Munich is not the problem, the problem is the upstream. In Germany we have DE-CIX and the big carriers. Most peer at DE-CIX do RPKI now, but the smaller ones... mixed.
I work with a hosting company here and we had to drop one upstream because they were not filtering RPKI invalid. Not malicious, just lazy. But lazy is how hijacks happen.
This thread went from "how do I make these coexist" to "the whole system is held together with hope" real fast. Which is fair. That's BGP.
For anyone finding this later: the original point stands. Make your ROA maxLength match what you actually announce. Set your IRR objects to match. Test both with
rpki-client
or RIPE's validator or whatever. Don't assume your upstream cares as much as you do.
And yeah, test your restore. Bellaauc is right about that.
Sorry to revive but has anyone got a working config for Bird2 that checks both IRR and RPKI in the same filter? The examples in the wiki only show one or the other and my attempts to combine them are failing with syntax errors.
Using Bird 2.13 on Debian 12 if it matters.
Post a reply
You need an account to reply.
Log in or
register to join the conversation.