Summary
- CAMIX’s third point of presence adds a useful attachment option in Douala, but the public record does not yet establish that its switching, inter-site transport, power and member-access paths are independent of the older Bépanda site.
- Public inventories indicate a 40 Gbps aggregate of listed Douala ports and 4 Gbps at Yaoundé, materially below CAMIX’s attributed 100G-capable fabric claim; none of those figures states how much domestic traffic remains usable after a site, circuit or route server fails.
- The strongest proof would be a repeatable one-site-outage exercise showing the surviving member paths, route-server convergence, powered cross-connects and packet path between Cameroonian networks without recourse to international transit.
The packet that must not leave Cameroon
Take a packet sent from the network of one Cameroonian access provider to a service hosted behind another Cameroonian network. In normal conditions, an internet exchange should give that packet a short domestic route: the two networks announce reachability across a shared switching fabric, learn one another’s routes directly or through a route server, and exchange the packet without buying an international detour. The packet is a better unit of analysis than the number of pins on a map because it forces every dependency into view.
It needs a live customer edge, a live access circuit, a powered port, a working switching path, valid BGP reachability, and a live egress path to the destination.
CAMIX describes its mission in those terms. Its institutional page says the member-governed, non-profit exchange is intended to keep national traffic local, improve service quality and reduce reliance on international links. That purpose is more exacting than keeping a website or a switch online. A local exchange has delivered continuity only when the domestic packet still has a domestic end-to-end path. If one entity loses its only cable to the exchange, or if two nominally separate sites depend on the same inter-city circuit, an operational switch elsewhere does not rescue the packet.
The new location sharpens the question. In an announcement dated 7 April 2026, CAMIX identified a third point of presence at the ST-DIGITAL data centre in Douala, alongside CAMTEL Bépanda in Douala and CAMPOST in Yaoundé. CAMIX presented the site as a carrier hotel and said INK and ST-DIGITAL were initially connected, with SANCFIS and Afri-IX preparing connections and discussions under way with Orange, MTN and CAMTEL. Those are useful indications of intent and early occupancy. They do not say which of the named networks were carrying production traffic through that site on the publication date, whether any network had simultaneous independent attachment to two CAMIX sites, or how traffic would move after Bépanda disappeared.
CAMIX’s public home page attributes three further headline numbers to the exchange: more than 12 active members, 100G Ethernet circuit capacity and local latency of one millisecond. Each number describes a different thing, and none is a resilience result. A port or fabric can be capable of 100 Gbps even when the connected member ports add up to much less. One-millisecond latency may describe a successful local path under ordinary conditions but says nothing about the route taken during failure. A member count may include content, infrastructure services and access networks with different attachment patterns. The relevant count during an outage is the number of independently reachable entities and prefixes on the surviving fabric.
That distinction is central because the public promise of the third site is not merely more rack space. It is the possibility of separating failure domains. The older Douala exchange location sits at CAMTEL Bépanda; the new one is at a different Douala facility. In principle, that separation could protect local exchange traffic from a building outage, maintenance event, failed switch or localised fibre cut.
In practice, the protection exists only if the two facilities are linked through a path that does not fail with the original site, if the surviving site has its own powered exchange equipment, if member circuits reach it independently, and if control-plane sessions reconverge without leaving stale or unusable next hops.
An exchange therefore needs to be evaluated as a chain, not as three addresses. The first link is physical: where the equipment and cross-connects actually sit. The second is transport: how the sites form one or more exchange fabrics. The third is electrical: what keeps every active device and optical handoff powered. The fourth is member attachment: whether entities arrive over distinct paths. The fifth is control: whether BGP reachability remains correct when one component disappears. The sixth is outcome: whether representative domestic packets still remain domestic.
CAMIX’s third site creates the opportunity to strengthen each link; the available evidence does not yet demonstrate the whole chain.
Three addresses, but how many failure domains?
CAMIX’s own descriptions establish a three-location footprint at the level of named premises. Its frequently asked questions identify CAMPOST Yaoundé, CAMTEL Bépanda in Douala and ST-DIGITAL in Douala, and describe member ports from 1 Gbps to 100 Gbps. The separate member list displays 14 active entries, including access operators, networks and infrastructure or content services. These pages are useful first-party statements, but their categories should not be combined into a claim that 14 networks are independently attached at all three locations. The pages do not publish a site-by-site port matrix.
Two external registries show why “three PoPs” and “three independently working exchange sites” should not be treated as synonyms. CAMIX’s PeeringDB organisation record describes three separated points of presence—two in Douala and one in Yaoundé—yet it links to two exchange records, one for Douala and one for Yaoundé. The Douala exchange record lists CAMTEL Bépanda as its local facility and shows ten connections whose displayed capacities sum to 40 Gbps. ST-DIGITAL appears as a connected network, but the page does not identify ST-DIGITAL’s data centre as a second local facility for that exchange record. The absence may reflect delayed registry maintenance rather than physical reality; it nevertheless means the registry cannot presently corroborate the third site’s physical topology.
The same caution applies to Packet Clearing House. Its CAMIX Douala entry identifies an active exchange in Douala at CAMTEL Bépanda, while its CAMIX Yaoundé entry identifies the CAMPOST location. These are directory snapshots, not cable surveys. Their value lies in confirming the older two-city footprint and in providing dated observations that can be compared with CAMIX’s newer claim. They do not reveal whether ST-DIGITAL has a dedicated exchange switch, a remote extension back to Bépanda, or some intermediate arrangement.
A community-maintained page offers a more granular but still provisional picture. The cmNOG Cameroon IXP federation page names CAMIX-Yde01, CAMIX-Dla01 and CAMIX-Dla02, placing Dla02 at ST-DIGITAL and recording a late-2024 date with three peers. That entry supports the existence of a third operational identity before the 2026 announcement, but it introduces a chronology that the other public pages do not explain. It could describe an early deployment, a test phase, a relaunch or simply a page updated on a different schedule. It still does not publish a physical path diagram. The responsible conclusion is narrow: three site names recur across first-party, registry and community records, while the independence of the site-level dependencies remains unproven.
Physical independence has several layers. Different street addresses protect against some building incidents but not against a shared metro duct. Separate racks protect against accidental work in one cabinet but not against a shared top-of-rack power distribution unit. Separate switches protect against one hardware fault but not against a single remote-management error applied to every device. Separate generators protect against a grid interruption only if the cross-connect optics, carrier transmission equipment and member routers also receive backed-up power.
A second site reached solely through the first site protects against very little when the first site is the failure under test.
Industry guidance makes that hierarchy explicit. The Euro-IX physical requirements guidance treats multi-location design as a means to improve geographic and disaster independence, but also notes that member resilience depends on dual routers, interfaces and access choices. In other words, an exchange operator can build a diverse core while an individual member remains single-homed. Conversely, a member can buy two circuits that converge onto one exchange switch or one common duct. Both perspectives have to be shown.
The third CAMIX site is therefore best understood as a hypothesis about resilience, not yet the result. Its new failure domain must be demonstrated across at least five boundaries: building, power, exchange switching, inter-site transport and entity access. Public evidence currently clears the first boundary—the premises are separately named—and offers facility-level indications for power. It is thin at the other three. This does not diminish the strategic value of the expansion. It defines what must be measured before the value can be translated into a continuity claim.
The Bépanda-to-ST-DIGITAL path is the missing map
The most consequential missing document is a current physical and logical map of the two Douala sites. A useful map would identify the exchange switches at Bépanda and ST-DIGITAL, every inter-site link, the carrier or operator responsible for each segment, the route diversity between the buildings, the optical and electrical handoff points, and whether the third site can reach the surviving exchange members when Bépanda is dark. It would also separate exchange-owned capacity from member-owned access circuits. None of the reviewed public material supplies that map.
CAMIX’s peering service page attributes a Layer 2 fabric of more than 100 Gbps, redundant BGP route servers, RPKI and Internet Routing Registry filtering, IPv4 and IPv6 support, and ports at 1, 10 and 100 Gbps to the exchange. Those statements describe capabilities, not topology. “Layer 2” could encompass independent switches joined in a protected ring, a star centred on one site, a single inter-site extension, or several other designs. “Redundant” route servers could mean two processes on separate hardware in one building, servers distributed between sites, or resilient virtual instances sharing a hidden dependency. Without placement and path information, none of those interpretations can be selected as fact.
The public national-fibre picture gives context but cannot be substituted for an exchange map. Cameroon’s Ministry of Posts and Telecommunications described a national backbone programme with thousands of kilometres of fibre and a 55-kilometre Douala loop, while noting plans for a Yaoundé metropolitan loop. That is evidence of fibre infrastructure in the relevant cities. It does not establish which strands, ducts or transport services CAMIX uses, nor whether the exchange has contractual or physical diversity over them.
CAMTEL has separately argued that its backbone includes a redundant Douala–Bafoussam–Yaoundé route. That claim may be relevant to national continuity, particularly if CAMIX buys or receives services over distinct backbone paths. No public CAMIX document reviewed here connects the third site to that redundancy, states the protected capacity available to the exchange, or shows that a member circuit to ST-DIGITAL avoids the same CAMTEL segment used to reach Bépanda. Backbone reach and exchange reach are not automatically the same asset.
There is a practical reason to insist on exact routing. An Orange Cameroon statement republished after disruptions in September 2024 attributed instability in Douala, Yaoundé and elsewhere to multiple fibre cuts affecting backbone connections between the two cities. That episode is not evidence that CAMIX failed or that any particular exchange circuit was on the affected route. It is evidence that apparently separate services can share a corridor whose disruption reaches both metros. A resilience design should be evaluated against that correlated event, not only against a clean single-device failure.
The Douala path question has two versions. The first is intra-city: if the Bépanda exchange switch, building power or immediate fibre approaches fail, can ST-DIGITAL continue to exchange traffic among members physically present there? The second is fabric-wide: can members attached only at Bépanda still be reached through an alternative circuit, or do they disappear until their own diverse attachment becomes active? The first version can be solved at the new facility with local members and local routes. The second requires diversity on both sides of the exchange: a surviving core link and surviving member access.
The distinction also prevents a misleading interpretation of the term “carrier hotel.” A neutral facility can offer many carriers and cross-connect choices, which is valuable. But choice at the endpoint does not prove diverse paths after those cables leave the building. Two carrier services can share a duct, an optical platform, a bridge, a roadside cut risk or a common upstream transport operator. A proper path map should therefore show shared-risk groups rather than only supplier names.
Where exact fibre routes cannot be made public for security or commercial reasons, CAMIX can still publish an abstract topology with independent-path attestations, test dates and bounded descriptions of common dependencies.
Until such evidence appears, the most defensible reading is that ST-DIGITAL adds a distinct place to attach in Douala and may add a distinct local switching point. Whether it creates an independently survivable exchange path remains an open operational question. That is not a demand for commercially sensitive coordinates. It is a request for the minimum information needed to distinguish a third failure domain from a third endpoint.
Yaoundé turns a metro question into a national one
CAMPOST Yaoundé is not merely another rack on the Douala fabric. It is the site that turns CAMIX’s continuity claim from metro resilience into national resilience. If a major Douala incident removes both Douala exchange locations, a functioning Yaoundé fabric could still keep traffic local among networks independently attached there. If inter-city transport survives but one Douala site fails, Yaoundé could also form part of an alternative exchange path. Both outcomes depend on who is connected, at what capacity and over which physical routes.
The PeeringDB Yaoundé exchange record currently displays four 1 Gbps connections, for an aggregate of 4 Gbps. The listed networks—CAMTEL, Matrix Telecoms, MTN Cameroon and Newtelnet—also appear on the Douala exchange record. That overlap is potentially valuable because presence in both cities can support geographic continuity. The registry does not specify whether each operator’s two attachments use independent routers, power feeds and transport, nor whether they actively announce the same reachability at both sites. It therefore indicates multi-site opportunity, not proven failover.
The facility record provides similarly bounded evidence. PeeringDB’s CAMPOST facility entry associates the site with CAMIX Yaoundé and lists a small number of networks. It does not disclose diverse utility substations, exchange switch power, carrier entrances or the route of member circuits. The corresponding CAMTEL Bépanda facility entry identifies the older Douala location and more network presence, but likewise contains no public substation-diversity detail. These omissions should not be read as proof that diversity is absent. They show that a facility registry cannot answer the continuity question on its own.
Internet Society Pulse adds a dated synthesis of the same registry material. Its Douala CAMIX tracker page reported 40 Gbps of visible capacity and ten autonomous systems in May 2026. Its Yaoundé CAMIX tracker view reported 4 Gbps and four autonomous systems in a late-2025 snapshot. These figures are useful for comparing the publicly listed edges of the two fabrics. They inherit the limitations and update cadence of the underlying registry; they are not live measurements of traffic, headroom or outage survival.
The asymmetry matters. If the visible Douala attachment total is ten times the Yaoundé total, a complete Douala loss could leave far less exchange capacity available nationally even when every Yaoundé port works. Capacity alone is not the only constraint: the surviving four networks may not originate or provide paths to all domestic destinations normally exchanged in Douala. Content caches present only in Douala may vanish from the local path. A user could still reach the content through international transit, but that would not satisfy the narrower test of domestic continuity.
The reverse direction matters too. If CAMPOST fails, networks with genuine independent Douala attachments should continue exchanging locally. Yet a Yaoundé member whose Douala presence is reached over a common inter-city service could lose both logical attachments from a single transport event. Multi-city labels are strongest when accompanied by router-level and circuit-level diversity. They are weakest when a distant port is effectively a remote extension of the same member edge.
The Internet Society’s analysis of local and remote peering explains the broader trade-off. Remote attachment can extend the benefits of an exchange to networks that cannot colocate locally, but concentration in intermediaries and distant infrastructure can also create hidden dependencies. For CAMIX, remote access may be commercially and geographically necessary. It should be described separately from physically diverse attachment so that members understand which failures each arrangement survives.
Yaoundé should therefore be evaluated as its own continuity island and as a node in a national fabric. The island test asks which entities can exchange within Yaoundé with every Douala dependency removed. The national-fabric test asks which routes and traffic can move between surviving sites after a single inter-site path fails. Publishing both results would show whether CAMIX has three operating locations or a genuinely resilient three-site system.
Ports advertised are not capacity surviving an outage
Capacity figures around CAMIX refer to at least four different layers. There is the maximum speed of a product or port, the installed switching capacity, the sum of contracted or listed member ports, and the traffic that can actually be carried after a failure. CAMIX’s attributed 100G figure appears to describe the first or second layer. The visible registry totals—40 Gbps in Douala and 4 Gbps in Yaoundé—describe portions of the third. None directly measures the fourth.
CAMIX’s service descriptions are internally consistent about offering high-speed interfaces. Its peering page lists 1, 10 and 100 Gbps ports; its FAQ describes the same range. Its 100G-capable claim is plausible as an equipment capability and may reflect a 100 Gbps interconnect or switching interface. The public pages do not identify a member using a 100 Gbps port, the total installed backplane at each site, or the capacity of the Bépanda–ST-DIGITAL and Douala–Yaoundé links. A fabric with a 100 Gbps interface could still be constrained by a 10 Gbps inter-site path or by 1 Gbps member access.
The PeeringDB records offer a transparent but incomplete arithmetic. Douala’s displayed connections sum to 40 Gbps; Yaoundé’s sum to 4 Gbps. These are nominal port values supplied through a community registry, not necessarily committed information rates or currently lit capacity. Some connections belong to exchange services or route servers rather than end-user access networks. A nominal port may carry little traffic, be reserved for a service, or be unavailable during maintenance. Conversely, a new active port may exist before the registry is updated.
The totals should be labelled as displayed connected-port capacity at a stated date, not as measured exchange throughput.
Packet Clearing House illustrates the importance of timestamping. Its exchange directories are useful external observations, but entity, capacity and traffic fields can change between snapshots as records are refreshed. A single directory value should not be promoted into an enduring engineering fact. Internet exchange capacity is particularly prone to category errors because traffic rate, port capacity and switching capability all use bits per second while describing different constraints.
Failure-usable capacity requires a more demanding calculation. Suppose Bépanda holds most of the visible member ports and ST-DIGITAL has only its two initially named occupants. Losing Bépanda could remove the majority of endpoints before the inter-site link becomes a bottleneck. Suppose instead that major members are dual-attached but both access circuits share a duct. The nominal sum would overstate surviving capacity. Or suppose every physical circuit survives while a route server fault withdraws a large set of routes. Electrical and optical capacity would remain, but usable routed capacity could fall sharply.
A credible capacity statement after a site failure therefore needs a matrix, not one headline. For each failure scenario, it should show surviving exchange switch capacity, surviving inter-site capacity, surviving member ports, expected route count, observed peak traffic and available headroom. It should state whether capacity is installed, lit, powered, operational and carrying representative traffic. It should distinguish protected capacity from capacity that becomes unavailable with the failed site.
The CAMIX services network record reinforces the need for scope labels. It identifies CAMIX Services under AS328091, lists a 1 Gbps Douala connection and associates the network with CAMPOST and CAMTEL Bépanda. That is evidence about an exchange-services network, not the size of the switching fabric. The CAMIX route-server record identifies AS37718 as the route-server network. Again, an autonomous-system record confirms a control-plane identity; it does not reveal route-server host placement, session distribution or forwarding capacity.
Public traffic telemetry would help reconcile the categories, but CAMIX’s looking-glass page says the BGP view is to become available rather than presenting a current public view. A looking glass would not by itself show physical diversity, but it could reveal route availability, next-hop behaviour and convergence around announced maintenance. Site-level traffic graphs, route-server session state and dated capacity tables would allow members and researchers to test whether headline capacity corresponds to operational use.
The correct current conclusion is not that CAMIX lacks capacity. It is that the public evidence supports several attributed capability and connection figures whose scopes differ. The 100G number should remain attached to CAMIX’s own description. The 40 Gbps and 4 Gbps totals should remain attached to dated registry views. Failure-usable capacity remains undisclosed and should not be inferred by adding or comparing those numbers without a scenario.
Members attach to fabrics, not to a roster
Membership is institutionally important, but a resilience analysis needs attachment detail. CAMIX’s public roster contains 14 entries, while the home page uses the looser phrase “12+ active members” and the third-site announcement names two initial connections plus several prospective ones. Those statements can all be true at different dates or under different definitions. They do not establish how many production networks are attached to each switch, how many announce routes, or how many have diverse access.
The central unit is a member path. It begins at a entity router, crosses a local cross-connect or remote-access service, reaches an exchange port, and terminates on a switching domain from which other entities are reachable. A resilient member has at least two paths that do not share the failure being protected against. Two logical VLANs over one fibre are not two physical paths. Two fibres in one duct may protect against an optic failure but not an excavation. Two ports on one router may protect against a port failure but not a router or power failure.
Two exchange sites reached by the same transport hub may not protect against loss of that hub.
The initial ST-DIGITAL member picture is encouraging but narrow. CAMIX named INK and ST-DIGITAL as connected and described other organisations at different stages of engagement. That wording should not be converted into an assumption that every prospective entity is now exchanging routes or traffic. Nor should the presence of a data-centre operator at its own facility be counted as evidence that the large access networks have independent last-mile circuits there.
A cmNOG technical note shows how operational detail can change the interpretation. A draft meeting record from September 2024 discussed an MTN point-to-point transit link for a Cloudflare cache at the older Douala site, observed packet loss from one view, identified a need for a second physical link to Dla01, and anticipated later presence at Dla02. The record is provisional, dated and specific to one arrangement; it cannot establish the current state of MTN, Cloudflare or CAMIX. Its value is diagnostic. It shows that second physical paths and presence at the newer site were treated as concrete engineering tasks rather than automatic consequences of adding a location.
That lesson applies to the four networks appearing in both PeeringDB exchange records. Simultaneous listings in Douala and Yaoundé are evidence of multi-site logical presence. To turn that into continuity evidence, CAMIX or the entities would need to state whether they use separate edge routers, separate carrier or self-built paths, separate building entrances, and active route announcements at both sites. A controlled failure could then verify that traffic moves to the surviving path within an observed convergence interval.
The composition of the roster also affects the “stay domestic” result. An exchange can keep a packet local only when the destination prefix or a valid local route remains reachable at the surviving site. If an access provider survives but a content cache is connected only at the failed site, users may fall back to an international copy. If a public institution has only one local attachment, government-to-user traffic may leave the domestic exchange path even though commercial networks remain connected. Continuity therefore needs to be measured by route and service category, not just by entity count.
The MANRS programme for internet exchanges adds a routing-security dimension. Its expectations include filtering based on authoritative route information, protecting the exchange platform, coordinating incidents and providing useful routing information to members. These practices reduce the risk that a surviving fabric carries bad reachability after a failure. They do not replace physical diversity; they make the surviving control plane more trustworthy.
Member confidentiality is not an obstacle to meaningful disclosure. CAMIX could publish anonymised attachment classes: locally colocated single-homed, locally colocated dual-homed, remotely connected over one path, remotely connected over protected paths, and present at two or three sites. It could pair those counts with the number of active BGP sessions and prefixes per site. Large entities could voluntarily publish their own diversity claims. The result would be far more useful than a flat logo roster while preserving sensitive circuit details.
Until then, the visible evidence supports a modest conclusion. CAMIX has a broader community than the ports displayed in any one external registry, and the third site has attracted initial attachment. The number of member paths that survive loss of Bépanda, ST-DIGITAL or CAMPOST is not publicly established. That unknown sits directly between the three-PoP claim and the domestic-continuity outcome.
The route server can fail while the switches still forward
Internet exchange resilience is often discussed as if it were purely a matter of fibre and power. The route server shows why that is incomplete. A route server accepts BGP routes from entities and distributes selected reachability information to other clients, reducing the need for every member to establish a bilateral session with every peer. It normally stays outside the data path: packets flow directly between entity routers using the next hop learned through BGP.
RFC 7947 formalises that separation. A route server brokers control-plane information while preserving the entity next hop rather than forwarding user packets. This means a route-server host can fail while already learned routes continue forwarding until BGP timers, withdrawals or policy changes take effect. It also means a healthy route server can announce a path whose data-plane next hop is unreachable because of a Layer 2 fault. Control-plane green does not guarantee packet delivery.
RFC 7948 describes operational practices for route servers, including the value of multiple servers and safeguards against route leaks. It also highlights a non-transitive Layer 2 failure: two clients may each reach the route server while being unable to reach one another. That scenario is highly relevant to a multi-site exchange. If the route server sits at a point reachable from Bépanda and ST-DIGITAL but the entity-to-entity path across the fabric is broken, BGP sessions can remain established while domestic packets fail.
CAMIX says it operates redundant BIRD route servers. The statement is useful, but resilience depends on where those servers run and what they share. Two processes on one host protect against a software-process fault but not a host failure. Two hosts in one rack protect against a host fault but may share a switch, power feed and building. Two hosts in different sites improve physical separation but can still depend on one inter-site control path or common configuration. The public AS37718 record identifies the route-server identity, not this placement.
The route server also shapes the failure behaviour of members that rely on it exclusively. A entity with bilateral peering sessions may retain some domestic routes when every route server is unavailable. A entity that learns all exchange routes only from the route server may keep stale routes temporarily and then lose them, depending on session state and timers. A entity connected to two sites may receive two paths but select one based on attributes that do not correspond to physical diversity. The topology of BGP sessions must therefore be tested alongside the topology of cables.
Euro-IX’s exchange-management guidance warns that a route server can become a single point of failure and recommends multiple servers, sound monitoring and traffic observation. For CAMIX, the test should be site-specific. Removing the route server or control connection at Bépanda should not prevent members at ST-DIGITAL and Yaoundé from learning valid surviving routes. Removing ST-DIGITAL should not leave next hops pointing to unreachable entity ports. Removing the inter-city link should produce two internally coherent islands rather than a deceptively healthy set of sessions with broken forwarding.
Convergence time should be reported as a distribution, not a marketing minimum. It should include BGP session loss detection, route withdrawal or replacement, forwarding-table update and the first successful representative packet on the surviving path. Different members may use different timers and policies, so one route can recover while another remains unavailable. The exercise should also detect route oscillation and accidental fallback through international transit, which can make a service appear restored while defeating the domestic-continuity objective.
Routing security must remain active during the event. If failover causes a entity to announce a broader or different set of prefixes, route-server filters should accept only authorised origins and policy-compliant routes. RPKI and registry checks help, but their local caches, validators and management connections also have dependencies. A complete test records whether filtering and monitoring remain available when the site hosting one of those support services is removed.
CAMIX can demonstrate this without exposing individual routing policy. It can publish the number of route-server instances, the failure domains across which they are placed, the number of active sessions by site, the fraction of routes available after each test, and a bounded convergence result. It can also show synthetic reachability between test prefixes at each location. Those data would connect its redundant-route-server claim to an observable operational outcome.
Power independence ends at the weakest unpowered handoff
ST-DIGITAL gives CAMIX a facility that publicly emphasises continuity. The operator’s data-centre page describes the Douala site as a Tier III facility with electrical redundancy, precision cooling and multiple connectivity options. An OIX-2 certification announcement identifies DLA01 as a certified data-centre site with a meet-me room and interconnection services. These records support the characterisation of ST-DIGITAL as a purpose-built carrier-neutral environment. They do not certify the precise power path of CAMIX’s switch, optics or member cross-connects.
ST-DIGITAL has published unusually specific continuity claims in an account of its energy measures. The operator says generators can support full load for 48 hours with additional stored fuel extending that period, that battery autonomy exceeds 18 hours, and that equipment is tested monthly. These are operator-attributed figures rather than independently observed runtime results. They establish the intended facility capability and identify testable claims.
An Open Compute Project site assessment supplies further detail through a self-reported assessment: two utility feeds, three generators, a battery bank, a stated critical IT load and a list of carriers. Its format makes the provenance clear—the facility supplied the answers. It is useful evidence about designed redundancy at DLA01, not proof that every CAMIX component is dual-fed or that the carriers leave by physically diverse routes.
The weakest-handoff principle matters because an exchange path crosses equipment owned by several parties. Facility utility feeds may be diverse while the CAMIX switch has one power supply. The switch may be dual-fed while a media converter or optical amplifier has one supply. Both may be protected while a member router sits on an unprotected circuit. The data centre may run for days while a carrier cabinet outside the protected room loses power. Each condition breaks the packet path even though the main facility remains operational.
Power independence also has a geographic side. A grid problem can affect a district, while fuel logistics, extreme heat or control-system error can create wider common risks. The Internet Society’s review of electricity failures at internet hubs describes how facilities use generators and batteries yet can still encounter cascading dependencies in cooling, fuel and surrounding networks. The lesson for CAMIX is not that ST-DIGITAL’s protections are inadequate. It is that facility resilience must be joined to exchange-device and access-network resilience.
The older sites need the same evidence standard. CAMPOST Yaoundé and CAMTEL Bépanda are named locations, but the reviewed public pages do not set out their utility feeds, generator autonomy, battery condition, cooling redundancy or CAMIX load allocation. It would be wrong to infer that they lack backup simply because public details are sparse. It would be equally wrong to assume that three powered sites have equivalent endurance.
A useful power test would isolate each site from utility supply under controlled conditions and observe the complete exchange path. The record should show transfer to battery and generator, switch and route-server uptime, optical signal continuity, member-session continuity, temperature, fuel status and the performance of any carrier handoff serving the site. It should include restoration, because transfer back to utility power can itself cause interruption. A shorter controlled test can verify transition behaviour; a longer facility exercise can test endurance and refuelling assumptions.
Power results should be expressed per dependency. “The data centre remained online” is one result. “The CAMIX fabric and representative member paths remained operational” is a stronger result. “Domestic traffic between selected prefixes stayed local throughout the test” is the result aligned with the exchange’s public purpose. The three should not be collapsed.
The third site improves CAMIX’s options because it places exchange presence in a facility with documented continuity ambitions and a neutral interconnection environment. Its resilience contribution becomes measurable when CAMIX identifies the powered exchange components, confirms diverse feed use, tests the carrier handoffs and shows that members can use the surviving paths. Facility credentials are a strong starting point, not the final packet-level proof.
What one-site failure would do to domestic traffic
No single public document currently answers the central counterfactual: if one CAMIX site disappears, which domestic traffic remains on-net? The evidence does allow the likely outcomes to be bounded, provided they are labelled as inferences rather than observations.
Start with Bépanda. The public Douala exchange registry places the exchange facility there and lists most of the visible Douala connections. If Bépanda hosts a central switch or an essential inter-site link, its loss could remove both local ports and remote reachability. If ST-DIGITAL has an autonomous switch, a surviving route server and local members, some traffic among those members could continue. Whether they can reach the rest of CAMIX depends on a Bépanda-independent path to Yaoundé or to other surviving entities. Because that path is not public, the fraction of domestic traffic that stays local cannot be calculated.
Now remove ST-DIGITAL. The older Bépanda and Yaoundé records indicate that an exchange existed before the third-site expansion, so a large portion of previously established connectivity may continue. The affected traffic would include members or services attached only at the new site and any path whose transport unexpectedly traverses it. The impact might be small in aggregate while still serious for a particular entity. Aggregate traffic graphs alone would not identify that loss.
Remove CAMPOST Yaoundé. The two Douala locations could in principle continue metro exchange, and the larger displayed Douala port total suggests more visible capacity there. Yet Yaoundé-only entities or access paths would vanish. Networks listed in both cities might shift to Douala if their dual presence is physically and electrically independent. If their Douala path depends on the same failed inter-city route, the registry’s two-site label would not translate into survival.
There are also failures that do not respect site boundaries. A cut on a shared Douala–Yaoundé corridor could split the exchange into metro islands while leaving every building powered. A configuration error could affect all switches or route servers at once. Loss of a common authentication, monitoring or RPKI validation service could degrade control without removing the forwarding fabric. A fibre event near Bépanda could remove both member access and the path from ST-DIGITAL if they converge there. A useful design treats these shared-risk events separately from the simple site-out cases.
The Internet Society’s overview of exchange points identifies the basic ingredients—neutral facilities, switching, routing equipment, power, cooling, security and skilled operations. For CAMIX, every ingredient has to survive in the combination needed by the packet. A live switch without a route, a live route without a next hop, or a live member without the destination service does not preserve the domestic exchange.
International transit complicates observation. During a CAMIX failure, two networks may still communicate because both retain upstream routes through Europe or another external hub. A conventional uptime test would mark the service available. A national-resilience test must additionally inspect the path and latency, or use controlled test prefixes whose exchange and transit policies are known. The result should distinguish fully local continuity, restored service via international transit, partial reachability and complete loss.
The official one-millisecond latency claim can be used as a baseline only with attribution and scope. If a path rises sharply during failure, that can signal international diversion, but latency alone cannot prove geography. A domestic alternative route can also be longer, and an international route can sometimes be unexpectedly fast. Traceroute, BGP next-hop data and entity confirmation provide stronger evidence when combined with latency.
The likely answer today is conditional. Traffic between members independently attached to a surviving CAMIX site, with valid surviving routes and a destination still present there, can remain domestic. Traffic involving a single-homed member at the failed site cannot use CAMIX unless that member has another active path. Traffic that depends on a failed inter-site link may fragment into local islands. Traffic may remain reachable through international transit without remaining domestic. The size of each category is not publicly quantified.
That bounded answer is more useful than declaring the three-site network either resilient or fragile. It shows exactly which facts would change the assessment: site-level member sessions, independent path attestations, topology of inter-site links, power allocation, route-server placement and outage observations. Each can be measured without publishing sensitive packet payloads or detailed street-level fibre routes.
A test programme that would turn claims into evidence
CAMIX can convert its three-site claim into credible national-continuity evidence through a repeatable exercise. The exercise should begin with a declared baseline: timestamp, participating sites, test prefixes, active member sessions, route-server state, normal path, normal latency and traffic level. It should identify the failure boundary in advance and state the dependencies deliberately left outside the test. This avoids presenting a switch reboot as a full site-outage result.
The first exercise should remove Bépanda at the exchange edge. CAMIX could disable the relevant fabric links and route-server instances under controlled maintenance while keeping measurement systems outside the affected domain. Test traffic should run between representative prefixes at ST-DIGITAL, Yaoundé and dual-attached members. The record should show packet loss, convergence time, path locality, route count and surviving capacity. A physical power test can follow after the logical behaviour is understood.
The second exercise should remove ST-DIGITAL. This validates that the new site has not become an unexpected dependency for the older fabric and measures the effect on its locally attached members. The third should remove CAMPOST and the inter-city path separately. Treating those as two tests distinguishes building failure from transport partition. In the partition test, each metro should retain internally valid forwarding without advertising unreachable next hops across the break.
The fourth exercise should fail each route server independently and then the route-server service as a class. Entities with bilateral sessions and those dependent on route-server distribution should be observed separately. The test should include a synthetic non-transitive Layer 2 fault so that monitoring has to detect a state where route-server sessions remain established but peer next hops fail. This is the failure most likely to expose the gap between a healthy control session and a working packet path.
The fifth exercise should validate member attachment. A sample of dual-site members should remove one access circuit at a time and show that the alternative does not traverse the failed site or shared local duct. Remote entities should identify the class of protected service they buy. The result can be aggregated to protect commercial details: number of tested paths, number that met the independence claim, and common causes where they did not.
The sixth should validate power transfer at all three sites. It should observe the exchange switch, route server, optical equipment, carrier handoff and representative entity router, rather than only the facility supply. Generator runtime claims do not need to be tested to exhaustion every time; fuel inspection, maintenance records and periodic endurance exercises can complement shorter live transfer tests. Results should include restoration to utility supply.
The public report can be compact. For each scenario it should state the failed domain, expected result, observed result, convergence interval, percentage of test routes retained, traffic that remained domestic, minimum surviving headroom and unresolved common dependencies. It should date every result and identify whether the test was simulated, logically isolated or physically powered down. Historical results should remain accessible so that members can see whether resilience improves as the third site gains entities.
External registries should then be reconciled with operations. CAMIX can update the Douala exchange record to identify the ST-DIGITAL facility when appropriate, publish a site-by-site connection matrix or aggregate, and expose a working looking glass and traffic graphs. Registry values need not match the exchange’s internal counters in real time, but discrepancies should be explained by date and scope. The public would then know why a 100G-capable interface, 44 Gbps of listed site ports and a lower traffic peak are not contradictory.
The measurement design should use failure independence as its organising principle. Each asserted backup should be tested against the component it is meant to replace and against shared dependencies that could remove both. This is consistent with standard exchange practice, but tailored to Cameroon’s geography and CAMIX’s particular three-site footprint. It also produces evidence that public-sector users and commercial members can incorporate into their own continuity planning.
Publication is not the final step. CAMIX should set a cadence after major topology changes, new large members, route-server upgrades and facility power modifications. A third point of presence is a moving system: its resilience can improve as members dual-home, or weaken as traffic grows faster than protected capacity. Dated repetition turns a one-off demonstration into an operating record.
The resilience verdict and watchpoints
CAMIX’s third point of presence is strategically meaningful. It adds a separate named facility in Douala, a carrier-neutral environment, an additional place for networks to meet and a plausible route away from dependence on one older building. It can also make the overall exchange more attractive to networks whose first connection is easier at ST-DIGITAL. Those are real benefits even before complete failure independence is demonstrated.
The evidence is strongest at the level of institutional intent and location. CAMIX consistently describes three sites and a mission to keep local traffic local. External and community records corroborate the older Bépanda and CAMPOST sites and provide signals for the ST-DIGITAL presence. Facility sources describe substantial power and interconnection protections at DLA01. Registry records expose current logical exchange connections in Douala and Yaoundé.
The evidence is medium at the level of connected capacity. Dated public records permit a 40 Gbps sum of displayed Douala connections and a 4 Gbps sum at Yaoundé, while CAMIX attributes 100G-capable infrastructure to itself. These figures are compatible because they measure different layers. They do not establish installed capacity at every site, the capacity of inter-site links, present traffic, reserved headroom or the amount usable after a failure.
The evidence is weakest where resilience is actually decided. There is no reviewed public topology for the Bépanda–ST-DIGITAL path, no route-diversity statement for Douala–Yaoundé exchange transport, no site-level member attachment matrix, no disclosed placement of redundant route servers, no power-path description for CAMIX equipment at all three sites, and no packet-level record of one-site failover. These are absences in the public record, not proof of poor engineering.
Four watchpoints should determine whether the third site matures into an independent national asset. The first is member density: do major access networks and content services establish active, physically diverse ports at ST-DIGITAL? The second is transport: does the new site have a Bépanda-independent path to the rest of the fabric and a resilient path toward Yaoundé? The third is control: do route-server placement, monitoring and filtering survive loss of any one site? The fourth is observed outcome: can representative packets remain between Cameroonian networks, within Cameroon, during the test?
The sequence matters. Adding members without protected transport can increase traffic concentrated on a shared link. Adding an inter-site link without diverse member access can leave most endpoints single-homed. Adding redundant route servers without testing peer-to-peer forwarding can leave a hidden Layer 2 fault. Strong resilience emerges only when the layers are tested together.
CAMIX should also resist the temptation to collapse all progress into one number. “Three PoPs,” “100G capable,” “14 members” and “one millisecond” are concise signals, but each can obscure a different dependency. A public continuity table with dated test results would be more persuasive to operators, government users and investors because it would connect the numbers to failure outcomes.
For now, the verdict is deliberately conditional. The third PoP expands CAMIX’s physical opportunity set and may already improve access for some Douala entities. The public evidence is limited public evidence to say that CAMIX can lose any one site while preserving a broad domestic exchange path. The gap is answerable: map the shared risks, identify powered components, classify member paths, publish control-plane placement, and run the failure.
When a packet can begin on one Cameroonian network, traverse a surviving CAMIX site, and reach another Cameroonian network after Bépanda, ST-DIGITAL or CAMPOST has been deliberately removed—without an international detour—the third PoP will have passed the test implied by its name. Until that packet trace exists, CAMIX has three points of presence and an important resilience proposition still waiting to be proven.

