nanog mailing list archives

Re: rpki roa irr - i now believe


From: Job Snijders via NANOG <nanog () lists nanog org>
Date: Fri, 16 May 2025 10:22:47 +0900

Ola!

On Fri, 16 May 2025 at 06:00, Laszlo H via NANOG <nanog () lists nanog org>
wrote:

If the goal of someone were to hijack your routing, they could (should)
announce it using your ASN and thus it would still be RPKI valid?


Sure, but AS spoofing generally means a longer AS_PATHs (you’d put the
spoofed thing behind a non-spoofed ASN), which is an impediment when trying
to win best path selection.

This posting might be of interest
https://www.kentik.com/blog/how-much-does-rpki-rov-reduce-the-propagation-of-invalid-routes/

Kind regards,

Job


_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/TXBPTH6TFVKBHYTVVYSAWVZAM2RXELC6/

Current thread: