Skip to Content.
Sympa Menu

netsec-sig - Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs....

Subject: Internet2 Network Security SIG

List archive

Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs....


Chronological Thread 
  • From:
  • To:
  • Subject: Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs....
  • Date: Wed, 15 May 2019 10:29:43 -0400


>
>> Should IU's ROAs include one that associates 129.79.0.0/16 with AS87
>> and a second ROA that includes 129.79.0.0/16 - 24 associated with
>> AS393676?
>
> When a prefix is moved to the DDoS mitigation provider, can you just
> create a specific /24 (or whatever) ROA with their origin at that time?
>
> Your suggestion above will certainly works, but there seems to be a
> consensus, not unreasonable, that "loose" ROAs are best avoided if
> possible.
>
> John
>

Creating a new ROA doesn’t necessarily result in a timely update to networks
operating RPKI validators. It’s more of batch process.

I’ve also been told that unless a network is using Zenedge’s Rapid BGP
scrubbing product, as opposed to the example I provided, Zenedge doesn’t
announce themselves as the origin.

Steve

Attachment: smime.p7s
Description: S/MIME cryptographic signature




Archive powered by MHonArc 2.6.19.

Top of Page