RPKI Deployment Panel

Post on 13-Aug-2015

117 views 0 download

Tags:

Transcript of RPKI Deployment Panel

Copyright © 2015 Japan Network Information Center

RPKI deployment panel

Copyright © 2015 Japan Network Information Center

People

• Geoff Huston (chair)

• Fakrul Alam, bdHUB• A week with analysing RPKI status

• Tomoya Yoshida, Internet Multifeed• Deployment factors and current status

• Yoshinobu Matsuzaki, Internet Initiative Japan• RPKI deployment at ISP

• Taiji Kimura, Japan Network Information Center• About JPNIC’s RPKI

1

Copyright © 2015 Japan Network Information Center

RPKI Deployment Panel

• Purpose

• Gathering experienced operators voice

• Discuss further RPKI deployment for useful mechanism

2

Copyright © 2015 Japan Network Information Center

Discussions

Copyright © 2015 Japan Network Information Center

Deployment model

Public cache server

/

local cache server

4

Copyright © 2015 Japan Network Information Center

Deployment model

RPKI in IXP

and

Route reflector

5

Copyright © 2015 Japan Network Information Center

Deployment model

RPKI and IRR

6

Copyright © 2015 Japan Network Information Center

HOWTO

Configuring RPKI cache

and

Building own RPKI CA

7

Copyright © 2015 Japan Network Information Center

What do you do when…

Copyright © 2015 Japan Network Information Center

(Customer AS)

• Customer claims their prefix has been announced from other AS!

9

Copyright © 2015 Japan Network Information Center

(Own prefix)

• You found your prefix has no reachability from other region.What do you do?

10

Copyright © 2015 Japan Network Information Center

(Customer AS)

• Customer claims their prefix has been announced from other AS!What do you do?

11

Copyright © 2015 Japan Network Information Center

(DDoS mitigation)

• DDoS packets are coming!You found if other AS announces specific announce.

12

Copyright © 2015 Japan Network Information Center

JPNIC’s RPKI

Taiji Kimura

Copyright © 2015 Japan Network Information Center

Issues on RPKI deployment in Japan

• Deployment for operators• How RPKI is use for people - BGP operators

• Language

14

Copyright © 2015 Japan Network Information Center

Developing items and technical specifications

• Internationalization

• Database

• Authentication

• Redundancy and easy maintenance

• Server security

• Key management and PKI operation

15

Copyright © 2015 Japan Network Information Center

Internationalization

16

Copyright © 2015 Japan Network Information Center

Further step

• Multi-language support

• Feedbacks for developer

17

Copyright © 2015 Japan Network Information Center

It is time to release.

RPKI pilot service