SlideShare a Scribd company logo
1 of 35
Download to read offline
https://twitter.com/rapappuhttp://bd.linkedin.com/in/fakrulalamfakrul@bdhub.comFakrul Alam
RPKI Deployment Status in Bangladesh
Agenda
โ€ข Little background on BGP & RPKI
โ€ข Creating ROA
โ€ข RPKI Status in Bangladesh
BGP
BGP (AS)
Send a packet to
2001:DB8::1
I have
2001:DB8::/32
AS Path
AS 100 AS 300AS 200
Send a packet to
2001:DB8::1
I have
2001:DB8::/32
2001:DB8::/32 100 200 300 i
AS Path
AS 100 AS 300
Send a packet to
2001:DB8::1
I have
2001:DB8::/32
I have
2001:DB8::/48
AS 420
AS 200
2001:DB8::/32 100 200 300 i
2001:DB8::/48 100 200 400 i
Current Trend
โ€ข Filtering limited to the edges facing the customer
โ€ข Filters on peering and transit sessions are often too complex or take too
many resources
โ€ข Check pre๏ฌx before announcing it
Filter Where?
โ€ข Secure BGP Templates
โ€ข http://www.cymru.com/gillsr/
documents/junos-bgp-
template.htm
โ€ข https://www.team-cymru.org/
ReadingRoom/Templates/
secure-bgp-template.html
Internet Registry (IR)
โ€ข Maintains Internet Resources such as IP addresses and ASNs, and publish
the registration information
โ€ข Allocations for Local Internet Registries
โ€ข Assignments for end-users
โ€ข APNIC is the Regional Internet Registry(RIR) in the Asia Paci๏ฌc region
โ€ข National Internet Registry(NIR) exists in several economies
The Eco-System
National IR (NIR)
Internet Service Provider
End User
Regional IR (RIR)
Still not enough
IRR is useful, but itโ€™s not perfect
RPKI
Resource Pubic Key Infrastructure
IP Address & AS Numbers Digital Certi๏ฌcate
RPKI Deployment
AS 100 AS 300AS 200
Phase 2
Path Validation
Send a packet to
2001:DB8::1
I have
2001:DB8::/32
Phase 1
Origin Validation
Goals of RPKI
โ€ข Able to authoritatively prove who owns an IP Pre๏ฌx and what AS(s) may
Announce It
โ€ข Reducing routing leaks
โ€ข Attaching digital certi๏ฌcates to network resources (AS Number & IP
Address)
โ€ข Pre๏ฌx Ownership Follows the Allocation Hierarchy IANA, RIRs, ISPs, โ€ฆ
Create Your ROA
Phase I - Publishing ROA
โ€ข Login to your MyAPNIC portal
โ€ข Required valid certi๏ฌcate
โ€ข Go to Resources > Certi๏ฌcation Tab
1
2
*
Phase I - Publishing ROA
1
2
3
Phase I - Publishing ROA
โ€ข Show available pre๏ฌx for which you can create ROA
Phase I - Publishing ROA - IPv4
1. Write your ASN 2. Your IP Block 3. Subnet 4. Click Add
โ€ข Create ROA for smaller block.
Phase I - Publishing ROA - IPv6
โ€ข ROA for your IPv6 pre๏ฌx
1. Write your ASN 2. Your IP Block 3. Subnet 4. Click Add
Phase I - Check your ROA
# whois -h whois.bgpmon.net 202.4.96.0/24
Prefix: 202.4.96.0/24
Prefix description: APT (Dhakacom)
Country code: BD
Origin AS: 23956
Origin AS Name: DHAKACOM-BD-AS dhakaCom Limited,BD
RPKI status: ROA validation successful
First seen: 2013-12-23
Last seen: 2014-07-20
Seen by #peers: 203
# whois -h whois.bgpmon.net " --roa 23956 202.4.96.0/24"
0 - Valid
------------------------
ROA Details
------------------------
Origin ASN: AS23956
Not valid Before: 2014-07-20 15:20:10
Not valid After: 2014-12-30 00:00:00 Expires in 161d12h52m42s
Trust Anchor: rpki.apnic.net
Prefixes: 202.4.96.0/19 (max length /24)
2405:7600::/32 (max length /32)
Phase I - Check your ROA
Check your pre๏ฌx
Cisco (hosted by the RIPE NCC)
Public Cisco router: rpki-rtr.ripe.net
Telnet username: ripe / No password
Juniper (hosted by Kaia Global Networks)
Public Juniper routers: 193.34.50.25, 193.34.50.26
Telnet username: rpki / Password: testbed
source : http://www.ripe.net/lir-services/resource-management/certi๏ฌcation/tools-and-resources
Con๏ฌguration - Reference Link
Cisco
http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/iproute_bgp/command/irg-cr-
book/bgp-m1.html#wp3677719851
Juniper
http://www.juniper.net/techpubs/en_US/junos12.2/topics/topic-map/bgp-origin-
as-validation.html
RPKI Status in Bangladesh
Is some one really announcing my
pre๏ฌx!!!
source : https://www.internetsociety.org/rrs/
ISOC Routing Resiliency Survey
RPKI Breakdown
Total Pre๏ฌx Valid Invalid Unknown Accuracy
RPKI
Adoption
Rate
APNIC
135876
(100%)
581 (0.43%) 684 (0.5%)
134611
(99.07%)
45.93% 0.93%
BD 2079 (100%) 71 (3.42%) 26 (1.25%)
1982
(95.33%)
73.2% 4.67%
source : http://rpki.surfnet.nl/perrir.html & http://rpki.surfnet.nl/country.php
Adoption Rate RPKI vs IPv6
RPKI Adoption 4.67%
source : https://www.google.com/intl/en/ipv6/statistics.html#tab=per-country-ipv6-adoption
Invalid Pre๏ฌx
source : http://rpki.surfnet.nl/bd.html
All Invalid pre๏ฌxes from BD
source : http://rpki.surfnet.nl/bd.html
All Invalid pre๏ฌxes from BD
source : http://rpki.surfnet.nl/bd.html
Something more serious
source : https://stat.ripe.net/widget/announced-pre๏ฌxes#w.resource=58717
source : http://www.cidr-report.org/cgi-bin/as-report?as=as58717&view=2.0
Special thanks to
Jac Kloots
SURFnet
http://rpki.surfnet.nl/index.html
Thank You

More Related Content

What's hot

The Next Generation Internet Number Registry Services
The Next Generation Internet Number Registry ServicesThe Next Generation Internet Number Registry Services
The Next Generation Internet Number Registry ServicesMyNOG
ย 
Routing Security - its importance and status in South Asia
Routing Security - its importance and status in South AsiaRouting Security - its importance and status in South Asia
Routing Security - its importance and status in South AsiaBangladesh Network Operators Group
ย 
APNIC Updates
APNIC UpdatesAPNIC Updates
APNIC UpdatesMyNOG
ย 
Network State Awareness & Troubleshooting
Network State Awareness & TroubleshootingNetwork State Awareness & Troubleshooting
Network State Awareness & TroubleshootingAPNIC
ย 
RPKI: An Operatorโ€™s Implementation
RPKI: An Operatorโ€™s ImplementationRPKI: An Operatorโ€™s Implementation
RPKI: An Operatorโ€™s ImplementationMyNOG
ย 
Rpki -manrs_(7_september)
Rpki  -manrs_(7_september)Rpki  -manrs_(7_september)
Rpki -manrs_(7_september)NaveenLakshman
ย 
Route Origin Validation With Routinator - A MANRS Approach for Operators
Route Origin Validation With Routinator - A MANRS Approach for OperatorsRoute Origin Validation With Routinator - A MANRS Approach for Operators
Route Origin Validation With Routinator - A MANRS Approach for OperatorsBangladesh Network Operators Group
ย 
Traffic Engineering Using Segment Routing
Traffic Engineering Using Segment Routing Traffic Engineering Using Segment Routing
Traffic Engineering Using Segment Routing Cisco Canada
ย 
Flowspec @ Bay Area Juniper User Group (BAJUG)
Flowspec @ Bay Area Juniper User Group (BAJUG)Flowspec @ Bay Area Juniper User Group (BAJUG)
Flowspec @ Bay Area Juniper User Group (BAJUG)Juniper Networks
ย 
Innovation is back in the transport and network layers
Innovation is back in the transport and network layersInnovation is back in the transport and network layers
Innovation is back in the transport and network layersOlivier Bonaventure
ย 
RPKI (Resource Public Key Infrastructure)
RPKI (Resource Public Key Infrastructure)RPKI (Resource Public Key Infrastructure)
RPKI (Resource Public Key Infrastructure)Fakrul Alam
ย 
PhNOG 2020: Securing your resources with RPKI and IRT
PhNOG 2020: Securing your resources with RPKI and IRTPhNOG 2020: Securing your resources with RPKI and IRT
PhNOG 2020: Securing your resources with RPKI and IRTAPNIC
ย 
Setting up VPN between F5 LTM & ASA
Setting up VPN between F5 LTM & ASASetting up VPN between F5 LTM & ASA
Setting up VPN between F5 LTM & ASADhruv Sharma
ย 
Resource Public Key Infrastructure - A Step Towards a More Secure Internet Ro...
Resource Public Key Infrastructure - A Step Towards a More Secure Internet Ro...Resource Public Key Infrastructure - A Step Towards a More Secure Internet Ro...
Resource Public Key Infrastructure - A Step Towards a More Secure Internet Ro...akg1330
ย 
TechWiseTV Workshop: Segment Routing for the Datacenter
TechWiseTV Workshop: Segment Routing for the DatacenterTechWiseTV Workshop: Segment Routing for the Datacenter
TechWiseTV Workshop: Segment Routing for the DatacenterRobb Boyd
ย 
PhNOG 2020: ROA and RPKI in the Philippines
PhNOG 2020: ROA and RPKI in the PhilippinesPhNOG 2020: ROA and RPKI in the Philippines
PhNOG 2020: ROA and RPKI in the PhilippinesAPNIC
ย 
NZNOG 2020: APNIC update
NZNOG 2020: APNIC updateNZNOG 2020: APNIC update
NZNOG 2020: APNIC updateAPNIC
ย 
An Introduction to BGP Flow Spec
An Introduction to BGP Flow SpecAn Introduction to BGP Flow Spec
An Introduction to BGP Flow SpecShortestPathFirst
ย 

What's hot (20)

The Next Generation Internet Number Registry Services
The Next Generation Internet Number Registry ServicesThe Next Generation Internet Number Registry Services
The Next Generation Internet Number Registry Services
ย 
Routing Security - its importance and status in South Asia
Routing Security - its importance and status in South AsiaRouting Security - its importance and status in South Asia
Routing Security - its importance and status in South Asia
ย 
APNIC Updates
APNIC UpdatesAPNIC Updates
APNIC Updates
ย 
Network State Awareness & Troubleshooting
Network State Awareness & TroubleshootingNetwork State Awareness & Troubleshooting
Network State Awareness & Troubleshooting
ย 
RPKI: An Operatorโ€™s Implementation
RPKI: An Operatorโ€™s ImplementationRPKI: An Operatorโ€™s Implementation
RPKI: An Operatorโ€™s Implementation
ย 
Rpki -manrs_(7_september)
Rpki  -manrs_(7_september)Rpki  -manrs_(7_september)
Rpki -manrs_(7_september)
ย 
Route Origin Validation With Routinator - A MANRS Approach for Operators
Route Origin Validation With Routinator - A MANRS Approach for OperatorsRoute Origin Validation With Routinator - A MANRS Approach for Operators
Route Origin Validation With Routinator - A MANRS Approach for Operators
ย 
Traffic Engineering Using Segment Routing
Traffic Engineering Using Segment Routing Traffic Engineering Using Segment Routing
Traffic Engineering Using Segment Routing
ย 
Flowspec @ Bay Area Juniper User Group (BAJUG)
Flowspec @ Bay Area Juniper User Group (BAJUG)Flowspec @ Bay Area Juniper User Group (BAJUG)
Flowspec @ Bay Area Juniper User Group (BAJUG)
ย 
Innovation is back in the transport and network layers
Innovation is back in the transport and network layersInnovation is back in the transport and network layers
Innovation is back in the transport and network layers
ย 
RPKI (Resource Public Key Infrastructure)
RPKI (Resource Public Key Infrastructure)RPKI (Resource Public Key Infrastructure)
RPKI (Resource Public Key Infrastructure)
ย 
PhNOG 2020: Securing your resources with RPKI and IRT
PhNOG 2020: Securing your resources with RPKI and IRTPhNOG 2020: Securing your resources with RPKI and IRT
PhNOG 2020: Securing your resources with RPKI and IRT
ย 
Resource Public Key Infrastructure (RPKI)
Resource Public Key Infrastructure (RPKI) Resource Public Key Infrastructure (RPKI)
Resource Public Key Infrastructure (RPKI)
ย 
Setting up VPN between F5 LTM & ASA
Setting up VPN between F5 LTM & ASASetting up VPN between F5 LTM & ASA
Setting up VPN between F5 LTM & ASA
ย 
Resource Public Key Infrastructure - A Step Towards a More Secure Internet Ro...
Resource Public Key Infrastructure - A Step Towards a More Secure Internet Ro...Resource Public Key Infrastructure - A Step Towards a More Secure Internet Ro...
Resource Public Key Infrastructure - A Step Towards a More Secure Internet Ro...
ย 
TechWiseTV Workshop: Segment Routing for the Datacenter
TechWiseTV Workshop: Segment Routing for the DatacenterTechWiseTV Workshop: Segment Routing for the Datacenter
TechWiseTV Workshop: Segment Routing for the Datacenter
ย 
PhNOG 2020: ROA and RPKI in the Philippines
PhNOG 2020: ROA and RPKI in the PhilippinesPhNOG 2020: ROA and RPKI in the Philippines
PhNOG 2020: ROA and RPKI in the Philippines
ย 
NZNOG 2020: APNIC update
NZNOG 2020: APNIC updateNZNOG 2020: APNIC update
NZNOG 2020: APNIC update
ย 
An Introduction to BGP Flow Spec
An Introduction to BGP Flow SpecAn Introduction to BGP Flow Spec
An Introduction to BGP Flow Spec
ย 
14121725(1).ppt
14121725(1).ppt14121725(1).ppt
14121725(1).ppt
ย 

Viewers also liked

Towards characterizing international routing detours
Towards characterizing international routing detoursTowards characterizing international routing detours
Towards characterizing international routing detoursAPNIC
ย 
Route Origin Authorization (ROA) using RPKI, PhNOG, Philippines
Route Origin Authorization (ROA) using RPKI, PhNOG, PhilippinesRoute Origin Authorization (ROA) using RPKI, PhNOG, Philippines
Route Origin Authorization (ROA) using RPKI, PhNOG, PhilippinesAPNIC
ย 
BGP Hijack Issue on Nov 6 2015
BGP Hijack Issue on Nov 6 2015BGP Hijack Issue on Nov 6 2015
BGP Hijack Issue on Nov 6 2015APNIC
ย 
Resource Certification
Resource CertificationResource Certification
Resource CertificationRIPE NCC
ย 
Certification
CertificationCertification
CertificationRIPE NCC
ย 
Tutorial: Using GoBGP as an IXP connecting router
Tutorial: Using GoBGP as an IXP connecting routerTutorial: Using GoBGP as an IXP connecting router
Tutorial: Using GoBGP as an IXP connecting routerShu Sugimoto
ย 

Viewers also liked (6)

Towards characterizing international routing detours
Towards characterizing international routing detoursTowards characterizing international routing detours
Towards characterizing international routing detours
ย 
Route Origin Authorization (ROA) using RPKI, PhNOG, Philippines
Route Origin Authorization (ROA) using RPKI, PhNOG, PhilippinesRoute Origin Authorization (ROA) using RPKI, PhNOG, Philippines
Route Origin Authorization (ROA) using RPKI, PhNOG, Philippines
ย 
BGP Hijack Issue on Nov 6 2015
BGP Hijack Issue on Nov 6 2015BGP Hijack Issue on Nov 6 2015
BGP Hijack Issue on Nov 6 2015
ย 
Resource Certification
Resource CertificationResource Certification
Resource Certification
ย 
Certification
CertificationCertification
Certification
ย 
Tutorial: Using GoBGP as an IXP connecting router
Tutorial: Using GoBGP as an IXP connecting routerTutorial: Using GoBGP as an IXP connecting router
Tutorial: Using GoBGP as an IXP connecting router
ย 

Similar to RPKI Deployment Status in Bangladesh

Route Hijaking and the role of RPKI
Route Hijaking and the role of RPKIRoute Hijaking and the role of RPKI
Route Hijaking and the role of RPKIAPNIC
ย 
32nd TWNIC IP OPM: ROA+ROV deployment & industry development
32nd TWNIC IP OPM: ROA+ROV deployment & industry development32nd TWNIC IP OPM: ROA+ROV deployment & industry development
32nd TWNIC IP OPM: ROA+ROV deployment & industry developmentAPNIC
ย 
VNIX-NOG 2023: State of RPKI in APAC - Cleaning up invalids
VNIX-NOG 2023: State of RPKI in APAC - Cleaning up invalidsVNIX-NOG 2023: State of RPKI in APAC - Cleaning up invalids
VNIX-NOG 2023: State of RPKI in APAC - Cleaning up invalidsAPNIC
ย 
State of RPKI in Cambodia and SEA, presentation by Shane Hermoso for KHNOG
State of RPKI in Cambodia and SEA, presentation by Shane Hermoso for KHNOG  State of RPKI in Cambodia and SEA, presentation by Shane Hermoso for KHNOG
State of RPKI in Cambodia and SEA, presentation by Shane Hermoso for KHNOG APNIC
ย 
HKNOG 7.0: RPKI - it's time to start deploying it
HKNOG 7.0: RPKI - it's time to start deploying itHKNOG 7.0: RPKI - it's time to start deploying it
HKNOG 7.0: RPKI - it's time to start deploying itAPNIC
ย 
IAA Life in Lockdown series: Securing Internet Routing
IAA Life in Lockdown series: Securing Internet RoutingIAA Life in Lockdown series: Securing Internet Routing
IAA Life in Lockdown series: Securing Internet RoutingAPNIC
ย 
npNOG 5: Securing Internet Routing
npNOG 5: Securing Internet Routing npNOG 5: Securing Internet Routing
npNOG 5: Securing Internet Routing APNIC
ย 
IXP Route Servers with RPKI and IXP Manager
IXP Route Servers with RPKI and IXP ManagerIXP Route Servers with RPKI and IXP Manager
IXP Route Servers with RPKI and IXP ManagerAPNIC
ย 
ICANN APAC-TWNIC Engagement Forum: Internet Number Registry Services - The Ne...
ICANN APAC-TWNIC Engagement Forum: Internet Number Registry Services - The Ne...ICANN APAC-TWNIC Engagement Forum: Internet Number Registry Services - The Ne...
ICANN APAC-TWNIC Engagement Forum: Internet Number Registry Services - The Ne...APNIC
ย 
Introduction to RPKI
Introduction to RPKIIntroduction to RPKI
Introduction to RPKIAPNIC
ย 
Routing Registry Function Automation using RPKI & RPSL
Routing Registry Function Automation using RPKI & RPSLRouting Registry Function Automation using RPKI & RPSL
Routing Registry Function Automation using RPKI & RPSLAPNIC
ย 
RPKI Overview, Case Studies, Deployment and Operations
RPKI Overview, Case Studies, Deployment and OperationsRPKI Overview, Case Studies, Deployment and Operations
RPKI Overview, Case Studies, Deployment and OperationsAPNIC
ย 
BGP
BGPBGP
BGPKHNOG
ย 
Cloud Traffic Engineer โ€“ Google Espresso Project by Shaowen Ma
Cloud Traffic Engineer โ€“ Google Espresso Project  by Shaowen MaCloud Traffic Engineer โ€“ Google Espresso Project  by Shaowen Ma
Cloud Traffic Engineer โ€“ Google Espresso Project by Shaowen MaMyNOG
ย 
PhNOG 2019: RPKI Deployment Update
PhNOG 2019: RPKI Deployment UpdatePhNOG 2019: RPKI Deployment Update
PhNOG 2019: RPKI Deployment UpdateAPNIC
ย 
SIP and DNS - federation, failover, load balancing and more
SIP and DNS - federation, failover, load balancing and moreSIP and DNS - federation, failover, load balancing and more
SIP and DNS - federation, failover, load balancing and moreOlle E Johansson
ย 

Similar to RPKI Deployment Status in Bangladesh (20)

Route Hijaking and the role of RPKI
Route Hijaking and the role of RPKIRoute Hijaking and the role of RPKI
Route Hijaking and the role of RPKI
ย 
32nd TWNIC IP OPM: ROA+ROV deployment & industry development
32nd TWNIC IP OPM: ROA+ROV deployment & industry development32nd TWNIC IP OPM: ROA+ROV deployment & industry development
32nd TWNIC IP OPM: ROA+ROV deployment & industry development
ย 
VNIX-NOG 2023: State of RPKI in APAC - Cleaning up invalids
VNIX-NOG 2023: State of RPKI in APAC - Cleaning up invalidsVNIX-NOG 2023: State of RPKI in APAC - Cleaning up invalids
VNIX-NOG 2023: State of RPKI in APAC - Cleaning up invalids
ย 
State of RPKI in Cambodia and SEA, presentation by Shane Hermoso for KHNOG
State of RPKI in Cambodia and SEA, presentation by Shane Hermoso for KHNOG  State of RPKI in Cambodia and SEA, presentation by Shane Hermoso for KHNOG
State of RPKI in Cambodia and SEA, presentation by Shane Hermoso for KHNOG
ย 
HKNOG 7.0: RPKI - it's time to start deploying it
HKNOG 7.0: RPKI - it's time to start deploying itHKNOG 7.0: RPKI - it's time to start deploying it
HKNOG 7.0: RPKI - it's time to start deploying it
ย 
Route Origin Validation - A MANRS Approach
Route Origin Validation - A MANRS ApproachRoute Origin Validation - A MANRS Approach
Route Origin Validation - A MANRS Approach
ย 
IAA Life in Lockdown series: Securing Internet Routing
IAA Life in Lockdown series: Securing Internet RoutingIAA Life in Lockdown series: Securing Internet Routing
IAA Life in Lockdown series: Securing Internet Routing
ย 
npNOG 5: Securing Internet Routing
npNOG 5: Securing Internet Routing npNOG 5: Securing Internet Routing
npNOG 5: Securing Internet Routing
ย 
IXP Route Servers with RPKI and IXP Manager
IXP Route Servers with RPKI and IXP ManagerIXP Route Servers with RPKI and IXP Manager
IXP Route Servers with RPKI and IXP Manager
ย 
ICANN APAC-TWNIC Engagement Forum: Internet Number Registry Services - The Ne...
ICANN APAC-TWNIC Engagement Forum: Internet Number Registry Services - The Ne...ICANN APAC-TWNIC Engagement Forum: Internet Number Registry Services - The Ne...
ICANN APAC-TWNIC Engagement Forum: Internet Number Registry Services - The Ne...
ย 
ION Belfast - Securing BGP - David Freedman
ION Belfast - Securing BGP - David FreedmanION Belfast - Securing BGP - David Freedman
ION Belfast - Securing BGP - David Freedman
ย 
Introduction to RPKI
Introduction to RPKIIntroduction to RPKI
Introduction to RPKI
ย 
Bgp (1)
Bgp (1)Bgp (1)
Bgp (1)
ย 
Routing Registry Function Automation using RPKI & RPSL
Routing Registry Function Automation using RPKI & RPSLRouting Registry Function Automation using RPKI & RPSL
Routing Registry Function Automation using RPKI & RPSL
ย 
RPKI Overview, Case Studies, Deployment and Operations
RPKI Overview, Case Studies, Deployment and OperationsRPKI Overview, Case Studies, Deployment and Operations
RPKI Overview, Case Studies, Deployment and Operations
ย 
BGP
BGPBGP
BGP
ย 
Cloud Traffic Engineer โ€“ Google Espresso Project by Shaowen Ma
Cloud Traffic Engineer โ€“ Google Espresso Project  by Shaowen MaCloud Traffic Engineer โ€“ Google Espresso Project  by Shaowen Ma
Cloud Traffic Engineer โ€“ Google Espresso Project by Shaowen Ma
ย 
PhNOG 2019: RPKI Deployment Update
PhNOG 2019: RPKI Deployment UpdatePhNOG 2019: RPKI Deployment Update
PhNOG 2019: RPKI Deployment Update
ย 
SIP and DNS - federation, failover, load balancing and more
SIP and DNS - federation, failover, load balancing and moreSIP and DNS - federation, failover, load balancing and more
SIP and DNS - federation, failover, load balancing and more
ย 
2012 ah vegas top10 tips from aruba tac
2012 ah vegas   top10 tips from aruba tac2012 ah vegas   top10 tips from aruba tac
2012 ah vegas top10 tips from aruba tac
ย 

More from Bangladesh Network Operators Group

Accelerating Hyper-Converged Enterprise Virtualization using Proxmox and Ceph
Accelerating Hyper-Converged Enterprise Virtualization using Proxmox and CephAccelerating Hyper-Converged Enterprise Virtualization using Proxmox and Ceph
Accelerating Hyper-Converged Enterprise Virtualization using Proxmox and CephBangladesh Network Operators Group
ย 
Network eWaste : Community role to manage end of life Product
Network eWaste : Community role to manage end of life ProductNetwork eWaste : Community role to manage end of life Product
Network eWaste : Community role to manage end of life ProductBangladesh Network Operators Group
ย 
A plenarily integrated SIEM solution and itโ€™s Deployment
A plenarily integrated SIEM solution and itโ€™s DeploymentA plenarily integrated SIEM solution and itโ€™s Deployment
A plenarily integrated SIEM solution and itโ€™s DeploymentBangladesh Network Operators Group
ย 
Contents Localization Initiatives to get better User Experience
Contents Localization Initiatives to get better User ExperienceContents Localization Initiatives to get better User Experience
Contents Localization Initiatives to get better User ExperienceBangladesh Network Operators Group
ย 
Re-define network visibility for capacity planning & forecasting with Grafana
Re-define network visibility for capacity planning & forecasting with GrafanaRe-define network visibility for capacity planning & forecasting with Grafana
Re-define network visibility for capacity planning & forecasting with GrafanaBangladesh Network Operators Group
ย 

More from Bangladesh Network Operators Group (20)

Accelerating Hyper-Converged Enterprise Virtualization using Proxmox and Ceph
Accelerating Hyper-Converged Enterprise Virtualization using Proxmox and CephAccelerating Hyper-Converged Enterprise Virtualization using Proxmox and Ceph
Accelerating Hyper-Converged Enterprise Virtualization using Proxmox and Ceph
ย 
Recent IRR changes by Yoshinobu Matsuzaki, IIJ
Recent IRR changes by Yoshinobu Matsuzaki, IIJRecent IRR changes by Yoshinobu Matsuzaki, IIJ
Recent IRR changes by Yoshinobu Matsuzaki, IIJ
ย 
Fact Sheets : Network Status in Bangladesh
Fact Sheets : Network Status in BangladeshFact Sheets : Network Status in Bangladesh
Fact Sheets : Network Status in Bangladesh
ย 
AI Driven Wi-Fi for the Bottom of the Pyramid
AI Driven Wi-Fi for the Bottom of the PyramidAI Driven Wi-Fi for the Bottom of the Pyramid
AI Driven Wi-Fi for the Bottom of the Pyramid
ย 
IPv6 Security Overview by QS Tahmeed, APNIC RCT
IPv6 Security Overview by QS Tahmeed, APNIC RCTIPv6 Security Overview by QS Tahmeed, APNIC RCT
IPv6 Security Overview by QS Tahmeed, APNIC RCT
ย 
Network eWaste : Community role to manage end of life Product
Network eWaste : Community role to manage end of life ProductNetwork eWaste : Community role to manage end of life Product
Network eWaste : Community role to manage end of life Product
ย 
A plenarily integrated SIEM solution and itโ€™s Deployment
A plenarily integrated SIEM solution and itโ€™s DeploymentA plenarily integrated SIEM solution and itโ€™s Deployment
A plenarily integrated SIEM solution and itโ€™s Deployment
ย 
IPv6 Deployment in South Asia 2022
IPv6 Deployment in South Asia  2022IPv6 Deployment in South Asia  2022
IPv6 Deployment in South Asia 2022
ย 
Introduction to Software Defined Networking (SDN)
Introduction to Software Defined Networking (SDN)Introduction to Software Defined Networking (SDN)
Introduction to Software Defined Networking (SDN)
ย 
RPKI Deployment Status in Bangladesh
RPKI Deployment Status in BangladeshRPKI Deployment Status in Bangladesh
RPKI Deployment Status in Bangladesh
ย 
An Overview about open UDP Services
An Overview about open UDP ServicesAn Overview about open UDP Services
An Overview about open UDP Services
ย 
12 Years in DNS Security As a Defender
12 Years in DNS Security As a Defender12 Years in DNS Security As a Defender
12 Years in DNS Security As a Defender
ย 
Contents Localization Initiatives to get better User Experience
Contents Localization Initiatives to get better User ExperienceContents Localization Initiatives to get better User Experience
Contents Localization Initiatives to get better User Experience
ย 
BdNOG-20220625-MT-v6.0.pptx
BdNOG-20220625-MT-v6.0.pptxBdNOG-20220625-MT-v6.0.pptx
BdNOG-20220625-MT-v6.0.pptx
ย 
Route Leak Prevension with BGP Community
Route Leak Prevension with BGP CommunityRoute Leak Prevension with BGP Community
Route Leak Prevension with BGP Community
ย 
Tale of a New Bangladeshi NIX
Tale of a New Bangladeshi NIXTale of a New Bangladeshi NIX
Tale of a New Bangladeshi NIX
ย 
MANRS for Network Operators
MANRS for Network OperatorsMANRS for Network Operators
MANRS for Network Operators
ย 
Re-define network visibility for capacity planning & forecasting with Grafana
Re-define network visibility for capacity planning & forecasting with GrafanaRe-define network visibility for capacity planning & forecasting with Grafana
Re-define network visibility for capacity planning & forecasting with Grafana
ย 
RPKI ROA updates
RPKI ROA updatesRPKI ROA updates
RPKI ROA updates
ย 
Blockchain Demystified
Blockchain DemystifiedBlockchain Demystified
Blockchain Demystified
ย 

Recently uploaded

Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGAPNIC
ย 
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...singhpriety023
ย 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableSeo
ย 
Call Girls In Ashram Chowk Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”
Call Girls In Ashram Chowk Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”Call Girls In Ashram Chowk Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”
Call Girls In Ashram Chowk Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”soniya singh
ย 
Call Girls In Saket Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”
Call Girls In Saket Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”Call Girls In Saket Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”
Call Girls In Saket Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”soniya singh
ย 
All Time Service Available Call Girls Mg Road ๐Ÿ‘Œ โญ๏ธ 6378878445
All Time Service Available Call Girls Mg Road ๐Ÿ‘Œ โญ๏ธ 6378878445All Time Service Available Call Girls Mg Road ๐Ÿ‘Œ โญ๏ธ 6378878445
All Time Service Available Call Girls Mg Road ๐Ÿ‘Œ โญ๏ธ 6378878445ruhi
ย 
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call GirlVIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girladitipandeya
ย 
โœ‚๏ธ ๐Ÿ‘… Independent Andheri Escorts With Room Vashi Call Girls ๐Ÿ’ƒ 9004004663
โœ‚๏ธ ๐Ÿ‘… Independent Andheri Escorts With Room Vashi Call Girls ๐Ÿ’ƒ 9004004663โœ‚๏ธ ๐Ÿ‘… Independent Andheri Escorts With Room Vashi Call Girls ๐Ÿ’ƒ 9004004663
โœ‚๏ธ ๐Ÿ‘… Independent Andheri Escorts With Room Vashi Call Girls ๐Ÿ’ƒ 9004004663Call Girls Mumbai
ย 
How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)Damian Radcliffe
ย 
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxAWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxellan12
ย 
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Servicesexy call girls service in goa
ย 
Low Rate Young Call Girls in Sector 63 Mamura Noida โœ”๏ธโ˜†9289244007โœ”๏ธโ˜† Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida โœ”๏ธโ˜†9289244007โœ”๏ธโ˜† Female E...Low Rate Young Call Girls in Sector 63 Mamura Noida โœ”๏ธโ˜†9289244007โœ”๏ธโ˜† Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida โœ”๏ธโ˜†9289244007โœ”๏ธโ˜† Female E...SofiyaSharma5
ย 
CALL ON โžฅ8923113531 ๐Ÿ”Call Girls Lucknow Lucknow best sexual service Online
CALL ON โžฅ8923113531 ๐Ÿ”Call Girls Lucknow Lucknow best sexual service OnlineCALL ON โžฅ8923113531 ๐Ÿ”Call Girls Lucknow Lucknow best sexual service Online
CALL ON โžฅ8923113531 ๐Ÿ”Call Girls Lucknow Lucknow best sexual service Onlineanilsa9823
ย 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...APNIC
ย 
Call Girls In Pratap Nagar Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”
Call Girls In Pratap Nagar Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”Call Girls In Pratap Nagar Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”
Call Girls In Pratap Nagar Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”soniya singh
ย 
VVVIP Call Girls In Connaught Place โžก๏ธ Delhi โžก๏ธ 9999965857 ๐Ÿš€ No Advance 24HRS...
VVVIP Call Girls In Connaught Place โžก๏ธ Delhi โžก๏ธ 9999965857 ๐Ÿš€ No Advance 24HRS...VVVIP Call Girls In Connaught Place โžก๏ธ Delhi โžก๏ธ 9999965857 ๐Ÿš€ No Advance 24HRS...
VVVIP Call Girls In Connaught Place โžก๏ธ Delhi โžก๏ธ 9999965857 ๐Ÿš€ No Advance 24HRS...Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
ย 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...tanu pandey
ย 

Recently uploaded (20)

Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOG
ย 
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
ย 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
ย 
Call Girls In Ashram Chowk Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”
Call Girls In Ashram Chowk Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”Call Girls In Ashram Chowk Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”
Call Girls In Ashram Chowk Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”
ย 
Call Girls In Saket Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”
Call Girls In Saket Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”Call Girls In Saket Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”
Call Girls In Saket Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”
ย 
All Time Service Available Call Girls Mg Road ๐Ÿ‘Œ โญ๏ธ 6378878445
All Time Service Available Call Girls Mg Road ๐Ÿ‘Œ โญ๏ธ 6378878445All Time Service Available Call Girls Mg Road ๐Ÿ‘Œ โญ๏ธ 6378878445
All Time Service Available Call Girls Mg Road ๐Ÿ‘Œ โญ๏ธ 6378878445
ย 
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call GirlVIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
ย 
โœ‚๏ธ ๐Ÿ‘… Independent Andheri Escorts With Room Vashi Call Girls ๐Ÿ’ƒ 9004004663
โœ‚๏ธ ๐Ÿ‘… Independent Andheri Escorts With Room Vashi Call Girls ๐Ÿ’ƒ 9004004663โœ‚๏ธ ๐Ÿ‘… Independent Andheri Escorts With Room Vashi Call Girls ๐Ÿ’ƒ 9004004663
โœ‚๏ธ ๐Ÿ‘… Independent Andheri Escorts With Room Vashi Call Girls ๐Ÿ’ƒ 9004004663
ย 
Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
Russian Call Girls in %(+971524965298  )#  Call Girls in DubaiRussian Call Girls in %(+971524965298  )#  Call Girls in Dubai
Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
ย 
How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)
ย 
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxAWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
ย 
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
ย 
Low Rate Young Call Girls in Sector 63 Mamura Noida โœ”๏ธโ˜†9289244007โœ”๏ธโ˜† Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida โœ”๏ธโ˜†9289244007โœ”๏ธโ˜† Female E...Low Rate Young Call Girls in Sector 63 Mamura Noida โœ”๏ธโ˜†9289244007โœ”๏ธโ˜† Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida โœ”๏ธโ˜†9289244007โœ”๏ธโ˜† Female E...
ย 
@9999965857 ๐Ÿซฆ Sexy Desi Call Girls Laxmi Nagar ๐Ÿ’“ High Profile Escorts Delhi ๐Ÿซถ
@9999965857 ๐Ÿซฆ Sexy Desi Call Girls Laxmi Nagar ๐Ÿ’“ High Profile Escorts Delhi ๐Ÿซถ@9999965857 ๐Ÿซฆ Sexy Desi Call Girls Laxmi Nagar ๐Ÿ’“ High Profile Escorts Delhi ๐Ÿซถ
@9999965857 ๐Ÿซฆ Sexy Desi Call Girls Laxmi Nagar ๐Ÿ’“ High Profile Escorts Delhi ๐Ÿซถ
ย 
CALL ON โžฅ8923113531 ๐Ÿ”Call Girls Lucknow Lucknow best sexual service Online
CALL ON โžฅ8923113531 ๐Ÿ”Call Girls Lucknow Lucknow best sexual service OnlineCALL ON โžฅ8923113531 ๐Ÿ”Call Girls Lucknow Lucknow best sexual service Online
CALL ON โžฅ8923113531 ๐Ÿ”Call Girls Lucknow Lucknow best sexual service Online
ย 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
ย 
Call Girls In Pratap Nagar Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”
Call Girls In Pratap Nagar Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”Call Girls In Pratap Nagar Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”
Call Girls In Pratap Nagar Delhi ๐Ÿ’ฏCall Us ๐Ÿ”8264348440๐Ÿ”
ย 
VVVIP Call Girls In Connaught Place โžก๏ธ Delhi โžก๏ธ 9999965857 ๐Ÿš€ No Advance 24HRS...
VVVIP Call Girls In Connaught Place โžก๏ธ Delhi โžก๏ธ 9999965857 ๐Ÿš€ No Advance 24HRS...VVVIP Call Girls In Connaught Place โžก๏ธ Delhi โžก๏ธ 9999965857 ๐Ÿš€ No Advance 24HRS...
VVVIP Call Girls In Connaught Place โžก๏ธ Delhi โžก๏ธ 9999965857 ๐Ÿš€ No Advance 24HRS...
ย 
Dwarka Sector 26 Call Girls | Delhi | 9999965857 ๐Ÿซฆ Vanshika Verma More Our Se...
Dwarka Sector 26 Call Girls | Delhi | 9999965857 ๐Ÿซฆ Vanshika Verma More Our Se...Dwarka Sector 26 Call Girls | Delhi | 9999965857 ๐Ÿซฆ Vanshika Verma More Our Se...
Dwarka Sector 26 Call Girls | Delhi | 9999965857 ๐Ÿซฆ Vanshika Verma More Our Se...
ย 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
ย 

RPKI Deployment Status in Bangladesh

  • 2. Agenda โ€ข Little background on BGP & RPKI โ€ข Creating ROA โ€ข RPKI Status in Bangladesh
  • 3. BGP
  • 4. BGP (AS) Send a packet to 2001:DB8::1 I have 2001:DB8::/32
  • 5. AS Path AS 100 AS 300AS 200 Send a packet to 2001:DB8::1 I have 2001:DB8::/32 2001:DB8::/32 100 200 300 i
  • 6. AS Path AS 100 AS 300 Send a packet to 2001:DB8::1 I have 2001:DB8::/32 I have 2001:DB8::/48 AS 420 AS 200 2001:DB8::/32 100 200 300 i 2001:DB8::/48 100 200 400 i
  • 7. Current Trend โ€ข Filtering limited to the edges facing the customer โ€ข Filters on peering and transit sessions are often too complex or take too many resources โ€ข Check pre๏ฌx before announcing it
  • 8. Filter Where? โ€ข Secure BGP Templates โ€ข http://www.cymru.com/gillsr/ documents/junos-bgp- template.htm โ€ข https://www.team-cymru.org/ ReadingRoom/Templates/ secure-bgp-template.html
  • 9. Internet Registry (IR) โ€ข Maintains Internet Resources such as IP addresses and ASNs, and publish the registration information โ€ข Allocations for Local Internet Registries โ€ข Assignments for end-users โ€ข APNIC is the Regional Internet Registry(RIR) in the Asia Paci๏ฌc region โ€ข National Internet Registry(NIR) exists in several economies
  • 10. The Eco-System National IR (NIR) Internet Service Provider End User Regional IR (RIR)
  • 11. Still not enough IRR is useful, but itโ€™s not perfect
  • 12. RPKI Resource Pubic Key Infrastructure IP Address & AS Numbers Digital Certi๏ฌcate
  • 13. RPKI Deployment AS 100 AS 300AS 200 Phase 2 Path Validation Send a packet to 2001:DB8::1 I have 2001:DB8::/32 Phase 1 Origin Validation
  • 14. Goals of RPKI โ€ข Able to authoritatively prove who owns an IP Pre๏ฌx and what AS(s) may Announce It โ€ข Reducing routing leaks โ€ข Attaching digital certi๏ฌcates to network resources (AS Number & IP Address) โ€ข Pre๏ฌx Ownership Follows the Allocation Hierarchy IANA, RIRs, ISPs, โ€ฆ
  • 16. Phase I - Publishing ROA โ€ข Login to your MyAPNIC portal โ€ข Required valid certi๏ฌcate โ€ข Go to Resources > Certi๏ฌcation Tab 1 2 *
  • 17. Phase I - Publishing ROA 1 2 3
  • 18. Phase I - Publishing ROA โ€ข Show available pre๏ฌx for which you can create ROA
  • 19. Phase I - Publishing ROA - IPv4 1. Write your ASN 2. Your IP Block 3. Subnet 4. Click Add โ€ข Create ROA for smaller block.
  • 20. Phase I - Publishing ROA - IPv6 โ€ข ROA for your IPv6 pre๏ฌx 1. Write your ASN 2. Your IP Block 3. Subnet 4. Click Add
  • 21. Phase I - Check your ROA # whois -h whois.bgpmon.net 202.4.96.0/24 Prefix: 202.4.96.0/24 Prefix description: APT (Dhakacom) Country code: BD Origin AS: 23956 Origin AS Name: DHAKACOM-BD-AS dhakaCom Limited,BD RPKI status: ROA validation successful First seen: 2013-12-23 Last seen: 2014-07-20 Seen by #peers: 203
  • 22. # whois -h whois.bgpmon.net " --roa 23956 202.4.96.0/24" 0 - Valid ------------------------ ROA Details ------------------------ Origin ASN: AS23956 Not valid Before: 2014-07-20 15:20:10 Not valid After: 2014-12-30 00:00:00 Expires in 161d12h52m42s Trust Anchor: rpki.apnic.net Prefixes: 202.4.96.0/19 (max length /24) 2405:7600::/32 (max length /32) Phase I - Check your ROA
  • 23. Check your pre๏ฌx Cisco (hosted by the RIPE NCC) Public Cisco router: rpki-rtr.ripe.net Telnet username: ripe / No password Juniper (hosted by Kaia Global Networks) Public Juniper routers: 193.34.50.25, 193.34.50.26 Telnet username: rpki / Password: testbed source : http://www.ripe.net/lir-services/resource-management/certi๏ฌcation/tools-and-resources
  • 24. Con๏ฌguration - Reference Link Cisco http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/iproute_bgp/command/irg-cr- book/bgp-m1.html#wp3677719851 Juniper http://www.juniper.net/techpubs/en_US/junos12.2/topics/topic-map/bgp-origin- as-validation.html
  • 25. RPKI Status in Bangladesh
  • 26. Is some one really announcing my pre๏ฌx!!!
  • 28. RPKI Breakdown Total Pre๏ฌx Valid Invalid Unknown Accuracy RPKI Adoption Rate APNIC 135876 (100%) 581 (0.43%) 684 (0.5%) 134611 (99.07%) 45.93% 0.93% BD 2079 (100%) 71 (3.42%) 26 (1.25%) 1982 (95.33%) 73.2% 4.67% source : http://rpki.surfnet.nl/perrir.html & http://rpki.surfnet.nl/country.php
  • 29. Adoption Rate RPKI vs IPv6 RPKI Adoption 4.67% source : https://www.google.com/intl/en/ipv6/statistics.html#tab=per-country-ipv6-adoption
  • 30. Invalid Pre๏ฌx source : http://rpki.surfnet.nl/bd.html
  • 31. All Invalid pre๏ฌxes from BD source : http://rpki.surfnet.nl/bd.html
  • 32. All Invalid pre๏ฌxes from BD source : http://rpki.surfnet.nl/bd.html
  • 33. Something more serious source : https://stat.ripe.net/widget/announced-pre๏ฌxes#w.resource=58717 source : http://www.cidr-report.org/cgi-bin/as-report?as=as58717&view=2.0
  • 34. Special thanks to Jac Kloots SURFnet http://rpki.surfnet.nl/index.html