bar Chart and Observed Traffic By Rule Pie Chart   Figure 7: Visualization panels showing attack distribution by IP and rule type. * **Live Update Indicator:** Message like “No attack traffic observed (last 30 seconds)” shows the current state of threat in near real time. ### 7.6. Time Selection (Top Right) * Use the dropdown to change data granularity (Auto, 30s, 1m, 5m, 1h). * Allows switching between BPS (Bits Per Second) and PPS (Packet Per Second). * Time range: Last hour/last 7 days. ## 8. Use Case Scenarios ### 8.1. Use Case 1: SYN Flood Attack 1. An alert is triggered on one of your web servers. 2. Mitigation is automatically applied. 3. You view affected IP and traffic patterns in real-time. 4. Download a report for internal analysis.   SYN Flood Attack Scenario Flow   Figure 8: A diagram showing the workflow during a SYN Flood Attack scenario. ### 8.2. Use Case 2: UDP Reflection Attack 1. You observe a sharp rise in UDP traffic from random sources. 2. Mitigation is visible, and traffic is filtered. 3. You confirm no DNS/NTP service degradation. # Configuring Firewall Rules Source: https://docs.zayo.com/Services/fw Learn how to create and manage firewall rules in the DynamicLink portal.
services
## Creating a Firewall Rule Firewall rules allow you to control traffic flow based on specific criteria. To create a new firewall rule, follow these steps: 1. In the Admin GUI, navigate to the **Services** menu option. 2. Select **Firewall**. 3. Click the **Add** button to open the "Create Firewall Rule" dialog. 4. Fill out the fields in the dialog box: * **Name**: A descriptive name for the firewall rule (e.g., `Allow-Web-Traffic-From-Office`). * **Priority**: Set the priority for the rule. Lower values indicate higher priority (e.g., `100` is higher priority than `200`). * **Admin State**: Enable or disable the rule. * **Description**: (Optional) A more detailed description of the rule's purpose. * **IP Protocol**: Specify the IP version (`IPv4` or `IPv6`). This must match the version used in the Source and Destination IP fields. * **Protocol**: Select the transport layer protocol (e.g., `TCP`, `UDP`, `ICMP`, or `Any`). * **Action**: Choose the action to take when the rule is matched (`Permit` or `Deny`). * **Source**: Define the source IP prefix (e.g., `192.168.1.0/24`) or a pre-defined IP Group. * **Destination**: Define the destination IP prefix or a pre-defined IP Group. * **Source Port**: Specify the source port or a port range (e.g., `1024-65535`). * **Destination Port**: Specify the destination port or a port range (e.g., `443` for HTTPS). * **Source VI**: Select the source Virtual Interface (VI) where the traffic originates. * **Destination VI**: Select the destination Virtual Interface (VI) where the traffic is headed. 5. Click **Add** to save and apply the new rule. ### How Rules Are Processed It is important to understand how the firewall processes rules to ensure your policies are effective: * **Execution by Priority**: Firewall rules are executed in order of their priority value, starting with the lowest number. The first rule that matches the traffic is the one that is applied. * **Logical AND Condition**: All the filters (Source, Destination, Port, etc.) within a single rule are combined with a logical **AND**. This means that for a rule to be triggered, *all* specified conditions within that rule must be true for the given network packet. # Configuring DIA Firewall Rules Source: https://docs.zayo.com/Services/fwdia Learn how to create and manage Dedicated Internet Access (DIA) firewall rules in the DynamicLink portal. ## Introduction This guide provides a step-by-step process for creating firewall rules specifically for your Dedicated Internet Access (DIA) service. These rules are essential for securing your network by controlling inbound and outbound traffic. ## Creating a New DIA Firewall Rule Follow these instructions carefully to configure a new rule. 1. **Navigate to DIA Firewall** * In the Admin GUI, open the **Services** menu from the main navigation bar. * From the dropdown, select **DIA Firewall**. This will take you to the DIA firewall rule management page. 2. **Add a New Rule** * Click the **Add** button to launch the "Create DIA Firewall Rule" dialog box. 3. **Configure Rule Parameters** * Fill in the following fields to define the behavior of your rule: * **Name**: Enter a unique and descriptive name that helps you identify the rule's purpose (e.g., `Block-Outbound-FTP`). * **Priority**: Assign a numerical value. **Lower numbers have higher priority** and are processed first. * **Admin State**: Toggle to **Enable** or **Disable** the rule. New rules should be enabled to be active. * **Description**: (Optional) Provide a detailed explanation of what the rule does for future reference. * **IP Protocol**: Select either `IPv4` or `IPv6`. This choice must match the IP version of the Source and Destination prefixes. * **Protocol**: Choose the transport protocol, such as `TCP`, `UDP`, `ICMP`, or select `Any` to have the rule apply to all protocols. * **Action**: * `Permit`: Allows traffic that matches the rule. * `Deny`: Blocks traffic that matches the rule. * **Source**: Define the traffic's origin by entering an IP prefix (e.g., `10.0.0.0/8`) or selecting a pre-configured IP Group. * **Destination**: Define the traffic's destination by entering an IP prefix or selecting a pre-configured IP Group. * **Source Port**: Specify the source port number or a range (e.g., `1024-65535`). * **Destination Port**: Specify the destination port number or a range (e.g., `22` for SSH). * **Source VI**: Select the source Virtual Interface (VI) where the traffic originates. * **Destination VI**: Select the destination Virtual Interface (VI) where the traffic is going. 4. **Save the Rule** * After reviewing your settings, click the **Add** button at the bottom of the dialog to save and activate the new rule. > **Key Concept: Rule Processing Logic** > Firewall rules are processed based on their **Priority**, with lower numbers being evaluated first. For a rule's action (`Permit` or `Deny`) to be applied, all the defined filters (Source, Destination, Port, etc.) within that single rule must match the traffic. This is a logical **AND** condition. # New file Source: https://docs.zayo.com/Services/image/fwdia Description of your new file. # My Services Overview Source: https://docs.zayo.com/Services/myservices An explanation of all the services available on the 'My Services' page in the DynamicLink portal. services The **My Services** page is your central dashboard for managing all the features and capabilities available for your account. From this single view, you can access, configure, and monitor all network, security, and observability services. This guide provides a brief overview of each service available on this page. ## Insights 👁️ The Insights section provides powerful monitoring and visibility tools to help you understand the health and performance of your network and applications. * **Network Observability**: Gives you deep visibility into your network traffic. Use this service to monitor performance, troubleshoot connectivity, and understand data flow across your entire infrastructure. * **Application Observability**: Focuses on the performance of specific applications. It helps you quickly determine if an issue is caused by the network or the application itself. * **DNS Observability**: Monitors all Domain Name System (DNS) requests. This is crucial for troubleshooting name resolution problems and identifying security threats that leverage DNS. *** ## Services 🛡️ This category contains active security and traffic management features that protect and control your network. * **DDoS**: Enables **Distributed Denial-of-Service** protection. This service defends your network against malicious traffic floods intended to disrupt and take your services offline. * **Web Filtering**: Allows you to create granular policies to block or permit access to specific websites or entire categories of web content (e.g., social media, malware sites). * **Stateful Firewall**: A core security component that controls traffic based on a set of security rules. It actively tracks the state of connections, offering robust protection for your network. * **DIA Firewall**: A specialized **Dedicated Internet Access (DIA) Firewall** designed specifically to secure your primary, high-capacity connection to the public internet. *** ## Network 🌐 This section includes the core networking functions that manage routing and connectivity. * **Cloud Router**: Provides dynamic and intelligent routing for your hybrid and multi-cloud environments. This service simplifies traffic management between your on-premises locations and various cloud providers (like AWS, Azure, and Google Cloud). * **Address Translation (NAT)**: Modifies the IP address information in network traffic. It is essential for allowing devices on a private network to share a single public IP (**SNAT**) or for securely exposing an internal server to the internet (**1:1 NAT**). # DynamicLink Services Source: https://docs.zayo.com/Services/servicesintro This guide introduces the key services designed to provide automated, advanced network and security management. services The DynamicLink portal’s firewall services provide robust security for your network. By allowing you to create granular rules, you can control traffic flow and protect your network from unauthorized access. The DIA (Dedicated Internet Access) Firewall specifically secures your internet connections with a protective default policy, ensuring a safe starting point for your network security configuration. Ensure your network's availability and performance with our DDoS (Distributed Denial of Service) protection service. This feature safeguards your infrastructure from malicious attacks by providing real-time monitoring and automated mitigation, allowing you to maintain business continuity even when under attack. Enhance your organization's security and productivity with integrated Web Filtering. This service allows you to enforce acceptable use policies by blocking access to malicious websites, phishing attempts, and inappropriate content categories, thereby protecting your users and network from online threats. Securely connect your private network resources to the internet using the Network Address Translation (NAT) service. NAT enables devices within your private Cloud Router environment to access the internet via a public DIA connection, providing essential connectivity for your internal network. The 'My Services' section provides a clear overview of all the features and capabilities included in your DynamicLink subscription. This allows you to easily understand and manage your service packages: Essentials, Pro, and Premium, ensuring you are leveraging the full benefits of your chosen plan. # How to Use Web Filtering Source: https://docs.zayo.com/Services/webfilter Learn what web filtering is and how to configure it to control web traffic in the DynamicLink portal. ## What is Web Filtering? Web filtering, when enabled as a service for a tenant in the platform, provides granular control over web traffic by allowing you to define policies to either block or permit access to specific URLs or categories of web content. It integrates with your firewall rules, adding a third action option for managing web traffic. You can also configure general company-wide web access policies via the general Web Filter Service.
services
*** ## How to Use Web Filtering in the DynamicLink Portal To configure web filtering, follow these steps: ### Step 1: Enable Web Filter Service for the Tenant Before you can use web filtering in your firewall rules, the service must be enabled for the specific tenant. 1. Navigate to the **Tenants** menu (usually found at the bottom of the navigation panel). 2. Locate the desired tenant in the list. 3. Click the **pencil icon (edit)** next to the tenant's entry to access their settings. 4. Ensure that **Web Filter** is enabled under the **Services** section. ### Step 2: Configure Web Filter Rules within Firewall Rules Once the Web Filter Service is enabled, a new action option will be available when creating or editing Firewall rules, allowing you to apply a web filter policy. *** #### Option A: Default Filter Action "Block" (Allowlist Only Selected URLs) Use this approach when you want to block all web traffic by default and only permit access to a specific list of URLs. 1. **Access Firewall Rules:** * Navigate to the **Services** menu (bottom). * Select **Firewall**. * Click the **Add** button to create a new firewall rule, or select an existing rule to edit. 2. **Set Default Filter Action:** * Within the firewall rule configuration, locate the **Default filter action** setting. * Choose **Block**. 3. **Specify Allowed URLs:** * A field will appear where you can enter the URLs that are permitted. You can add multiple URLs. > **Valid URL Formats:** > > * `google.com`: Matches the exact URL. > * `*.google.com`: Matches any URL ending with `.google.com` (e.g., `mail.google.com`). > * `*google.com`: Matches any URL containing `google.com` (e.g., `mygoogle.com`). > * `www.google.*`: Matches any URL starting with `www.google.` (e.g., `www.google.co.uk`). > > **Invalid URL Formats:** > > * `*.google.*` > * `www.*.google.com` > * `www.*google.com` 4. **Save the Firewall Rule.** *** #### Option B: Default Filter Action "Allow" (Blocklist Selected URLs/Categories) Use this approach when you want to allow most web traffic by default but block specific URLs or categories of content. 1. **Access Firewall Rules:** * Navigate to the **Services** menu (bottom). * Select **Firewall**. * Click the **Add** button to create a new firewall rule, or select an existing rule to edit. 2. **Set Default Filter Action:** * Within the firewall rule configuration, locate the **Default filter action** setting. * Choose **Allow**. 3. **Configure Additional Filtering Options:** * **Allow only HTTPS traffic with valid SNI**: Check this option to block HTTPS traffic on Port 443 that does not include a valid Server Name Indication (SNI). * **Content Filter**: Select categories of web content you wish to block (e.g., social media, adult content). * **Web Threats Filter**: Choose categories of web threats to block (e.g., malware sites, phishing). * **Block**: Manually enter specific URLs you want to block. * **Allow**: Manually enter specific URLs to allow. This acts as an exception list, overriding blocks from the content filter categories. 4. **Save the Firewall Rule.** *** services ### Step 3: (Optional) Configure General Web Filter Service Policies If the main firewall service is disabled for a tenant, you can still use the general Web Filter Service to create company-wide web access policies. 1. Navigate to the **Services** menu (bottom). 2. Select **Web Filter Service** (or a similar option if available separately from the firewall). 3. Configure the desired general web filtering policies as needed. # Quick Start Source: https://docs.zayo.com/Welcome Welcome to DynamicLink! Follow these steps to begin using the platform. ### 1. Add users to your tenant As an Administrator, add team members to your tenant (your DynamicLink organization). See [Users](/docs/users). If you're the first person to register your company, you're automatically assigned the Administrator role. If you're joining an existing organization, contact an Administrator for access. ### 2. Provision a port A port is a physical connection point between your network and the DynamicLink infrastructure. At this time, all ports must be ordered through Tranzact. See [Ports](/docs/ports). ### 3. Request an API token If you are planning to use the API, you will need a token associated with your user account. See our [developer portal](https://developer.zayo.com/). ### 4. Get familiar with DashAI DashAI is an AI-powered assistant integrated into the DynamicLink portal that can help you: * **Get instant answers**: Ask questions about DynamicLink processes, troubleshooting, and concepts. DashAI uses DynamicLink knowledge base to provide accurate, up-to-date answers. * **Manage resources**: Use natural language to create, view, update, or delete network resources. See [DashAI](docs/dash-ai). ### 5. Review the documentation See the following pages: * [Ports](/docs/ports) * [DIA](/docs/dia-overview) * [Public IPs](/docs/public-ips) * [E-Line](/docs/elan) * [ELAN](/docs/eline) * [Cloud Links](/docs/cloud-links) * [Cloud Router](/docs/cloud-router) ## Support If you still need support, reach out using any of the following: * 📚 [Visit our support page](https://www.zayo.com/support/) * 💬 [Start a live chat](https://www.zayo.com/chat/) * ✉️ [Email support](mailto:dynamiclinksupport@zayo.com) * 📞 866.239.6565 # Welcome to DynamicLink Portal Knowledge Base Source: https://docs.zayo.com/Welcome-saved Your comprehensive guide to automated and advanced network, security, and management. DynamicLink NaaS Portal 🚀 Quick Start Guide: DynamicLink Portal The DynamicLink Portal empowers businesses with automated and advanced network, security, and management capabilities. This documentation is designed to help you navigate, configure, and optimize your network infrastructure with ease. Watch video tutorials and demonstrations to help you get started and optimize your network. InsideIQ is an AI assistant designed to streamline your workflow, provide instant support, and give you unprecedented control over your network resources using simple, natural language. **Build Your Network** Begin your journey by setting up your network infrastructure. Discover how to order and provision physical connection points for your network. Establish direct network connections between two data center ports for seamless data transfer. Manage and configure your Cloud Router for multi-cloud connectivity and routing. Set up fast, reliable internet service with dedicated, symmetrical bandwidth. Connect directly and securely to global cloud regions like AWS, GCP, and Azure. **Insights** Gain real-time visibility and detailed analytics into your network and application performance. Get real-time insights into network traffic, application usage, and user activity. Monitor server traffic, IP connections, geolocation data, and bandwidth usage. View real-time status and performance of cloud tunnels and remote site links. **Network and Services** Configure and manage network components and security features. Configure robust firewall rules, web filtering, and DDoS protection. Manage Border Gateway Protocol settings for advanced routing. Utilize diagnostic tools like Route Lookup, Ping, Trace Route, and Packet Capture. Displays the MAC address table showing which devices are learned on which interfaces. Safeguard your network from distributed denial-of-service attacks. Lists all active routes on the device, including BGP, static, and connected routes. **Quick Access:** Need to get up and running quickly? A concise guide to rapidly set up your account and initial network configurations. # Get all ipam pools usage Source: https://docs.zayo.com/api-reference/config--ipam/get-all-ipam-pools-usage /openapi.json get /config/ipam/pfx_available # Get All Tenant Request Source: https://docs.zayo.com/api-reference/config--request/get-all-tenant-request /openapi.json get /config/request/tenant/all # Get All User Requests Source: https://docs.zayo.com/api-reference/config--request/get-all-user-requests /openapi.json get /config/request/user/all # Get Request Source: https://docs.zayo.com/api-reference/config--request/get-request /openapi.json get /config/request/{request_id} # Get all services_packages Source: https://docs.zayo.com/api-reference/config--services_package/get-all-services_packages /openapi.json get /config/services_package # Create Plant Source: https://docs.zayo.com/api-reference/endpoint/create POST /plants # Delete Plant Source: https://docs.zayo.com/api-reference/endpoint/delete DELETE /plants/{id} # Get Plants Source: https://docs.zayo.com/api-reference/endpoint/get GET /plants # New Plant Source: https://docs.zayo.com/api-reference/endpoint/webhook WEBHOOK /plant/webhook # Get Group Source: https://docs.zayo.com/api-reference/group/get-group /openapi.json get /group/{group_name} # Get Groups Source: https://docs.zayo.com/api-reference/group/get-groups /openapi.json get /group # Introduction Source: https://docs.zayo.com/api-reference/introduction ## Authentication All API endpoints are authenticated using Bearer tokens and picked up from the specification file. ```json theme={null} "security": [ { "bearerAuth": [] } ] ``` To get a Bearer token, you must request one from Zayo here: [Zayo Developer Portal](https://developer.zayo.com/) # Get the ARP information for specific tenant Source: https://docs.zayo.com/api-reference/service--arp/get-the-arp-information-for-specific-tenant /openapi.json get /service/{tenant_name}/arp # Create Asn Source: https://docs.zayo.com/api-reference/service--asn/create-asn /openapi.json post /service/{tenant_name}/asn # delete a request for port Source: https://docs.zayo.com/api-reference/service--asn/delete-a-request-for-port /openapi.json delete /service/{tenant_name}/asn/{asn} # Get Asns Source: https://docs.zayo.com/api-reference/service--asn/get-asns /openapi.json get /service/{tenant_name}/asn # Update Asn Source: https://docs.zayo.com/api-reference/service--asn/update-asn /openapi.json put /service/{tenant_name}/asn/{asn} # Create Tenant Bgp Route Map Source: https://docs.zayo.com/api-reference/service--bgp_pfx_list/create-tenant-bgp-route-map /openapi.json post /service/{tenant_name}/bgp_pfx_list # Delete Tenant Bgp Route Map Source: https://docs.zayo.com/api-reference/service--bgp_pfx_list/delete-tenant-bgp-route-map /openapi.json delete /service/{tenant_name}/bgp_pfx_list/{name} # Get All Tenant Bgp Route Maps Source: https://docs.zayo.com/api-reference/service--bgp_pfx_list/get-all-tenant-bgp-route-maps /openapi.json get /service/{tenant_name}/bgp_pfx_list # Get Tenant Bgp Route Map Source: https://docs.zayo.com/api-reference/service--bgp_pfx_list/get-tenant-bgp-route-map /openapi.json get /service/{tenant_name}/bgp_pfx_list/{name} # Create Tenant Bgp Route Map Rule Source: https://docs.zayo.com/api-reference/service--bgp_route_map_rule/create-tenant-bgp-route-map-rule /openapi.json post /service/{tenant_name}/bgp_route_map_rule # Delete Tenant Bgp Route Map Rule Source: https://docs.zayo.com/api-reference/service--bgp_route_map_rule/delete-tenant-bgp-route-map-rule /openapi.json delete /service/{tenant_name}/bgp_route_map_rule/{name} # Get All Tenant Bgp Route Map Rules Source: https://docs.zayo.com/api-reference/service--bgp_route_map_rule/get-all-tenant-bgp-route-map-rules /openapi.json get /service/{tenant_name}/bgp_route_map_rule # Get Tenant Bgp Route Map Rule Source: https://docs.zayo.com/api-reference/service--bgp_route_map_rule/get-tenant-bgp-route-map-rule /openapi.json get /service/{tenant_name}/bgp_route_map_rule/{name} # Create Connections Source: https://docs.zayo.com/api-reference/service--connection/create-connections /openapi.json post /service/{tenant_name}/connection/connections # Get All Tenant Enabled Services Source: https://docs.zayo.com/api-reference/service--enabled-services/get-all-tenant-enabled-services /openapi.json get /service/{tenant_name}/enabled_service # Update Tenant Enabled Services Source: https://docs.zayo.com/api-reference/service--enabled-services/update-tenant-enabled-services /openapi.json put /service/{tenant_name}/enabled_service # Create Tenant Dia Fw Rule Source: https://docs.zayo.com/api-reference/service--firewall/create-tenant-dia-fw-rule /openapi.json post /service/{tenant_name}/firewall_rule/dia # Create Tenant Fw Rule Source: https://docs.zayo.com/api-reference/service--firewall/create-tenant-fw-rule /openapi.json post /service/{tenant_name}/firewall_rule # Delete Tenant Fw Rule Source: https://docs.zayo.com/api-reference/service--firewall/delete-tenant-fw-rule /openapi.json delete /service/{tenant_name}/firewall_rule/{rule_name} # Get All Tenant Fw Rules Source: https://docs.zayo.com/api-reference/service--firewall/get-all-tenant-fw-rules /openapi.json get /service/{tenant_name}/firewall_rule # Get Tenant Fw Rule Source: https://docs.zayo.com/api-reference/service--firewall/get-tenant-fw-rule /openapi.json get /service/{tenant_name}/firewall_rule/{rule_name} # Modify rule's description Source: https://docs.zayo.com/api-reference/service--firewall/modify-rules-description /openapi.json patch /service/{tenant_name}/firewall_rule/{rule_name}/description # Modify rule's enable/disable Source: https://docs.zayo.com/api-reference/service--firewall/modify-rules-enabledisable /openapi.json patch /service/{tenant_name}/firewall_rule/{rule_name}/enable # Modify rule's filter Source: https://docs.zayo.com/api-reference/service--firewall/modify-rules-filter /openapi.json patch /service/{tenant_name}/firewall_rule/{rule_name}/filters # Modify rule's forwarding policy Source: https://docs.zayo.com/api-reference/service--firewall/modify-rules-forwarding-policy /openapi.json patch /service/{tenant_name}/firewall_rule/{rule_name}/forwarding_policy # Modify rule's name Source: https://docs.zayo.com/api-reference/service--firewall/modify-rules-name /openapi.json patch /service/{tenant_name}/firewall_rule/{rule_name}/name # Modify rule's priority Source: https://docs.zayo.com/api-reference/service--firewall/modify-rules-priority /openapi.json patch /service/{tenant_name}/firewall_rule/{rule_name}/priority # Update FW rule Source: https://docs.zayo.com/api-reference/service--firewall/update-fw-rule /openapi.json put /service/{tenant_name}/firewall_rule/{rule_name} # Update FW rule Source: https://docs.zayo.com/api-reference/service--firewall/update-fw-rule-1 /openapi.json put /service/{tenant_name}/firewall_rule/{rule_name}/dia # Create Tenant Group Source: https://docs.zayo.com/api-reference/service--group/create-tenant-group /openapi.json post /service/{tenant_name}/group # Delete Tenant Group Source: https://docs.zayo.com/api-reference/service--group/delete-tenant-group /openapi.json delete /service/{tenant_name}/group/{group_name} # Get Tenant Group Source: https://docs.zayo.com/api-reference/service--group/get-tenant-group /openapi.json get /service/{tenant_name}/group/{group_name} # Get Tenant Groups Source: https://docs.zayo.com/api-reference/service--group/get-tenant-groups /openapi.json get /service/{tenant_name}/group # Update Tenant Group Source: https://docs.zayo.com/api-reference/service--group/update-tenant-group /openapi.json put /service/{tenant_name}/group/{group_name} # Create Aws Tenant L2 Source: https://docs.zayo.com/api-reference/service--l2_interface/create-aws-tenant-l2 /openapi.json post /service/{tenant_name}/l2/aws_direct_connect # Create Tenant L2 Source: https://docs.zayo.com/api-reference/service--l2_interface/create-tenant-l2 /openapi.json post /service/{tenant_name}/l2/customer_port/{customer_port_name}/vlan # delete a request for port Source: https://docs.zayo.com/api-reference/service--l2_interface/delete-a-request-for-port /openapi.json delete /service/{tenant_name}/l2/customer_port/{name} # Delete an interface Source: https://docs.zayo.com/api-reference/service--l2_interface/delete-an-interface /openapi.json delete /service/{tenant_name}/l2/customer_port/{customer_port_name}/vlan/{name} # Delete an interface Source: https://docs.zayo.com/api-reference/service--l2_interface/delete-an-interface-1 /openapi.json delete /service/{tenant_name}/l2/aws_direct_connect/{customer_port_name} # Delete an interface Source: https://docs.zayo.com/api-reference/service--l2_interface/delete-an-interface-2 /openapi.json delete /service/{tenant_name}/l2/azure_direct_connect/{customer_port_name} # Delete an interface Source: https://docs.zayo.com/api-reference/service--l2_interface/delete-an-interface-3 /openapi.json delete /service/{tenant_name}/l2/gcp_direct_connect/{customer_port_name} # discover the azure secret key Source: https://docs.zayo.com/api-reference/service--l2_interface/discover-the-azure-secret-key /openapi.json get /service/{tenant_name}/l2/azure_service_key # Get All Tenant L2 Interface Source: https://docs.zayo.com/api-reference/service--l2_interface/get-all-tenant-l2-interface /openapi.json get /service/{tenant_name}/l2 # Get All Tenant L2 Interface Requests Source: https://docs.zayo.com/api-reference/service--l2_interface/get-all-tenant-l2-interface-requests /openapi.json get /service/{tenant_name}/l2/customer_port # Request Customer Port Source: https://docs.zayo.com/api-reference/service--l2_interface/request-customer-port /openapi.json post /service/{tenant_name}/l2/customer_port # Update Customer Port Labels Source: https://docs.zayo.com/api-reference/service--l2_interface/update-customer-port-labels /openapi.json put /service/{tenant_name}/l2/customer_port/{name} # Update Port Vlan Interface Bandwidth Source: https://docs.zayo.com/api-reference/service--l2_interface/update-port-vlan-interface-bandwidth /openapi.json put /service/{tenant_name}/l2/customer_port/{customer_port_name}/vlan/{name} # Get Result Source: https://docs.zayo.com/api-reference/service--looking-glass/get-result /openapi.json post /service/looking_glass/result # Get Route Lookup Source: https://docs.zayo.com/api-reference/service--looking-glass/get-route-lookup /openapi.json post /service/looking_glass/route_lookup # Pcap Source: https://docs.zayo.com/api-reference/service--looking-glass/pcap /openapi.json post /service/looking_glass/pcap # Ping Source: https://docs.zayo.com/api-reference/service--looking-glass/ping /openapi.json post /service/looking_glass/ping # Get the MAC information for specific tenant Source: https://docs.zayo.com/api-reference/service--mac/get-the-mac-information-for-specific-tenant /openapi.json get /service/{tenant_name}/mac # Create NAT rule Source: https://docs.zayo.com/api-reference/service--nat/create-nat-rule /openapi.json post /service/{tenant_name}/nat_rule # Delete NAT rule Source: https://docs.zayo.com/api-reference/service--nat/delete-nat-rule /openapi.json delete /service/{tenant_name}/nat_rule/{rule_name} # Get all NAT rules Source: https://docs.zayo.com/api-reference/service--nat/get-all-nat-rules /openapi.json get /service/{tenant_name}/nat_rule # Get specific NAT Rule Source: https://docs.zayo.com/api-reference/service--nat/get-specific-nat-rule /openapi.json get /service/{tenant_name}/nat_rule/{rule_name} # Modify NAT rule Source: https://docs.zayo.com/api-reference/service--nat/modify-nat-rule /openapi.json put /service/{tenant_name}/nat_rule/{rule_name} # Get all user events Source: https://docs.zayo.com/api-reference/service--orders/get-all-user-events /openapi.json get /service/{tenant_name}/events # Create Tenant Pbm Rule Source: https://docs.zayo.com/api-reference/service--pbm/create-tenant-pbm-rule /openapi.json post /service/{tenant_name}/pbm_rule # Delete Tenant Pbm Rule Source: https://docs.zayo.com/api-reference/service--pbm/delete-tenant-pbm-rule /openapi.json delete /service/{tenant_name}/pbm_rule/{rule_name} # Get All Tenant Pbm Rules Source: https://docs.zayo.com/api-reference/service--pbm/get-all-tenant-pbm-rules /openapi.json get /service/{tenant_name}/pbm_rule # Get Tenant Pbm Rule Source: https://docs.zayo.com/api-reference/service--pbm/get-tenant-pbm-rule /openapi.json get /service/{tenant_name}/pbm_rule/{rule_name} # Update PBM rule Source: https://docs.zayo.com/api-reference/service--pbm/update-pbm-rule /openapi.json put /service/{tenant_name}/pbm_rule/{rule_name} # Create Tenant Pbr Rule Source: https://docs.zayo.com/api-reference/service--pbr/create-tenant-pbr-rule /openapi.json post /service/{tenant_name}/pbr_rule # Delete Tenant Pbr Rule Source: https://docs.zayo.com/api-reference/service--pbr/delete-tenant-pbr-rule /openapi.json delete /service/{tenant_name}/pbr_rule/{rule_name} # Get All Tenant Pbr Rules Source: https://docs.zayo.com/api-reference/service--pbr/get-all-tenant-pbr-rules /openapi.json get /service/{tenant_name}/pbr_rule # Get Tenant Pbr Rule Source: https://docs.zayo.com/api-reference/service--pbr/get-tenant-pbr-rule /openapi.json get /service/{tenant_name}/pbr_rule/{rule_name} # Update PBR rule Source: https://docs.zayo.com/api-reference/service--pbr/update-pbr-rule /openapi.json put /service/{tenant_name}/pbr_rule/{rule_name} # Get the routes information for specific tenant Source: https://docs.zayo.com/api-reference/service--routes/get-the-routes-information-for-specific-tenant /openapi.json get /service/{tenant_name}/route # Create an autonomous system for a Tenant Source: https://docs.zayo.com/api-reference/service--routing--bgp/create-an-autonomous-system-for-a-tenant /openapi.json post /service/{tenant_name}/bgp/autonomous_system # Create Tenant Neighbor Source: https://docs.zayo.com/api-reference/service--routing--bgp/create-tenant-neighbor /openapi.json post /service/{tenant_name}/bgp/neighbor # Delete an autonomous system from a Tenant Source: https://docs.zayo.com/api-reference/service--routing--bgp/delete-an-autonomous-system-from-a-tenant /openapi.json delete /service/{tenant_name}/bgp/autonomous_system # Delete Tenant Neighbor Source: https://docs.zayo.com/api-reference/service--routing--bgp/delete-tenant-neighbor /openapi.json delete /service/{tenant_name}/bgp/neighbor/{remote_router_ip} # Get advertised routes Source: https://docs.zayo.com/api-reference/service--routing--bgp/get-advertised-routes /openapi.json put /service/{tenant_name}/bgp/neighbor/{remote_router_ip}/reset # Get advertised routes Source: https://docs.zayo.com/api-reference/service--routing--bgp/get-advertised-routes-1 /openapi.json get /service/{tenant_name}/bgp/neighbor/{remote_router_ip}/advertised_routes # Get All Tenant Neighbors Source: https://docs.zayo.com/api-reference/service--routing--bgp/get-all-tenant-neighbors /openapi.json get /service/{tenant_name}/bgp/neighbor # Get Bfd Status Source: https://docs.zayo.com/api-reference/service--routing--bgp/get-bfd-status /openapi.json get /service/{tenant_name}/bgp/bfd_status # Get Bgp Status Source: https://docs.zayo.com/api-reference/service--routing--bgp/get-bgp-status /openapi.json get /service/{tenant_name}/bgp/status # Get Bgp Summery Source: https://docs.zayo.com/api-reference/service--routing--bgp/get-bgp-summery /openapi.json get /service/{tenant_name}/bgp/summery # Get filtered routes Source: https://docs.zayo.com/api-reference/service--routing--bgp/get-filtered-routes /openapi.json get /service/{tenant_name}/bgp/neighbor/{remote_router_ip}/filtered_routes # Get received routes Source: https://docs.zayo.com/api-reference/service--routing--bgp/get-received-routes /openapi.json get /service/{tenant_name}/bgp/neighbor/{remote_router_ip}/received_routes # Get Tenant Neighbor By Ip Source: https://docs.zayo.com/api-reference/service--routing--bgp/get-tenant-neighbor-by-ip /openapi.json get /service/{tenant_name}/bgp/neighbor/{remote_router_ip} # Get the autonomous system info for a Tenant Source: https://docs.zayo.com/api-reference/service--routing--bgp/get-the-autonomous-system-info-for-a-tenant /openapi.json get /service/{tenant_name}/bgp/autonomous_system # Update neighbor Source: https://docs.zayo.com/api-reference/service--routing--bgp/update-neighbor /openapi.json put /service/{tenant_name}/bgp/neighbor/{remote_router_ip} # Create a new static route Source: https://docs.zayo.com/api-reference/service--routing--static-route/create-a-new-static-route /openapi.json post /service/{tenant_name}/static_route # Delete a static route Source: https://docs.zayo.com/api-reference/service--routing--static-route/delete-a-static-route /openapi.json delete /service/{tenant_name}/static_route # Get all static routes by tenant Source: https://docs.zayo.com/api-reference/service--routing--static-route/get-all-static-routes-by-tenant /openapi.json get /service/{tenant_name}/static_route # Modify a static routes description Source: https://docs.zayo.com/api-reference/service--routing--static-route/modify-a-static-routes-description /openapi.json put /service/{tenant_name}/static_route/description # Modify a static routes enabled status Source: https://docs.zayo.com/api-reference/service--routing--static-route/modify-a-static-routes-enabled-status /openapi.json put /service/{tenant_name}/static_route/enabled # Get Tenant Sdr Source: https://docs.zayo.com/api-reference/service--sdr/get-tenant-sdr /openapi.json get /service/{tenant_name}/sdr # Check Trusted Access Source: https://docs.zayo.com/api-reference/service--trusted-access/check-trusted-access /openapi.json get /service/{tenant_name}/trusted_access/{user_name}/{tunnel_id} # Request Trusted Access Source: https://docs.zayo.com/api-reference/service--trusted-access/request-trusted-access /openapi.json post /service/{tenant_name}/trusted_access/{user_name}/{tunnel_id} # vpn app get status Source: https://docs.zayo.com/api-reference/service--vpn-app--status/vpn-app-get-status /openapi.json get /service/{tenant_name}/wg_tunnel_status # vpn app get status Source: https://docs.zayo.com/api-reference/service--vpn-app--status/vpn-app-get-status-1 /openapi.json get /service/{tenant_name}/wg_tunnel_status/{user_name} # Collect remote user app data Source: https://docs.zayo.com/api-reference/service--vpn-app/collect-remote-user-app-data /openapi.json post /service/{tenant_name}/wg_tunnel/{user_name}/{tunnel_id}/device_data # Create a new VPN app tunnel Source: https://docs.zayo.com/api-reference/service--vpn-app/create-a-new-vpn-app-tunnel /openapi.json post /service/{tenant_name}/wg_tunnel/{user_name}/{system_name} # Delete a VPN app tunnel Source: https://docs.zayo.com/api-reference/service--vpn-app/delete-a-vpn-app-tunnel /openapi.json delete /service/{tenant_name}/wg_tunnel/{user_name}/{tunnel_id} # Get List Wg Tunnel Source: https://docs.zayo.com/api-reference/service--vpn-app/get-list-wg-tunnel /openapi.json get /service/{tenant_name}/wg_tunnel/get_list # Get Tunnel Wg Conf Source: https://docs.zayo.com/api-reference/service--vpn-app/get-tunnel-wg-conf /openapi.json get /service/{tenant_name}/wg_tunnel/get_conf/{user_name}/{tunnel_id} # Get User List Wg Tunnel Source: https://docs.zayo.com/api-reference/service--vpn-app/get-user-list-wg-tunnel /openapi.json get /service/{tenant_name}/wg_tunnel/get_user_list/{user_name} # Get Wg Tunnel Source: https://docs.zayo.com/api-reference/service--vpn-app/get-wg-tunnel /openapi.json get /service/{tenant_name}/wg_tunnel/get_one/{user_name}/{tunnel_id} # Get all services items Source: https://docs.zayo.com/api-reference/service-catalog/get-all-services-items /openapi.json get /orders/catalog # Get DDoS attack traffic Statistics Source: https://docs.zayo.com/api-reference/statistics/get-ddos-attack-traffic-statistics /openapi.json post /statistics/ddos_attack_traffic # Get firewall traffic Statistics Source: https://docs.zayo.com/api-reference/statistics/get-firewall-traffic-statistics /openapi.json post /statistics/firewall_traffic # Get flood traffic Statistics Source: https://docs.zayo.com/api-reference/statistics/get-flood-traffic-statistics /openapi.json post /statistics/flood_traffic # Get l2 Statistics Source: https://docs.zayo.com/api-reference/statistics/get-l2-statistics /openapi.json post /statistics/l2_interface # Get NAT traffic Statistics Source: https://docs.zayo.com/api-reference/statistics/get-nat-traffic-statistics /openapi.json post /statistics/nat_traffic # Get PBR traffic Statistics Source: https://docs.zayo.com/api-reference/statistics/get-pbr-traffic-statistics /openapi.json post /statistics/pbr_traffic # Get Statistics Source: https://docs.zayo.com/api-reference/statistics/get-statistics /openapi.json post /statistics/virtual_interface # Get a system Source: https://docs.zayo.com/api-reference/system/get-a-system /openapi.json get /system/{system_name} # Get list of all system Source: https://docs.zayo.com/api-reference/system/get-list-of-all-system /openapi.json get /system # Delete Gate VI Source: https://docs.zayo.com/api-reference/tenant--dia/delete-gate-vi /openapi.json delete /tenant/{tenant_name}/dia/{name} # Request a Gate VI Source: https://docs.zayo.com/api-reference/tenant--dia/request-a-gate-vi /openapi.json post /tenant/{tenant_name}/dia # customize new ip flood Source: https://docs.zayo.com/api-reference/tenant--ip-flood/customize-new-ip-flood /openapi.json post /service/{tenant_name}/ddos/dia/customize/{ip_flood_id} # Delete a ip flood Source: https://docs.zayo.com/api-reference/tenant--ip-flood/delete-a-ip-flood /openapi.json delete /service/{tenant_name}/ddos/dia/{ip_flood_id} # Get tenant ip_flood Source: https://docs.zayo.com/api-reference/tenant--ip-flood/get-tenant-ip_flood /openapi.json get /service/{tenant_name}/ddos/dia # Update ip flood Source: https://docs.zayo.com/api-reference/tenant--ip-flood/update-ip-flood /openapi.json put /service/{tenant_name}/ddos/dia/{ip_flood_id} # Update ip flood Source: https://docs.zayo.com/api-reference/tenant--ip-flood/update-ip-flood-1 /openapi.json put /service/{tenant_name}/ddos/dia/all # Delete Gate VI Source: https://docs.zayo.com/api-reference/tenant--public-ip/delete-gate-vi /openapi.json delete /tenant/{tenant_name}/request_gate_vi/{name} # Request a Gate VI Source: https://docs.zayo.com/api-reference/tenant--public-ip/request-a-gate-vi /openapi.json post /tenant/{tenant_name}/request_gate_vi # Create new user for tenant Source: https://docs.zayo.com/api-reference/tenant--users/create-new-user-for-tenant /openapi.json post /tenant/{tenant_name}/users # Delete user Source: https://docs.zayo.com/api-reference/tenant--users/delete-user /openapi.json delete /tenant/{tenant_name}/users # Get tenant user or all tenant users Source: https://docs.zayo.com/api-reference/tenant--users/get-tenant-user-or-all-tenant-users /openapi.json get /tenant/{tenant_name}/users # Update tenant user Source: https://docs.zayo.com/api-reference/tenant--users/update-tenant-user /openapi.json put /tenant/{tenant_name}/users # Get all virtual interfaces per tenant type gate Source: https://docs.zayo.com/api-reference/tenant--virtual-interface--gate/get-all-virtual-interfaces-per-tenant-type-gate /openapi.json get /tenant/{tenant_name}/virtual_interface/gate # Create a new virtual interface for a tenant Source: https://docs.zayo.com/api-reference/tenant--virtual-interface/create-a-new-virtual-interface-for-a-tenant /openapi.json post /tenant/{tenant_name}/virtual_interface # Delete Tenant Virtual Interface Source: https://docs.zayo.com/api-reference/tenant--virtual-interface/delete-tenant-virtual-interface /openapi.json delete /tenant/{tenant_name}/virtual_interface/{virtual_interface_name} # Get all virtual interfaces of type bridge domain per tenant Source: https://docs.zayo.com/api-reference/tenant--virtual-interface/get-all-virtual-interfaces-of-type-bridge-domain-per-tenant /openapi.json get /tenant/{tenant_name}/virtual_interface # Get all virtual interfaces per tenant Source: https://docs.zayo.com/api-reference/tenant--virtual-interface/get-all-virtual-interfaces-per-tenant /openapi.json get /tenant/{tenant_name}/virtual_interface/all_types # Modify virtual interface IP addresses Source: https://docs.zayo.com/api-reference/tenant--virtual-interface/modify-virtual-interface-ip-addresses /openapi.json patch /tenant/{tenant_name}/virtual_interface/{virtual_interface_name}/ip_addresses # Update virtual interface Source: https://docs.zayo.com/api-reference/tenant--virtual-interface/update-virtual-interface /openapi.json put /tenant/{tenant_name}/virtual_interface/{virtual_interface_name} # Get notifications for each tenant Source: https://docs.zayo.com/api-reference/tenant/get-notifications-for-each-tenant /openapi.json get /tenant/{tenant_name}/notifications # Get tenants L2 max bandwidth Source: https://docs.zayo.com/api-reference/tenant/get-tenants-l2-max-bandwidth /openapi.json get /tenant/{tenant_name}/max_bandwidth # Modify tenant's contact info Source: https://docs.zayo.com/api-reference/tenant/modify-tenants-contact-info /openapi.json patch /tenant/{tenant_name}/contact_info # Modify tenant's contact info Source: https://docs.zayo.com/api-reference/tenant/modify-tenants-contact-info-1 /openapi.json patch /tenant/{tenant_name}/full_name # Modify tenant's services package Source: https://docs.zayo.com/api-reference/tenant/modify-tenants-services-package /openapi.json patch /tenant/{tenant_name}/services_package # Get all terms and conditions Source: https://docs.zayo.com/api-reference/terms-and-conditions/get-all-terms-and-conditions /openapi.json get /orders/terms_and_conditions/all # Get terms and conditions Source: https://docs.zayo.com/api-reference/terms-and-conditions/get-terms-and-conditions /openapi.json get /orders/terms_and_conditions # Sign Terms Source: https://docs.zayo.com/api-reference/terms-and-conditions/sign-terms /openapi.json post /orders/terms_and_conditions/{tenant_name}/sign # Delete user Source: https://docs.zayo.com/api-reference/users/delete-user /openapi.json delete /users # Get Current User Source: https://docs.zayo.com/api-reference/users/get-current-user /openapi.json get /users/current # Get user access token. New password used only for users who need to update it. Source: https://docs.zayo.com/api-reference/users/get-user-access-token-new-password-used-only-for-users-who-need-to-update-it /openapi.json post /users/get_token # Update Current User Source: https://docs.zayo.com/api-reference/users/update-current-user /openapi.json put /users/current # Update Current User Password Source: https://docs.zayo.com/api-reference/users/update-current-user-password /openapi.json put /users/current/password # Using the Dynamic API for Integrations Source: https://docs.zayo.com/docs/api-summary The DynamicLink API is a comprehensive RESTful API that allows you to interact with DynamicLink programmatically to manage your network infrastructure, services, and resources. The DynamicLink API exposes the full functionality of the DynamicLink platform, allowing you to: * **Automate Network Operations**: Provision and manage network resources without manual intervention * **Build Custom Integrations**: Connect DynamicLink with your existing tools, workflows, and systems * **Create Third-Party Applications**: Develop applications that leverage DynamicLink's network capabilities * **Implement Infrastructure as Code**: Manage your network infrastructure through code and version control * **Enable CI/CD Pipelines**: Integrate network provisioning into your deployment workflows ## API reference documentation For detailed information about specific endpoints, request/response formats, and examples, see the [API Reference](/api-reference/introduction) documentation. ## Key capabilities * **Tenant and user management** * **Network infrastructure** * **Cloud connections** * **Routing and BGP** * **Security services** * **Network insights** * **Monitoring and diagnostics** ## Authentication All API requests require authentication using Bearer tokens. The API uses the `HTTPBearerFromCookie` security scheme, which supports tokens obtained through the authentication flow. To get a Bearer token, you must request one from Zayo here: [Zayo Developer Portal](https://developer.zayo.com/) ## API structure The DynamicLink API follows RESTful conventions: * **GET** - Retrieve resources and query information * **POST** - Create new resources * **PUT** - Update existing resources * **DELETE** - Remove resources All responses are returned in JSON format with standard HTTP status codes. ## Examples The DynamicLink API is designed to make integration straightforward. Here are common integration patterns: ### Automation workflows Automate repetitive network management tasks: ```bash theme={null} # Example: Automate DIA provisioning curl -X POST "https://api.dynamiclink.zayo.com/tenant/{tenant_name}/dia" \ -H "Authorization: Bearer YOUR_TOKEN" \ -H "Content-Type: application/json" \ -d '{ "name": "production-dia", "bandwidth": 1000, "public_ip_pool": "dia-pool-1" }' ``` ### Infrastructure as code Use the API with tools like Terraform, Ansible, or custom scripts to manage your network as code: ```python theme={null} # Example: Python integration for automated provisioning import requests def create_cloud_router(tenant_name, router_config): response = requests.post( f"https://api.dynamiclink.zayo.com/service/{tenant_name}/connection/connections", headers={"Authorization": f"Bearer {token}"}, json=router_config ) return response.json() ``` ### Event-driven integrations Build integrations that respond to network events and changes: ```bash theme={null} # Monitor connection status curl -X GET "https://api.dynamiclink.zayo.com/service/{tenant_name}/connection/connections" \ -H "Authorization: Bearer YOUR_TOKEN" ``` ## Best practices When building integrations with the DynamicLink API: * **Use Idempotent Operations**: Design your integration to handle retries safely * **Implement Proper Error Handling**: Check HTTP status codes and handle errors gracefully * **Respect Rate Limits**: Implement exponential backoff and respect API rate limits * **Secure Your Credentials**: Never expose API tokens in logs, code repositories, or client-side applications * **Version Your Integrations**: Be prepared for API changes and version your integration code * **Monitor API Usage**: Track your API usage to optimize performance and costs * **Test in Non-Production**: Always test integrations in a non-production environment first # Application Observability Source: https://docs.zayo.com/docs/application-observability The **Application Observability** dashboard provides visibility into the applications and hostnames your network is communicating with. While the [Network Observability](network-observability) dashboard focuses on infrastructure-level traffic patterns, the Application Observability dashboard shows you *what* your users and devices are connecting to — which websites, services, and applications are consuming bandwidth across your DynamicLink network. Access it from **Insights > Application Observability**. Application Observability dashboard ## Date filter In the upper right, use the **date range** selector to adjust the time window for all dashboard data (e.g., Last 12 hours, Last 24 hours, Last 7 days). ## Traffic filters Below the tab name, the **Filter** option lets you narrow the dashboard data by criteria such as locations, IPs, and connections. ## Summary cards At the top of the dashboard, four summary cards provide a quick snapshot of activity within the selected time window: | Card | Description | | ----------------------------- | ------------------------------------------------------------------------------------ | | **Locations** | The number of physical locations generating application traffic | | **Unique Group and Segments** | The number of network segments and unique groups observed in the traffic | | **Users and Source IP** | The number of distinct source IP addresses and mapped users | | **Applications** | The total number of applications detected, along with how many are currently blocked | ## Incoming Connections The center of the dashboard displays an **Incoming Connections** flow diagram. This is a Sankey-style visualization that maps the path of traffic from its source through to the destination hostnames. * **Connections** — The named connections originating the traffic (e.g., DIA\_pool\_1\_NY) * **Destination** — The destination category (e.g., Internet) * **Hostname** — The specific hostnames receiving traffic, sized proportionally to their traffic volume The width of each flow band represents relative traffic volume, making it easy to spot which connections are driving the most traffic and which hostnames are the busiest destinations. You can switch the view using the sub-tabs above the diagram: | Sub-tab | Description | | --------------- | ------------------------------------------------ | | **Locations** | Groups incoming connections by physical location | | **Source IPs** | Groups incoming connections by source IP address | | **Connections** | Groups incoming connections by named connection | ## Top Applications The bottom of the dashboard is divided into two sections: ### Top Applications table A sortable table listing individual application flows with the following columns: | Column | Description | | -------------------------- | ---------------------------------------------------- | | **Location** | The physical location where the traffic originated | | **Source IP** | The source IP address initiating the connection | | **Destination IP** | The destination IP address | | **Source Connection** | The named source connection (e.g., DIA\_pool\_1\_NY) | | **Destination Connection** | The destination connection category (e.g., Internet) | | **Hostname** | The resolved hostname of the destination | | **Count** | The number of connections observed for this flow | The table is sortable by any column. Use it to identify which specific source IPs are generating the most connections to a given hostname, or to trace traffic from a particular location to its destinations. ### Top Application chart A donut chart to the right of the table provides a visual breakdown of the most-visited applications by connection count. Each segment represents a distinct hostname, making it easy to see at a glance which applications dominate your network traffic. ## Common use cases **Identifying top bandwidth consumers** Use the Incoming Connections flow diagram and the Top Applications table to see which hostnames account for the most traffic. If a non-business-critical application (e.g., streaming media) is consuming a disproportionate share of bandwidth, consider creating a [DIA Firewall](dia-firewall) rule or web filter to manage access. **Verifying application access policies** After configuring firewall rules or web filters, check the Application Observability dashboard to confirm that blocked applications no longer appear in the traffic data. The **Blocked Applications** count in the summary cards provides a quick confirmation. **Investigating unexpected destinations** If you notice traffic flowing to unfamiliar hostnames, use the Top Applications table to identify the source IPs and locations responsible. Cross-reference with the [Network Observability](network-observability) dashboard for deeper flow-level analysis, or the [Cyber Threats](firewall) dashboard if the traffic appears suspicious. **Understanding per-location application usage** Switch to the **Locations** sub-tab in the Incoming Connections diagram to see application usage patterns by site. This is useful for understanding how different offices or branches use the network and whether location-specific policies are needed. # Submit an ASN in DynamicLink Source: https://docs.zayo.com/docs/asn An Autonomous System Number (ASN) is a unique identifier assigned to your network that allows it to participate in Border Gateway Protocol (BGP) routing on the internet. To use [DIA BGP](dia-overview#dia-bgp), you must submit your ASN in DynamicLink and have it approved before you can build a connection. You only need to submit an ASN if you're using DIA BGP. Standard DIA connections do not require an ASN. You can submit your ASN in advance for network planning—you don't need an active port or DIA BGP connection to submit one. ## Submit an ASN Go to **Build Your Network > Public IPs > ASN**. Click **Set up new** and complete the following field: | Field | Description | | ------- | --------------------------------------------- | | **ASN** | The public ASN assigned to your organization. | Click **Setup**. Your ASN will appear in the **ASN** section with a **Pending** status while Zayo reviews it. Screenshot of ASN section ## ASN approval Zayo verifies that the submitted ASN belongs to your organization before approving it for use on the platform. Once verified, the status changes from **Pending** to **Approved** and displays in green. If your ASN is declined, the reason for the decline will be shown in the **ASN** section. Common reasons include: * The ASN is not registered to your organization * The ASN is not publicly routable * The ASN information does not match Zayo's records You can submit a corrected ASN at any time by repeating the steps above. ## Use or delete an ASN Once your ASN is approved, you can select it when [creating a DIA BGP connection](dia-bgp). A single approved ASN can be used across multiple DIA BGP connections. Deleting an ASN is optional and should only be done if you no longer plan to use it for any DynamicLink service. If you delete an ASN and need it again later, you must submit it again and wait for re-approval. To delete an ASN, go to **Build Your Network > Public IPs > ASN**, locate the ASN, and click the trash icon. # Guide: Public IP Pools and DIA Source: https://docs.zayo.com/docs/build-your-network/DIA Learn how to manage and allocate Public IP addresses for NaaS and Direct Internet Access (DIA) services. The DynamicLink platform includes a robust Public IP Pools Management (IPAM) system. This guide explains what IPAM is and provides a step-by-step process for configuring and using public IP pools for both Network as a Service (NaaS) and Direct Internet Access (DIA). ## What are Public IP Pools? **Public IP Pools** are ranges of public IP addresses managed within the DynamicLink platform. They are used to automatically or manually allocate IP addresses to tenant services that require internet connectivity. Properly configuring these pools is the first step in providing internet access to your tenants. The platform distinguishes between two fundamental types of internet access, each with its own type of IP pool. * **NaaS Pools**: These pools are reserved for services that connect to the internet through the shared, multi-tenant DynamicLink NaaS platform infrastructure. This is a secure, managed way to provide internet access. * **DIA Pools**: These pools are used for services that require **Direct Internet Access**. A DIA connection provides a dedicated, uncontended link to the internet, often used for critical applications that need guaranteed bandwidth and performance. *** ## Step-by-Step Guide to Configuring Public IP Pools Follow this process to set up and utilize your public IP address pools correctly. ### Step 1: Understand IPAM Routing Types Before configuring pools, it's important to understand how the platform routes traffic for NaaS and DIA services. While detailed routing configurations are handled by the system, knowing the distinction is key: * **NaaS Internet Access**: Traffic is routed from the tenant's virtual network through the platform's central internet gateways. IP addresses from the **NaaS Pool** are applied here. * **Direct Internet Access (DIA)**: Traffic is routed directly from the tenant's service to the internet via a dedicated circuit. IP addresses from the **DIA Pool** are assigned to this dedicated connection. ### Step 2: Configure Public IP Pools As an administrator, you must define the IP address ranges that the platform can use. 1. Navigate to the administrator dashboard. 2. Locate the **IPAM** or **Address Management** section. 3. You will find options to configure **NaaS Pools** and **DIA Pools**. 4. **For NaaS Pools**: * Click **Add NaaS Pool**. * Enter a descriptive name for the pool (e.g., `Shared-Tenant-NaaS-Pool-1`). * Enter the public IP range in CIDR notation (e.g., `45.67.89.0/24`). * Save the configuration. 5. **For DIA Pools**: * Click **Add DIA Pool**. * Enter a name for the pool (e.g., `Customer-A-DIA-Pool`). * Enter the dedicated public IP range in CIDR notation (e.g., `123.45.67.0/28`). * Save the configuration. ### Step 3: Provision Tenant Internet Access Once your IP pools are configured, you can use them to provide internet access to your tenants. 1. Navigate to the **Tenants** menu and select the tenant you wish to configure. 2. Go to the tenant's **Services** or **Connectivity** settings. 3. Click **Add Internet Access**. 4. In the configuration dialog, you will be prompted to choose the type of internet access: * **For NaaS Internet Access**: Select this option. The platform will automatically assign an available IP address from the pre-configured **NaaS Pools**. * **For Direct Internet Access**: Select this option. You will then be prompted to choose a specific, pre-configured **DIA Pool** to allocate an IP address from for this tenant's dedicated service. 5. Complete the remaining service configuration details and save. By following these steps, you can effectively manage your public IP address allocation and provide the appropriate type of internet access for your tenants' needs. # Cloud Router Source: https://docs.zayo.com/docs/build-your-network/cloud-router Manage your Cloud Router settings, including static and dynamic routes, BGP, ARPs, and policy-based routing to control traffic flow across your network **Overview** The Cloud Router is the virtual routing and switching core of your NaaS platform. It intelligently directs traffic between all your connected resources, including data center ports, cloud links, and internet connections. This section provides a comprehensive guide to viewing and configuring its components. To access these settings, navigate to Network > Cloud Router from the left-side menu. **Routing** The Cloud Router supports both static and dynamic routing protocols to give you full control over your network's traffic paths. The Routers tab provides a breakdown of your routing table. Static Routes: Displays manually configured routes. You can add a new static route by clicking the + Add button and specifying the destination network, the next-hop gateway, and the interface. Dynamic Routes: Shows routes learned automatically from routing protocols like BGP. The table provides key details for each route: Destination: The IP address of the route destination. Gateway: The assigned gateway for the route. Distance: The administrative distance or metric used to determine the best path. Type: The protocol from which the route was learned (e.g., BGP, OSPF). The BGP tab is where you manage peering with other networks. Initial BGP Setup: Set Local ASN: Before adding a neighbor, you must set the AS number for your Cloud Router. Click the pencil icon next to the ASN field to configure it. You can also set default keepalive and hold timers here. Add a Neighbor: Once the ASN is set, click + Add Neighbor. Configure Neighbor Details: Neighbor IP & Remote ASN: The IP and AS number of the remote peer. Authentication: Set an optional BGP password. Address Family: Choose the address family (e.g., IPv4 Unicast). Advanced Options: Configure BFD for faster failure detection, adjust timers for the specific neighbor, or set the session to passive mode. Monitoring BGP: The BGP neighbor table shows the status, prefix counts, and uptime for each peer. Click the triangle next to a neighbor to see detailed statistics, including lists of sent, received, and filtered routes. The PBR tab allows you to create rules that forward traffic based on policies rather than the main routing table. This is useful for directing specific types of traffic through a particular interface, such as a firewall or a dedicated internet link. Layer 2 Information The ARPs tab displays the ARP table, which maps Layer 3 IP addresses to Layer 2 MAC addresses. This is useful for troubleshooting connectivity issues at the data link layer. The table shows: The resolved IP address. The corresponding MAC address. The interface where the device was learned. The age of the entry. Whether the entry is static or dynamic. The Groups tab allows you to create, edit, and delete logical groups of objects, such as IP addresses or interfaces. These groups can then be used to simplify the configuration of firewall rules, routing policies, and other network settings, making your configurations more organized and manageable. # Build Your Network Source: https://docs.zayo.com/docs/build-your-network/introduction A comprehensive guide to creating, managing, and monitoring your network infrastructure using the NaaS portal. **Overview** The Build Your Network section is your central hub for provisioning and managing all aspects of your network infrastructure. From ordering physical ports to establishing complex cloud connections, this area provides the tools you need to construct a robust, scalable, and secure network tailored to your organization's requirements. Whether you are setting up a new data center connection, expanding your cloud presence, or managing your IP address space, each tool is designed to be intuitive and automated, simplifying traditional networking challenges. **Core Capabilities** Explore the core functionalities within the "Build Your Network" section. Each capability is designed to streamline a specific aspect of your network setup and management. Order and manage the physical connection points (Ports) between your internal network and the insidepacket network fabric. A port is the foundational step for all connectivity. Establish direct, secure, and high-performance connections from your ports to major cloud service providers (AWS, Azure, GCP) or create data-center-to-data-center (DC-to-DC) links. Request and manage public IPv4 or IPv6 addresses. Public IPs are essential for enabling external services, such as Dedicated Internet Access (DIA). Configure and manage your virtual routing and switching service. The Cloud Router is the core of your network, enabling interconnection between all your ports, cloud connections, and services. Activate and manage value-added services for your network, including Stateful Firewall, Network Observability, and Web Filtering to enhance security and visibility. Create logical connections (VLANs) over your physical ports to segment traffic and connect to various services and destinations. View a detailed history of all provisioning activities and orders, including port setups, service changes, and connection requests, to track approvals and changes. # Creating a Layer 2 DC-to-DC Connection Source: https://docs.zayo.com/docs/build-your-network/l2 A step-by-step guide to establishing a Layer 2 data center-to-data center connection on the DynamicLink platform. **What You'll Accomplish** This guide will walk you through the process of provisioning a private, point-to-point Layer 2 circuit between two data center ports on the DynamicLink NaaS platform. To create a Layer 2 data center-to-data center (DC-to-DC) connection in DynamicLink, follow these steps: Start by logging into the DynamicLink portal. From the main dashboard, click on the **Build Your Network** tab, and then select **Ports** from the sub-menu. Navigate to Ports Before creating the connection, it's crucial to verify that both the A-side and Z-side ports have enough capacity. Review the `Available Bandwidth` for each port to ensure there is sufficient bandwidth for your new circuit. 1. Locate the first port for your connection and click the **Add a Connection** button next to it. 2. The port name will be automatically populated. 3. Choose an available VLAN from the dropdown menu. 4. Specify the desired bandwidth for the connection (e.g., `1 Gbps`). Configure A-Side Port 1. In the Z-port section, select the second data center port you wish to connect to. 2. Choose an available VLAN from the dropdown menu. Ensure this VLAN has not been used previously on this port. 3. The bandwidth will automatically match the value you selected for the A-side port. 1. Provide a meaningful and easily identifiable name for your new connection in the `Connection Name` field. 2. Review all the details to ensure they are correct. 3. Click the **Add** button at the bottom of the page to finalize the setup and create the connection. Your new Layer 2 connection will now be provisioned and will appear in your list of active connections. # My Services Source: https://docs.zayo.com/docs/build-your-network/my-services Activate, configure, and manage value-added services like Firewall, NAT, and Web Filtering to enhance your network’s security and functionality **Overview** The My Services section allows you to enable and manage a suite of powerful, integrated services for your network. These services are available through different packages and can be configured to protect your network, control traffic flow, and filter content according to your organization's policies. Available Services and Packages Our services are offered in tiered packages to meet your specific needs. You can enable features like Network Observability, Stateful Firewall, and Web Filtering to gain deeper insights and stronger security. Firewall Configuration The firewall allows you to control traffic flow between network segments. You can create rules to explicitly allow or drop traffic based on various parameters. The main firewall secures traffic between your internal network segments (e.g., untrusted to private). To create a firewall rule: Navigate to Firewall: Go to Services > Firewall. Add a Rule: Click the + Add button. Configure Rule: Name: Give the rule a descriptive name. Action: Choose Drop or Allow. Source/Destination: Specify the source and destination, including IP, Protocol, Port, and Segment. You can use Any for broad rules. Description: Add details about the rule's purpose. Priority: Assign a priority (lower numbers are processed first). Save: Click Add to save and activate the rule. The DIA Firewall is specifically designed to protect your Dedicated Internet Access connections from external threats. To create a DIA firewall rule: Navigate to DIA Firewall: Go to Services > Firewall and select the DIA Firewall tab. Add a Rule: Click + Add. Configure Rule: Direction: Choose Incoming or Outgoing. Source/Destination: Define the source and destination IPs. For an inbound rule blocking all public IPs, you could set the source to 0.0.0.0/0. DIA IP Connections: Select the specific DIA connection this rule applies to. Protocol & Port: Specify the protocol (TCP/UDP) and port number (e.g., 22 for SSH). Action: Choose Block, Allow, or Web Filtering. Save: Click the action button to save the rule. Web Filtering Web Filtering enhances security by allowing you to block access to websites based on categories and specific threats. This feature can be enabled as an action in your firewall rules. Content Filtering: Block categories like Adult, Social Network, or Entertainment. Web Threats Filtering: Protect against Phishing URLs, Spam, Malicious Websites, and Hacking/C2C domains. Custom URL Filtering: Create custom allow/deny lists using specific URLs or wildcard patterns. To use Web Filtering, simply select it as the Action when creating a firewall rule. Network Address Translation (NAT) NAT allows you to translate private IP addresses to public IPs, enabling devices on your private network to access the internet. To create a NAT rule: Navigate to NAT: Go to Services > NAT. Add a Rule: Click + Add. Configure Rule: Name: Assign a name to the rule. Type: Specify the NAT type (e.g., Source NAT). Inside & Outside: Define the internal source and the external interface or IP address for the translation. Description: Briefly describe the rule's function. Save: Click Add to create the rule. # Order Log Source: https://docs.zayo.com/docs/build-your-network/order-log Learn how to use the Order Log to track all provisioning activities, configuration changes, and service requests across your network. ## Overview The **Order Log** provides a comprehensive and detailed audit trail of every action performed within your NaaS portal account. It serves as a centralized place to monitor the status of pending requests, review historical changes, and verify all provisioning activities. Whether you've ordered a new port, deleted a connection, or enabled a new service, the Order Log captures it all. ## How to Access the Order Log You can access the Order Log directly from the main navigation menu. 1. **Navigate to Order Log:** In the left-side menu, under the **Build Your Network** section, click on **Order Log**. 2. **View Activities:** The log will display a chronological list of all actions performed. ## Understanding the Order Log Table The Order Log is presented in a clear table format, providing key details for each event. ### Columns in the Log * **Timestamp:** The exact date and time the action was performed. * **Activity:** The type of action taken, such as `Create`, `Delete`, or `Enable`. * **Item:** The type of resource that was affected, for example: * Port * Connection * Public IPs * Service/Package * **Name:** The specific name of the resource that was changed (e.g., `Evoque WDC1 port_1` or `Network Observability`). ### Filtering the Log To help you find specific information quickly, the Order Log includes powerful filtering capabilities. You can filter the entire log by a specific category, such as **Ports**, **Links**, **Cloud**, **Public IPs**, or **Services**, to narrow down the results and focus only on the events that are relevant to your search. # Guide: Managing Public IPs & DIA Connections Source: https://docs.zayo.com/docs/build-your-network/public-ips A step-by-step guide on how to order public IPs and use them to create and manage Dedicated Internet Access (DIA) connections. ## Overview 🌐 Public IP addresses are essential for making your services accessible from the internet. The DynamicLink portal provides a streamlined process to request and manage blocks of **IPv4** or **IPv6** addresses. Once a public IP block is assigned to your account, you can use it to provision powerful services like **Dedicated Internet Access (DIA)**, including advanced connections that use **BGP** for routing. This guide will walk you through ordering IPs and configuring both standard and BGP-enabled DIA connections. *** ## How to Order Public IPs Your existing IP pool, already assigned to your network, is displayed on the Public IPs page. Follow these steps to request a new block. 1. **Navigate to Public IPs**: From the main portal menu, go to **Build Your Network > Public IPs**. 2. **Request IPs**: Click the **+ Request IP** button to open the request form. 3. **Configure Your Request**: * **Name**: Give your request a descriptive name for easy identification (e.g., `WebApp-DIA-IPs-London`). * **Location**: Select the metro location where the IP addresses will be used. * **Pool Size**: Choose the size of the IP block you need from the dropdown menu (e.g., `/29` for 5 usable IPs, `/28` for 13 usable IPs). 4. **Submit Request**: Click **Request**. Your request will be provisioned and the new IP block will be added to your pool. *** ## How to Create a Standard DIA Connection A standard DIA connection provides dedicated, reliable internet service with symmetrical (equal upload/download) bandwidth. ### Step 1: Verify Prerequisites * **Public IP**: Ensure you have an available Public IP block in the desired location by checking the **Public IPs** tab. * **Port Bandwidth**: Go to the **Ports** tab and confirm the port in that same location has enough available bandwidth for the new connection. ### Step 2: Create the Connection 1. **Start Connection**: Navigate to the **Ports** tab, find the desired port, and click **Add a Connection**. The A-side (your port) will be auto-populated. 2. **Configure A-Side**: Set up the **VLAN** and select the **bandwidth speed** for the connection. 3. **Configure Z-Side (Internet)**: * In the Z-side destination search box, select the **Internet** link. * Under **DIA Name**, a dropdown will appear. Pick the **Public IP block** you want to use for this connection. 4. **Finalize**: Confirm the bandwidth and other details, then click **Add** to activate the DIA connection. *** ## How to Create a BGP DIA Connection A BGP DIA connection offers advanced routing capabilities, allowing you to announce your own IP addresses (**BYOIP**) or set up multi-homed connections for enhanced resilience. ### Step 1: Set Up Your ASN * Navigate to **Build Your Network > Public IPs**. * If you are bringing your own IP space, find the **ASN** section and click **+ Set up new**. * Enter your **Autonomous System Number** and save it. ### Step 2: Create the BGP Connection 1. **Request IP (If Needed)**: If you are not using your own IPs, request a new block by following the steps in the first section. 2. **Create the Connection**: Follow the same initial steps as a standard DIA connection (select port, configure A-side). 3. **Configure BGP**: In the Z-side (Internet) configuration, you will see a toggle or checkbox to **Use BGP**. * Enable this option. * Choose the **ASN** you configured in the previous step. 4. **Finalize**: Complete the connection setup. After activation, you will need to configure your BGP peering details on your edge device. *** ## How to Modify DIA Connection Speed You can easily adjust the bandwidth of an existing DIA connection. 1. **Access Connection Settings**: Locate your DIA connection in your connection list and click the **Edit icon** (pencil). 2. **Verify Port Bandwidth**: Before increasing speed, ensure the underlying physical port has enough available capacity to support the change. 3. **Edit Bandwidth**: In the connection settings, change the **bandwidth** to your desired new speed (e.g., from 50 Mbps to 100 Mbps). 4. **Save Changes**: Click **Edit** to apply the new speed. The change is typically provisioned within minutes. # Creating a Layer 2 DC-to-DC Connection Source: https://docs.zayo.com/docs/build-your-network/virtual-circuit A step-by-step guide to establishing a Layer 2 data center-to-data center connection on the DynamicLink platform. **What You'll Accomplish** This guide will walk you through the process of provisioning a private, point-to-point Layer 2 circuit between two data center ports on the DynamicLink NaaS platform. To create a Layer 2 data center-to-data center (DC-to-DC) connection in DynamicLink, follow these steps: Start by logging into the DynamicLink portal. From the main dashboard, click on the **Build Your Network** tab, and then select **Ports** from the sub-menu. Navigate to Ports Before creating the connection, it's crucial to verify that both the A-side and Z-side ports have enough capacity. Review the `Available Bandwidth` for each port to ensure there is sufficient bandwidth for your new circuit. 1. Locate the first port for your connection and click the **Add a Connection** button next to it. 2. The port name will be automatically populated. 3. Choose an available VLAN from the dropdown menu. 4. Specify the desired bandwidth for the connection (e.g., `1 Gbps`). Configure A-Side Port 1. In the Z-port section, select the second data center port you wish to connect to. 2. Choose an available VLAN from the dropdown menu. Ensure this VLAN has not been used previously on this port. 3. The bandwidth will automatically match the value you selected for the A-side port. 1. Provide a meaningful and easily identifiable name for your new connection in the `Connection Name` field. 2. Review all the details to ensure they are correct. 3. Click the **Add** button at the bottom of the page to finalize the setup and create the connection. Your new Layer 2 connection will now be provisioned and will appear in your list of active connections. # Cloud Links Overview Source: https://docs.zayo.com/docs/cloud-links Cloud Links provide private, high-performance connectivity between your physical ports and a public cloud provider. Use them to: * Establish private, low-latency paths between your network and a public cloud (AWS, Azure, GCP). * Build a resilient, scalable foundation for hybrid and multi-cloud architectures. * Bypass the internet to provide enhanced security, reliability, and performance. Cloud Links come through your provisioned ports and leverage the Zayo DynamicLink fabric for reliability, performance, and security. ## Core concepts * **A-side / Z-side**: A connection links two sides. The A-side is your initiating port; the Z-side is the destination. * **Bandwidth**: You allocate bandwidth for the connection. Ensure both ends have sufficient available capacity. * **VLANs**: VLANs segment traffic on a port. Each connection uses selected VLANs to isolate and identify the connection. * **Status lifecycle**: **Ordering**, **Pending**/**Provisioning** and **Available**/**Active**. Status is visible in the portal and (for clouds) within the provider console. * **BGP**: For cloud connections, BGP enables dynamic route exchange once the NNI is established. ## Design guidance * **Redundancy**: Build dual links on separate ports/locations for high availability * **Capacity planning**: Size bandwidth to peak traffic; monitor and adjust as needs evolve * **Segmentation**: Use distinct VLANs per environment or application to simplify operations * **Observability**: Enable monitoring to track utilization, latency, and loss end-to-end ## Connection types ### Port-to-cloud connectivity Connect directly to public cloud providers via Network-to-Network Interface (NNI): * **AWS Direct Connect**: Create the connection in DynamicLink portal, then approve it in the AWS console. * **GCP Cloud Interconnect**: Start in the Google Cloud Console to create the interconnect and obtain a pairing key. You will use this key to create the connection in DynamicLink. * **Azure ExpressRoute**: Create the circuit in Azure to obtain a service key. You will use this key to create the connection in DynamicLink. #### Bandwidth options AWS, Azure, and Google Cloud allow the following bandwidths: * **50 Mbps**: Suitable for small workloads and testing * **100 Mbps**: Good for development environments * **200 Mbps**: Appropriate for small production workloads * **300 Mbps**: Medium-sized applications * **400 Mbps**: Larger applications with moderate traffic * **500 Mbps**: High-traffic applications * **1 Gbps**: Enterprise applications * **2 Gbps**: Large enterprise workloads * **5 Gbps**: High-bandwidth applications * **10 Gbps**: Maximum hosted connection bandwidth ### Cloud-to-cloud connectivity You can create a Layer 2 virtual circuit between two cloud locations or two different cloud providers. This is useful if you need Layer 2 connectivity rather than [Layer 3 connectivity](l2-l3) (such as with Cloud Routers). Multi-cloud network fabrics allow AWS, Azure, and GCP resources to communicate as if on the same Layer-2 domain. This unified approach enables true workload portability across providers, removing the need for repeated reconfiguration. # Cloud Link to AWS Direct Connect Source: https://docs.zayo.com/docs/cloud-links-aws AWS Hosted Direct Connect gives you a private, dedicated network connection between your on-premises infrastructure and AWS, allowing you to bypass the public internet entirely. With DynamicLink, you create the connection in the DynamicLink portal and then accept it in the AWS console. This guide covers creating a **Cloud Link** to AWS, which is a direct port-to-cloud connection. If you need to connect multiple clouds or sites together through a shared routing domain, see [Cloud Router to AWS](cloud-router-aws) instead. ## Before you begin Make sure you have the following ready before you start: You need an existing port in DynamicLink to serve as the "A" side (your side) of the connection. If you don't have a port yet, see [Ports](ports) to get one set up. Your port must have enough unused bandwidth to support the cloud link you want to create — for example, if your port is 1 Gbps and you already have 800 Mbps in use, you can allocate up to 200 Mbps to this connection. You need an AWS account with permissions to work with Direct Connect. At minimum, your AWS IAM user or role needs the `directconnect:*` permissions (or the **AWSDirectConnectFullAccess** managed policy). If you're unsure whether you have the right permissions, check with your AWS administrator. See [Identity-based policy examples for Direct Connect](https://docs.aws.amazon.com/directconnect/latest/UserGuide/security_iam_id-based-policy-examples.html). This is the 12-digit number that identifies your AWS account. You can find it by clicking your account name in the upper-right corner of the AWS console. It's displayed in the dropdown menu and looks like `123456789012`. ## Step 1: Create the connection in DynamicLink In this step, you'll configure both sides of the connection: the "A" side (your DynamicLink port) and the "Z" side (the AWS cloud endpoint). 1. In the DynamicLink portal, navigate to **Build Your Network**. 2. Click **Add a Connection** in the upper right, or click **Add connection** next to the specific port you want to use. Screenshot ### Configure the "A" port (your side) The "A" port is the DynamicLink side of the connection. This is your physical port. Select **Customer Port** as the connection type and complete the following fields: | Field | What to enter | | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Port** | Select the port you want to use as the starting point for this connection. If you only have one port, it will be pre-selected. | | **VLAN** | Enter a VLAN ID (a number between 2 and 4094).
VLANs let you run multiple connections over a single physical port by tagging each one with a unique ID.
If this is your first connection on this port, you can use any number (e.g., `100`). If you already have connections, choose a number that isn't already in use. | | **BW** | Select how much bandwidth to allocate to this connection. This must not exceed the available bandwidth on your port. If you're unsure, start with a smaller allocation. You can adjust this later. | ### Configure the "Z" port (AWS side) The "Z" port is the cloud side of the connection. This is where AWS Direct Connect will terminate. #### On-ramp selection When you configure your Z port, you'll need to select an on-ramp (region and site). A “cloud on-ramp” is a colocation facility that houses edge devices from a cloud provider. In this case, it's a data center in which Zayo has already established a direct physical connection to AWS. When you select your region and on-ramp, consider where you are and where you want to go. For example, if you are located in Chicago (`us-east-2`) and you want to access an AWS-hosted resource in Seattle (`us-west-2`). **Option 1: Select an on-ramp location closest to where you are (`us-east-2`)** * Short access link, long WAN link * Traffic travels over the **AWS backbone** * You pay AWS for that backbone transit **Option 2: Select an on-ramp closest to your destination (`us-west-2`)** * Long WAN link via the DynamicLink backbone, then short hop into the site where you're accessing your data * You use DynamicLink's network instead of AWS's backbone for the long haul #### Configure the Z port Select **Cloud Connection**, then select **AWS**. Complete the following fields: | Field | What to enter | | ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | **Region** | The AWS region either closest to you or where your cloud resources live (see [On-ramp selection](#on-ramp-selection) above for more details). | | **Site Name** | After you select a region, a list of available on-ramps appears. | | **BW** | The bandwidth for the AWS side of the connection. This should be pre-filled with the bandwidth you selected when configuring the A side. | | **AWS Customer ID** | Your 12-digit AWS account ID (see [Before you begin](#before-you-begin) above for where to find this). | | **Connection name** | A name for your connection in the DynamicLink portal.
In the AWS console, the connection name will have a unique ID and a name using the following pattern: `__` | Click **Add** to submit the connection request. Click the **Cloud Links** tab on the right to see your connection: Screenshot After you click **Add**, DynamicLink submits the connection request to AWS. The connection will appear on the **Cloud Links** page with an **Ordering** status. This is normal and it means AWS is processing the request. You may need to wait a few minutes before the connection is ready to accept from the AWS side. ## Step 2: Accept the connection in the AWS console Once DynamicLink submits the connection, it appears in your AWS account as a pending hosted connection. You need to accept it before it becomes active. You can navigate to the connection in two ways: ### Click the connection ID in DynamicLink From **DynamicLink > Build Your Network**, select **Cloud Links** on the left. Find your connection and click the ID. This will open your AWS console Direct Connect page in a new tab. Screenshot Click **Accept** in the upper right: Screenshot of the Accept action ### Find the connection in the AWS console You can also find your connection by navigating to it in AWS. Log in to the [AWS Management Console](https://console.aws.amazon.com/) and then use the search field to find the AWS Direct Connect page. AWS screenshot If you don't see the connection, make sure you're looking in the correct AWS region. The region selector is in the upper-right corner of the AWS console. Switch to the region you selected when creating the connection in DynamicLink. Once you have located the connection, click **Accept** in the upper right: Screenshot of the Accept action After acceptance, the connection status will progress through several states: | Status | What it means | | ------------- | --------------------------------------------------------------------------- | | **Ordering** | The connection request has been submitted and is being processed. | | **Pending** | AWS has received the request and is setting up the connection on their end. | | **Available** | The connection is active and ready for you to create virtual interfaces. | The transition from **Pending** to **Available** usually takes a few minutes. ## Step 3: Verify the connection in DynamicLink After you accept the connection in AWS, return to DynamicLink to confirm everything is in sync. 1. Navigate to **Cloud Links** in the DynamicLink portal. 2. Locate your connection and check that the status has changed from **Ordering** to **Available** (or **Active**). If the status hasn't updated yet, wait a few minutes and refresh the page. The status update depends on AWS completing their side of the provisioning. ## Step 4: Create a virtual interface (VIF) in AWS Your Direct Connect connection is now active, but it can't carry traffic yet. You need to create at least one **virtual interface (VIF)** to define how traffic flows between your network and AWS. Think of the Direct Connect connection as a physical road and the VIF as the lane markings that direct traffic to the right destination. ### Choose the right VIF type | VIF type | Use it when you need to... | Example | | --------------- | ------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------- | | **Private VIF** | Connect to resources inside a specific VPC (Virtual Private Cloud), such as EC2 instances, RDS databases, or internal load balancers. | You have a production VPC in `us-east-1` and want to access your servers over a private connection instead of the internet. | | **Public VIF** | Access AWS public services (like S3, DynamoDB, or public API endpoints) over your Direct Connect link instead of the internet. | You want to transfer large files to S3 at high speed without going over the public internet. | | **Transit VIF** | Connect to an AWS Transit Gateway (TGW), which lets you reach multiple VPCs and on-premises networks through a single connection. | You have several VPCs across multiple accounts and want to reach all of them through one Direct Connect connection. | If you're not sure which type to use: most users start with a **Private VIF** to connect to a single VPC. You can always add more VIFs later. ### Create the VIF in AWS 1. In the AWS Direct Connect console, click **Virtual Interfaces** in the left sidebar. 2. Click **Create virtual interface**. 3. Select the type of VIF you need and fill in the required fields (such as the VLAN ID, BGP ASN, and the VPC or gateway you want to connect to). For detailed instructions on each VIF type, see the AWS documentation: [Create a virtual interface](https://docs.aws.amazon.com/directconnect/latest/UserGuide/create-vif.html). You can create multiple VIFs on a single Direct Connect connection. For example, you might have a Private VIF for your production VPC and a Public VIF for accessing S3 — both running over the same connection. ## Troubleshooting ### Connection stuck in "Ordering" status If your connection stays in **Ordering** status for more than 10 minutes: * Verify that the AWS account ID you entered in DynamicLink is correct (a common mistake is transposing digits). * Make sure you're checking the correct AWS region in the AWS console. * If the issue persists, contact [Zayo support](https://www.zayo.com/support/). ### Connection not visible in AWS console * Double-check that you're in the correct AWS region. The region selector is in the upper-right corner of the AWS console. * Verify that you're logged into the AWS account that matches the account ID you provided in DynamicLink. * Ensure your IAM user/role has permissions for AWS Direct Connect. ### Connection shows "Down" after acceptance * The connection may still be provisioning on the AWS side. Wait 5–10 minutes and check again. * If it remains down, verify that the DynamicLink port is active and that the VLAN configuration is correct. ### VIF won't come up * Confirm that the Direct Connect connection itself shows **Available** before creating a VIF. * For Private VIFs, verify that the Virtual Private Gateway is attached to your VPC. * For Transit VIFs, verify that the Transit Gateway is in the same region as your Direct Connect connection. * Check that your BGP settings (ASN, authentication) match on both sides. # Cloud Link to Azure ExpressRoute Source: https://docs.zayo.com/docs/cloud-links-azure Azure ExpressRoute lets you create private connections between your on-premises infrastructure and Microsoft Azure services. ## Prerequisites Before creating an Azure ExpressRoute connection, ensure you have: * An active Azure subscription with appropriate permissions. * A DynamicLink port with available bandwidth. ## Step 1: Create an ExpressRoute circuit in Azure First, you need to create an ExpressRoute circuit in the Azure portal. This is required to obtain a service key, which you will then use to provision your connection in DynamicLink. Log in to the [Azure portal](https://portal.azure.com) and use the search bar at the top to find the **ExpressRoute circuits** page. Click **Create** and then complete the following fields: **Configuration** | Field | Description | | -------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Subscription** | Your [subscription](https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/azure-subscription-service-limits) is created at the account level and determines how you are billed. | | **Resource group** | A resource group acts like a folder that organizes related resources. You can use it to perform actions on multiple resources at once—for example, applying permissions, duplicating configurations, or deleting the entire group.

Each resource can belong to only one resource group, and each resource group is associated with a single subscription. | | **Resiliency** | Select your resiliency type. For more information, see [Design and architect Azure ExpressRoute for resiliency](https://learn.microsoft.com/en-us/azure/expressroute/design-architecture-for-resiliency). | | **Region** | Select the Azure region that you want to use. This region represents the availability zone or data center in which a resource is located.

This region does not need to match your Zayo peering location. For example, you may want to choose the same region as other resources within your selected resource group. | | **Circuit name** | Enter a name for the circuit. | | **Port type** | Select **Provider**. | | **Peering location** | Choose from the available on-ramp locations provided by Zayo. | | **Provider** | Select **Zayo DynamicLink**. | | **Bandwidth** | Select your desired capacity. | | **SKU** | Choose the appropriate [service tier](https://azure.microsoft.com/en-us/pricing/details/expressroute/). | | **Billing model** | Select the correct billing option.

• **Metered:** Usage-based billing.
• **Unlimited:** Fixed monthly rate. | The SKU and billing model apply only to Microsoft’s billing structure. Zayo billing is separate. **Monitoring** Here you can enable monitoring rules to receive alerts when certain events occur, such as a drop in BGP availability or high bandwidth utilization. For more information, see [Monitor Azure ExpressRoute](https://learn.microsoft.com/en-us/azure/expressroute/monitor-expressroute). **Tags** Here you can add tags as name/value pairs. These can help you organize and sort resources across groups. For more information, see [Use tags to organize your Azure resources and management hierarchy](https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/tag-resources). **Review + create** Confirm your selections and then click **Create**. It may take a few moments for your ExpressRoute resource to deploy. When it's complete, click **Go to resource**. Screenshot From your resource list, select the ExpressRoute circuit you just created. From here, you find and copy the **Service key**: Screenshot ## Step 2: Create the connection in DynamicLink Once you have your ExpressRoute service key from Azure, return to the DynamicLink portal. Navigate to **Build Your Network > Ports**. Click **Add a Connection** in the upper right or click **Add connection** next to the port you are using. Complete the following fields: **"A" Port** Select **Customer Port** and then complete the following fields: | Field | Description | | -------- | ------------------------------------------------------------------------------- | | **Port** | Select your source port. | | **VLAN** | Enter an available VLAN. | | **BW** | You can leave this blank. It will pre-populate when you enter your service key. | **"Z" Port** Select **Cloud Connection** and then select **Azure**. Complete the following fields: | Field | Description | | -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Service Key** | Enter the service key you copied from the Azure portal. | | **BW** | This is automatically populated with the bandwidth you selected when creating your ExpressRoute circuit. | | **Peering Location** | This is automatically populated with the peering location you selected when creating your ExpressRoute circuit. | | **Connection Type** | Select the [peering type](https://learn.microsoft.com/en-us/azure/expressroute/expressroute-circuit-peerings) you want to use:

• **Azure Private Peering:** For private virtual networks and Azure services.
• **Microsoft Peering:** For accessing Microsoft services like Office 365 and Dynamics 365. | | **VLAN** | Enter a VLAN that is unique to this circuit. You will use this when configuring peering in the Azure portal. | You can configure both peering types if your use case requires access to both private Azure resources and Microsoft services. Enter a connection name and then click **Add**. ## Step 3: Create a secondary connection (optional) You can re-use your service key to create a secondary circuit connection. This is optional, but recommended. ## Step 4: Set up peering Return to the Azure portal and open your ExpressRoute circuit. From here you can finish setting up peering. See [Create and modify peering for an ExpressRoute circuit using the Azure portal](https://docs.azure.cn/en-us/expressroute/expressroute-howto-routing-portal-resource-manager). # Cloud Link to Google Cloud Interconnect Source: https://docs.zayo.com/docs/cloud-links-gcp Google Cloud Interconnect enables you to create private connections between your on-premises infrastructure and Google Cloud Platform services. ## Prerequisites Before creating a Google Cloud Interconnect connection, ensure you have: * An active Google Cloud account with appropriate permissions. * [Compute Engine API](https://console.cloud.google.com/marketplace/product/google/compute.googleapis.com) enabled for your Google Cloud project. * A VPC in your Google Cloud environment. For more information, see [Google Cloud - Create and manage VPC networks](https://cloud.google.com/vpc/docs/create-modify-vpc-networks). * A DynamicLink port with available bandwidth. ## Step 1: Create a partner interconnect VLAN attachment in Google Cloud In the search field at the top of Google Cloud Console home page, enter "Interconnect" and select the product page. Go to the **Interconnect** page and click **Create VLAN attachments**. There are two types of partner interconnect VLAN attachments: * **Encrypted**: HA VPN over your connection. See [HA VPN over Cloud Interconnect overview](https://cloud.google.com/network-connectivity/docs/interconnect/concepts/ha-vpn-interconnect). Note that while this is supported on the Zayo NaaS platform, you will need to deploy and configure IPsec on-prem. * **Unencrypted**: Unencrypted connections are still private and secure, but do not use VPN tunneling and do not require IPsec. For instructions on provisioning a VLAN attachment, see [Create VLAN attachments](https://cloud.google.com/network-connectivity/docs/interconnect/how-to/partner/creating-vlan-attachments). When creating your VLAN attachment, note the following: | Field | Comments | | ----------------- | -------------------------------------------------------------------- | | **MTU** | Support for up to 9000 MTU | | **IP stack type** | Select **IPv4 (single-stack)** (we do not support IPv6 at this time) | After you provision your interconnect, you will be provided a pairing key for each VLAN attachment. Copy this key as you will need to provide it when setting up the connection in DynamicLink. screenshot ## Step 2: Create the connection in DynamicLink Once you have your pairing key from Google Cloud, return to the DynamicLink portal. Navigate to **Build Your Network > Ports**. Click **Add a Connection** in the upper right or click **Add connection** next to the port you are using. Complete the following fields: **"A" Port** Select **Customer Port** and then complete the following fields: | Field | Description | | -------- | ---------------------------------------------------------------- | | **Port** | Select your source port. | | **VLAN** | Enter an available VLAN. | | **BW** | Select the bandwidth you'd like to allocate for this connection. | **"Z" Port** Select **Cloud Connection** and then select **Google**. Complete the following fields: | Field | Description | | ----------------------------------------------- | ---------------------------------------------------------------------------------------------------- | | **Pairing key 1**      
**Pairing key 2** | Enter the pairing keys you copied from Google Cloud console after creating your VLAN attachment. | | **Region** | This is automatically populated with the region you selected while provisioning the VLAN attachment. | | **BW** | Select the same bandwidth you selected for your source port above. | Enter a connection name and then click **Add**. ## Activate the connection Return to the Google Cloud Console and activate the connection. See [Activating connections](https://cloud.google.com/network-connectivity/docs/interconnect/how-to/partner/activating-connections). # Cloud Router Overview Source: https://docs.zayo.com/docs/cloud-router The Cloud Router is the virtual routing and switching core of your DynamicLink NaaS platform. It intelligently directs traffic between all your connected resources, including data center ports, cloud links, and internet connections, providing a centralized hub for managing complex network topologies. You can use the Cloud Router to build your own network between data centers, cloud service providers, and DIA connections. Diagram ## How the Cloud Router works The Cloud Router operates as a virtualized routing engine that: 1. Learns network topology from all connected resources and routing protocols. 2. Maintains routing tables with both static and dynamic routes. 3. Makes forwarding decisions based on destination IP addresses and routing policies. 4. Manages BGP sessions with external networks and cloud providers. 5. Implements security policies through integrated firewall and filtering capabilities. # Cloud Router ARP Table Source: https://docs.zayo.com/docs/cloud-router-arp The Address Resolution Protocol (ARP) table on the Cloud Router maps Layer 3 IP addresses to Layer 2 [MAC addresses](cloud-router-arp). Every device that communicates through the Cloud Router must have a corresponding ARP entry so that the router can encapsulate IP packets into the correct Ethernet frames and forward them to the right physical or virtual interface. Use the ARP table to verify that adjacent devices (BGP neighbors, cloud gateways, data center routers) are reachable at Layer 2 before troubleshooting higher-layer issues. ## View the ARP table You can view the ARP table from **Network > Cloud Router > ARPs**. The tab title shows the total number of active ARP entries. Each row in the table represents a resolved mapping between an IP address and a MAC address on a specific Cloud Router interface. | Column | Description | | --------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **IP Address** | The IPv4 address of the remote device (e.g., `192.168.49.5`). | | **MAC Address** | The corresponding MAC address (e.g., `2c:6b:f5:ab:fb:df`). | | **Virtual Interface** | The Cloud Router interface on which the entry was learned (e.g., the name of your port connection, cloud link, or DIA). | | **Age** | How long ago (in seconds) the entry was last refreshed. A high or increasing age may indicate that the remote device is no longer reachable. | | **Type** | Whether the entry is **Dynamic** (learned automatically through ARP requests and replies) or **Static** (manually configured or set by the platform, for example for Type-5 routes in the underlay). | ## Dynamic vs. static entries * **Dynamic entries** are created automatically when the Cloud Router sends an ARP request and receives a reply from a neighboring device. \ \ These entries age out if the neighbor stops responding, and are refreshed periodically while traffic flows. * **Static entries** are [configured manually](/docs/cloud-router-routes). Static entries do not age out and persist until they are removed. ## When to use the ARP table #### Verify Layer 2 reachability If you cannot reach a next-hop gateway, cloud gateway, or BGP peer, check whether an ARP entry exists for that IP address. A missing entry indicates a Layer 2 problem — verify physical connectivity, VLAN tagging, and interface configuration before investigating routing or BGP. #### Confirm device connectivity After provisioning a new Cloud Router connection, check the ARP table to confirm that the remote device has been learned on the expected virtual interface. A valid ARP entry confirms that the link is up and Layer 2 frames are being exchanged. #### Troubleshoot BGP peering failures A valid ARP entry for a BGP neighbor's IP address is a definitive confirmation that Layer 2 connectivity is working. If BGP will not establish but the ARP entry exists, the issue is almost certainly a Layer 3 BGP configuration problem — for example, an incorrect ASN, a mismatched MD5 password, or a route filter policy. This lets you skip physical and VLAN debugging and focus on [BGP configuration](cloud-router-bgp) directly. #### Identify stale or missing entries If the **Age** value for an entry is unusually high, the remote device may have become unreachable. If an expected entry is missing entirely, there is likely a Layer 2 issue between the Cloud Router and the neighbor — check the physical link, VLAN assignment, and interface status. # Cloud Router connection to AWS Direct Connect Source: https://docs.zayo.com/docs/cloud-router-aws When attached to a Cloud Router, your AWS Hosted Direct Connect can be share a routing domain with other cloud links and virtual circuits. ## Prerequisites Before you begin, ensure you have: * An active AWS account with permissions to accept Direct Connect connections * A DynamicLink port with available bandwidth * Your AWS account ID (12‑digit number) ## Step 1: Create the Cloud Router connection in DynamicLink Navigate to **Build Your Network > Ports** in the DynamicLink portal. Under **Connections**, click the **Cloud Router** vertical tab. Select **Cloud Connection** and then AWS: Screenshot Complete the following fields: | Field | Description | | --------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Connection Type** | At this time, we only support Direct Connect connections. | | **Region** | AWS region of your VPC (e.g., `us-east-1`). | | **Site Name** | An available site for the chosen region. | | **BW** | Desired bandwidth for the Direct Connect link. | | **AWS Customer ID** | Your AWS account ID (12 digits). | | **Cloud Router IP Address** | The IP address that the Cloud Router will use for BGP peering with AWS. This is typically the customer-side IP address in a `/30` subnet. When creating your Virtual Interface in AWS, you'll specify both the AWS-side and customer-side IP addresses for the BGP session. | Enter a name for the connection and then click **Add**. ## Step 2: Accept the connection in AWS 1. Log in to the AWS Management Console and open **AWS Direct Connect**. 2. Locate the new connection (it will reference your DynamicLink account/username). 3. Select the connection and click **Accept**. Screenshot of the Accept action After acceptance, statuses typically progress from **Ordering** to **Pending** and then to **Available** once AWS completes provisioning (usually a few minutes). ## Step 3: Create AWS virtual interfaces (VIFs) After the physical connection is available, create one or more VIFs to carry traffic: * Private VIF for VPC connectivity * Public VIF for AWS public services * Transit VIF for AWS Transit Gateway (TGW) Refer to AWS docs: [AWS Direct Connect virtual interfaces](https://docs.aws.amazon.com/directconnect/latest/UserGuide/create-vif.html). ## Step 4: Verify in DynamicLink Return to the Cloud Routers page and verify your connection appears as **Available**. ## Next steps (routing) Next, you will need to set up BGP and configure your Cloud Router ASN and peerings. # Cloud Router connection to Azure ExpressRoute Source: https://docs.zayo.com/docs/cloud-router-azure When attached to a Cloud Router, your Azure ExpressRoute can share a routing domain with other cloud links and virtual circuits. ## Prerequisites Before you begin, ensure you have: * An active Azure subscription with appropriate permissions * A DynamicLink port with available bandwidth ## Step 1: Create an ExpressRoute circuit in Azure First, you need to create an ExpressRoute circuit in the Azure portal. This is required to obtain a service key, which you will then use to provision your connection in DynamicLink. Log in to the [Azure portal](https://portal.azure.com) and use the search bar at the top to find the **ExpressRoute circuits** page. Click **Create** and then complete the following fields: **Configuration** | Field | Description | | -------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Subscription** | Your [subscription](https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/azure-subscription-service-limits) is created at the account level and determines how you are billed. | | **Resource group** | A resource group acts like a folder that organizes related resources. You can use it to perform actions on multiple resources at once—for example, applying permissions, duplicating configurations, or deleting the entire group.

Each resource can belong to only one resource group, and each resource group is associated with a single subscription. | | **Resiliency** | Select your resiliency type. For more information, see [Design and architect Azure ExpressRoute for resiliency](https://learn.microsoft.com/en-us/azure/expressroute/design-architecture-for-resiliency). | | **Region** | Select the Azure region that you want to use. This region represents the availability zone or data center in which a resource is located.

This region does not need to match your Zayo peering location. For example, you may want to choose the same region as other resources within your selected resource group. | | **Circuit name** | Enter a name for the circuit. | | **Port type** | Select **Provider**. | | **Peering location** | Choose from the available on-ramp locations provided by Zayo. | | **Provider** | Select **Zayo DynamicLink**. | | **Bandwidth** | Select your desired capacity. | | **SKU** | Choose the appropriate [service tier](https://azure.microsoft.com/en-us/pricing/details/expressroute/). | | **Billing model** | Select the correct billing option.

• **Metered:** Usage-based billing.
• **Unlimited:** Fixed monthly rate. | The SKU and billing model apply only to Microsoft's billing structure. Zayo billing is separate. **Monitoring** Here you can enable monitoring rules to receive alerts when certain events occur, such as a drop in BGP availability or high bandwidth utilization. For more information, see [Monitor Azure ExpressRoute](https://learn.microsoft.com/en-us/azure/expressroute/monitor-expressroute). **Tags** Here you can add tags as name/value pairs. These can help you organize and sort resources across groups. For more information, see [Use tags to organize your Azure resources and management hierarchy](https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/tag-resources). **Review + create** Confirm your selections and then click **Create**. It may take a few moments for your ExpressRoute resource to deploy. When it's complete, click **Go to resource**. Screenshot From your resource list, select the ExpressRoute circuit you just created. From here, you find and copy the **Service key**: Screenshot ## Step 2: Create the Cloud Router connection in DynamicLink Once you have your ExpressRoute service key from Azure, return to the DynamicLink portal. Navigate to **Build Your Network > Ports** in the DynamicLink portal. Under **Connections**, click the **Cloud Router** vertical tab. Select **Cloud Connection** and then Azure: Screenshot Complete the following fields: | Field | Description | | --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Connection Type** | At this time, we only support ExpressRoute connections. | | **Service Key** | Enter the service key you copied from the Azure portal. | | **BW** | This is automatically populated with the bandwidth you selected when creating your ExpressRoute circuit. | | **Peering Location** | This is automatically populated with the peering location you selected when creating your ExpressRoute circuit. | | **Connection Type** | Select the [peering type](https://learn.microsoft.com/en-us/azure/expressroute/expressroute-circuit-peerings) you want to use:

• **Azure Private Peering:** For private virtual networks and Azure services.
• **Microsoft Peering:** For accessing Microsoft services like Office 365 and Dynamics 365. | | **VLAN** | Enter a VLAN that is unique to this circuit. You will use this when configuring peering in the Azure portal. | | **Cloud Router IP Address** | The IP address that the Cloud Router will use for BGP peering with Azure. This is typically the customer-side IP address in a `/30` subnet. When creating your ExpressRoute peering, you'll specify both the Azure-side and customer-side IP addresses for the BGP session. | You can configure both peering types if your use case requires access to both private Azure resources and Microsoft services. Enter a name for the connection and then click **Add**. ## Step 3: Set up peering in Azure Return to the Azure portal and open your ExpressRoute circuit. From here you can finish setting up peering. See [Create and modify peering for an ExpressRoute circuit using the Azure portal](https://docs.azure.cn/en-us/expressroute/expressroute-howto-routing-portal-resource-manager). After setting up peering, statuses typically progress from **Not Provisioned** to **Provisioned** once Azure completes provisioning (usually a few minutes). ## Step 4: Verify in DynamicLink Return to the Cloud Routers page and verify your connection appears as **Available**. ## Next steps (routing) Next, you will need to set up BGP and configure your Cloud Router ASN and peerings. # Configure BGP for a Cloud Router Source: https://docs.zayo.com/docs/cloud-router-bgp Border Gateway Protocol (BGP) lets your Cloud Router learn and advertise routes dynamically to external networks such as data centers, DIA edges, and cloud provider gateways. Use BGP when you need scalable, policy-driven routing instead of manually maintaining static routes. Use Cloud Router BGP routing when: * You connect to **cloud gateways** (AWS, Azure, GCP) and want prefixes to be exchanged automatically. * You connect to **data center routers or on‑premises WANs** and need dynamic failover between multiple paths. * You provide **DIA with BGP** and want customer prefixes to be advertised from the Cloud Router. * Your prefixes change frequently and you want the routing table to adapt automatically. If you only have a few stable prefixes and a simple topology, [static routes](cloud-router-routes) may be sufficient. You can configure BGP from **Network > Cloud Router > BGP**. ## Set the Cloud Router ASN Each Cloud Router uses its own ASN for BGP sessions. You must set this before adding neighbors. Under the **BGP** tab, click the **pencil** icon next to the ASN field to open the configuration dialog. Enter the **ASN** for the Cloud Router. And, optionally, set the keepalive and hold timers (available in the advanced options). * Keepalive timer: The time interval between keepalive messages sent to the neighbor. * Hold timer: The time interval to wait for a BGP session to be established before declaring it down. Click **Save** to apply the changes. ## Add BGP neighbors Once the ASN is set, you can add BGP neighbors that will exchange routes with the Cloud Router. Click **Add Neighbor** to open the configuration dialog. Complete the fields: | Field | Description | | ------------------------ | -------------------------------------------------------------------------------------------------------------------------- | | **Neighbor IP** | IP address of the BGP neighbor (for example, a cloud gateway or data center router). | | **Remote ASN** | Autonomous System Number of the neighbor. | | **Description** | Optional label to identify this peer (for example, `AWS-us-east-1` or `DC-Core-1`). | | **Password** | Optional BGP/MD5 authentication password, if required by the peer. | | **Address Family** | Address family to use (for example, IPv4 Unicast). Must match what the peer supports. | | **Route Filter** | Route filter policy attached to this neighbor (see **Route filters** below). Default is typically an **allow-all** policy. | | **Maximum Prefixes In** | Maximum number of prefixes to receive from the neighbor. | | **Maximum Prefixes Out** | Maximum number of prefixes to advertise to the neighbor. | ### BFD [Bidirectional Forwarding Detection](https://en.wikipedia.org/wiki/Bidirectional_Forwarding_Detection) (BFD) allows for faster failure detection. BFD is a protocol that allows you to detect failures faster than the default BGP keepalive and hold timers. | Field | Description | | --------------------- | ----------------------------------------------------------------------------------- | | **Enable BFD** | Enable BFD. | | **Transmit Interval** | The time interval between BFD control packets sent to the neighbor. | | **Receive Interval** | The time interval to wait for a BFD packet from the neighbor. | | **Detect Multiplier** | The number of consecutive missed control packets before declaring the session down. | | **Passive Mode** | If the remote side should start the BFD session. | ### Advanced options | Field | Description | | ---------------- | ----------------------------------------------------------------------------------------- | | **Multihop TTL** | The time-to-live value for BGP packets sent to the neighbor. | | **Passive Mode** | If the remote side should start the BGP session. | | **Hold timer** | The time interval between keepalive and hold messages sent to the neighbor. | | **Open Delay** | The time interval to wait for the BGP session to be established before declaring it down. | Click **Save** to create the neighbor. After the configuration is pushed, the neighbor appears in the list on the BGP tab. When the session state is **Established**, the Cloud Router will start learning and advertising routes according to your route filters and policies. ## Add route filters Route filters control which prefixes are accepted from a neighbor and which prefixes are advertised to it. To add a route filter, click **Route Filters** in the upper right under the **BGP** tab. Click **Add** and then complete the fields: | Field | Description | | --------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Name** | The name of the route filter. | | **Description** | The description of the route filter. | | **IP Prefix** | The prefixes to filter. | | **Subnet Mask Range** | The subnet mask range of the prefix.

**Exact**: The prefix must match both the network and the mask exactly.

**Max**: Allow the specified network and any more-specific subnet up to the maximum mask length. | | **Action** | The action to take when the prefix matches the filter. | ### Subnet mask range #### Exact **Exact** means the prefix must match both the network and the mask exactly. This is useful when you want to ensure that only the aggregate route is advertised to the neighbor, not any more-specific networks. Example filter: ``` 10.10.0.0/16 exact ``` Allowed: ``` 10.10.0.0/16 ``` Denied: ``` 10.10.1.0/24 10.10.0.0/17 10.10.10.0/24 ``` #### Max **Max** means allow the specified network and any more-specific subnet up to the maximum mask length. Example: ``` 10.10.0.0/16 max /24 ``` Allowed: ``` 10.10.0.0/16 10.10.0.0/17 10.10.10.0/24 10.10.20.0/23 ``` Denied: ``` 10.10.5.0/25 10.10.1.128/25 ``` Because those are longer than /24. ### Common route filter use cases Some typical patterns when designing route filters for Cloud Router BGP: * **Allow only tenant prefixes outbound** * Goal: Ensure that only prefixes belonging to your tenant VRF are advertised to external peers. * Behavior: Outbound route filter permits the tenant prefix list and denies everything else. * **Block default route inbound** * Goal: Prevent a neighbor from accidentally sending a `0.0.0.0/0` route that would override your intended internet path. * Behavior: Inbound filter denies `0.0.0.0/0` (and optionally other broad aggregates) and permits the specific prefixes you expect. * **Limit inbound route scale** * Goal: Avoid pulling a large number of specific prefixes into the Cloud Router. * Behavior: Inbound filter accepts only routes within a defined prefix-length range (for example, `/8`–`/24`) or only specific aggregates provided by the peer. When you attach a stricter route filter to an existing neighbor, any routes that no longer match become **Filtered Routes** and are not installed in the Cloud Router routing table. ## Verify BGP sessions and dynamic routes After configuring neighbors and route filters, verify that dynamic routing behaves as expected. 1. In the **BGP** tab: * Check that each neighbor shows a healthy **Status** (for example, Established). * Expand a neighbor to see: * **Sent Routes** – prefixes the Cloud Router is advertising. * **Received Routes** – prefixes learned and accepted. * **Filtered Routes** – prefixes dropped because of route filters or policy. 2. In the [**Routes**](cloud-router-routes) (routing table) view for the Cloud Router: * Confirm that expected dynamic routes appear with **Type** `BGP`. * Check the **Destination**, **Gateway**, and **Distance/metric**. * Use the search and export options if you need to audit large tables. If expected routes are missing: * Confirm the **BGP session** is up. * Confirm the neighbor is **advertising** the prefixes you expect on its side. * Review the **Route Filter** attached to the neighbor to ensure it permits the routes in the correct direction. * Check for more advanced policies in your underlay (for example, route aggregation or RPKI validation) as described in the NaaS User Guide. # Cloud Router connection to Google Cloud Interconnect Source: https://docs.zayo.com/docs/cloud-router-gcp When attached to a Cloud Router, your Google Cloud Interconnect can share a routing domain with other cloud links and virtual circuits. ## Prerequisites Before you begin, ensure you have: * An active Google Cloud account with appropriate permissions * [Compute Engine API](https://console.cloud.google.com/marketplace/product/google/compute.googleapis.com) enabled for your Google Cloud project * A VPC in your Google Cloud environment. For more information, see [Google Cloud - Create and manage VPC networks](https://cloud.google.com/vpc/docs/create-modify-vpc-networks) * A DynamicLink port with available bandwidth ## Step 1: Create a partner interconnect VLAN attachment in Google Cloud In the search field at the top of Google Cloud Console home page, enter "Interconnect" and select the product page. Go to the **Interconnect** page and click **Create VLAN attachments**. There are two types of partner interconnect VLAN attachments: * **Encrypted**: HA VPN over your connection. See [HA VPN over Cloud Interconnect overview](https://cloud.google.com/network-connectivity/docs/interconnect/concepts/ha-vpn-interconnect). Note that while this is supported on the Zayo NaaS platform, you will need to deploy and configure IPsec on-prem. * **Unencrypted**: Unencrypted connections are still private and secure, but do not use VPN tunneling and do not require IPsec. For instructions on provisioning a VLAN attachment, see [Create VLAN attachments](https://cloud.google.com/network-connectivity/docs/interconnect/how-to/partner/creating-vlan-attachments). When creating your VLAN attachment, note the following: | Field | Comments | | ----------------- | -------------------------------------------------------------------- | | **MTU** | Support for up to 9000 MTU | | **IP stack type** | Select **IPv4 (single-stack)** (we do not support IPv6 at this time) | After you provision your interconnect, you will be provided one pairing key for each VLAN attachment. Copy this key as you will need to provide it when setting up the connection in DynamicLink. screenshot ## Step 2: Create the Cloud Router connection in DynamicLink Once you have your pairing key from Google Cloud, return to the DynamicLink portal. Navigate to **Build Your Network > Ports** in the DynamicLink portal. Under **Connections**, click the **Cloud Router** vertical tab. Select **Cloud Connection** and then Google: Screenshot Complete the following fields: | Field | Description | | ----------------------------------------------- | ---------------------------------------------------------------------------------------------------- | | **Pairing key 1**      
**Pairing key 2** | Enter the pairing keys you copied from Google Cloud console after creating your VLAN attachment. | | **Region** | This is automatically populated with the region you selected while provisioning the VLAN attachment. | | **BW** | Desired bandwidth for the Google Cloud Interconnect link. | Enter a name for the connection and then click **Add**. ## Step 3: Activate the connection in Google Cloud Return to the Google Cloud Console and activate the connection. See [Activating connections](https://cloud.google.com/network-connectivity/docs/interconnect/how-to/partner/activating-connections). After activation, statuses typically progress from **Pending** to **Available** once Google Cloud completes provisioning (usually a few minutes). ## Step 4: Verify in DynamicLink Return to the Cloud Routers page and verify your connection appears as **Available**. ## Next steps (routing) Next, you will need to set up BGP and configure your Cloud Router ASN and peerings. # Cloud Router MAC Address Table Source: https://docs.zayo.com/docs/cloud-router-mac The MAC address table shows which Layer 2 MAC addresses have been learned on which virtual interfaces. While the [ARP table](cloud-router-arp) maps IP addresses to MAC addresses, the MAC table provides a pure Layer 2 view — confirming that Ethernet frames from remote devices are actually arriving at the Cloud Router and on the correct interface. Use the MAC table to verify physical connectivity, diagnose VLAN or cabling issues, and confirm that devices are reachable at the data link layer. ## View the MAC address table You can view the MAC address table from **Network > Cloud Router > MACs**. Each row represents a MAC address that the Cloud Router has learned on a specific interface. | Column | Description | | --------------------- | --------------------------------------------------------------------------------------------------------------------------------------- | | **MAC Address** | The learned or configured MAC address of the remote device (e.g., `2c:6b:f5:ab:fb:df`). | | **Virtual Interface** | The Cloud Router interface on which the MAC address was learned (e.g., the name of your port connection, cloud link, or DIA). | | **Port** | The underlying physical port associated with the entry, when applicable. | | **Age** | How long ago (in minutes) the entry was last seen. An increasing age may indicate that the device has stopped sending traffic. | | **Type** | Whether the entry is **Dynamic** (learned from incoming Ethernet frames) or **Static** (manually configured or pinned by the platform). | ## Dynamic vs. static entries * **Dynamic entries** are created automatically when the Cloud Router receives an Ethernet frame from a device. \ \ The Cloud Router records the source MAC address and the interface the frame arrived on. Dynamic entries age out after a period of inactivity — if the device stops sending traffic, the entry will eventually be removed. * **Static entries** are [configured manually](/docs/cloud-router-routes). Static entries do not age out and persist until they are removed. ## When to use the MAC address table #### Verify device connectivity After connecting a new device, provisioning a Cloud Router connection, or making cabling changes, check the MAC table to confirm that the remote device's MAC address appears on the expected virtual interface. A valid MAC entry confirms that the physical link is up and Layer 2 frames are being received. #### Diagnose Layer 2 issues If a device's MAC address is missing from the table, the device is either: * Not sending traffic (powered off, interface down, or no active sessions). * Not connected to the correct port or VLAN. * Experiencing a physical link issue (bad cable, incorrect SFP, or port mismatch). A missing MAC entry points to a problem below Layer 3 — resolve it before investigating routing or BGP. #### Identify unexpected devices Review the MAC table periodically to ensure that only expected devices are connected to your Cloud Router interfaces. An unfamiliar MAC address may indicate a misconfiguration, a cabling error, or an unauthorized device on the network. #### Correlate with the ARP table The MAC and ARP tables complement each other: * A **MAC entry without a corresponding ARP entry** means the device is sending Layer 2 frames but has not yet participated in an ARP exchange. This can happen if the device is in a different subnet or has not yet sent IP traffic. * An **ARP entry without a corresponding MAC entry** is unusual and may indicate a stale ARP cache. Refreshing the view or waiting for the next ARP cycle typically resolves this. * **Both entries present** confirms full Layer 2 reachability — the device is physically connected and IP-to-MAC resolution is working. # Cloud Router Network Pages Source: https://docs.zayo.com/docs/cloud-router-network Once you have created a Cloud Router, you can add routing rules to it to build your own network between data centers, cloud service providers, and DIA connections. 1. In the DynamicLink portal, select **Network** from the bottom menu. 2. Select **Cloud Router**. Network menu Under the **Cloud Router** tab, you can configure the following: * [**Routes**](cloud-router-routes): Add static and dynamic routes to the Cloud Router. * [**BGP**](cloud-router-bgp): Configure BGP peering with external networks. * [**ARP**](/docs/cloud-router-arp): Configure ARP tables for static IP addresses. * **MACs**: Configure MAC addresses for static IP addresses. * **Policy-Based Routing (PBR)**: Configure policy-based routing to control traffic flow. # Configure Policy-Based Routing for a Cloud Router Source: https://docs.zayo.com/docs/cloud-router-pbr A Policy-Based Route (PBR) lets you make routing decisions based on source IP, destination IP, protocol, and ports. Connections that match the policy are directed to a configured gateway independently from the regular routing table. Use PBR when you need to: * **Implement source-based routing** (also called source routing), where traffic from different source subnets exits through different gateways. * **Steer specific traffic through a particular path**, such as sending all traffic from a guest network through a dedicated internet link or firewall. * **Route by protocol or port**, for example directing all UDP traffic to a specific next-hop. * **Create failover policies** where traffic matching a rule is skipped if the preferred gateway becomes unavailable, allowing a backup rule to take over. * **Exempt specific traffic from other PBR rules** by setting the gateway to "None," which forces matching connections back to the standard routing table. If your routing needs can be met with destination-based forwarding alone, [static routes](cloud-router-routes) or [BGP](cloud-router-bgp) may be simpler options. ## PBR rule evaluation PBR rules are evaluated by priority (lowest priority value first), not by longest prefix match and distance like regular routes. The Cloud Router checks each connection against the PBR rules in order. The first rule where **all filters match** (logical `AND`) determines the gateway for that connection. If no PBR rule matches, the connection is routed according to the standard routing table. Each PBR rule consists of: * **Priority** — The order in which the rule is evaluated relative to other PBR rules. * **Policy** — The filter conditions a connection must match (source IP, destination IP, protocol, ports, ingress interface). All filters in a rule are combined with logical `AND`. * **Action** — Direct matched connections to the next-hop IP address or (if you select **None**) route them via the standard routing table. ## Add a PBR rule You can configure policy-based routing from **Network > Cloud Router > PBR**. Click **Add** in the upper right and complete the following fields: ### General | Field | Description | | --------------- | --------------------------------------------------------------------------------------- | | **Name** | A descriptive name for the rule (e.g., `Guest-to-Internet` or `Source-Route-Branch-A`). | | **Priority** | Numerical priority. Lower values are evaluated first. | | **Description** | Optional note explaining the purpose of the rule. | ### Policy Define the filters to determine which traffic the rule applies to. All specified filters must match for the rule to take effect. | Filter | Description | | -------------------- | --------------------------------------------------------------------------------------------------------------------------------- | | **IP Protocol** | The IP version to match. Must match the version used in the source and destination fields (IPv4 or IPv6). | | **Protocol** | Transport protocol to match (e.g., TCP, UDP, ICMP, or Any). | | **Source** | Source IP prefix or [Group](groups) to match (e.g., `192.168.10.0/24`). Leave empty to match all sources. | | **Destination** | Destination IP prefix or [Group](groups) to match. Leave empty to match all destinations. | | **Source Port** | Source port or port range (optional). | | **Destination Port** | Destination port or port range (optional). | | **Source Interface** | Ingress virtual interface to match. Use this to route all traffic entering through a specific connection to a designated gateway. | ### Route Action | Field | Description | | ----------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Gateway** | Enter the next-hop IP address to direct matched connections to (e.g., `192.168.49.1`), or select **None** from the dropdown.

**IP address** — Matched connections are forwarded to this gateway, independent from the standard routing table.

**None** — Matched connections are routed according to the standard routing table. This is useful for creating exceptions — connections that match this rule are routed normally even if a lower-priority PBR rule with a gateway would otherwise capture them. | | **Track Gateway** | When selected, traffic matching this rule will be skipped if the gateway is unavailable.
This lets you create redundant rules, e.g. a second rule with the same filters but a different gateway and a higher priority value (lower precedence) takes over automatically. See [Understanding rule processing](#understanding-rule-processing) below. | ## Understanding rule processing * **Priority-based evaluation**: Rules are processed in order of their priority value, starting with the lowest number. The first matching rule determines where the connection is sent. * \*\*Logical \*\*`AND`: All filters in a single rule must match for the rule to apply. For example, a rule with both a source prefix and a destination port will only match connections that satisfy both conditions. * **Fallthrough to routing table**: If no PBR rule matches a connection, the Cloud Router forwards it using the standard [routing table](cloud-router-routes) (static and dynamic routes). * **"None" gateway stops PBR evaluation**: When a rule's gateway is set to **None**, matching connections are routed via the standard routing table and no further PBR rules are evaluated for that connection. Use this to create exceptions that exempt specific traffic from broader PBR rules defined at lower priorities. * **Gateway tracking**: When **Track Gateway** is selected and the configured gateway becomes unavailable, traffic matching that rule is skipped. This lets you create a second PBR rule with the same filters, a different gateway, and a higher priority value (lower precedence) as an automatic failover path. ## Common use cases ### Route a guest network through a dedicated internet link Steer all traffic from a guest subnet through a specific DIA connection rather than the default route. 1. **Name**: `Guest-Internet-DIA2` 2. **Priority**: `10` 3. **Source**: `10.100.0.0/24` (guest network) 4. **Gateway**: The next-hop IP of the dedicated DIA connection 5. **Track Gateway**: Checked (traffic is skipped to default routing if DIA2 is down) ### Source-based routing for multi-homed sites Send traffic from different branch subnets out through different gateways for load distribution or compliance. 1. **Rule 1** — Branch A traffic through Gateway 1: * **Name**: `Branch-A-GW1` * **Priority**: `10` * **Source**: `172.16.1.0/24` * **Gateway**: `192.168.49.1` 2. **Rule 2** — Branch B traffic through Gateway 2: * **Name**: `Branch-B-GW2` * **Priority**: `20` * **Source**: `172.16.2.0/24` * **Gateway**: `192.168.49.2` ### Force traffic from a specific interface through a firewall Route all traffic arriving on a particular port connection through an inline firewall appliance before it reaches the rest of the network. 1. **Name**: `Untrusted-Port-to-FW` 2. **Priority**: `5` 3. **Source Interface**: Select the untrusted port's virtual interface 4. **Gateway**: The firewall appliance's IP address ### Exempt specific traffic from a PBR rule You have a broad PBR rule that sends all traffic from `10.0.0.0/8` through a specific gateway, but you want management traffic to `10.0.99.0/24` to use the standard routing table instead. Create a higher-priority rule with the gateway set to **None**. 1. **Rule 1** (exception — evaluated first): * **Name**: `Mgmt-Use-Routing-Table` * **Priority**: `5` * **Source**: `10.0.0.0/8` * **Destination**: `10.0.99.0/24` * **Gateway**: **None** 2. **Rule 2** (broad policy): * **Name**: `All-Internal-to-FW` * **Priority**: `10` * **Source**: `10.0.0.0/8` * **Gateway**: `192.168.50.1` (firewall) Management traffic matches Rule 1 first and is routed normally. All other traffic from `10.0.0.0/8` falls through to Rule 2 and is directed to the firewall. ### Failover between two gateways Create two PBR rules with the same filters but different priorities and gateways. Check **Track Gateway** on both so that when the primary gateway becomes unavailable, traffic matching that rule is skipped and automatically shifts to the secondary. 1. **Rule 1** (primary): * **Name**: `Primary-GW` * **Priority**: `10` * **Source**: `10.0.0.0/8` * **Gateway**: `192.168.1.1` * **Track Gateway**: Checked 2. **Rule 2** (secondary): * **Name**: `Secondary-GW` * **Priority**: `20` * **Source**: `10.0.0.0/8` * **Gateway**: `192.168.2.1` * **Track Gateway**: Checked ## Troubleshooting ### Traffic is not being redirected 1. **Check rule priority**: A higher-priority rule (lower number) may be matching the traffic first. Review the full PBR rule list sorted by priority. 2. **Verify all filters match**: Remember that all filters are combined with AND. If any single filter doesn't match, the entire rule is skipped. 3. **Confirm IP version**: The **IP Protocol** filter must match the IP version of the source and destination prefixes. An IPv4 source with an IPv6 protocol setting will never match. 4. **Check that the rule is enabled**: Ensure the rule's admin state is active. ### Gateway is unreachable 1. Verify that the gateway IP has a valid [ARP entry](cloud-router-arp) in the Cloud Router. A missing ARP entry indicates a Layer 2 issue. 2. Confirm that a route to the gateway exists in the [routing table](cloud-router-routes) (either via a connected route, a static route, or BGP). 3. If **Track Gateway** is checked and the gateway is down, traffic matching this rule will be skipped — check whether connections are falling through to the next rule or the routing table as expected. ### Unexpected traffic hitting the PBR rule If traffic you didn't intend to redirect is matching a PBR rule, narrow the filters. Add a more specific source prefix, destination prefix, protocol, or port to reduce the scope of the match. # Configure Static and Dynamic Routes for a Cloud Router Source: https://docs.zayo.com/docs/cloud-router-routes The DynamicLink Cloud Router supports both static and dynamic routing so you can control how traffic is forwarded across your network. * Static routes are manually defined. * Ideal for small, secure networks. * Predictable and efficient with resources. * Requires manual updates. * Dynamic routes are learned automatically from routing protocols (in DynamicLink, we use BGP). * Ideal for large, changing networks. * Scalable and automatic failover. * Higher bandwidth usage and complexity. You can configure routing from **Network > Cloud Router > Routes**. ## Add static routes Static routes define a fixed path to a destination network. Use them when you need a specific next-hop or interface. Next to **Routes > Static Routes**, click **Add**. Complete the following fields: | Field | Description | | --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Destination** | IP prefix to reach (IPv4 or IPv6), e.g. `192.168.1.0/24` or `10.0.0.0/8` | | **Type** | **IP Address** for a normal next-hop route.

**Interface** for a route to an interface. This is only supported for **IPSec** interfaces. | | **Distance** | Route distance (priority) for the route. By default, this is `1`.

Set a higher distance to make the route less desirable, for example to make it a backup route. | | **Description** | Optional note for this route. | Click **Add** to save. ## Dynamic routes (BGP) Dynamic routes are learned from BGP neighbors (e.g. cloud gateways, data centers, or other networks). You do not "add" dynamic routes manually; you configure BGP and the Cloud Router learns and displays them. For more information, see [Configure BGP for the Cloud Router](cloud-router-bgp). If dynamic routes are missing: * Confirm the **BGP session** is up (neighbor status in the BGP tab). * Confirm the neighbor is **advertising** the expected prefixes (check Sent/Received in AWS, Azure, or your peer). * Review **route filters** and policies that might block or filter advertisements. ## Route selection and precedence When several routes exist to the same destination, the Cloud Router typically: 1. Prefers **static** over **dynamic** routes. 2. Uses **longest prefix match** (more specific prefix wins). 3. Uses **distance/metric** to choose among same-type routes. # DashAI Assistant Source: https://docs.zayo.com/docs/dash-ai DashAI is an intelligent, conversational assistant integrated directly into the DynamicLink portal. DashAI is designed to streamline your workflow, provide instant support, and give you unprecedented control over your network resources using simple, natural language. ## Access DashAI From anywhere in the app, click the DashAI icon in the bottom right: Screenshot Screenshot From the dashboard, you can see common questions and create a new chat: Screenshot ## Context and RAG DashAI uses Retrieval-Augmented Generation (RAG). Retrieval-Augmented Generation (RAG) is an AI technique that combines a retrieval system with a generative model. Instead of relying only on what an external model was trained on, DashAI first searches the Zayo DynamicLink knowledge base. That retrieved context is then passed into the DashAI LLM so its answer is grounded in current, specific, and domain-accurate data. This reduces hallucinations and lets models handle topics they weren’t originally trained on. ## Use DashAI as a question and support bot You can use the DashAI LLM as a support bot where you can ask troubleshooting questions, how-to questions, and any other questions about DynamicLink processes or concepts. For example: * "My latency to the AWS us-east-1 on-ramp seems high. What are the first steps to investigate?" * "How do I add a new VLAN to my existing port?" * "What is the difference between an E-Line and an E-LAN service?" DashAI will analyze your question, retrieve the relevant information from the knowledge base, and provide a synthesized, easy-to-understand answer directly in the chat window. ## Use DashAI as an operational tool You can perform **CRUD (Create, Read, Update, Delete)** operations on your network resources simply by telling DashAI what you want to do. This feature applies to a wide range of your DynamicLink resources, including: * L2 & L3 Connections (E-Line, E-LAN, etc.) * Dedicated Internet Access (DIA) * Cloud Connections (AWS, Azure, Google Cloud, etc.) * Service Events & Alarms * Performance Statistics * Enable /Disable Services * Set Security rules You will **always be presented with a confirmation prompt** before execution. See [Command verification](#command-verification) below ### Command structure and best practices * **Be specific**: Include identifiers like circuit IDs, locations, or service names for clarity. * **State your intent clearly**: Use action words like "create," "show," "get," "update," "change," "increase," or "delete." * **Combine queries**: You can ask for information and then act on it in a subsequent command. ### Example CRUD commands The following table provides examples of how you can manage your resources using natural language. | Intent / Action | Resource | Example Command | Expected Outcome | | :-------------- | :--------------- | :------------------------------------------------------------------------------------------ | :----------------------------------------------------------------------------------------------------------------------- | | **Create (C)** | L2 Connection | "Create a new 1 Gbps E-Line service between our port in Chicago and our port in New York." | DashAI initiates the provisioning workflow and prompts you for any additional required details. | | **Create (C)** | Cloud Connection | "Provision a new 500 Mbps connection to AWS in us-east-1 using my existing port." | DashAI begins the cloud on-ramp provisioning process. | | **Read (R)** | Statistics | "Show me the bandwidth utilization stats for circuit ID `ZYO-12345` for the last 24 hours." | DashAI displays a chart or summary of the requested statistics directly in the chat. | | **Read (R)** | Events / Alarms | "Are there any active alarms on my DIA service in London?" | DashAI queries the event management system and reports the status of any relevant alarms. | | **Read (R)** | Service Details | "Get the configuration details for my Azure ExpressRoute connection `ER-ASH-01`." | DashAI returns key configuration data like VLAN IDs, peer IPs, and service keys. | | **Update (U)** | Bandwidth | "Increase the bandwidth of circuit `ZYO-54321` to 2 Gbps." | DashAI presents a summary of the change and the associated cost, then asks for confirmation to proceed. | | **Update (U)** | Configuration | "Update the description of my port in Dallas to 'Primary Data Center Uplink'." | DashAI makes the requested text change to the resource's metadata after confirmation. | | **Delete (D)** | Connection | "Decommission the Layer 2 service with ID `ZYO-98765`." | DashAI presents a **critical warning** and requires explicit confirmation before initiating the de-provisioning process. | ### Command verification No service-impacting change (Update, Delete) or new service creation (Create) will ever be executed without your explicit approval. After you issue a command to modify a resource, DashAI will respond with a summary of the planned action, including the specific resource to be changed and the nature of the change. You will then be prompted to confirm by typing "yes," "confirm," or clicking an "Approve" button before the action is sent to the orchestration engine. This ensures you have a final opportunity to review and prevent any unintended changes. # Create a Dedicated Internet Access (DIA) Connection with BGP Source: https://docs.zayo.com/docs/dia-bgp [DIA BGP](dia-overview#dia-bgp) is a type of Dedicated Internet Access (DIA) connection that uses Border Gateway Protocol (BGP) to route traffic to the internet using your own public IP addresses and Autonomous System Number (ASN). Think of it like choosing to use your own address label and delivery route rather than having someone else assign one to you. This gives your organization more control over how your traffic flows, and allows you to use your existing network identity on the platform. DIA BGP is best suited for organizations that already manage their own public IP space and ASN, and have network engineers on hand to configure BGP on their end. ## Before you begin To create a DIA BGP connection, you need: * An active customer port in DynamicLink. * An [approved ASN](asn) in DynamicLink. * Public IP prefixes registered to your ASN that you intend to advertise. You'll also need the following information from Zayo, which is provided during or after provisioning: * Zayo BGP peer IP address (IPv4 and/or IPv6) * Zayo remote ASN (`6461`) * BGP authentication password * Maximum prefix limit for the service ## Create a DIA BGP connection Navigate to **Build Your Network > Virtual Circuit**. Click **Add Connection**. **"A" Port** Select **Customer Port** and then complete the following fields: | Field | Description | | -------- | -------------------------------------------------------------------------------------------------------------------- | | **Port** | Select your source port. | | **VLAN** | Enter an available VLAN or enter "Native" to automatically direct traffic without using a VLAN ID. | | **BW** | Select a bandwidth capacity for the connection. You can later edit the connection to increase or decrease bandwidth. | **"Z" Port** Select **Internet** and then complete the following fields: | Field | Description | | ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | **Public IP** | Select **Use BGP**. | | **ASN** | Select the approved ASN you want to use for this connection. | | **Allow asymmetric routing** | Allows outbound and return traffic to take different network paths through Zayo's network. Most customers leave this disabled, since asymmetric routing prevents proper firewall enforcement on the connection. Enable only if your network design specifically requires asymmetric paths. | | **BW** | This will automatically update to match the bandwidth you selected for your port. | Enter a connection name and then click **Add**. The connection will appear in your virtual circuit list in a pending state. It will remain pending until your router is configured and the BGP session establishes between your network and Zayo's. ## Configuration details You can find configuration details, such as the MD5 password, under **Build Your Network > Public IPs**. Click the information icon next to your BGP connection. screenshot ## Configure your router Because BGP configuration commands vary by router vendor (Cisco, Juniper, Nokia, Palo Alto, and others), the requirements below are vendor-neutral. Refer to your router's documentation for the exact command syntax. Your router must be configured with: * An interface or subinterface for the DynamicLink handoff, with the same VLAN ID you selected in the portal (if tagged). * The IPv4 and/or IPv6 address assigned to the customer side of the connection. * A BGP process using your approved customer ASN. * A BGP neighbor pointing to the Zayo peer IP address, with remote ASN set to `6461`. * The BGP authentication password. * IPv4 unicast address family activation if IPv4 is used, and IPv6 unicast address family activation if IPv6 is used. * An outbound route filter that allows only the approved customer prefixes to be advertised. For dual-stack service, configure and validate IPv4 and IPv6 separately. Your router must be able to reach the Zayo BGP peer IP address over the service interface, and TCP port 179 must be allowed through any firewall or ACL in the path. For more information, see [Configure Your Router for DIA BGP](dia-bgp-router). # Delete a Dedicated Internet Access (DIA) Connection with BGP Source: https://docs.zayo.com/docs/dia-bgp-delete Deleting a DIA BGP connection is a 3-step process: 1. Delete the actual DIA connection. 2. Delete the public IP pool that was imported with your ASN (optional) 3. Delete your ASN (optional) ## Delete the connection Navigate to **Build Your Network > Virtual Circuit**. Locate the DIA BGP connection you want to remove and click the trash icon on the right side of the row. Confirm the deletion. ## Remove the public IP pool (optional) After the connection is deleted, the public IP pool that was associated with it remains in DynamicLink in case you want to use it for another connection. If you no longer need the pool, remove it. Go to **Public IPs**. Locate the pool under the port that the connection was built on — it has the same name you gave the connection. Click the trash can icon and confirm. ## Delete the ASN (optional) Your approved ASN remains available for use with other DIA BGP connections. In most cases, you should leave it in place. Only delete your ASN if you no longer plan to use it for any DynamicLink service. If you delete it and need it again later, you must [submit it again](asn) and wait for re-approval. To delete an ASN, go to **Public IPs > ASN**, locate the ASN, and click the trash can icon. ## Decommission your router After deleting the connection in DynamicLink, remove the corresponding configuration from your router. At a minimum, confirm the following: * The BGP neighbor for the deleted connection is removed or disabled. * The service VLAN or subinterface is removed if no longer in use. * The service IP addresses are removed if no longer in use. * Outbound prefix advertisements for the deleted service are removed. * Service-specific route policies are removed if no longer in use. * No traffic is being routed toward the deleted service. # Configure Your Router for DIA BGP Source: https://docs.zayo.com/docs/dia-bgp-router Because router configuration commands vary by vendor and platform (Cisco, Juniper, Nokia, Palo Alto, and others), the requirements on this page are vendor-neutral. Refer to your router's documentation for the exact command syntax. ## Information Zayo provides Zayo provides the following information for each DIA BGP connection. You'll need it to complete your router configuration: | Value | Description | | ------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | | **Zayo BGP peer address** | The IPv4 and/or IPv6 address your router will peer with. | | **Zayo remote ASN** | `6461`. | | **Customer-side IP** | The IPv4 and/or IPv6 address assigned to the customer side of the connection. | | **BGP authentication password** | This is required, and is automatically generated. The session will not establish if this does not match on your router. | | **Maximum prefix limit** | The maximum number of prefixes you are permitted to advertise on this session. | ## Router configuration requirements Your router must be configured with: | Requirement | Description | | ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | **Interface and VLAN** | The customer-facing interface or subinterface must be enabled and operational, with the same VLAN ID selected in the portal (if tagged). | | **IP addressing** | The IPv4 and/or IPv6 customer-side address assigned by Zayo for this connection. | | **Local ASN** | Your approved customer ASN. | | **BGP neighbor** | The Zayo BGP peer IP address, with remote ASN set to `6461`. | | **Authentication password** | The BGP authentication password provided by Zayo. You can find this by clicking the information icon next to the DIA BGP connection under **Build Your Network > Public IPs**. | | **Address family activation** | IPv4 unicast if IPv4 is used, IPv6 unicast if IPv6 is used. For dual-stack service, configure and validate IPv4 and IPv6 separately. | | **Outbound route filter** | A filter that allows only the approved customer prefixes to be advertised. | Your router must be able to reach the Zayo BGP peer IP address over the service interface, and TCP port `179` must be allowed through any firewall or ACL in the path. ## Prefix advertisement Advertise only the public prefixes approved for your DIA BGP service. The advertised prefixes must match the approved service record. Apply outbound route filtering on your router to prevent accidental route leaks. Do not advertise: * Private IPv4 address space * Link-local prefixes * Documentation prefixes * Internal infrastructure routes * A default route toward DynamicLink, unless explicitly approved * The full internet routing table * Third-party routes not authorized for this service * Any prefix not assigned or approved for your organization ### Prefix length For IPv4, advertise prefixes no longer than `/24` unless explicitly approved. For IPv6, advertise prefixes no longer than `/64` unless explicitly approved. Longer prefixes may receive special routing policy handling. ### Maximum prefix limit The number of prefixes you advertise must not exceed the maximum prefix limit for your service. If you exceed the limit, the BGP session may be protected by platform policy. ## Supported BGP communities DIA BGP supports the following BGP communities for routing policy control. You can attach these communities to prefixes you advertise to influence how Zayo handles them. | Community | Name | Description | | ----------- | ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- | | `6461:5990` | Blackhole | Discards traffic destined to the tagged prefix at Zayo's edge. Use for DDoS mitigation or to drop traffic to a specific destination upstream. | | `6461:5060` | Lower preference / backup | Marks the route as a backup path. Zayo will prefer other paths to the prefix when available. | | `6461:5100` | Peer match | Applies peer-match routing policy to the tagged prefix. | | `6461:5180` | De-preference | Reduces the preference of the route within Zayo's network. | | `6461:5220` | Preferred | Increases the preference of the route within Zayo's network. | Only the communities listed above are supported for DIA BGP. Unsupported or undocumented communities may be ignored, removed, or handled differently by routing policy. ### Blackhole routing If blackhole routing is enabled for your service, you can advertise an approved prefix with the `6461:5990` community to have traffic to that prefix discarded upstream at Zayo's edge. Blackhole routes must be within your authorized prefix range. Use blackhole routing only when you intentionally want traffic to the advertised prefix dropped. # Create a Dedicated Internet Access (DIA) Connection Source: https://docs.zayo.com/docs/dia-create Direct Internet Access (DIA) provides a dedicated, uncontended link to the internet for critical applications that need guaranteed bandwidth and performance. Unlike shared internet connections, DIA offers exclusive access to your allocated bandwidth, ensuring consistent performance and reliability.