Re: ROA mirror to IRR?

2021-10-26 Thread Vincent Bernat
❦ 26 October 2021 10:17 -10, Shawn: > Curious if any IRR databases are mirroring/importing ROA data - creating > route|6 objects from ROA? This is a feature of IRRd 4: https://irrd.readthedocs.io/en/stable/admins/rpki/ > IRR questions: > How do most large networks maintain (automate) their IRR

Re: . (was IPv6 and CDN's)

2021-10-26 Thread John Levine
It appears that Bryan Fields said: >Can you explain how it would work? Say you have a root server operator who >starts messing up, is there any ability to remove them? Nope. We are fortunate that for over 30 years the root servers have all been competent and reliable. >> It’s a hard question,

FORT monitoring/visibility

2021-10-26 Thread Randy Bush
i run a FORT RPKI relying party instance. i am looking for some visibility into its operation. is it up: both ways, fetching and serving routers? from what CAs has it pulled, how recently and frequently with what success? what routers is it serving with rpki-rtr 323? blah blah blah

Re: ROA mirror to IRR?

2021-10-26 Thread Rubens Kuhl
TC(bgp.net.br) is using IRRd 4.2, which has an RPKI pseudo-source with exactly that. ROAs are downloaded from NTT. You can see how they look like at: https://bgp.net.br/whois/?q=-s%20RPKI%20200.160.0.0/20 But this is not used to create route(6) objects in the TC source, only to invalidate

Re: ROA mirror to IRR?

2021-10-26 Thread George Michaelson
On Wed, Oct 27, 2021 at 6:31 AM Shawn wrote: > > Curious if any IRR databases are mirroring/importing ROA data - creating > route|6 objects from ROA? > > LACNIC requires a route object to be created when creating a ROA. > APNIC you create a route object, then may generate a ROA during that >

Re: IPv6 and CDN's

2021-10-26 Thread Tom Hill
On 22/10/2021 17:08, t...@pelican.org wrote: > I don't think it'll ever make money, but I think it will reduce > costs. CGNAT boxes cost money, operating them costs money, dealing > with the support fallout from them costs money. Especially in the > residential space, where essentially if the

ROA mirror to IRR?

2021-10-26 Thread Shawn
Curious if any IRR databases are mirroring/importing ROA data - creating route|6 objects from ROA? LACNIC requires a route object to be created when creating a ROA. APNIC you create a route object, then may generate a ROA during that process. Other RIR's, curious if anything tries to bring the

Re: IPv6 and CDN's

2021-10-26 Thread Mikael Abrahamsson via NANOG
On Tue, 26 Oct 2021, David Conrad wrote: Ah. Cogent. I suspect IPv6 peering policies. Somebody should bake a cake. According to https://twitter.com/Benjojo12/status/1452673637606166536 Cogent<->Google IPv6 now works. A cake is in order, but perhaps a celebratory one!? -- Mikael

Re: . (was IPv6 and CDN's)

2021-10-26 Thread John Curran
Bryan - One of the things that was clarified with the IANA Stewardship Transition is that ICANN has (at least) two distinct roles contained within it: one is coordination of the domain name community to develop Domain Name policy and the other is the IANA / Public Technical Identifiers (PTI)

Re: . (was IPv6 and CDN's)

2021-10-26 Thread Bryan Fields
On 10/26/21 12:10 PM, David Conrad wrote: >> Surely IANA has the power to compel a root server operator to abide by >> policy or they lose the right to be a root server? > To compel? No. Not in the slightest. That is not how the root server system > works. This is a (very) common misconception.

Re: IPv6 and CDN's

2021-10-26 Thread David Conrad
Bryan, On Oct 23, 2021, at 5:56 PM, Bryan Fields wrote: >> Excepting temporary failures, they are as far as I am aware. Why do you >> think they aren’t? > > I can't reach C, 2001:500:2::c, from many places in v6 land. My home and > secondary data center can't reach it, but my backup VM's at

Guam Private Line

2021-10-26 Thread Robert DeVita
Any recommendations for Private Line service into Guam from the US? 2 gigs? Thanks Rob [photo] [cid:image002.png@01D7CA4B.D0993B20] Robert DeVita CEO & Founder [cid:image003.png@01D7CA4B.D0993B20]

Re: question about enabling RPKI using Hosted mode

2021-10-26 Thread Dale W. Carder
Thus spake Edvinas Kairys (edvinas.em...@gmail.com) on Tue, Oct 26, 2021 at 10:11:14AM +0300: > > Also, about ROA expirations is it possible to configure an automatic ROA > extension after it's expires ? Well, you probably hit one of the next biggest operational issues, so congrats ;-). If

Re: question about enabling RPKI using Hosted mode

2021-10-26 Thread Edvinas Kairys
thanks, will keep in mind. Also, about ROA expirations is it possible to configure an automatic ROA extension after it's expires ? On Tue, Oct 26, 2021 at 12:35 AM Job Snijders wrote: > Dear Edvinas, > > On Mon, Oct 25, 2021 at 11:49:09PM +0300, Edvinas Kairys wrote: > > We're thinking of