RPKI Validation Alone Does Not Determine Route Fate, Policy Does
A technical tutorial series called Protocol in Code has published its fifth BGP session, focusing on how origin validation and routing policy are two distinct layers in the BGP decision process. The session explains that RPKI validation only answers whether a route's origin AS matches its ROA records, returning a state of valid, invalid, or not found. What actually happens to the route — rejection, deprioritization, or acceptance — is determined separately by locally configured routing policy. The code demonstrates that rejecting invalid routes is an opt-in behavior, not a protocol default, meaning the same validation result can produce different actions on different routers. The session aims to correct the widespread misconception that an RPKI-invalid route is automatically dropped by the router.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in