rpki deployment panel
TRANSCRIPT
Copyright © 2015 Japan Network Information Center
RPKI deployment panel
Copyright © 2015 Japan Network Information Center
People
• Geoff Huston (chair)
• Fakrul Alam, bdHUB• A week with analysing RPKI status
• Tomoya Yoshida, Internet Multifeed• Deployment factors and current status
• Yoshinobu Matsuzaki, Internet Initiative Japan• RPKI deployment at ISP
• Taiji Kimura, Japan Network Information Center• About JPNIC’s RPKI
1
Copyright © 2015 Japan Network Information Center
RPKI Deployment Panel
• Purpose
• Gathering experienced operators voice
• Discuss further RPKI deployment for useful mechanism
2
Copyright © 2015 Japan Network Information Center
Discussions
Copyright © 2015 Japan Network Information Center
Deployment model
Public cache server
/
local cache server
4
Copyright © 2015 Japan Network Information Center
Deployment model
RPKI in IXP
and
Route reflector
5
Copyright © 2015 Japan Network Information Center
Deployment model
RPKI and IRR
6
Copyright © 2015 Japan Network Information Center
HOWTO
Configuring RPKI cache
and
Building own RPKI CA
7
Copyright © 2015 Japan Network Information Center
What do you do when…
Copyright © 2015 Japan Network Information Center
(Customer AS)
• Customer claims their prefix has been announced from other AS!
9
Copyright © 2015 Japan Network Information Center
(Own prefix)
• You found your prefix has no reachability from other region.What do you do?
10
Copyright © 2015 Japan Network Information Center
(Customer AS)
• Customer claims their prefix has been announced from other AS!What do you do?
11
Copyright © 2015 Japan Network Information Center
(DDoS mitigation)
• DDoS packets are coming!You found if other AS announces specific announce.
12
Copyright © 2015 Japan Network Information Center
JPNIC’s RPKI
Taiji Kimura
Copyright © 2015 Japan Network Information Center
Issues on RPKI deployment in Japan
• Deployment for operators• How RPKI is use for people - BGP operators
• Language
14
Copyright © 2015 Japan Network Information Center
Developing items and technical specifications
• Internationalization
• Database
• Authentication
• Redundancy and easy maintenance
• Server security
• Key management and PKI operation
15
Copyright © 2015 Japan Network Information Center
Internationalization
16
Copyright © 2015 Japan Network Information Center
Further step
• Multi-language support
• Feedbacks for developer
17
Copyright © 2015 Japan Network Information Center
It is time to release.
RPKI pilot service