On Fri, 11 Sept 2026 at 18:04, Christopher Hawker via NANOG <nanog@lists.nanog.org> wrote:
I would look at creating ASPAs objects with $rir in the first instance. Would help combat these sorts of issues :) Ask your upstream to create objects, then ask them to ask their upstreams, and so on… You get the picture.
If someone feels like vibing, may I suggest. a) recover AS-SET <-> ASN relation - look at RIR data, check if (mp-)export has exactly one AS-SET -> match - look at peeringDB b) resolve AS-SET into an ASN tree c) prune from the tree ASPA violating branches d) return prefix-list, and origin ASN list This way anyone already doing RIR prefix-list generation, without any ASPA support in NOS, could get a significant amount of ASPA benefits without changing anything in the NOS side, just changing command they call to translate customer AS-SET into prefix-list or AS origin list or both. -- ++ytti