Skip to content

Your automated RPKI invalid filtering has false positives

Networking by liam_funky 6 replies 427 views
#1

1. Background
A) I operate a small anycast network
B) Prefix: 203.0.113.0/24
C) Origin AS 64496

2. The problem
A) Your automated RPKI filtering marked my prefix INVALID yesterday
B) No outage on other upstreams
C) ROA valid per rpki-validator, your tool disagreed

3. Timeline
I. 14:00 UTC - routine ROA refresh
Ii. 14:03 UTC - your filters applied new state
Iii. 14:05 UTC - traffic dropped 40%
Iv. 14:30 UTC - manual intervention restored

4. Request
A) Review timing between ROA propagation and filter application
B) Grace period of 15 minutes would prevent this

5. Contact
A) My NOC available 24/7
B) Happy to share logs

#2

He, my VPS it had same problem last month!!! Caramba!!!

My provider it filtered my prefix more fast than the ROA he propagated, nossa!!! Not funny when he happens at 3am

I think he is timing bug too, my ROA was new but valid

4 #3

Yaml
Rpki_filtering:
Timing_bug: true
Symptoms:
- ROA_valid: true
- filter_state: INVALID
- propagation_delay: ignored
Fix:
- RTFM # the RFC
- add:
- grace_period: 900s
- staggered_deployment: true

`rpki-client` has this. `routinator` too. Your code does not.

RTFM

traffic worse than my packet loss
4 #4

@liam_funky lah your list very nice leh

Can confirm same thing happen to me before lor

Already move to different upstream liao

Their ROA cache stale one

#5

Stale cache hits anycast hardest.

#6

Which rpki-client version did they deploy

#7

Which upstream and what grace period

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft