So what about using
RPKI? What should we do? Well network
operators can make decisions
based on RPKI state,
invalid--discard the prefix. Several
operators are already doing this today
and more operators are doing this as
part of
the improved migration and securing of
their networks
the not found state is being allowed
through
and perhaps you make this a low local
preference
valid we let it through and we make it
high local preference
some operators have talked about making
not found a discard event
probably not very seriously because if
they do that the internet routing table
would
shrink substantially in both v4 and v6
now let's look at some of the deployment
situations
and some of the challenges for fully
supported route origin validation across
the network
all ebgp speaking routers need to talk
with a validator
supporting route origin validation means
we are dropping
invalids as they arrive in the network
ebgp speaking routers are part of the
operator ibgp mesh
ibgp speaking routers do not need to
talk to a validator
because only the valid and not found
prefixes will be distributed
from the ebgp speaking routers a note
the validation table is local to the
router
there's no protocol for distributing
this table from one router to another
but do note on cisco ios and ios xe
the routers will drop invalids by
default
if you want to allow invalids to be
distributed by IBGP
there is the per address family command
bgp best path
prefix validate allow invalid with this
implemented
IOS and IOS-XE will not drop in valids by
default
but distribute them across the IBGP mesh.
© Produced by Philip Smith and the Network Startup Resource Center, through the University of Oregon.
Attribution-NonCommercial 4.0 International (CC BY-NC 4.0)
This is a human-readable summary of (and not a substitute for) the license. Disclaimer. You are free to: Share — copy and redistribute the material in any medium or format Adapt — remix, transform, and build upon the material The licensor cannot revoke these freedoms as long as you follow the license terms. Under the following terms: Attribution — You must give appropriate credit, provide a link to the license, and indicate if changes were made. You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use. NonCommercial — You may not use the material for commercial purposes. No additional restrictions — You may not apply legal terms or technological measures that legally restrict others from doing anything the license permits.