APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN...

170
Issue Date: Revision: APNIC Internet Resource Management (IRM) Tutorial 17 May 2016 2.3.0 24-26 July 2017 Honiara, Solomon Islands Sponsored by:

Transcript of APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN...

Page 1: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Issue Date:

Revision:

APNIC Internet Resource Management (IRM) Tutorial

17 May 2016

2.3.0

24-26 July 2017 Honiara, Solomon Islands

Sponsored by:

Page 2: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Jessica Wei

Training Officer, APNIC

After graduating from China’s Huazhong University of Science and Technology in 2007 with a degree in electronic engineering, Bei(whose nickname is Jessica) joined Huawei as a network training officer.Over the next six years, she provided Huawei technical training on LAN/WAN systems, broadband access, IP core and IP mobile backhaul networks as well as working on technical training course design and the development of IP training materials. At the Huawei training center in China she provided technical training to engineers and administrators from more than 15 nations including Viet Nam, Papua New Guinea, Thailand, Pakistan and Bangladesh. She has also travelled to Bangladesh, Venezuela, Colombia, Egypt, Malaysia, Australia, Thailand, Indonesia and Singapore to provide training.

Contact:Email: [email protected]

Presenter

Page 3: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

PresenterJohn Chand

John Chand has more than 12 years of Telecommunication experience in Broadband and Wi-Fi network and ISP network design, operation and maintenance, having worked for one of the largest facilities-based providers of fixed line communication and networking services in Fiji – Telecom Fiji Limited (TFL).

John has a Bachelor’s degree in Engineering Technology from The University of the South Pacific in Suva, Fiji in addition to various industry standard ICT certifications including CISCO Certifications. He has been a speaker at a number of PacNOG events in the Pacific region and more recently at the Pacific IGF. He has had a leading role in working on setting up an IXP in Fiji with local internet service providers and the Fijian Government.

Apart from these work commitments, John has attended various international ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences and providing input to technical discussions.

Areas of Interests: IPv6, BGP, OSPF/IS-IS, Network Security and DNSSEC.

Contact: [email protected]

Page 4: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Agenda

• Introduction to APNIC• Policy Development Process• Internet Registry Policies

• Requesting IP Addresses• APNIC Whois Database • Using MyAPNIC

• Resource Certification (RPKI)

4

Page 5: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

• Asia-Pacific Network Information Centre

• One of five Regional Internet Registry (RIRs) charged with ensuring the fair distribution and responsible management of IP addresses and related resources

• A membership-based, not-for-profit organization

• Industry self-regulatory body– Open– Consensus-based– Transparent

5

Page 6: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Where is the APNIC Region?

6

Page 7: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Resource distribution- IP addresses- AS numbers

Registration services- reverse DNS- Internet routing

registry- resource certification- whois registry

7

What does APNIC do?APNIC servicesMembers

Page 8: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Policy development

Capacity building- training- workshops- conferences- fellowships- grants

Infrastructure- root servers- IXPs- engineering

assistance

8

What does APNIC do?APNIC supportsthe Asia Pacific region

Page 9: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

9

Original research

Data collection and measurements

Publications

Local/regional/global events

Government outreach

Intergovernmental & technical organizations collaboration

Internet security

What does APNIC do?APNIC collaborateswith the Internetcommunity

Page 10: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Internet Registry Structure

10

Page 11: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

APNIC – Vision

A global, open, stable, and secure Internet that serves the entire Asia Pacific community.

How we achieve this:• Serving Members

• Supporting the Asia Pacific Region• Collaborating with the Internet Community

11

Page 12: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

APNIC – Mission

• Function as the Regional Internet Registry for the Asia Pacific, in the service of the community of Members and others

• Provide Internet registry services to the highest possible standards of trust, neutrality, and accuracy

• Provide information, training, and supporting services to assist the community in building and managing the Internet

• Support critical Internet infrastructure to assist in creating and maintaining a robust Internet environment

• Provide leadership and advocacy in support of its vision and the community

• Facilitate regional Internet development as needed throughout the APNIC community

12

Page 13: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

APNIC from a Global Perspective

13

Page 14: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

APNIC in the Asia Pacific

14

ISOC chapters

Page 15: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Global Policy Coordination

The NRO is a coordinating body for the five regional Internet registries (RIRs)

www.nro.net

15

Page 16: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Where do IP Addresses come from?

16

Standards

Allocation

Allocation

Assignment

End user

RIRs

LIR/ISP

Page 17: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

17

Page 18: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Agenda

• Introduction to APNIC

• Policy Development Process

• Internet Registry Policies• Requesting IP Addresses

• APNIC Whois Database • Using MyAPNIC

• Resource Certification (RPKI)

18

Page 19: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Policy Development

• Creating a policy environment that supports the region’s Internet development

• Developed by the membership and broader Internet community

19

Page 20: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

You are part of the APNIC community!

20

APNIC Internet Community

Global Internet Community

Open forum in the Asia Pacific

APNICMembers

A voice in regional Internet operations through participation in APNIC

IETF Individuals

NationalNOG

RegionalNOGAPAN

ISOC

ISPAssociations

Page 21: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Policy Development Process

21

All decisions & policies documented & freely available to anyone

Internet community proposes and approves policy

Open

TransparentBottom up

Anyone can participate

Page 22: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Bef

ore

meeting

Authorproposes policyor amendment

Communitydiscusses

proposal on SIG mailing list

Policy Development ProcessBefore the conference

• Submit proposed policy to the APNIC Secretariat

• SIG Chair posts the proposal to mailing list

• Community discusses proposal

22

Page 23: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Policy Development Process

B

efore

meeting

Authorproposes policyor amendment

Communitydiscusses

proposal on SIG mailing list

Befo

re

meeting

Authorproposes policyor amendment

Communitydiscusses

proposal on SIG mailing list

During meeting

Communitydiscusses proposalface to face in SIG

SIG Chairgauges consensus

During the conference

• Proposed policies are presented at the Open Policy Meeting (OPM)

• Community comments on the proposal

• If it reaches consensus, SIG Chair reports the decision at the APNIC Member Meeting (AMM)

23

Page 24: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Policy Development ProcessAfter the conference

• Within a week, proposal is sent back to mailing list

• A comment period between 4-8 weeks is given

• If it reaches consensus, SIG Chair asks the Executive Council (EC) to endorse the proposal

• APNIC EC endorses proposal

• APNIC Secretariat implements the policy (minimum of 3 months)

During meeting

Bef

ore

meeting

Authorproposes policyor amendment

Communitydiscusses

proposal on SIG mailing list Community

discusses proposalface to face in SIG

During meetingBe

fore

meeting

Authorproposes policyor amendment

Communitydiscusses

proposal on SIGmailing list Community

discusses proposalface to face in SIG

After meeting

SIG Chairgauges consensus

Communityhas chance to raiseany final objections

during final call

SIG Chairconfirms

consensus

Executive Council(EC) endorses

policy

Secretariatimplements

policy

24

Page 25: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Policy Discussions

• Comment– Participants are encouraged to comment on the proposal

• Discuss– The Chair encourages discussion about the pros and cons of the

proposal

• Show of hands – to broadly measure opinion – not a vote

• Consensus – declared if there are no objections

25

Page 26: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

How to Participate

• Read the policy proposals currently under discussion• Check out discussions on the Policy SIG mailing list

• Join the discussion at APNIC conferences– webcast (live streaming)– live transcripts– comment on Jabber chat

• Provide your feedback– Training or community outreach events

26

Page 27: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

27

Page 28: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Agenda

• Introduction to APNIC• Policy Development Process

• Internet Registry Policies• Requesting IP Addresses• APNIC Whois Database • Using MyAPNIC

• Resource Certification (RPKI)

28

Page 29: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Growth of Global IPv4 Routing Table

http://www.cidr-report.org/as2.0/

653589 prefixesAs of 10 Feb 2017

2009: The GFC hits the Internet

2011: Address Exhaustion

2005: Broadband to the Masses2001: The Great Internet Boom and Bust

1994: Introduction of CIDR

Projected growth of

routing table before CIDR CIDR

deployment

Dot-Com boom

Sustainablegrowth

29

Page 30: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Growth of Global IPv6 Routing Table

http://www.cidr-report.org/as2.0/

36501 prefixesAs of 26 Feb 2017

30

2011: IPv4 Address Exhaustion

Page 31: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

IRM Objectives

31

- Efficient use of resources- Based on demonstrated need

Conservation

- Limit routing table growth- Support provider-based routing

Aggregation

- Ensure uniqueness- Facilitate trouble shooting

Registration

Uniqueness, fairness and consistency

Page 32: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

How IP Addresses are Delegated

32

Member (LIR)

LIR customer

Regi

stry

Rea

lm

Ope

rato

rs R

ealm

Customer / End User

delegates to customers

delegates to APNIC member

Member Allocation

/26 /27 /25

Customer Assignments

Sub Allocation

/26 /27

APNIC Allocation

/8

/24

APNIC

Page 33: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Customer Assignments

ISPAllocation

Customer Assignments

ISP

Portable and Non-Portable

• Portable Address– Provider-Independent (PI)– Assigned by RIR to end-user– Keep addresses when changing

ISP– Increases the routing table size

• Non-portable Address– Provider-aggregatable (PA)– End-user gets address space from

LIR– Must renumber if changing

upstream provider– Can be aggregated for improved

routing efficiency

33

Page 34: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

IPv6 Address Management Hierarchy

34

Describes “portability” of the address space

/12 APNIC Allocation

Portable

Portable

/48 Assignment /48 - /64 Assignment

APNIC Allocation

/48 - /64Assignment

Non-Portable Non-Portable

/40

/32 Member Allocation

Non-Portable

/12

Sub-allocation

Page 35: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Aggregation and Portability

35

Aggregation No Aggregation

(non-portable assignments)

(4 routes) (21 routes)

(portable assignments)

INTERNET INTERNET

ISP A ISP B ISP B

ISP C ISP D

ISP A

ISP C ISP D

Page 36: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

APNIC Policy Environment

• Internet resources are delegated on a license basis– Limited duration (usually one year)– Renewable on the following conditions

• Original basis of delegation remains valid• Address space is properly registered at the time of renewal

• Security and confidentiality– APNIC to maintain systems and practices that protect the

confidentiality of Members’ information and their customers

36

https://www.apnic.net/policy/policy-environment

Page 37: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Allocation Policies

• Aggregation of allocation– Provider responsible for aggregation– Customer assignments / sub-allocations must be non-portable

• Allocations based on demonstrated need– Detailed documentation required

• All address space held are to be declared

37

Page 38: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

IPv4 Allocation Policies

• APNIC IPv4 allocation size per account holder– Minimum /24– Maximum /21/22 from final /8 block/22 from the recovered block

• According to current allocation from the final /8 block

• Based on demonstrated need

38

Member allocation

Non-portableassignment

Non-portableassignment

/8

/22

APNIC

Page 39: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

IPv4 Sub-allocation

• No max or min size– Max 1 year requirement

• Assignment Window & 2nd Opinion – applies to both sub-allocation & assignments– Sub-allocation holders don’t need to send in 2nd opinions

39

APNIC MemberAllocation

Sub-allocation

Customer Assignments Customer Assignments

/24

/27 /26

/22

/25 /26 /27

Page 40: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

What is an Assignment Window?

“The amount of address space a member may assign without a ‘second opinion’”

• All members have an Assignment Window– Starts at zero, increases as member gains experience in address

management

• Second opinion process– Customer assignments require a ‘second-opinion’ when proposed

assignment size is larger than member’s current Assignment Window

40

Page 41: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Assignment Window

• Size of Assignment Window– Evaluated after about three 2nd-opinion requests– Increased as member gains experience and demonstrates

understanding of policies• Assignment Window may be reduced, in rare cases

• Why an Assignment Window?– Monitoring ongoing progress and adherence to policies– Mechanism for member education

41

Page 42: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

IPv6 / IPv4, Assignment / Sub-allocation

Network name, description, country

Planned IP usage

Customer’s existing network Customer assignments to end-sites

Sub-allocation infrastructure

Additional information

Confirm details

Contact details, password

IPs held by customer IPs held by customer & customer’s customers

IPv4 Sub-allocations IPv4/IPv6 Assignments

Any additional info that may aid the evaluation

Check your details

Applicant information

Type of request

Network name

Future network plan

2nd OpinionRequest

42

Page 43: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

2nd Opinion Request ApprovalDear XXXXXXX,

APNIC has approved your "second opinion" request to make the following assignment:

[netname]

[address/prefix]

* Please ensure that you update the APNIC whois database to register this assignment before informing your customer or requesting reverse DNS delegation. Do this using the form at:

http://www.apnic.net/apnic-bin/inetnum.pl

Important:

Unregistered assignments are considered as "unused"

43

Page 44: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

IPv6 Allocation Policies

• Initial allocation criteria– Minimum of /32 IPv6 block– Larger than /32 may be justified

• For APNIC Members with existing IPv4 space– One-click Policy (through MyAPNIC)

• Without existing IPv4 space– Must meet initial allocation criteria

• Subsequent allocation– Based on HD ratio (0.94)– Doubles the allocated address space

44

Page 45: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

IPv6 Utilisation (HD = 0.94)IPv6 Prefix

Site Address Bits

Total site address in /56

Threshold (HD = 0.94)

Utilisation %

/42 14 16,384 9,153 55.9%

/36 20 1,048,576 456,419 43.5%

/35 21 2,097,152 875,653 41.8 %

/32 24 16,777,216 6,185,533 36.9%

/29 27 134,217,728 43,665,787 32.5 %

/24 32 4,294,967,296 1,134,964,479 26.4 %

/16 40 1,099,511,627,776 208,318,498,661 18.9 %

RFC 3194 “In a hierarchical address plan, as the size of the allocation increases, the density of assignments will decrease.”

45

Page 46: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

IPv6 Sub-allocation

All /48 assignments to end sites must be registeredLIR must submit a second opinion request for assignments greater than /48

46

APNIC MemberAllocation

Sub-allocation

Customer Assignments Customer Assignments

/40

/64 /48

/32

/64 /56 /48

Page 47: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

IPv6 Assignment Policies

• Assignment address space size– Minimum of /64 (only 1 subnet)– Normal maximum of /48

• Assignment of multiple /48s to a single end site– Documentation must be provided– Will be reviewed at the RIR/NIR level

• Assignment to operator’s infrastructure– /48 per Point-of-Presence of an IPv6 service operator

47

Page 48: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Portable Assignments

• Small multi-homing assignment– For (small) organisations who require a portable assignment for

multi-homing purposes

• Criteria– Currently multi-homed, or currently using at least a /24 from its

upstream provider and intends to be multihomed, or intend to be multihomed, and advertise the prefixes within 6 months

– Demonstrate need to use 25% of requested space immediately, and 50% within 1 year

48

Page 49: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

IXP Assignments

• L1 or L2 network structure that interconnects 3 or more autonomous systems (AS) for internet traffic exchange

• Eligible to receive a delegation to be used exclusively to connect IXP participants devices to the Exchange Point

• Criteria:– 3 or more peers– Demonstrate “open peering policy”

• Assignment size– IPv4: /24– IPv6: /48 minimum

49

Page 50: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Portable Critical Infrastructure

• What is Critical Internet Infrastructure?– Domain registry infrastructure

• Root DNS operators, gTLD operators, ccTLD operators– Address Registry Infrastructure

• RIRs & NIRs, IANA

• Why a specific policy? – To protect the stability of core Internet functions

• Assignment size– IPv4: /24 – IPv6: /32 (maximum)

50

Page 51: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Sub-delegation Guidelines

• Sub-allocate cautiously– Seek APNIC advice if in doubt– If customer requirements meet the minimum allocation criteria,

customers can approach APNIC for portable allocation

• Efficient assignments– ISPs responsible for overall utilisation

• Database registration (WHOIS database)– Sub-allocations & assignments to be registered in the database

51

Page 52: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

IPv4 Transfer Policies

• Between APNIC Members– Minimum transfer size of /24– Source entity must be the currently registered holder of the IPv4

resources– Recipient entity will be subject to current APNIC policies

• Inter-RIR IPv4 Transfers– Minimum transfer size of /24– Conditions on the source and recipient RIR will apply

52

Page 53: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

IPv4 and ASN Transfer

53

• Transfer of IPv4 and AS Numbers between– APNIC Members (✓)– APNIC and NIR (✓)– APNIC and RIR (✓)

Page 54: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Transfer of IPv4 and AS Numbers between APNIC Members

54

• How to initiate such transfer request?– Source account to initiate transfer and recipient account to accept

transfer via MyAPNIC– Recipient account to justify the needs of the resources that will be

transferred

• Is there any transfer fees involved?– www.apnic.net/fees

Page 55: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Transfer of IPv4 and AS Numbers between APNIC and NIR

55

• Transfer from NIR Member to APNIC Member, or vice versa– Source account to initiate transfer request– IR of source account to contact IR of recipient account

• Who will be evaluating the request?– IR of the recipient account to evaluate transfer request

• How long will the whole process take?– Depends on how long correspondence is between the recipient and

IR

Page 56: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Transfer of IPv4 and AS Numbers between APNIC and RIR

56

• Similar to transfer between NIR and RIR• Transfer from RIR Member to APNIC Member, or vice

versa– Source account to initiate transfer request– IR of the recipient account to evaluate transfer request

www.apnic.net/transfer

Page 57: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Historical Resources

• Internet resources registered under early registry policies without formal agreements

• It includes:– Registrations transferred to APNIC as part of the AUNIC to APNIC

migration– Registrations transferred as part of the Early Registration Transfer

(ERX) project– Historical APNIC resources

57

https://www.apnic.net/policy/historical-resource-policies

Page 58: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Historical Resource Transfer

• Bring historical resource registrations into the current policy framework – Allow transfers of historical resources to APNIC Members – The recipient of the transfer must be an APNIC Member– No technical review or approval – Historical resource holder must be verified – Resources will then be considered as "current"

• Address space subject to current policy framework

58

Page 59: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

59

Page 60: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Agenda

• Introduction to APNIC• Policy Development Process

• Internet Registry Policies

• Requesting IP Addresses• APNIC Whois Database • Using MyAPNIC

• Resource Certification (RPKI)

60

Page 61: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

How do I get addresses?

• Decide what kind of number resources you need– IPv4? IPv6? Both?

• Check your eligibility– On the website www.apnic.net– Contact the helpdesk [email protected]

• Become familiar with the policies– www.apnic.net/policy

• Apply for membership and resources

61

Page 62: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

IPv4 Address Space

NRO Q4 2016

62

Page 63: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Available IPv4 /8s in Each RIR

NRO Q4 2016

63

Page 64: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

How do I get addresses?

• Decide what kind of number resources you need– IPv4? IPv6? Both?

• Check your eligibility– On the website www.apnic.net– Contact the helpdesk [email protected]

• Become familiar with the policies– www.apnic.net/policy

• Apply for membership and resources

64

Page 65: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Check for Eligibility – IPv4

• Initial LIR delegation:– Have used a /24 from their upstream provider or demonstrate an

immediate need for a /24– Have complied with applicable policies in managing all address

space previously delegated to it (including historical delegations)– Demonstrate a detailed plan for use of a /23 within a year

65

Page 66: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Check for Eligibility – IPv4

• Small multihoming delegation:– Currently multihomed, – or currently using at least a /24 from its upstream provider and

intends to be multihomed, – or intend to be multihomed, and advertise the prefixes within 6

months

– Demonstrate that they are able to use 25% of the requested addresses immediately and 50% within one year

66

Page 67: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Check for Eligibility – IPv4

• Internet Exchange Points:– Eligible to receive a delegation from APNIC to be used exclusively to

connect the IXP participant devices to the Exchange Point

• Critical Infrastructure:– If operating in the Asia Pacific region, are eligible to receive a

delegation– Available only to the actual operators of the network infrastructure

performing such functions

67

Page 68: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Check for Eligibility – IPv6

• APNIC Members with IPv4 but no IPv6 automatically qualify for an appropriately sized block of IPv6 addresses– Members with an IPv4 allocation are eligible for a /32 IPv6– Members with an IPv4 assignment are eligible for a /48 IPv6

• Minimum initial allocation– Must be an LIR– Not be an end site– Plan to announce IPv6 within two years– Must meet one of these:

• Plan to make at least 200 assignments to other organizations within two years• Be an existing LIR with IPv4 allocations from an APNIC or an NIR, which will make

IPv6 assignments or sub-allocations within two years

68

Page 69: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

How do I get addresses?

• Decide what kind of number resources you need– IPv4? IPv6? Both?

• Check your eligibility– On the website www.apnic.net– Contact the helpdesk [email protected]

• Become familiar with the policies– www.apnic.net/policy

• Apply for membership and resources

69

Page 70: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

How do I get addresses?

• Decide what kind of number resources you need– IPv4, IPv6

• Check your eligibility– On the website www.apnic.net– Contact the helpdesk [email protected]

• Become familiar with the policies– www.apnic.net/policy

• Apply for membership and resources

70

Page 71: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Initial IP Address Request

• You are required to be an APNIC Member in order to initiate your IP address request.

• However, you can apply for membership and request an initial address allocation at the same time.

71

http://www.apnic.net/apply

Page 72: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Application Process

• Application– Have your information handy and complete the application form

• Evaluation– Info provided will be evaluated. APNIC will contact you if additional

info is required

• Payment – Once application is approved, Member receives an invoice

• Completion– APNIC activates the membership and delegate the resource

72

https://www.apnic.net/get-ip/application-process

Page 73: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

New Member Application Form

73

Provide info about you andyour organisation

Page 74: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

74

Select IPv4 or IPv6 and theblock size. Make sure youmeet the criteria.

Page 75: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

75

Provide the type of ASNrequest, and details of twopeering networks

Page 76: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Initial Delegation

• APNIC IPv4 delegation size per account holder– Minimum of /24– Maximum of /21

/22 from the final /8 block/22 from the recovered block

• Initial IPv6 delegation criteria– Allocation

• Minimum of /32 IPv6 block• Larger than /32 may be justified

– Assignment• /48

76

Page 77: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

77

Request for additionalresources can be donethrough MyAPNIC

Page 78: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

78

Page 79: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Agenda

• Introduction to APNIC• Policy Development Process

• Internet Registry Policies• Requesting IP Addresses

• APNIC Whois Database • Using MyAPNIC

• Resource Certification (RPKI)

79

Page 80: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

What is the APNIC Database?

• Public network management database– Operated by Internet Registries– APNIC maintains the database of resources for the AP region

• Tracks network resources– IP addresses, ASNs, Reverse DNS delegations, Routing policies

• Records administrative information– Contact information (person/role) of relevant resource holders– Authorization for updating these info– Network abuse handling (IRT)

80

Page 81: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Resource Registration

As part of the membership agreement with APNIC, all Members are required to register their resources

in the APNIC database.

• Members must keep records up to dateü When ever there is a change in contactsü When new resources are receivedü When resources are sub-allocated or assigned

81

Page 82: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Whois Object TypesOBJECT PURPOSEperson Technical or administrative contacts responsible for an

objectrole Technical or administrative contacts represented by a role,

performed by one or more peopleinetnum Allocation or assignment of IPv4 address spaceinet6num Allocation or assignment of IPv6 address spaceaut-num Registered holder of an AS number and corresponding

routing policydomain in-addr.arpa (IPv4) or ip6.arpa (IPv6) reverse DNS

delegationsroute / route6 Single IPv4/IPv6 route injected into the Internet routing

meshmntner Authorized agent to make changes to an objectirt Dedicated abuse handling team

82

Page 83: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Objects for New Members

• If you are receiving your first allocation or assignment, APNIC will create the following objects for you:– role object– inetnum / inet6num object – aut-num object – maintainer object – irt object

• Information is taken from your application for resources and membership

83

Page 84: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

84

http://www.apnic.net/whois

Page 85: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

What if Whois information is invalid?

• Members are responsible for reporting changes to APNIC under the formal membership agreement

• Report invalid contact details to APNIC– http://www.apnic.net/invalidcontact– APNIC will contact the Member responsible to update the registration

85

Page 86: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

What if Whois information is invalid?

• Customer assignment information is the responsibility of the LIR– LIR must update their customer network registrations

• Tools such as traceroute, looking glass may be used to track the upstream provider if needed

86

Page 87: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Using the Whois – Step by Step

87

inetnum:

Allocation (Created by APNIC)

3

Customer Assignments (Created by Member)

person: nic-hdl:

KX17-AP

Contact info

Data Protection

1

2

inetnum: ... KX17-AP ... mnt-by: ...

4 inetnum: ...

...

...

5 inetnum: ... KX17-AP ...

...

6

mntner: mnt-by: mnt-by:

KX17-AP

Page 88: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Inetnum / Inet6num Objects

• Contains IP delegation information

• APNIC creates an inetnum or inet6num object for each delegation they make to the Member

• All members must create inetnum or inet6num objects for each sub-allocation or assignment they make to customers

88

Page 89: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Inet6num Objectinet6num: 2406:6400:FFFF::/48netname: ABCINTERNET-IPv6descr: IPv6 address block for ABC INTERNETcountry: SGadmin-c: AINT1-APtech-c: AINT1-APmnt-by: MAINT-SG-ABCINTERNETmnt-lower: MAINT-SG-ABCINTERNETmnt-routes: MAINT-SG-ABCINTERNETmnt-irt: IRT-ABCINTERNET-SGstatus: ALLOCATED NON-PORTABLEchanged: [email protected] 20160503source: APNIC

Role and maintainer object reference

Status shows the type of delegation

89

Page 90: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Person Object

• Represents a contact person for an organization– Every Member must have at least one contact person registered – Large organizations often have several contacts for different

purposes

• Referenced in other objects

• Has a nic-hdl – a unique identifier for a person or role object

Format: [A-Z][0-9]-AP

90

Page 91: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Person Objectperson: Nelly Tanaddress: 1000 Jalan Bukit Merahcountry: SGphone: +65 6400 7333fax-no: +65 6400 7334e-mail: [email protected]: NT324-APmnt-by: MAINT-SG-ABCINTERNETchanged: [email protected] 20160503source: APNIC

91

Page 92: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Role Object

• Contains details of technical or administrative contacts as represented by a role performed by one or more people within an organization

• Also has a nic-hdl

• Preferred over person object as reference in other objects– Eases administration

92

Page 93: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Role Objectrole: ABC Internet Network Teamaddress: 1000 Jalan Bukit Merahcountry: SGphone: +65 6400 7333fax-no: +65 6400 7334e-mail: [email protected]: AB731-APtech-c: NT324-APnic-hdl: AINT1-APmnt-by: MAINT-SG-ABCINTERNETchanged: [email protected] 20160503source: APNIC

Points to a person object

93

Page 94: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Replacing Contacts – Person Object

94

KX17-AP is the original contact Referenced by three (or more) objects

BW101-AP is replacing him Update all three (or more) objects with new contact one by one

Delete old contact KX17-AP

Customer Assignments (Created by Member)

person: nic-hdl:

KX17-AP

Contact info

1 person: nic-hdl:

BW101-AP

Contact info

2

inetnum: ... KX17-AP ... mnt-by: ...

4 inetnum: ...

...

...

5 inetnum: ... KX17-AP ...

...

6

mnt-by: mnt-by:

KX17-AP

Page 95: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Replacing Contacts – Person Object

95

KX17-AP is the original contact Referenced by three (or more) objects

BW101-AP is replacing him Update all three (or more) objects with new contact one by one

Delete old contact KX17-AP

Customer Assignments (Created by Member)

person: nic-hdl:

KX17-AP

Contact info

1 person: nic-hdl:

BW101-AP

Contact info

2

inetnum: ... BW101-AP ... mnt-by: ...

4 inetnum: ...

...

...

5 inetnum: ... BW101-AP ...

...

6

mnt-by: mnt-by:

BW101-AP

Page 96: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Replacing Contacts – Role Object

96

role: nic-hdl: AT480-AP ... tech-c:

No change in inetnum objects Customer Assignments (Created by Member)

person: nic-hdl: KX17-AP

Contact info

1 person: nic-hdl: BW101-AP

Contact info

2

KX17-APContact info

3

inetnum: ... AT480-AP ... mnt-by: ...

inetnum: ...

...

...

inetnum: ... AT480-AP...

... mnt-by: mnt-by:

AT480-AP

Replace old contact with new contact in Role object

Page 97: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Replacing Contacts – Role Object

97

role: nic-hdl: AT480-AP ... tech-c:

No change in inetnum objects Customer Assignments (Created by Member)

person: nic-hdl: KX17-AP

Contact info

1 person: nic-hdl: BW101-AP

Contact info

2

BW101-APContact info

3

inetnum: ... AT480-AP ... mnt-by: ...

inetnum: ...

...

...

inetnum: ... AT480-AP...

... mnt-by: mnt-by:

AT480-AP

Replace old contact with new contact in Role object

Page 98: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Whois Database Query

Flags Meaning

-l / -L less specific

-m / -M More specific

-x Exact match

-d Associated reverse domain

-I Inverse attributes

-T Object types

98

Page 99: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Whois Database Query - inetnum

99

inetnum: 202.64.0.0 – 202.64.15.255

202.64.0.0/20

inetnum: 202.0.0.0 – 202.255.255.255

202.0.0.0/8

202.64.12.128/25

inetnum:

whois–L 202.64.0.0 /20

whois 202.64.0.0 /20

whois–m 202.64.0.0 /20 inetnum: 202.64.15.192/26

inetnum: 202.64.10.0/24

More specific (= smaller blocks)

Less specific (= bigger block)

Page 100: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Inverse Queries

• Inverse queries are performed on inverse keys See object template (whois –t)

• Returns all public objects that reference the object with the key specified as a query argument

Practical when searching for objects in which a particular value is referenced, such as your nic-hdl

Syntax: whois -i <attribute> <value>

100

Page 101: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Customer Privacy

• Public data– Includes portable and non-portable addresses (inetnum)

and other objects (route, domain, etc)– must be visible

• Private data– Includes non-portable addresses (inetnum objects)– Members have the option to make private data visible

101

Page 102: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

What needs to be visible?

102

IANA range

Non-APNIC range APNIC range

NIR range APNIC allocations & assignments

NIR allocations & assignments

Customer assignments Infrastructure Sub-allocations

must be visible

visibility optional

LIR/ISP

PORTABLE addresses

NON-PORTABLE addresses

Page 103: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

What is a Maintainer?

• Protects objects in the Whois Database• Applied to any object created directly below that maintainer

object• Why do we need Maintainer?

– Prevent unauthorized person from changing the details in the Whois– As parts of a block are sub-allocated or assigned, another layer of

maintainers is often created to allow the new users to protect their (sub)set of addresses

• Authentication options– CRYPT-PW, MD5, PGPKEY

103

Page 104: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Maintainer Objectmntner: MAINT-SG-ABCINTERNETdescr: Maintainer for ABC Internetcountry: SGadmin-c: AINT1-APtech-c: AINT1-APupd-to: [email protected]: # Filtered mnt-by: MAINT-SG-ABCINTERNETreferral-by: APNIC-HMchanged: [email protected] 20160503source: APNIC

104

Page 105: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

mnt-by and mnt-lower Attributes

• mnt-by– Used to protect any object– Changes to protected object must satisfy authentication rules of

mntner object

• mnt-lower– Used for sub-assignment creation (customer assignment)

• mnt-routes– Used for the creation of route or route6 objects – inetnum, inet6num and aut-num must have the same mnt-route

maintainer

105

Page 106: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Authorisation Mechanism user1@www:~$ whois -h whois.apnic.net 2406:6400::/32

% Information related to '2406:6400::/32'

inet6num: 2406:6400::/32netname: APNIC-TRAININGIPv6-Lab-APdescr: APNIC TRAINING Labdescr: LEVEL 1, 33 PARK RDcountry: AUadmin-c: AT480-APtech-c: AT480-APmnt-by: APNIC-HMmnt-lower: MAINT-AU-APNICTRAININGmnt-routes: MAINT-AU-APNICTRAININGstatus: ALLOCATED PORTABLE

106

1. This object can only be modified by APNIC-HM

2. Creation of more specific objects within this range has to pass the authentication of MAINT-AU-APNICTRAINING3. Creation of route objects matching/within this range has to pass the authentication of MAINT-AU-APNICTRAINING

12

3

Page 107: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Whois IRT Contact

• Incident Response Team (IRT)– Dedicated abuse handling teams (not netops)

• IRT objects are mandatory when creating inetnum, inet6num and aut-num objects

• Provide an abuse contact email– Dedicated team to resolve incidents– Efficient and accurate response– Stops the tech-c and admin-c from getting abuse reports

107

Page 108: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

IRT Object

irt: IRT-ABCINTERNET-SGaddress: 1000 Jalan Bukit Merah

address: SG

e-mail: [email protected]

abuse-mailbox: [email protected]

admin-c: AINT1-AP

tech-c: AINT1-AP

auth: # Filtered

mnt-by: MAINT-SG-ABCINTERNET

changed: [email protected] 20160503

source: APNIC

108

Page 109: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

109

Page 110: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Agenda

• Introduction to APNIC• Policy Development Process

• Internet Registry Policies• Requesting IP Addresses

• APNIC Whois Database

• Using MyAPNIC• Resource Certification (RPKI)

110

Page 111: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

What is MyAPNIC?

• A secure website that enables Members to manage Internet resources and account interactions with APNIC online

https://myapnic.net

111

Page 112: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

How it Works

112

Firewall

Finance system

Membership & resource

system

Whois master

Member’s staff

APNICPublic

Servers

Client

MyAPNIC server

Member ID Person

Authority

https://myapnic.net

APNIC internal system APNIC public servers

Page 113: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Access to MyAPNIC

• Available to all authorized contacts of APNIC accounts by registering your email address and password

• Corporate Contacts can register and get instant access• Non-Corporate Contacts need their registration approved

by their Corporate Contact through MyAPNIC– Requestor must send the authorization code to the Corporate

Contact

113

www.apnic.net/corporate-contacts

Page 114: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

MyAPNIC Registration

https://myapnic.net/register

114

• Go to www.myapnic.net

Page 115: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

MyAPNIC Registration

115

Page 116: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Registration – Corporate Contact

116

Page 117: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Registration – Other Contacts

117

Send this authorisation code to your Corporate Contact

Page 118: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Registration – Other Contacts

118

Use the authorisation code to approve access

Page 119: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Registration – Other Contacts

119

Page 120: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Multiple Account Access

120

New tab for TOTP

Page 121: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

MyAPNIC Two Factor Authentication

121

• Time-based One-Time Passwords (TOTP)

Required for:

• Online voting• Resource certification• Approve other non Corporate Contact certificate requests

• Edit permissions for non Corporate Contacts

For step by step instructions on how to activate TOTP in MyAPNIC, please visit our 2fa page.

www.apnic.net/2fa

Page 122: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Time-based One-Time Passwords (TOTP)

122

Page 123: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Time-based One-Time Passwords (TOTP)

123

“Remember Me” is valid for 30 days

Page 124: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

MyAPNIC Digital Certificate

Required for:

• Online voting• Resource certification

• Approve other contacts’ certificate request

124

Page 125: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Request Certificate

125

List of all certificates generated for this account. You may also download the current certificate to install on a new browser.

Page 126: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Administration Features

126

Member and Contact details, including Billing history and Referral

Page 127: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Contact Management

127

Page 128: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Resource Management

128

Portal to list and update your current Internet resources

Page 129: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Maintainer Page

129

Maintainers associated with Member resource are added automatically and

cannot be deleted

Page 130: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

One-Click IPv6

130

Claim your IPv6 address from

within MyAPNIC

Page 131: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

One-Click IPv6

131

Page 132: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Manage Resources

132

Page 133: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Sub-allocation

133

Page 134: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Updating Attributes in Parent Object

134

Page 135: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Parent object updates

135

Highlighted attributes can be changed by user.The greyed-out attributes can only be changed by APNIC.

Page 136: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Requesting Resources

136

Displays the amount of delegations already received and available resources you can still request

Page 137: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Whois Updates

137

New “View” tab lets you view objects associated to your account

Page 138: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

138

Select the Object type to view only these types of objects

Page 139: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Adding Objects

139

Adding objects

Page 140: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Updating Objects

140

Updating objects

Page 141: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Deleting Objects

141

Deleting objects

Page 142: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Bulk Update

142

Page 143: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Bulk Update

143

Page 144: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Resource Transfer / Return

144

Page 145: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Transfer Resources

145

Select multiple IPv4 and ASN blocks you wish to transfer.

Provide the recipient’s account name.

Page 146: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Receiving Resources

146

As recipient of the IP resource, you may choose to accept or reject the transfer.

Page 147: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

147

Page 148: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

148

Page 149: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Transfer Pre-approval

149

Page 150: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

150

…..........

Page 151: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

151

Page 152: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Referral Application

152

Page 153: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

CC to Authorize Application

153

Page 154: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Available Utilities

154

Page 155: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Tools – IPv6 Sparse Assignment

155

Page 156: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Tools – IPv6 Subnet

156

Page 157: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Tools – Reverse Domain Verification

157

Page 158: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

158

Page 159: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Agenda

• Introduction to APNIC• Policy Development Process

• Internet Registry Policies• Requesting IP Addresses

• APNIC Whois Database • Using MyAPNIC• Resource Certification (RPKI)

159

Page 160: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

What is RPKI?

• Resource Public Key Infrastructure (RPKI)• A robust security framework for verifying the association

between resource holder and their Internet resources• Created to address the issues in RFC 4593 “Generic

Threats to Routing Protocols”• Helps to secure Internet routing by validating routes

– Proof that prefix announcements are coming from the legitimate holder of the resource

RFC 6480 – An Infrastructure to Support Secure Internet Routing (Feb 2012)

160

Page 161: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

“Right” to Resources

• Organization gets its resources from the RIR • Organization notifies its upstream of the prefixes to be

announced• Upstream must check the WHOIS database if resource has

been delegated to customer

We need to be able to authoritatively prove who owns an IP Prefix and what AS(s) may announce it.

161

Page 162: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

APNIC Resource Certification

• A robust security framework for verifying the association between resource holders and their Internet resources– Collaborative effort by all RIRs

• Initiative from APNIC to– Improve the security of inter-domain routing– Augment the information published in the Whois database with a

verifiable form of a holder's current right-of-use over an Internet resource

162

APNIC has integrated the RPKI management service into MyAPNIC for APNIC Member use

Page 163: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Route Origin Authorization (ROA)

• A digital object that contains a list of address prefixes and an AS number

• It is an authority created by a prefix holder to authorize an ASN to originate one or more specific route advertisements

• Create ROA objects using MyAPNIC

163

Page 164: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Activate RPKI Engine

164

Page 165: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Create ROA Objects

165

Page 166: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

ROA Suggestions

166

Page 167: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

Ready to ROA

• ROA sessions conducted at different events to help Members explore resource certification

• Join the ROA sessions• Check out the APNIC page

– http://www.apnic.net/roa

167

Page 168: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

168

Page 169: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

www.facebook.com/APNIC

www.twitter.com/apnic

www.youtube.com/apnicmultimedia

www.flickr.com/apnic

www.weibo.com/APNICrir

169

Page 170: APNIC Internet Resource Management (IRM)Tutorial...ICT meetings namely the IETF, APRICOT and ICANN meetings as a Fellow. Meetings in which he has shared his local and regional experiences

170170

Thank You!END OF SESSION