• About

http://blog.fakrul.com

http://blog.fakrul.com

Tag Archives: RPKI

bdNOG & “Ready for ROA” Campaign

02 Thursday Jul 2015

Posted by Fakrul Alam in Reading

≈ Leave a comment

Tags

bdNOG, RPKI

There are many discussions going on Resource Certification or Resource Public Key Infrastructure (RPKI) and it’s one of the models for Securing Internet Routing. RPKI; the SIDR model has multiple components and deployment phase; but for successful RPKI implementation; creating Route Origin Authorization (ROA) is the first step. A ROA is a cryptographically signed object that states which Autonomous System (AS) is authorized to originate a certain prefix(es).

So far in this region (Asia Pacific) RPKI adoption rate is not impressive. Community is very slow understanding the necessity of Internet routing security and how it impacts the global Internet.

This year APNIC started “Ready for ROA” campaign; which has a significant impact on the growth in RPKI adoption in this region. From bdNOG (Bangladesh Network Operators Group) we are also part of the campaign. In our recent bdNOG events (bdNOG2 & bdNOG3) we try to make community understand the necessity of Internet routing security and how they can be part of it. We encourage them creating ROA object. We simulate the whole process; starting from ROA object creation, configure RPKI validator server and how all the components work.

Continue reading →

RPKI and My presentation in APRICOT2015

30 Tuesday Jun 2015

Posted by Fakrul Alam in Tutorial

≈ Leave a comment

Tags

RPKI

In APRICOT2015 I was the panelist for “RPKI Deployment Session” where I present RPKI adoption status in BD and compare it with other RIR and few other findings on route leckage. 

For details you can read the following blog from APNIC BLOG

https://blog.apnic.net/2015/03/04/apricot-2015-rpki-deployment-session/

RPKI Presentation in SANOG24

13 Wednesday Aug 2014

Posted by Fakrul Alam in My Work, Tutorial

≈ Leave a comment

Tags

RPKI

<div style=”margin-bottom:5px”> <strong> <a href=”https://www.slideshare.net/fakrulalam/rpki-resource-public-key-infrastructure&#8221; title=”RPKI (Resource Public Key Infrastructure)” target=”_blank”>RPKI (Resource Public Key Infrastructure)</a> </strong> from <strong><a href=”http://www.slideshare.net/fakrulalam&#8221; target=”_blank”>Fakrul Alam</a></strong> </div>

RPKI (Resource Public Key Infrastructure)

08 Saturday Mar 2014

Posted by Fakrul Alam in Uncategorized

≈ Leave a comment

Tags

RPKI

RPKI Validation:

For Valid ROA:

fakrulalam@Fakruls-MacBook-Air ~/Downloads> whois -h whois.bgpmon.net " --roa 58656 103.12.179.0/24"
0 - Valid
------------------------
ROA Details
------------------------
Origin ASN: AS58656
Not valid Before: 2014-08-06 05:36:18
Not valid After: 2015-10-31 00:00:00 Expires in 1y11d9h15m54.6000000014901s
Trust Anchor: rpki.apnic.net
Prefixes: 103.12.176.0/22 (max length /24)
 118.179.0.0/19 (max length /24)
 2404:d900::/32 (max length /48)

For Invalid ROA:

fakrulalam@Fakruls-MacBook-Air ~/Downloads> whois -h whois.bgpmon.net " --roa 23956 103.12.179.0/24"
2 - Not Valid: Invalid Origin ASN, expected 58656

For non-presence ROA:

fakrulalam@Fakruls-MacBook-Air ~/Downloads> whois -h whois.bgpmon.net " --roa 23956 202.4.97.0/24"
1 - Not Found

Social

  • View rapappu’s profile on Twitter
  • View fakrulalam’s profile on LinkedIn
  • View fakrul’s profile on GitHub
  • View FakrulAlamPappu’s profile on Google+
  • View fakrulalam’s profile on Flickr

Twitter Updates

  • krebsonsecurity.com/2021/03/whistl… 1 week ago
  • very production vs code extension marketplace.visualstudio.com/items?itemName… 1 week ago
  • afr.com/companies/tour… 1 week ago
  • RT @Tyriar: We're looking at finally adding terminal tabs to @code soon. This month we explored what the UX should look like and have some… 2 weeks ago
  • RT @teamcymru: April 7 at 10AM GMT +3 We're hosting a webinar on our FREE community services! Live DEMO of Nimbus and learn about • DDoS mi… 2 weeks ago
  • Interesting! Looks like #cloudflare is not just a CDN only. cloudflare.com/en-au/magic-wan 2 weeks ago
  • still beta but good to see #meraki is rolling out AnyConnect client for MX. Windows L2TP VPN client is pain-in-the-… twitter.com/i/web/status/1… 3 weeks ago
  • one more bug reported cisco.ios.ios_bgp_address_family module github.com/ansible-collec… #ansible #cisco #ios… twitter.com/i/web/status/1… 4 weeks ago
  • #azure canola oil https://t.co/yEj1mCbQ4K 1 month ago
  • My first attempt to fix bug for cisco.ios.ios_bgp_address_family ansible module. PR done. github.com/ansible-collec… 1 month ago
  • RT @C_C_Krebs: This is the real deal. If your organization runs an OWA server exposed to the internet, assume compromise between 02/26-03/0… 1 month ago
  • RT @MirjamKuhne: This morning at #apricot2021 an update from NOGs in the region. https://t.co/kv7tEhszZf 1 month ago
  • RT @hfpreston: A Type 3 LSA walks into a bar and the bartender asks, “Not from the area?” A Type 5 LSA walks into a bar and orders a drink… 1 month ago
  • ansible.com/blog/announcin… 1 month ago
  • Time to refresh home wifi. Moving from #meraki to #Unifi https://t.co/9t6FYIfQfb 1 month ago
Follow @rapappu

Tags

antismap antivirus automation Azure bangladesh BASH BASH Script BDCERT bgp bind ccsp centos CentOS mirror CERT CISA cisco Cyber Security ddos dhaka dhakacom DNS DNSSEC GSM intrusion detectoin system Intrusion prevention system ips IPv6 ISACA junos linux Looking Glass lxc lxc profile lxd mailqueue mailscanner Mail Server mailwatch Meraki mikrotik monitor mpls MPLS L3 VPN mysql My Work network network management nginx NSD observium OpenVPN perl PHP ping postfix Proxy PTA python RANCID Reading RPKI Shell Script sms sms server SNMP SSH Tutorial ubuntu Ubuntu Mirror Server Virtual Box vispan vmware websvn Youtube hack খামাখা

Blog at WordPress.com.