RPKI Synchronization
RPKI (Resource Public Key Infrastructure) is a security framework for verifying the association between IP address blocks and their authorized origin ASes. This guide covers setting up RPKI validation on your network and ensuring synchronization with the global RPKI repositories.
How RPKI Works
┌─────────────┐ ┌──────────────┐ ┌──────────────┐
│ RIPE NCC │────▶│ RPKI Cache │────▶│ Router │
│ Repository │ │ (Validator) │ │ (RTR Client)│
└─────────────┘ └──────────────┘ └──────────────┘
ROAs Validated ROAs Route filtering
via RPKI-RTR based on validation
- RIRs (RIPE NCC, ARIN, APNIC, etc.) publish ROAs in their RPKI repositories
- RPKI validators fetch and cryptographically validate these ROAs
- Routers connect to validators via the RTR (RPKI-to-Router) protocol and apply route origin validation
Setting Up an RPKI Validator
Option 1: Routinator (NLnet Labs)
Routinator is a widely-used, open-source RPKI relying party software.
Installation on Debian/Ubuntu
# Add the NLnet Labs repository
sudo apt install -y ca-certificates curl gnupg
curl -fsSL https://packages.nlnetlabs.nl/aptkey.asc | sudo gpg --dearmor -o /usr/share/keyrings/nlnetlabs-archive-keyring.gpg
echo "deb [signed-by=/usr/share/keyrings/nlnetlabs-archive-keyring.gpg] https://packages.nlnetlabs.nl/linux/debian $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/nlnetlabs.list
# Install Routinator
sudo apt update
sudo apt install -y routinator
Initial Setup
# Initialize Routinator (accept the ARIN TAL)
routinator init --accept-arin-rpa
# Start Routinator with RTR server on port 3323 and HTTP on 8323
routinator server --rtr 0.0.0.0:3323 --http 0.0.0.0:8323
Systemd Service
Create a systemd service for automatic startup:
sudo systemctl enable routinator
sudo systemctl start routinator
Verify it is running:
# Check status
sudo systemctl status routinator
# Check the HTTP interface
curl http://localhost:8323/api/v1/status
Option 2: FORT Validator
FORT Validator is another open-source RPKI validator.
# Install on Debian/Ubuntu
sudo apt install -y fort-validator
# Configure and start
sudo systemctl enable fort-validator
sudo systemctl start fort-validator
Option 3: Using RIPE NCC's Hosted RPKI Validator
If you don't want to run your own validator, you can use public RTR endpoints. However, for production environments, running your own validator is strongly recommended.
Configuring Routers for RPKI
Cisco IOS-XR
router bgp 64496
rpki server 10.0.0.1
transport tcp port 3323
refresh-time 300
!
address-family ipv4 unicast
route-policy rpki-validation in
!
!
route-policy rpki-validation
if validation-state is valid then
set local-preference 200
pass
elseif validation-state is invalid then
drop
else
set local-preference 100
pass
endif
end-policy
Juniper JunOS
routing-options {
validation {
group rpki-validators {
session 10.0.0.1 {
port 3323;
refresh-time 300;
}
}
}
}
policy-options {
policy-statement rpki-validation {
term valid {
from {
protocol bgp;
validation-database valid;
}
then {
local-preference 200;
accept;
}
}
term invalid {
from {
protocol bgp;
validation-database invalid;
}
then reject;
}
term unknown {
from protocol bgp;
then {
local-preference 100;
accept;
}
}
}
}
BIRD 2
roa4 table r4;
roa6 table r6;
protocol rpki rpki_validator {
roa4 { table r4; };
roa6 { table r6; };
remote "10.0.0.1" port 3323;
retry keep 90;
refresh keep 300;
expire keep 600;
}
filter bgp_in {
if (roa_check(r4, net, bgp_path.last) = ROA_INVALID) then reject;
if (roa_check(r4, net, bgp_path.last) = ROA_VALID) then {
bgp_local_pref = 200;
}
accept;
}
MikroTik RouterOS 7
/routing/rpki
add group=rpki-validator address=10.0.0.1 port=3323 refresh-interval=300
/routing/filter/rule
add chain=bgp-in rule="rpki-verify rpki-validator"
add chain=bgp-in rule="if (rpki invalid) { reject }"
add chain=bgp-in rule="if (rpki valid) { set bgp-local-pref 200 }"
Verifying RPKI Synchronization
Check Validator Status
# Routinator: check number of validated ROAs
curl -s http://localhost:8323/api/v1/status | jq '.
# Check specific prefix validation
curl -s "http://localhost:8323/api/v1/validity/AS64496/192.0.2.0/24"
Check Router RPKI Session
Cisco IOS-XR:
show bgp rpki summary
show bgp rpki table
show bgp ipv4 unicast <prefix> detail
Juniper JunOS:
show validation session
show validation database
show route <prefix> detail | match validation
BIRD 2:
birdc show protocols all rpki_validator
birdc show route <prefix> all
External Validation Tools
- RIPE Stat RPKI Dashboard — Check RPKI status for any prefix
- Cloudflare RPKI Portal — View RPKI adoption statistics
- RPKI Monitor — NIST RPKI monitoring tool
Troubleshooting
Validator not syncing
# Check if Routinator can reach RPKI repositories
routinator vrps --format csv | head -20
# Check logs for errors
journalctl -u routinator -f
RTR session not establishing
- Verify network connectivity to the validator:
telnet 10.0.0.1 3323 - Check firewall rules — TCP port 3323 must be open
- Verify the validator is running and listening:
ss -tlnp | grep 3323
Routes marked as Invalid
- Verify a ROA exists for your prefix in the RIPE Database
- Check the ROA parameters match your announcement (AS, prefix, max length)
- Wait for propagation — ROA changes can take up to 1 hour to propagate to all validators
RPKI propagation typically takes 10–30 minutes after a ROA is created or modified in the RIPE NCC portal.