Re: [FROG] RPKI, this is getting a bit frustrating
Hi Chris, On 28/09/2023 20:38, frog-request@lists.frrouting.org wrote:
[...] My RPKI config: rpki rpki cache 172.65.0.2 8282 preference 1 rpki cache 172.65.0.2 8283 preference 2 [...]
Is there a reason to use the same validator on two different ports ? Why not use another one? (by the way I was not even aware of port 8283 on that validator) In my setup running FRRouting 9.0.1 (bdr2) on Linux(6.1.0-12-amd64), debian 12. I have 3 validators - 2 from Cloudflare (IPv4 and IPv6) - another one on IPv6 We perform route origin validation without any issue. Config b# sh rpki cache-connection Connected to group 2 rpki tcp cache rp.my.domain 323 pref 5 rpki tcp cache 2606:4700:60::2 8282 pref 2 (connected) rpki tcp cache 172.65.0.2 8282 pref 3 sh memory bgpd --> http://paste.debian.net/1293467/ -- Willy Manga @ongolaboy https://ongola.blogspot.com/
I’m not currently convinced that this is a rpki issue yet. Hence my ask for a second show memory Donald Sent from my iPhone
On Sep 29, 2023, at 2:39 AM, Willy Manga <mangawilly@gmail.com> wrote:
Hi Chris,
On 28/09/2023 20:38, frog-request@lists.frrouting.org wrote: [...] My RPKI config: rpki rpki cache 172.65.0.2 8282 preference 1 rpki cache 172.65.0.2 8283 preference 2 [...]
Is there a reason to use the same validator on two different ports ? Why not use another one? (by the way I was not even aware of port 8283 on that validator)
In my setup running FRRouting 9.0.1 (bdr2) on Linux(6.1.0-12-amd64), debian 12.
I have 3 validators - 2 from Cloudflare (IPv4 and IPv6) - another one on IPv6
We perform route origin validation without any issue.
Config
b# sh rpki cache-connection Connected to group 2 rpki tcp cache rp.my.domain 323 pref 5 rpki tcp cache 2606:4700:60::2 8282 pref 2 (connected) rpki tcp cache 172.65.0.2 8282 pref 3
sh memory bgpd --> http://paste.debian.net/1293467/
-- Willy Manga @ongolaboy https://ongola.blogspot.com/ _______________________________________________ frog mailing list frog@lists.frrouting.org https://lists.frrouting.org/listinfo/frog
participants (2)
-
Donald Sharp -
Willy Manga