cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1667
Views
11
Helpful
28
Replies

RPKI Validator Server Configuration

onibala
Level 1
Level 1

Can IOS, IOS-XE, or IOS-XR support server functioning as RPKI Validator? This is similar of PKI CA server configuration in any IOS platform.

I want to test it in our Lab without connecting to any RPKI servers in the Internet.

Thanks,

Audie

 

3 Accepted Solutions

Accepted Solutions

M02@rt37
VIP
VIP

Hello @onibala

IOS-XE XR Ok. A doubt about IOS.... because you have a peering with ISP and have the full table.... you need plateform with IOS-XR or XE. Thens it is ok! 

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

View solution in original post

Hi @onibala ,

The validator function is normally run on a separate Linux server. As far as I know, XR and XE do not support the RPKI Validator (or equivalent) functionality natively, but they both allow you to run 3rd party applications in a container. This might be an option, but I think the safest implementation would be to run it on a separate Linux server.

Regards,

 

Harold Ritter
Sr Technical Leader
CCIE 4168 (R&S, SP)
harold@cisco.com
México móvil: +52 1 55 8312 4915
Cisco México
Paseo de la Reforma 222
Piso 19
Cuauhtémoc, Juárez
Ciudad de México, 06600
México

View solution in original post

28 Replies 28

onibala
Level 1
Level 1

Thanks for the quick response Balaji! This config is for VPN certificate. I am looking for securing BGP Prefix and AS exchange. 

Here are examples:

How to Install an RPKI Validator | RIPE Labs

https://rpki.readthedocs.io/en/latest/

 

 

got you, IOS XE and XR support that features as per the document.

setting offline RPKI Server (not that i have done before)

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Balaji,

Please provide the link of how to setup RPKI server.

Thanks!

@onibala 

Refer here 

xr: https://beufa.net/fr/blog/rpki-use-routinator-rtr-cache-validator-cisco-ios-xr/

xe: https://www.rheintal-ix.net/tech/rpki/

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

M02@rt37
VIP
VIP

Hello @onibala

IOS-XE XR Ok. A doubt about IOS.... because you have a peering with ISP and have the full table.... you need plateform with IOS-XR or XE. Thens it is ok! 

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

Thanks for replying M02@rt37

I will get the XR or XE as long it can function as RPKI server.

M02@rt37,

I knew already the link given (https://beufa.net/blog/rpki-use-routinator-rtr-cache-validator-cisco-ios-xr/). I will accept it as solution, but I was looking an article from Cisco.com.

Thank You

onibala
Level 1
Level 1

Anyone has the solution from Cisco.com, and "other than" from beufa.net?

I have seen this link before. Has anyone tried it?

Thanks

What you need exactly' you want to try it in lab?

MHM Cisco World,

I want to setup simple setup of 5 (IOS, IOS-XE) routers, with one functioning as the Validator. I am hesitant to buy an XR router functioning as the Validator, and does not work! I have not found an article by Cisco to back it up.

I want to see proof by Cisco that the XR can support the Validator function.

Hi @onibala ,

The validator function is normally run on a separate Linux server. As far as I know, XR and XE do not support the RPKI Validator (or equivalent) functionality natively, but they both allow you to run 3rd party applications in a container. This might be an option, but I think the safest implementation would be to run it on a separate Linux server.

Regards,

 

Harold Ritter
Sr Technical Leader
CCIE 4168 (R&S, SP)
harold@cisco.com
México móvil: +52 1 55 8312 4915
Cisco México
Paseo de la Reforma 222
Piso 19
Cuauhtémoc, Juárez
Ciudad de México, 06600
México

This is what I suspected Harold. I hope you are wrong though. That is why I was skeptical of the beufa.net article.

Thanks!

 

 

Review Cisco Networking for a $25 gift card