Stuttgart-IX operates two Route Servers, to allow peers to exchange routes without setting up bilateral BGP Sessions. Anyone peering with the Route Server will receive all routes of all other route server peers, unless overwritten by a control community.

BGP Session Parameters

Please set up a BGP session to both Route Servers.

RouteServerIPv4IPv6ASNMax. Prefix IPv4Max. Prefix IPv6IRRDB
rs1.s-ix.de193.138.31.2522001:7f8:56::141139200005000AS-STUTTGARTIX-RS
rs2.s-ix.de193.138.31.2532001:7f8:56::241139200005000AS-STUTTGARTIX-RS

BGP Communities

Control Communities

You can use the following Large Communities to control the Route Server’s behavior:

Large CommunityDescription
41139:0:0Don’t announce to any AS (overwrite with 41139:1:PEERAS)
41139:0:PEERASDo not advertise to PEERAS
41139:1:PEERASAdvertise to PEERAS (in combination with 41139:0:0)
41139:101:PEERASPrepend PEERAS 1x
41139:102:PEERASPrepend PEERAS 2x
41139:103:PEERASPrepend PEERAS 3x

For compatibility with older routers the following communities are supported:

CommunityDescription
0:PEERASDo not advertise to PEERAS
41139:PEERASAdvertise to PEERAS
0:41139Do not advertise (overwrite with 41139:PEERAS)

Informational Communities

To assist in debugging, the route server will set the following large communities when filtering routes; you can see them in our Looking Glass.

Large CommunityDescription
41139:1101:1Prefix is too long
41139:1101:2Prefix is too short
41139:1101:3The prefix mustn’t be routed in the internet (Bogon)
41139:1101:4The ASN mustn’t be routed in the internet (Bogon)
41139:1101:5The AS-Path is too long
41139:1101:6The AS-Path is too short
41139:1101:7First AS in AS-Path isn’t the PEER-AS
41139:1101:8Next-hop doesn’t match peer IP
41139:1101:9Prefix not in the peer’s AS-SET
41139:1101:10Origin AS is not in the peer’s AS-SET
41139:1101:11Prefix is not in origin AS
41139:1101:12RPKI Unknown
41139:1101:13RPKI Invalid
41139:1101:14A transit free AS was found in the AS-Path
41139:1101:15Too many BGP Communities
41139:1000:1RPKI valid
41139:1000:2RPKI Unknown
41139:1000:3RPKI not checked
41139:1001:1IRRDB valid
41139:1001:2IRRDB not checked
41139:1001:3Prefix doesn’t exist in IRRDB, but a less specific does
41139:1001:1000IRRDB filtered loose
41139:1001:1001IRRDB filtered strict
41139:1001:1002IRRDB prefix is empty
41139:1001:200same as next-hop

Filter Mechanism

Stuttgart-IX takes routing security serious, you can find a list of steps taken below:

1. Filter too small prefixes

Routes more specific than a /24 IPv4 or /48 IPv6 will be rejected.

2. Filter Martians and Bogons

Prefixes that are not intented for routing in the internet will be rejected, see NLNOG BGP Filter Guide.

3. AS-Path Validation

Routes with no AS-Path or more than 64 ASNs in the AS-Path will be rejected.
Routes where the first AS in the AS-Path doesn’t math the Peers AS will be rejected.

4. Next Hop Validation

Routes whose next-hop don’t match the peers IP will be rejected.

5. Known Transit Networks

Routes whose AS-Path contain a known transit network will be rejected, see NLNOG BGP Filter Guide

6. IRRDB AS-Set verification

Routes whose Origin-AS is not included in the Peers AS-Set will be rejected.

7. RPKI Validation

Routes with a published ROA will be validated by the route server.
If the RPKI ROA Status is invalid the route will be rejected. If the RPKI ROA Status is unknwown the route will be filtered according to IRRDB You can find more information on RPKI in the RPKI guid of RIPE NCC or in the RPKI FAQ of NLNetLabs.

7.1 IRRDB Filtering

Routes with RPKI ROA Status unknown will be filtered according to the respective IRRDB, only routes with a valid route or route6 object will be accepted, others will be rejected.
The IRRDB-Data will be refreshed every 6 hours by the route server.