3. Evolution!
• At AFRINIC’s inception it was recommend that
the RIPE RR be used!
• Over 33k route object of AFRINIC managed IP
blocks in RIPE RR!
• Beta version of AFRINIC RR launched at AIS’13!
• Deployment of functional instance bundled up
with WHOIS 2.0 in August 2014!
• Boot camp organised to assist with population of
registry!
4. Benefits!
• Reduced cost: Free service!
• Ease of maintenance:!
– All information stored in same location!
– Same set of maintainers as in WHOIS Database!
– Security!
– RR objects linked to WHOIS!
– Use of same mntner objects to protect your route
objects!
– Maintainers auth scheme - PGP or X509 keycert!
– Considerably reduced risk of hijacking!
6. Challenges!
• Low uptake from regional community!
• Secured referencing of resources not
administered by AFRINIC currently not possible!
• Multi-level authorisation of object creation!
• IRR Lockdown!
• Improve migration of AFRINIC administered
objects from RIPE!
• Improve adoption of AFRINIC RR!
!
7. Way Forward!
• AFRINIC RR v2.0!
– Internal testing – end of June 2015!
– Beta testing – end of July 2015!
– Production deployment – end of August 2015!
• IRR Homing project!
– Objective: Ensure objects belong to authoritative
registry!
– Collaborative effort with RIPE for bulk migration!
– Continuous mirroring and monitoring for 12 – 24
months!
8. AFRINIC RR v2.0!
• Prefix = in – Autnum = in!
– Case 1 Prefix and Autnum protected by same mntn!
ü Auth performed!
ü Creation approved!
– Case 2 Prefix and Autnum protected by different mntn!
ü First mntn auth performed and request queued in whois!
ü Second mntn auth performed!
ü Creation approved!
• Prefix = in – Autnum = out!
– Request captured and ticket opened!
– Hostmaster due diligence!
– Creation approved or denied!
8!
9. AFRINIC RR v2.0 cont’d!
• Prefix = out – Autnum = in!
– Request captured and ticket opened!
– Hostmaster due diligence!
– Creation approved or denied!
• Prefix = out – Autnum = out!
– Creation denied!
9!
11. Call to Community!
• Adoption of our regional RR!
– Need to see more objects created!
– Upstream providers and community at large need to
use for filters!
• x-Registry auth (BoF at RIPE70)!
– Several options investigated (RPKI, RDAP) !
– No clear direction yet adopted!
• AFRINIC RR v2.0!
– Beta testers needed!
• IRR Homing project!
– Bulk migration or not?!
12. Thank you for
your Attention!
!
Questions?!
neriah@afrinic.net!
AIS_Africa
afrinic
afrinic!
afrinic!
afrinic!
afrinic!
!
!
!
!
media!
.net!
twitter.com/
flickr.com/!
facebook.com/
linkedin.com/company/
youtube.com/
www.!