Abstract
In the past it was believed that network operators should periodically download clear text data from the Internet and put them into the configuration of their routers to make routing more secure.
RPKI is a technology to secure routing which employs proper cryptography. For years we have used it for Route Origin Authorization. In 2026, new feature of RPKI is being deployed: Autonomous System Provider Authorization.
It complements existing Route Origin validation with a (partial) path validation: each Autonomous System can declare which autonomous systems are expected to provide transit services. Network operators validating ASPA can then drop routes coming via unauthorised providers.
In this tutorial we will dive deeper into the principles of ASPA, show how to create ASPA objects for the ASNs you hold and how to properly configure validation in your routers. We will also cover how to troubleshoot ASPA validation failures.
Recording
Video will be added soon.
Speaker
Ondřej Caletka
Ondřej Caletka works as a Systems Engineer in the Learning and Development team. His main responsibility includes developing and operating the lab environment for training courses and online learning.
Ondřej graduated from Czech Technical University in Prague and worked as network services administrator and developer for the Czech national research and education network CESNET before joining the RIPE NCC. He is also active in local IT communities around open source/free software, and acts as an IPv6 and DNSSEC ambassador, delivering talks and trainings at various events.
Rate this talk
Rating will open: Monday, 26 October 2026 09:00 (+0200).