Skip to content

ASPA: the new protocol for improving BGP routing security

This is a draft agenda: changes are still being made.

Speaker:
Ondřej Caletka, RIPE NCC
Date:
Time:
Room:
Main Room
Session:
Tutorial
Duration:
90 min
Transcript:
Not Available
Meetecho chat:
Not Available
Type:
Tutorial
Slides:
—
Recording:
Not Available
Add to calendar

Abstract

In the past it was believed that network operators should periodically download clear text data from the Internet and put them into the configuration of their routers to make routing more secure.
RPKI is a technology to secure routing which employs proper cryptography. For years we have used it for Route Origin Authorization. In 2026, new feature of RPKI is being deployed: Autonomous System Provider Authorization.

It complements existing Route Origin validation with a (partial) path validation: each Autonomous System can declare which autonomous systems are expected to provide transit services. Network operators validating ASPA can then drop routes coming via unauthorised providers.

In this tutorial we will dive deeper into the principles of ASPA, show how to create ASPA objects for the ASNs you hold and how to properly configure validation in your routers. We will also cover how to troubleshoot ASPA validation failures.

Recording

Video will be added soon.

Speaker

Ondřej Caletka

Ondřej Caletka

Ondřej Caletka works as a Systems Engineer in the Learning and Development team. His main responsibility includes developing and operating the lab environment for training courses and online learning.

Ondřej graduated from Czech Technical University in Prague and worked as network services administrator and developer for the Czech national research and education network CESNET before joining the RIPE NCC. He is also active in local IT communities around open source/free software, and acts as an IPv6 and DNSSEC ambassador, delivering talks and trainings at various events.

Rate this talk

Rating will open: Monday, 26 October 2026 09:00 (+0200).