Hi all,
A quick question for those using RTBH together with RPKI.
How do you handle /32 announcements in IPv4 or /128 in IPv6 when the prefix
has a ROA with a maxLength of /24 or /48?
One option would be to extend the ROA to /32 or /128, but I’m not fully
comfortable with that since it would also make other more-specifics valid.
The other option would be to keep the ROA as it is and still announce the
host route for RTBH, but in that case it would be RPKI Invalid. Do
upstreams normally make an exception for routes marked as blackhole, or are
they dropped by RPKI before the RTBH policy is applied?
Creating a specific ROA at the time of the attack also doesn’t seem very
practical because of propagation times.
How are you handling this in production?
Regards,
Salvador