Start typing to search across invoices, services, domains, tickets, and more...
RPKI (Resource Public Key Infrastructure) uses certificates to prove which ASN may announce which IP prefix, and a ROA (Route Origin Authorization) is the signed object that states that permission. More and more networks drop RPKI-invalid routes, so a prefix without a correct ROA may be unreachable from parts of the internet. This guide explains what ROA and RPKI are, how to create a ROA for your IP block in the RIPE, APNIC, ARIN and AFRINIC portals, how to choose the max prefix length, and how to verify with rpki.cloudflare.com and Routinator on Debian/Ubuntu and CentOS/Rocky/AlmaLinux.
Routers compare received routes with ROAs and get one of three results: Valid (origin ASN and length match), Invalid (wrong ASN, or more specific than the max length; dropped by many networks) or NotFound (no ROA covers the prefix). Check the current status via the RIPEstat API:
curl -s "https://stat.ripe.net/data/rpki-validation/data.json?resource=AS64500&prefix=198.51.100.0/24" | grep -o '"status":"[^"]*"'Collect every prefix you actually announce and its origin ASN. The max length controls which more-specific sub-prefixes the ROA also allows. Set it equal to the announced length and create separate ROAs only for more-specifics you really announce. A loose max length lets an attacker forge your ASN and hijack sub-prefixes.
curl -s "https://stat.ripe.net/data/announced-prefixes/data.json?resource=AS64500" | grep -o '"prefix":"[^"]*"'
birdc show route export upstream1 # BIRD 2
vtysh -c "show bgp ipv4 unicast neighbors 203.0.113.1 advertised-routes" # FRRPrefix Origin ASN Max Length
198.51.100.0/24 AS64500 24
198.51.100.0/23 AS64500 23 # only if you also announce the /23
2001:db8:100::/48 AS64500 48Only the resource holder (or a member account it authorizes) can create ROAs. The entry points are roughly as follows; follow each RIR's current interface:
Enter prefix, origin ASN and max length and save; publication usually takes minutes to an hour. If the IPs are leased from IMIDC, IMIDC is the resource holder: open a ticket with the prefix, your ASN and the max length and we will create the ROA, and the IRR route object if needed.
Prefix: 198.51.100.0/24
Origin ASN: AS64500
Max Length: 24
IRR route object: yesOpen the validator view on rpki.cloudflare.com, enter ASN and prefix and you will see Valid or Invalid plus every ROA covering the prefix. RIPEstat and bgp.tools also show RPKI status. You can also repeat the command from Step 1 until it reports valid.
curl -s "https://stat.ripe.net/data/rpki-validation/data.json?resource=AS64500&prefix=198.51.100.0/24" | grep -o '"status":"[^"]*"'Routinator is NLnet Labs' open-source RPKI validator. It can validate independently on your server or feed routers over RTR. The commands below install it via the Rust toolchain (NLnet Labs also provides package repositories for Debian/Ubuntu and RHEL-based systems). The first run syncs the whole RPKI repository and may take several minutes.
# Debian / Ubuntu
apt install -y curl build-essential
# CentOS / Rocky / AlmaLinux
dnf install -y curl gcc
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y
source "$HOME/.cargo/env"
cargo install --locked routinatorroutinator validate --asn AS64500 --prefix 198.51.100.0/24
routinator vrps --select-asn AS64500Yes. Many upstreams still build prefix filters from IRR data, so keep ROAs and route/route6 objects in place and consistent.
RIRs usually publish within an hour, and validators refresh on their own schedule, so expect tens of minutes to a few hours.
Yes. Create one ROA per ASN, which is useful for multi-origin setups or during a migration.
Still stuck? Open a ticket with IMIDC 24/7 technical support.