Community discussions

MikroTik App
 
asturmas
just joined
Topic Author
Posts: 14
Joined: Mon Jan 27, 2014 8:50 pm

RPKI

Fri Jan 31, 2014 10:33 am

Someone'm already use RPKI in CCR? How to do it? http://www.ripe.net/lir-services/resour ... tification

For example ripe only have configuration for cisco and juniper http://www.ripe.net/lir-services/resour ... figuration
 
asturmas
just joined
Topic Author
Posts: 14
Joined: Mon Jan 27, 2014 8:50 pm

Re: RPKI

Sun Feb 09, 2014 12:53 pm

Any help?
 
User avatar
JanZorz
newbie
Posts: 37
Joined: Fri Jan 07, 2011 1:42 pm

Re: RPKI

Tue Jul 08, 2014 2:36 pm

I'm eagerly waiting for Mikrotik to deploy RPKI route origin validation. Currently I'm doing it on ASR1k router but would gladly move this function to CCR1036 as it seems to be powerfull enough to take care of this stuff. Mikrotik staff, any information when can we expect RPKI in RouterOS?

Cheers, Jan Zorz
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7186
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: RPKI

Tue Jul 08, 2014 2:39 pm

We have plans for RPKI in RouteroS v7
 
User avatar
JanZorz
newbie
Posts: 37
Joined: Fri Jan 07, 2011 1:42 pm

Re: RPKI

Tue Jul 08, 2014 5:40 pm

Thank you very much for this information. Any idea when ROS 7 will be available for testing? I'm willing to test RPKI for you (IPv6 and IPv4 routes) if you send me the code as soon as it's available ;)

Cheers, Jan Zorz
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12557
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: RPKI

Tue Jul 08, 2014 7:16 pm

First wait the fix of all bug on ROS 6.x or you have 7.x full of bug...
 
asturmas
just joined
Topic Author
Posts: 14
Joined: Mon Jan 27, 2014 8:50 pm

Re: RPKI

Sat Jul 12, 2014 3:32 am

Any ETA for ROS 7?
 
asturmas
just joined
Topic Author
Posts: 14
Joined: Mon Jan 27, 2014 8:50 pm

Re: RPKI

Fri Jun 10, 2016 4:38 am

Two years later... Still no plans to RPKI or Router OS 7?
 
User avatar
Hammy
Forum Veteran
Forum Veteran
Posts: 776
Joined: Fri May 28, 2004 5:53 pm
Location: DeKalb, IL
Contact:

Re: RPKI

Tue May 02, 2017 4:00 pm

Still waiting...
 
User avatar
nz_monkey
Forum Guru
Forum Guru
Posts: 2182
Joined: Mon Jan 14, 2008 1:53 pm
Location: Over the Rainbow
Contact:

Re: RPKI

Wed May 03, 2017 5:18 am

Still waiting on the long over due RouterOS v7

:(
 
helectro
newbie
Posts: 48
Joined: Mon Jun 28, 2010 1:09 am

Re: RPKI

Fri May 19, 2017 1:49 pm

+1 me too still
 
JimmyNyholm
Member Candidate
Member Candidate
Posts: 248
Joined: Mon Apr 25, 2016 2:16 am
Location: Sweden

Re: RPKI

Fri Aug 04, 2017 12:22 am

+1 Any day now....
 
kcdyer
just joined
Posts: 6
Joined: Wed Nov 08, 2017 4:29 pm

Re: RPKI

Wed Nov 08, 2017 4:38 pm

RPKI would be great right about now...
 
watigre
just joined
Posts: 3
Joined: Mon May 21, 2018 5:48 pm

Re: RPKI

Tue Sep 18, 2018 8:53 am

novedades sobre ros 7 con rpki?
 
ab130kd
newbie
Posts: 37
Joined: Thu Mar 02, 2006 8:11 pm
Location: Italy

Re: RPKI

Tue Oct 02, 2018 1:56 pm

ANY SOLUTION FOR ??? https://www.ripe.net/manage-ips-and-asn ... figuration
RIPE need certification....
 
chubbs596
Frequent Visitor
Frequent Visitor
Posts: 90
Joined: Fri Dec 06, 2013 6:07 pm

Re: RPKI

Tue Oct 02, 2018 8:48 pm

RPKI is becoming a requirement more and more,

When can we expect this?
 
schadom
Member Candidate
Member Candidate
Posts: 156
Joined: Sun Jun 25, 2017 2:47 am

Re: RPKI

Thu Oct 11, 2018 7:45 pm

+1

We have plans for RPKI in RouteroS v7
MT might consider backporting RPKI from ROSv7 to 6.x :-)
 
User avatar
Hammy
Forum Veteran
Forum Veteran
Posts: 776
Joined: Fri May 28, 2004 5:53 pm
Location: DeKalb, IL
Contact:

Re: RPKI

Fri Oct 19, 2018 10:02 pm

Some Internet Exchanges are going to start requiring RPKI validation to participate in 2019.

MIKROTIK NEEDS TO RELEASE A RELIABLE RPKI IMPLEMENTATION BY THE END OF THE YEAR!
 
patrick7
Member
Member
Posts: 351
Joined: Sat Jul 20, 2013 2:40 pm

Re: RPKI

Fri Oct 19, 2018 10:38 pm

dream on :lol:
 
mutinsa
just joined
Posts: 24
Joined: Tue Feb 06, 2018 4:55 am
Location: Plettenberg Bay, South Africa
Contact:

Re: RPKI

Sat Oct 20, 2018 3:16 pm

+1.
 
schadom
Member Candidate
Member Candidate
Posts: 156
Joined: Sun Jun 25, 2017 2:47 am

Re: RPKI

Mon Oct 22, 2018 4:19 pm

Some Internet Exchanges are going to start requiring RPKI validation to participate in 2019.

MIKROTIK NEEDS TO RELEASE A RELIABLE RPKI IMPLEMENTATION BY THE END OF THE YEAR!

Yes, SwissIX for example.

MT please really consider to implement RPKI in ROS. Most other vendors already have it and the trend is clearly going in that direction. ROS would need to be able to query an external RPKI server (like https://github.com/RIPE-NCC/rpki-validator-3) and allow for filtering (ROA valid, invalid, not-found) via route filters.
 
kcdyer
just joined
Posts: 6
Joined: Wed Nov 08, 2017 4:29 pm

Re: RPKI

Tue Oct 23, 2018 6:38 pm

Yes, SwissIX for example.
YYCIX in Calgary AB, Canada is starting to implement as well.
https://yycix.ca/communities.html

I'm sure it's just a matter of time before we cannot even peer in the in exchange without it.
 
schadom
Member Candidate
Member Candidate
Posts: 156
Joined: Sun Jun 25, 2017 2:47 am

Re: RPKI

Wed Oct 31, 2018 9:07 pm

I'm sure it's just a matter of time before we cannot even peer in the in exchange without it.
If you have valid ROAs for all your routes, no need to worry with IXPs or routeservers for now, although ultimately we also need to increase ROV adoption among networks, therefore we need routing software like ROS to support it!
 
chubbs596
Frequent Visitor
Frequent Visitor
Posts: 90
Joined: Fri Dec 06, 2013 6:07 pm

Re: RPKI

Thu Nov 01, 2018 7:19 am

+10000 for RPKI
 
User avatar
netravnen
Frequent Visitor
Frequent Visitor
Posts: 77
Joined: Sun Dec 31, 2017 2:48 am

Re: RPKI

Mon Dec 17, 2018 11:54 pm

We have plans for RPKI in RouteroS v7
Any chance one can be a test pilot along-side Jan Z. on this one? Alpha testing ROS 7?

2014 was around first time RPKI was asked about. Not we hit 2018.... Still ways to go for ROS 7 being available with RPKI and Large BGP Communities support (I assume?).
 
coelliale
just joined
Posts: 23
Joined: Fri Jun 09, 2017 7:47 pm

Re: RPKI

Wed Jun 26, 2019 8:06 am

2019 up up up
 
mmc
newbie
Posts: 41
Joined: Wed Dec 29, 2004 1:44 am

Re: RPKI

Wed Jun 26, 2019 9:59 am

rpki is an urgent must - and because it's a long path from beta to stable production (which is necessary for bgp), we need the beta asap...

rpki would have prevented this worldwide issue:
https://blog.cloudflare.com/how-verizon ... ine-today/
 
mutinsa
just joined
Posts: 24
Joined: Tue Feb 06, 2018 4:55 am
Location: Plettenberg Bay, South Africa
Contact:

Re: RPKI

Fri Jun 28, 2019 3:21 pm

up
+1.
 
helectro
newbie
Posts: 48
Joined: Mon Jun 28, 2010 1:09 am

Re: RPKI

Fri Jun 28, 2019 7:57 pm

+1 again
 
TigerHuang
just joined
Posts: 2
Joined: Sun May 06, 2018 6:19 am

Re: RPKI

Sat Jun 29, 2019 8:05 am

+1 push it
 
User avatar
netravnen
Frequent Visitor
Frequent Visitor
Posts: 77
Joined: Sun Dec 31, 2017 2:48 am

Re: RPKI

Sat Jun 29, 2019 5:48 pm

Thank you very much for this information. Any idea when ROS 7 will be available for testing? I'm willing to test RPKI for you (IPv6 and IPv4 routes) if you send me the code as soon as it's available ;)
I agree with J.Z. here. If you are willing to accept select community members into an Alpha stage ROSv7 testing program.
 
User avatar
netravnen
Frequent Visitor
Frequent Visitor
Posts: 77
Joined: Sun Dec 31, 2017 2:48 am

Re: RPKI

Sat Jun 29, 2019 5:58 pm

Yes, SwissIX for example.
YYCIX in Calgary AB, Canada is starting to implement as well.
https://yycix.ca/communities.html

I'm sure it's just a matter of time before we cannot even peer in the in exchange without it.

Validity state Standard Extended Large
Prefix is included in client's AS-SET None None 53339:11:1
Prefix is NOT included in client's AS-SET None None 53339:11:2
Origin ASN is included in client's AS-SET None None 53339:11:3
Origin ASN is NOT included in client's AS-SET None None 53339:11:4
Prefix matched by a RPKI ROA for the authorized origin ASN None None 53339:11:5
Prefix matched by an entry of the ARIN Whois DB dump None None 53339:11:6

Hurts a bit you cannot do indirect discard of RPKI invalid routes there based upon the only current supported standard/extended bgp communities in ROSv6. :| When they only have deployed the functionality with bgp large communities at YYCIX.
 
User avatar
luciano
just joined
Posts: 12
Joined: Fri Nov 25, 2005 12:32 am
Location: Ponta Grossa/PR
Contact:

Re: RPKI

Fri Dec 13, 2019 3:47 pm

Hi! Still need a RPKI implementation. Here in Brazil, our RIR start to permit the use of RPKI. And here in Latin America a great number of ISP running they ASes on Mikrotik boxes.

Any update about this on RouterOS?
 
tippenring
Member
Member
Posts: 304
Joined: Thu Oct 02, 2014 8:54 pm
Location: St Louis MO
Contact:

Re: RPKI

Tue Dec 17, 2019 11:03 pm

Any idea when ROS 7 will be available for testing? I'm willing to test RPKI for you (IPv6 and IPv4 routes) if you send me the code as soon as it's available ;)
You didn't even try. It took you longer to post this reply than go check. https://www.mikrotik.com/download
 
mutinsa
just joined
Posts: 24
Joined: Tue Feb 06, 2018 4:55 am
Location: Plettenberg Bay, South Africa
Contact:

Re: RPKI

Sat Dec 21, 2019 12:06 pm

+1.
up
 
User avatar
netravnen
Frequent Visitor
Frequent Visitor
Posts: 77
Joined: Sun Dec 31, 2017 2:48 am

Re: RPKI

Sat Dec 21, 2019 12:25 pm

Hi! Still need an RPKI implementation. Here in Brazil, our RIR start to permit the use of RPKI. And here in Latin America a great number of ISP running they ASes on Mikrotik boxes.
A major PRO PLUS for implementing RPKI support directly into ROS!

The business case becomes stronger and stronger for going forward with this feature and implementing it into RouterOS. (I mean, using as-path and prefix-lists does not really get you quite the same long way RPKI does, in terms of up-to-date routing security in regards to dropping invalids. Especially now that ARIN has moved to publishing their ROA certs updates every few minutes - https://teamarin.net/2019/12/09/the-roa ... c-to-rrdp/)
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: RPKI

Sat Dec 21, 2019 12:45 pm

Back in 2014 the RouterOS v7 project was still the holy grail that would fix all problems. All new routing, all new BGP, etc etc etc.
Then nothing happened for 5 years and now there is a v7 beta, but unfortunately it is "just" a build with a new Linux kernel and nothing of those exciting features is in sight.
(almost no changes in functionality between v6 and v7beta)

The only "positive" thing that could be said is that v7beta does not contain any BGP at all, so we can still hope this is because there is an entirely new BGP but it is not completed, but it could be in a v7 final version.
Of course there is still no ETA for that. So best is to put this on the backburner for a couple more years...
 
mutinsa
just joined
Posts: 24
Joined: Tue Feb 06, 2018 4:55 am
Location: Plettenberg Bay, South Africa
Contact:

Re: RPKI

Sat Mar 28, 2020 8:18 am

+++
Back in 2014 the RouterOS v7 project was still the holy grail that would fix all problems. All new routing, all new BGP, etc etc etc.
Then nothing happened for 5 years and now there is a v7 beta, but unfortunately it is "just" a build with a new Linux kernel and nothing of those exciting features is in sight.
(almost no changes in functionality between v6 and v7beta)

The only "positive" thing that could be said is that v7beta does not contain any BGP at all, so we can still hope this is because there is an entirely new BGP but it is not completed, but it could be in a v7 final version.
Of course there is still no ETA for that. So best is to put this on the backburner for a couple more years...
 
markwien
Frequent Visitor
Frequent Visitor
Posts: 73
Joined: Sun Jul 22, 2018 10:49 am

Re: RPKI

Thu Apr 02, 2020 11:51 am

Because of issue with rustelecom urgent call to implement RPKI Origin Validation to ROS 6!
 
MCN
just joined
Posts: 16
Joined: Thu Feb 21, 2019 8:57 pm

Re: RPKI

Thu Apr 23, 2020 11:19 pm

So, as of now - with a STABLE version of ROS (April 23 2020)

RPKI is not supported / available on Mikrotik ROS.

Is this correct?

It would be nice to see a time line when this would be available.

But no rush - want it to be done correctly!
:)
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: RPKI

Thu Apr 23, 2020 11:42 pm

So, as of now - with a STABLE version of ROS (April 23 2020)

RPKI is not supported / available on Mikrotik ROS.

Is this correct?
yes
It would be nice to see a time line when this would be available.

But no rush - want it to be done correctly!
:)
MikroTik never gives time estimates to implementation of new features.
And as you can read above, it was sort of announced 6 years ago.
So no rush, be patient!
 
User avatar
nz_monkey
Forum Guru
Forum Guru
Posts: 2182
Joined: Mon Jan 14, 2008 1:53 pm
Location: Over the Rainbow
Contact:

Re: RPKI

Fri Apr 24, 2020 8:00 am

#soon


:lol:
 
User avatar
ploquets
Member Candidate
Member Candidate
Posts: 162
Joined: Tue Nov 17, 2015 12:49 pm
Location: Uruguaiana, RS, Brazil
Contact:

Re: RPKI

Wed May 27, 2020 12:38 am

Please, Mikrotik Staff, we need RPKI this year.... Impressive how this thread is from 2014 and nobody seems to care about it.
 
User avatar
eworm
Forum Guru
Forum Guru
Posts: 1092
Joined: Wed Oct 22, 2014 9:23 am
Location: Oberhausen, Germany
Contact:

Re: RPKI

Thu Jun 04, 2020 1:54 pm

What's new in 7.0beta7 (2020-Jun-3 16:31):
[...]
!) enabled BGP support with multicore peer processing (CLI only);
!) enabled RPKI support (CLI only);
[...]
 
paulct
Member
Member
Posts: 336
Joined: Fri Jul 12, 2013 5:38 pm

Re: RPKI

Thu Jun 04, 2020 4:24 pm

Thanks for listening Mikrotik.
 
paulct
Member
Member
Posts: 336
Joined: Fri Jul 12, 2013 5:38 pm

Re: RPKI

Thu Jun 04, 2020 4:52 pm

does the rpki in v7 include route origin validation?
 
paulct
Member
Member
Posts: 336
Joined: Fri Jul 12, 2013 5:38 pm

Re: RPKI

Thu Jun 04, 2020 4:54 pm

does the rpki in v7 include route origin validation?
I see it does, good news.Time to run a lab soon.
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7186
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: RPKI

Thu Jun 04, 2020 5:00 pm

Yes,
RouterOS implements RTR client. You connect to the server which will send route validity information.
This informaton can be used to validate routes in route filters against group with "rpki-validate".
ANd then further in filters "match-rpki" can be used to match exact state.
 
sebastianmeade2
just joined
Posts: 1
Joined: Sat Sep 19, 2020 2:19 am

Re: RPKI

Sat Sep 19, 2020 2:27 am

Hello, to validate do I need an external server? how do i do it? What external hardware do I need or do you recommend?
Thank you
Yes,
RouterOS implements RTR client. You connect to the server which will send route validity information.
This informaton can be used to validate routes in route filters against group with "rpki-validate".
ANd then further in filters "match-rpki" can be used to match exact state.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: RPKI

Sat Sep 19, 2020 3:39 pm

Is it too much trouble for you go google how RPKI works, how the structure of RTR client, RPKI server etc is, and how to obtain and install a server?

Who is online

Users browsing this forum: almdandi, garyjduk, jaclaz, massinia, sid5632 and 47 guests