APNIC Academy Training
Routing Security with RPKI ROV and ASPA Workshop
Synopsis
This workshop provides a practical and up-to-date introduction to modern mechanisms forsecuring inter-domain routing on the Internet. Focusing on the Resource Public KeyInfrastructure (RPKI) and its operational extensions, participants will learn how this frameworkhelps mitigate common routing threats such as prefix hijacking, route leaks, and pathmanipulation.
The course covers Route Origin Validation (ROV), demonstrating how network operators can useRPKI data to make real-time routing decisions and filter invalid BGP announcements. It alsointroduces Autonomous System Provider Authorization (ASPA), an emerging standard designedto enhance path validation and prevent route leaks by strengthening the integrity of AS paths.
By the end, participants will have the knowledge and hands-on experience needed to implementRPKI-based protections, enforce ROV, and prepare for ASPA adoption in operational networks.
Target Audience
Technical staff who are building or operating a service provider or enterprise network withinternational and/or multi-provider connectivity.
Pre-requisites
It is assumed that the workshop participants:
- have a working knowledge of an IGP (OSPF or IS-IS), and
- know how to use a router command line interface.
This workshop is not an introduction. The lab exercises use Cisco IOS configuration syntax.
Academy resources to be completed before start of workshop:
Course Outline
- Routing Security Incidents
- RPKI Framework
- Route Origin Authorization (ROA)
- Route Origin Validation (ROV)
- Autonomous System Provider Authorization (ASPA)
- Routing Security best practices
Other Requirements
- Participants are advised to bring their own laptop or desktop computers with high-speedinternet access and administrative access to system. It is also recommended that computershave Intel i5 or i7 processor, >=8GB of RAM and 30GB of free hard disk space.
- Software: SSH Client, Telnet Client (PuTTy)
- Confirm Secure SHell (SSH) is allowed from the office or home network to access the lab infrastructure. Test SSH connectivity, try to connect to route-views.routeviews.org. For example, from the CLI type: ssh rviews@route-views.routeviews.org
- Attendees must have an APNIC Academy login account. If you don't have one already, you can create an account for free at https://academy.apnic.net/