Successfully reported this slideshow.
Your SlideShare is downloading. ×

APNIC Updates: RPKI, what we’ve learned and what we’ve been doing by Zen Chuan

Ad
Ad
Ad
Ad
Ad
Ad
Ad
Ad
Ad
Ad

Check these out next

1 of 24 Ad
Advertisement

More Related Content

More from MyNOG (20)

Recently uploaded (20)

Advertisement

APNIC Updates: RPKI, what we’ve learned and what we’ve been doing by Zen Chuan

  1. 1. 1 RPKI, what we’ve learned and what we’ve been doing MyNOG 9 Zen Chuan Ng Senior Internet Resource Analyst
  2. 2. 2 2 Resource Public Key Infrastructure What is RPKI? A robust security framework for verifying the association between resource holders and their Internet number resources. 2
  3. 3. 3 3 Route Origin Authorization What is contained in a ROA? – The AS number you have authorized – The prefix that is being originated from it – The most specific prefix (maximum length) that the AS may announce For example: “ISP 4 permits AS65551 to originate a route for the prefix 198.51.100.0/24" 3
  4. 4. 4 4 RPKI initiatives 10 face-to-face and eLearning RPKI training courses delivered RPKI presentations to NOGs and conferences Development of the ‘Ready to ROA’ campaign – hands on sessions to help Members create ROAs New shirts, stickers, web content to promote campaign Ready to ROA launched in 2015 Initial challenge was to get APNIC Members to create ROAs
  5. 5. 5 ROA adoption in SEA 5 Economy ROA adoption rate (%) Philippines 96.36% Myanmar 89.09% Singapore 83.50% Lao PDR 76.90% Cambodia 68.14% Thailand 66.80% Vietnam 62.15%
  6. 6. 6 How is Malaysia doing? 6 https://lirportal.ripe.net/certification/content/static/statistics/world-roas.html
  7. 7. 7 Can Malaysia be the first to reach 100%?
  8. 8. 8 BUT….. more work needs to be done! Why???
  9. 9. 9 IPv4 ROA coverage in Malaysia https://stats.labs.apnic.net/roas
  10. 10. 10 IPv6 ROA coverage in Malaysia https://stats.labs.apnic.net/roas
  11. 11. 11 Route Origin Validation https://isbgpsafeyet.com/
  12. 12. 12 12 RPKI invalids
  13. 13. 13 13 RPKI invalids • On 27 April 2021, we saw 3,526 RPKI invalid routes for IPv4 addresses delegated to APNIC Members
  14. 14. 14 What improvements have we made?
  15. 15. 15 15 Cleaning up RPKI invalids • Email campaign in June 2021 to reach out to Members with RPKI invalid announcements
  16. 16. 16 16 ROA creation interface
  17. 17. 17 17 Improved ROA creation interface
  18. 18. 18 18 Routing status alerts in DASH https://dash.apnic.net/
  19. 19. 19 19 Routing status alerts in DASH
  20. 20. 20 20 Routing status alerts in DASH
  21. 21. 21 Reducing ROA downtime during transfers • Facilitate resource transfers involving live networks • Existing ROAs published for 2 weeks after transfers • Avoid any down time
  22. 22. 22 22 What we've learned?
  23. 23. 23 23 Upcoming RPKI improvements • Routing status alerts notification • ROA pre-validation • Registry API – https://blog.apnic.net/2022/03/22/apnic-registry-api/ • New ROA guides and Help Centre articles
  24. 24. 24 Questions?

×