CentauriNetAS46307

Routing policy

What AS46307's routers do with a route. This is the MANRS Action 4 document.

Origination

AS46307 originates eight prefixes, listed on Prefixes.

Import

  • Default deny (RFC 8212). Every session has explicit import and export policy.
  • RPKI-invalid routes are dropped first, on every upstream.
  • Each PoP keeps only paths of at most two ASNs after its upstream's.
  • Own space cannot come back in: a path containing AS46307 fails loop detection, and any other origin is RPKI-invalid.

Export

  • Own prefixes only, from an exact allow-list.
  • No transit. Upstream routes are tagged 46307:900 on ingress and denied first on every export.
  • Some PoPs prepend AS46307.

For customers

  • Announce only more-specifics of your own registered space.
  • To drop traffic to an address under attack, tag a /32 or /128 in your space with 65535:666 (BLACKHOLE, RFC 7999). Every PoP drops it. See Communities.
  • For changes, email noc@centauri.solutions.

RPKI

One exact-length ROA entry per announced prefix (RFC 9319), plus 2602:fb3c::/36 at maxLength 36 as a floor.

Any announcement from 2602:fb3c::/36 that is not listed on Prefixes is RPKI-Invalid, and is not us.

Background: Exact-length ROAs.

ASPA

Providers published at ARIN: AS20473, AS35661, AS197959. Checked against ARIN daily.

IRR

  • ARIN only. ARIN::AS-CENTAURINET has one member, AS46307. It is source-qualified because a RIPE copy once existed; it has been deleted.
  • ARIN's IRR Auto-Manager creates route objects from the ROAs.
  • Max-prefix: PeeringDB's info_prefixes4/6, currently 4 and 16.

Route collectors

bgp.tools gets a feed from every PoP, with ADD-PATH. Each session is sourced from its PoP's regional /48: 2602:fb3c:10::179, 2602:fb3c:13::179 and 2602:fb3c:20::179.

Want a feed for your collector? Email noc@centauri.solutions.