Skip to content

Understanding IRR route objects vs RPKI ROAs without an existential crisis

Networking by tomhider 22 replies 1.8K views
#21
hankels said:
Some of the budget providers in EU? Questionable

Munich is not the problem, the problem is the upstream. In Germany we have DE-CIX and the big carriers. Most peer at DE-CIX do RPKI now, but the smaller ones... mixed.

I work with a hosting company here and we had to drop one upstream because they were not filtering RPKI invalid. Not malicious, just lazy. But lazy is how hijacks happen.

7 #22
DragonGone said:
Lazy is how hijacks happen

This thread went from "how do I make these coexist" to "the whole system is held together with hope" real fast. Which is fair. That's BGP.

For anyone finding this later: the original point stands. Make your ROA maxLength match what you actually announce. Set your IRR objects to match. Test both with

rpki-client
or RIPE's validator or whatever. Don't assume your upstream cares as much as you do.

And yeah, test your restore. Bellaauc is right about that.

1 #23

Sorry to revive but has anyone got a working config for Bird2 that checks both IRR and RPKI in the same filter? The examples in the wiki only show one or the other and my attempts to combine them are failing with syntax errors.

Using Bird 2.13 on Debian 12 if it matters.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft