Route origin hijacks are operational events, not conference slides. This primer covers ROAs, origin validation and what to demand from an upstream.
BGP still assumes that an ASN announcing a prefix is allowed to do so. That assumption is how traffic for a payment provider ends up in a data centre it never contracted. RPKI (Resource Public Key Infrastructure) does not encrypt BGP. It signs who may originate which prefix.
ROA, not a firewall
A Route Origin Authorisation is a signed tuple: prefix, max length, originating ASN. Your RIR (RIPE, ARIN, APNIC) hosts the certificate. You publish the ROA; every validator on the internet can check it.
Three outcomes matter on a session:
- Valid. The announcement matches a covering ROA.
- Invalid. A ROA exists and this origin or length does not match. A well-configured peer drops it.
- Not found. No ROA. Most networks still accept the route. That is the gap hijackers use.
Creating ROAs for your allocations is the first duty. Dropping other people's invalids is the second. Doing only one of those is incomplete.
What to ask an upstream
Before you buy IP transit, ask in writing:
- Do you perform origin validation toward customers and toward the default-free zone?
- Do you reject invalids, or only mark them?
- Do you honour a customer ROA that is tighter than the IRR object?
- How fast do you withdraw a hijack you accepted in error?
“We have RPKI” is not an answer. Invalid = drop on the customer cone and on transit is the answer. Soft-fail (accept + community) is better than nothing and worse than a drop.
IRR is not a substitute
IRR objects are useful for filtering your customer cone when you are the ASN of record. They are not a global PKI. Anyone can still publish a conflicting route object in a weakly authenticated registry. Treat IRR as a provisioning database, RPKI as the cryptographic check.
How Zenix runs it
AS209604 publishes ROAs for on-net space and validates origins on eBGP. The network page and looking glass are the public surface. If you originate space through us, we will not announce a prefix we cannot authorise.
If you operate your own ASN on colocation or a dedicated server, bring the ROA to the session review. We will not “just announce /24s” because a spreadsheet said so.
Origin validation will not stop every path manipulation. It stops the cheap, loud hijack that still takes payment and game prefixes offline several times a year. That is enough reason to treat it as production, not a lab feature.
Related articles
About Zenix
Zenix operates AS209604 — dedicated servers, VPS, and colocation across Istanbul, Sofia, Dublin, and Karachi.
Get in touch

