How ASN Assignment on Leased IPv4 Prefixes Determines BGP Route Validity
When leasing an IPv4 prefix, the Autonomous System Number (ASN) used to originate it in BGP must exactly match the one listed in the Route Origin Authorization (ROA), or validating peers will drop the route entirely. There are four main origin scenarios: using your own ASN, letting an upstream provider announce under their ASN, using a cloud provider's BYOIP service, or routing through a third-party partner's ASN. A common mistake is creating a ROA against a future or incorrect ASN before the actual announcement is live, which triggers an 'Invalid' state that causes partial, hard-to-diagnose connectivity failures. The maxLength field in the ROA must also cover the exact prefix length being announced, as even a correct ASN paired with an overly specific prefix results in an Invalid status. Operators can verify ROA validity using RIPEstat's API or local relying-party tools like Routinator or rpki-client, while cloud platforms such as AWS and Azure impose additional ASN and prefix constraints specific to their infrastructure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in