BGP Preparations: ASN, IP Prefix, IRR, and RPKI Checklist

Route hijacking incidents are rising sharply across the internet. You need proactive defenses before announcing your IP space to the world or turning up a new Japan server. Your BGP line preparations must cover four essential pillars: ASN, IP prefix, IRR, and RPKI. These elements form your complete security checklist.
Without proper preparation, you risk costly misconfigurations and devastating security breaches. Attackers can redirect your traffic or impersonate your network, whether you operate a single Japan server or a global backbone. The MANRS initiative now expects operators to adopt these safeguards as standard practice.
This guide walks you through each pillar step by step. You will learn exactly what to obtain, configure, and verify. Follow this checklist to build a secure, reliable BGP foundation that peers will trust.
Key Takeaways
Get a public ASN from your RIR to identify your network on the internet.
Plan your IP prefixes to avoid fragmentation and keep routing tables clean.
Register route objects in the IRR to prove you own your prefixes.
Create ROAs in RPKI to cryptographically authorize your announcements.
Review your IRR and RPKI records regularly to maintain security.
BGP Line Preparations: ASN Essentials
Your ASN serves as your network’s unique identifier on the global internet. Without it, you cannot participate in BGP routing. Obtaining and configuring your ASN correctly forms the first critical step in your BGP line preparations.
ASN Basics and Acquisition
You need to understand the two types of ASNs before you apply. Public ASNs operate on the global internet. Private ASNs work only within local networks. The table below shows the key differences.
Aspect | Public AS Numbers | Private AS Numbers |
|---|---|---|
Scope of use | Global Internet | Local/private networks |
Visibility | Internet-wide | Within private networks |
Global uniqueness | Globally unique | Can be reused across many networks |
Registration | Allocated by IANA, assigned via RIRs | No registration required |
Cost and accessibility | Requires registration and fees | Freely available for internal use |
Typical users | ISPs, enterprises with global presence | Enterprises needing internal routing control |
For internet announcements, you need a public ASN. You must apply to a Regional Internet Registry (RIR) like ARIN or RIPE NCC. The process follows a clear timeline.
Submit an ASN request to your RIR.
A Resource Analyst reviews the request, typically within 2 business days.
Upon approval, you must pay fees and submit a signed Registration Services Agreement (RSA) within 60 days.
After the RIR receives the signed RSA and fees, the ASN resources are issued within 2 business days.
This timeline shows you can obtain your ASN in about one to two weeks.
Configuring Your ASN for Routing
Once you have your ASN, configure it on your router. The configuration starts with basic commands. On a Cisco router, you use these commands.
router bgp <ASN>: Enter router configuration mode to create a BGP process.neighbor <IP> remote-as <ASN>: Configure a BGP neighbor with its IP address and remote ASN.
These two commands form the minimum required setup. You can add optional commands like neighbor <IP> next-hop-self or neighbor <IP> route-map <name> for more control.
Your preparation also includes understanding traffic engineering. ASN prepending helps with this. It works by artificially lengthening the AS path attribute in BGP route advertisements. When you prepend your own AS multiple times, remote routers see a longer AS path. Given equal higher-priority attributes like weight and local preference, they prefer a shorter alternative path. This technique lets you steer inbound traffic away from specific links for load balancing, maintenance, or failover purposes.
Proper ASN configuration and prepending strategies give you control over your routing. This foundation supports all subsequent BGP line preparations, including IP prefix planning and route security.
IP Prefix Planning and Registration
Your IP prefixes represent your network’s addressable territory. Planning their allocation carefully prevents fragmentation and ensures efficient routing across the internet. This step in your BGP line preparations determines how easily peers can reach your services.
Allocating and Structuring Your Prefixes
You need a clear strategy for dividing your address space. Start with a single large block from your RIR. Then split it into smaller, logical subnets that match your network topology. This hierarchical structure keeps routing tables clean and manageable.
Avoid creating many small, scattered prefixes. Each prefix you announce adds an entry to the global routing table. The CIDR Report dated 19 August 2026 shows the global IPv4 BGP routing table currently contains approximately 1.072 million prefixes. Every unnecessary announcement contributes to this growing number. Peers may filter your routes if you announce too many small prefixes instead of aggregating them into larger blocks.
Plan your prefix sizes based on actual usage. Allocate /24 blocks for customer assignments. Reserve larger blocks for data center infrastructure. Keep room for growth within each allocation. This approach minimizes the need for renumbering later.
Consider your upstream and downstream relationships. Your prefix structure affects how you implement traffic engineering policies. A well-organized block allows you to apply route maps and prefix lists more effectively. You can control which specific subnets you advertise to different peers.
Registering Prefixes with Your RIR
Registration establishes your legal ownership of the address space. You must create route objects in your RIR database that document your prefixes. These objects link your prefixes to your ASN, proving you have the authority to announce them.
Unregistered prefixes create serious problems. Peers often filter routes that lack proper registration. Their automated systems check the IRR before accepting your announcements. Without registration, your traffic may never reach its destination.
Your RIR provides a portal for managing registrations. You log in, create the route objects, and specify your ASN as the origin. The process takes minutes but provides lasting protection. You should also maintain accurate contact information in your registration records.
Registration supports your security posture beyond basic routing. It enables other operators to validate your announcements automatically. This validation reduces the risk of your prefixes being hijacked or spoofed. Your registration records become part of the trust infrastructure that keeps the internet routing system reliable.
Setting Up IRR for Route Validation
The Internet Routing Registry (IRR) serves as a public database system where you document which ASN may announce which prefixes. These records, called route objects, form the trust layer that peers consult before accepting your BGP announcements. Without accurate IRR records, your routes may face filtering or rejection across the internet.
Creating Route Objects in the IRR
You create route objects through your RIR’s portal. Each object contains your prefix, your origin ASN, and contact information. For IPv4, you use the route: field. For IPv6, you use route6:. These objects tell the world that your ASN has legitimate authority to announce your address space.
The accuracy of these records matters more than you might think. A longitudinal analysis over 1.5 years identified 34,199 irregular route objects out of 1,542,724 in the largest IRR database. Of those irregular records, 6,373 were potentially suspicious. This means malicious actors could exploit false records to bypass your defenses.
The IRR lacks a strict validation standard. Limited coordination across database providers allows inaccuracies to persist. Attackers exploit this weakness. Consider these documented cases:
Attack Case | Attacker (ASN) | Target / Victim | Method & Consequence |
|---|---|---|---|
Case 1 | AS209243 (QuickHost.uk) | Amazon’s address space (hosting Celer Network’s crypto exchange) | Registered false objects in ALTDB, pretending to be an upstream provider of Amazon (AS16509), leading to a successful BGP hijack. |
Case 2 | AS207427 (GoHosted.eu) | 3 UCSD-announced prefixes | Registered false IRR objects for the prefixes and hijacked them in BGP for over a month. |
These attacks succeeded because operators trusted IRR data without verification. Your BGP line preparations must include creating accurate route objects and regularly auditing them for unauthorized changes.
Using IRR for Filtering and Compliance
Network operators use your IRR records to build prefix filters for their BGP sessions. The process follows a systematic approach:
Obtain the neighbor’s AS number and optionally an AS-SET object (AS-MACRO).
Recursively expand the AS-SET to retrieve the complete list of AS numbers the peer may announce.
For each AS number, query the IRR to find all associated prefixes (route objects).
Build a list of allowed prefixes, optionally including origin AS information.
Refresh the computed prefix filters regularly, daily is recommended, because IRR objects change frequently.
Tools like bgpq3 and bgpq4 automate this process. They generate prefix lists directly from IRR data. You can integrate them into automation scripts that push filter changes to routers over NETCONF. This automation ensures your filters stay current without manual intervention.
MANRS compliance requires you to maintain accurate IRR objects. The RIPE NCC developed the rpki-irr-bgp-stats tool to help you identify inconsistencies. This software analyzes BGP announcements against RPKI and IRR data. It takes three inputs: NRO delegated extended stats, BGP RIS dump with announcements, and an authorization file containing ROA data or route objects. The tool validates announcements against authorizations and reports metrics such as valid, invalid, and unknown announcements. You can group results by RIR, country, or generate a world map. This visibility helps you spot mismatched ASNs or prefix lengths before they cause problems.
Your IRR setup forms a critical component of your BGP line preparations. Accurate route objects protect your prefixes from hijacking attempts. They also build trust with peers who rely on your records for their filtering decisions. Review your IRR objects monthly and remove stale entries promptly.
Implementing RPKI for Enhanced Security
RPKI stands as your strongest defense against BGP hijacking. This system uses cryptographic certificates to bind your prefixes to your ASN. It creates a chain of trust that routers can verify automatically. Your BGP line preparations remain incomplete without this layer of protection.
Understanding ROAs and Their Role
A Route Origin Authorization (ROA) serves as the core building block of RPKI. You create this digitally signed statement to record three critical details: your subnet, your authorized ASN, and the maximum prefix length. This record tells the world exactly who may announce your address space.
The adoption of ROAs has grown dramatically. According to the MANRS annual RPKI growth report, the global RPKI repositories contained 280,692 ROAs as of December 31, 2024. This number represents a 49% increase from the 188,345 ROAs recorded at the end of 2023. Network operators worldwide recognize RPKI as essential infrastructure.
Route Origin Validation (ROV) uses your ROA to check every incoming BGP route. The validation process follows a clear sequence:
Your network creates a ROA that records the subnet, the authorized ASN, and the maximum prefix length.
When a BGP route for that subnet arrives, your router checks the origin ASN against the ROA.
If the origin ASN matches the authorized ASN in the ROA, your router labels the route Valid and accepts it.
If the origin ASN does not match, your router labels the route Invalid and rejects it.
This validation prevents BGP hijacking by ensuring only the authorized ASN can originate the prefix.
Networks that enforce RPKI reject invalid announcements automatically. This enforcement stops hijackers before they can redirect your traffic. Your peers gain confidence knowing your announcements pass cryptographic verification.
Creating and Managing ROAs
You create ROAs through your RIR’s portal. The process in ARIN Online demonstrates the standard workflow:
Log in to ARIN Online and select Routing Security from the navigation menu.
In the “Your Organization” window, select Manage RPKI for the organization you want to configure.
On the “Routing Security Dashboard” page, select Create ROA.
In the “Create a Route Origin Authorization (ROA)” window, complete the required fields, then select Next Step.
In the “Review ROA” window, review and submit your ROA request by selecting Submit.
Note that duplicate and overlapping ROAs are no longer allowed. The ROA auto-renew feature removed the need for duplicates.
The use of the Maximum Length field is discouraged. This field prevents hijacking through the announcement of a more specific prefix. The easiest way to create ROAs for existing known announcements is by using the “Create ROA” button on the announcements tab. This action creates a ROA that matches your announcement exactly, meaning the Max Length uses the recommended default and equals the prefix length. The field then gets omitted from the actual signed ROA object.
You should review your ROAs regularly. Remove stale records when you decommission prefixes. Update records when you change your network architecture. These maintenance tasks keep your RPKI configuration accurate and trustworthy.
Your complete BGP line preparations checklist now includes RPKI implementation. This final layer of cryptographic protection completes your security posture. You have prepared your ASN, planned your prefixes, registered your IRR objects, and secured your announcements with ROAs. Your network now stands ready for safe, reliable BGP operation.
Your BGP line preparations checklist now covers four essential pillars. You obtained your ASN, planned your IP prefixes, registered IRR objects, and implemented RPKI with ROAs. Each step builds your defense against route hijacking.
These preparations deliver tangible benefits. Your peers trust your announcements more readily. Your network resists unauthorized prefix claims. Your peering relationships operate more smoothly.
Security requires ongoing attention. Review your IRR objects monthly. Update your ROAs whenever your network architecture changes. Adopt MANRS best practices to stay aligned with industry standards.
Start your preparation today. Use this checklist as your foundation. Secure your BGP infrastructure before attackers exploit your vulnerabilities.
FAQ
How long does the ASN application process take?
You can expect to receive your ASN within one to two weeks. The RIR reviews your request in about two business days. You then have 60 days to sign the agreement and pay fees. The RIR issues the resources within two business days after that.
Do I need both IRR records and RPKI ROAs?
Yes, you need both. IRR records help peers build prefix filters for your routes. RPKI ROAs provide cryptographic proof of your authority to announce prefixes. Together they create a defense against hijacking. One without the other leaves gaps in your security.
What happens if I do not register my prefixes?
Peers often filter unregistered routes automatically. Their systems check the IRR before accepting your BGP announcements. Your traffic may never reach its destination. Registration also establishes your legal ownership of the address space. This step takes only minutes through your RIR portal.
How often should I review my IRR objects and ROAs?
Review your IRR objects monthly. Remove stale entries promptly. Update your ROAs whenever your network architecture changes. Regular maintenance keeps your records accurate and trustworthy. Outdated records can cause route filtering issues or expose you to hijacking attempts.
