home.social

#rpki — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #rpki, aggregated by home.social.

fetched live
  1. Without a ROA, your prefix announced from someone else's network looks exactly like your prefix announced from yours. A router has nothing to check it against.

    A ROA names which network is allowed to originate your prefix. Anyone else announcing it is then RPKI invalid, and networks filtering on validation drop them. That is the whole reason to sign.

    With isp6 it's a button on the dashboard: type your origin AS, press Add, and we publish the ROA to RIPE.

    #RPKI #BGP #IPv6

  2. Without a ROA, your prefix announced from someone else's network looks exactly like your prefix announced from yours. A router has nothing to check it against.

    A ROA names which network is allowed to originate your prefix. Anyone else announcing it is then RPKI invalid, and networks filtering on validation drop them. That is the whole reason to sign.

    With isp6 it's a button on the dashboard: type your origin AS, press Add, and we publish the ROA to RIPE.

    #RPKI #BGP #IPv6

  3. Without a ROA, your prefix announced from someone else's network looks exactly like your prefix announced from yours. A router has nothing to check it against.

    A ROA names which network is allowed to originate your prefix. Anyone else announcing it is then RPKI invalid, and networks filtering on validation drop them. That is the whole reason to sign.

    With isp6 it's a button on the dashboard: type your origin AS, press Add, and we publish the ROA to RIPE.

    #RPKI #BGP #IPv6

  4. Approximately 3.5% of ASNs seen making #BGP announcements have created RPKI #ASPA objects.

    This is a decent ramp up before the spec is even out of draft and the big iron from commercial router vendors have production code deployed for validating these (ASPA) paths from the #RPKI.

    social.bgp.tools/@newaspa/stat

  5. Approximately 3.5% of ASNs seen making #BGP announcements have created RPKI #ASPA objects.

    This is a decent ramp up before the spec is even out of draft and the big iron from commercial router vendors have production code deployed for validating these (ASPA) paths from the #RPKI.

    social.bgp.tools/@newaspa/stat

  6. Approximately 3.5% of ASNs seen making #BGP announcements have created RPKI #ASPA objects.

    This is a decent ramp up before the spec is even out of draft and the big iron from commercial router vendors have production code deployed for validating these (ASPA) paths from the #RPKI.

    social.bgp.tools/@newaspa/stat

  7. Approximately 3.5% of ASNs seen making #BGP announcements have created RPKI #ASPA objects.

    This is a decent ramp up before the spec is even out of draft and the big iron from commercial router vendors have production code deployed for validating these (ASPA) paths from the #RPKI.

    social.bgp.tools/@newaspa/stat

  8. Approximately 3.5% of ASNs seen making #BGP announcements have created RPKI #ASPA objects.

    This is a decent ramp up before the spec is even out of draft and the big iron from commercial router vendors have production code deployed for validating these (ASPA) paths from the #RPKI.

    social.bgp.tools/@newaspa/stat

  9. For future reference:

    /usr/bin/sh -c 'awk -v RS="" "/protocol static {\n\s+aspa/,/^}/" < /etc/bird-rpki/bird > /etc/bird-rpki/birdfilt'

    #rpki #bird #bgp

  10. For future reference:

    /usr/bin/sh -c 'awk -v RS="" "/protocol static {\n\s+aspa/,/^}/" < /etc/bird-rpki/bird > /etc/bird-rpki/birdfilt'

    #rpki #bird #bgp

  11. For future reference:

    /usr/bin/sh -c 'awk -v RS="" "/protocol static {\n\s+aspa/,/^}/" < /etc/bird-rpki/bird > /etc/bird-rpki/birdfilt'

    #rpki #bird #bgp

  12. For future reference:

    /usr/bin/sh -c 'awk -v RS="" "/protocol static {\n\s+aspa/,/^}/" < /etc/bird-rpki/bird > /etc/bird-rpki/birdfilt'

    #rpki #bird #bgp

  13. Can I get ASPA validation (with Debian stable packages?)
    fort-validator 1.6.6 does not seem to have it (only 1.7.0-experimental?)
    stayrtr 0.6.4 apparently doesn't either.
    What now?

    #bgp #rpki #aspa

  14. Can I get ASPA validation (with Debian stable packages?)
    fort-validator 1.6.6 does not seem to have it (only 1.7.0-experimental?)
    stayrtr 0.6.4 apparently doesn't either.
    What now?

    #bgp #rpki #aspa

  15. Can I get ASPA validation (with Debian stable packages?)
    fort-validator 1.6.6 does not seem to have it (only 1.7.0-experimental?)
    stayrtr 0.6.4 apparently doesn't either.
    What now?

    #bgp #rpki #aspa

  16. Can I get ASPA validation (with Debian stable packages?)
    fort-validator 1.6.6 does not seem to have it (only 1.7.0-experimental?)
    stayrtr 0.6.4 apparently doesn't either.
    What now?

    #bgp #rpki #aspa

  17. BGP security stack complete for AS201379: ASPA records published for upstream authorization, backed by valid RPKI ROAs and IRR objects.

    #AS201379 #BGP #RPKI #ASPA #IPv6 #RoutingSecurity #NetOps

  18. BGP security stack complete for AS201379: ASPA records published for upstream authorization, backed by valid RPKI ROAs and IRR objects.

    #AS201379 #BGP #RPKI #ASPA #IPv6 #RoutingSecurity #NetOps

  19. BGP security stack complete for AS201379: ASPA records published for upstream authorization, backed by valid RPKI ROAs and IRR objects.

    #AS201379 #BGP #RPKI #ASPA #IPv6 #RoutingSecurity #NetOps

  20. BGP security stack complete for AS201379: ASPA records published for upstream authorization, backed by valid RPKI ROAs and IRR objects.

    #AS201379 #BGP #RPKI #ASPA #IPv6 #RoutingSecurity #NetOps

  21. BGP security stack complete for AS201379: ASPA records published for upstream authorization, backed by valid RPKI ROAs and IRR objects.

    #AS201379 #BGP #RPKI #ASPA #IPv6 #RoutingSecurity #NetOps

  22. New blog post: Don't Deserialize: Serving 1.5M RPKI ROA Records from a Memory-Mapped Trie
    #BGP #RPKI
    bgpkit.com/blog/zero-copy-pref

  23. New blog post: Don't Deserialize: Serving 1.5M RPKI ROA Records from a Memory-Mapped Trie
    #BGP #RPKI
    bgpkit.com/blog/zero-copy-pref

  24. New blog post: Don't Deserialize: Serving 1.5M RPKI ROA Records from a Memory-Mapped Trie
    #BGP #RPKI
    bgpkit.com/blog/zero-copy-pref

  25. New blog post: Don't Deserialize: Serving 1.5M RPKI ROA Records from a Memory-Mapped Trie
    #BGP #RPKI
    bgpkit.com/blog/zero-copy-pref

  26. New blog post: Don't Deserialize: Serving 1.5M RPKI ROA Records from a Memory-Mapped Trie
    #BGP #RPKI
    bgpkit.com/blog/zero-copy-pref

  27. bgpipe v0.22 is out! 🚀

    New: MRT table dump support. A full RIB snapshot from RouteViews or RIPE RIS now streams as BGP updates, each tagged with the peer it came from.

    Which means every stage you already use just works on them:

    bgpipe --rpki <cache> -- read rib.bz2 -- rov -- grep 'tag[rov/status] == INVALID'

    That is RPKI validation of an entire routing table. 4.1M routes in 7s, validated in 8s.

    bgpipe.org

    #BGP #RPKI #networking

  28. bgpipe v0.22 is out! 🚀

    New: MRT table dump support. A full RIB snapshot from RouteViews or RIPE RIS now streams as BGP updates, each tagged with the peer it came from.

    Which means every stage you already use just works on them:

    bgpipe --rpki <cache> -- read rib.bz2 -- rov -- grep 'tag[rov/status] == INVALID'

    That is RPKI validation of an entire routing table. 4.1M routes in 7s, validated in 8s.

    bgpipe.org

    #BGP #RPKI #networking

  29. bgpipe v0.22 is out! 🚀

    New: MRT table dump support. A full RIB snapshot from RouteViews or RIPE RIS now streams as BGP updates, each tagged with the peer it came from.

    Which means every stage you already use just works on them:

    bgpipe --rpki <cache> -- read rib.bz2 -- rov -- grep 'tag[rov/status] == INVALID'

    That is RPKI validation of an entire routing table. 4.1M routes in 7s, validated in 8s.

    bgpipe.org

    #BGP #RPKI #networking

  30. bgpipe v0.22 is out! 🚀

    New: MRT table dump support. A full RIB snapshot from RouteViews or RIPE RIS now streams as BGP updates, each tagged with the peer it came from.

    Which means every stage you already use just works on them:

    bgpipe --rpki <cache> -- read rib.bz2 -- rov -- grep 'tag[rov/status] == INVALID'

    That is RPKI validation of an entire routing table. 4.1M routes in 7s, validated in 8s.

    bgpipe.org

    #BGP #RPKI #networking

  31. bgpipe v0.22 is out! 🚀

    New: MRT table dump support. A full RIB snapshot from RouteViews or RIPE RIS now streams as BGP updates, each tagged with the peer it came from.

    Which means every stage you already use just works on them:

    bgpipe --rpki <cache> -- read rib.bz2 -- rov -- grep 'tag[rov/status] == INVALID'

    That is RPKI validation of an entire routing table. 4.1M routes in 7s, validated in 8s.

    bgpipe.org

    #BGP #RPKI #networking