BGP & ROUTING

BGP Prefix Validation: RPKI & IRR

Validate a prefix and origin ASN using RIPEstat RPKI and prefix-routing-consistency endpoints.

39DExternal testRuns from the toolbox server

RUN TEST

BGP Prefix Validation: RPKI & IRR

Public targets only

HOW IT WORKS

About the BGP Prefix Validation: RPKI & IRR

RPKI checks whether a cryptographically authorised ROA permits the origin ASN to announce the prefix. IRR consistency compares route objects with routing behaviour observed by RIS.

How to use this result

  1. Run the test from this server.Use a public hostname, address, prefix or ASN in the format requested above.
  2. Compare with another observation point.Run a local command or use a second provider to identify location-specific behaviour.
  3. Correlate related evidence.Use the related tools below to compare DNS, routes, ports, TLS and application responses.
  4. Keep the time and context.Routing, DNS caches and reputation data change, so record when the result was collected.

Common interpretation issues

  • RPKI “unknown” means no covering ROA, not necessarily a hijack.
  • RPKI “invalid” can be caused by the wrong origin or an overly short maximum length.
  • IRR databases can contain stale or duplicated objects.

NEED HELP INTERPRETING THE RESULT?

39D supports business networks, cyber security and managed IT.

For ongoing support or a larger infrastructure project, speak to the 39D team.

Visit 39D

Frequently asked questions

Which result is cryptographically verifiable?

RPKI origin validation is based on the signed RPKI hierarchy.

Should invalid routes be accepted?

Network policy varies, but invalid announcements are commonly rejected by operators implementing ROV.