Routing security at CNX
CNX combines several independent controls. None of them replaces the others.
- IRR
routeandroute6objects describe which prefixes an ASN intends to originate. - A hierarchical AS-SET describes the origin ASNs a member may announce, including downstream networks.
- Route Origin Authorizations cryptographically authorize an origin ASN and maximum prefix length.
- Route Origin Validation classifies routes as Valid, Invalid, or NotFound.
- ASPA describes customer-to-provider relationships and supports validation of the AS path.
The route servers currently perform ROV and reject RPKI Invalid routes. They also enforce IRR/AS-SET-derived origin and prefix authorization, prefix-length limits, AS-path sanity checks, next-hop checks, bogon filtering, and maximum prefix limits.
ASPA payloads are available from the CNX validators. Route-server ASPA enforcement is planned but is not active yet. Peer-side ASPA configuration will be added when supported router implementations can be documented and tested.
Members should still perform ROV on routes learned from every external source, including transit, bilateral peers, and the route servers. CNX's filtering protects the shared route-server service; it does not replace the member's own edge policy.