Routing & Security

Secure Routing Infrastructure

Core routing safeguards and visibility tools built for resilient interconnection.

RPKI Validation

Route origin validation to prevent BGP hijacking and route leaks.

IRR Filtering

Internet Routing Registry filtering for additional route validation.

DDoS Mitigation

Always-on protection against volumetric and protocol attacks.

Route Servers

Redundant BGP route servers for simplified multilateral peering.

Traffic Engineering

BGP communities for granular control over traffic paths.

Real-Time Monitoring

Looking Glass and monitoring tools for network visibility.

Routing & Security

BGP Route Servers

Our redundant BGP route servers enable multilateral peering - connect once and exchange routes with all participating members automatically.

Features:

  • Redundant Infrastructure: Multiple route servers for high availability
  • RPKI Validation: Automatic validation of route origins
  • IRR Filtering: Route filtering based on routing registry data
  • AS Path Filtering: Protection against path manipulation
  • Max Prefix Limits: Automatic protection against route leaks
  • BGP Communities: Traffic engineering and selective announcement
  • IPv4 + IPv6: Dual-stack support on all route servers
  • Transparent ASN: Route server ASN not added to AS path

Route Server Details:

IPv4 Route Server

ASN: 65000

IPv4: 185.1.1.254

IPv6 Route Server

ASN: 65000

IPv6: 2001:7f8:xxx::254

Pricing:

FREE - Route server access is included with all public peering ports at no additional charge.

Routing & Security

RPKI & IRR Filtering

Resource Public Key Infrastructure (RPKI) and Internet Routing Registry (IRR) filtering provide multiple layers of routing security to prevent prefix hijacking and route leaks.

RPKI Route Origin Validation:

  • ROA Validation: All routes validated against RPKI ROAs
  • Real-Time Updates: Continuous synchronization with global RPKI repositories
  • Invalid Route Rejection: Routes failing RPKI validation are automatically rejected
  • Member Visibility: See validation status in Looking Glass
  • Best Practices: Following MANRS and industry standards

IRR Filtering:

  • Multi-Source IRR: Query RADB, RIPE, ARIN, APNIC, and other registries
  • AS-SET Expansion: Automatic expansion of customer AS-SETs
  • Prefix Filtering: Only registered prefixes accepted
  • Regular Updates: IRR data refreshed every 6 hours
  • Fallback Protection: RPKI used if IRR data unavailable

Pricing:

FREE - RPKI validation and IRR filtering included with all peering services.

Routing & Security

Blackhole Routing (RTBH)

Remote Triggered Black Hole (RTBH) filtering allows you to quickly mitigate DDoS attacks by blackholing specific prefixes or IPs at the exchange edge.

Features:

  • Instant Activation: Drop attack traffic within seconds
  • Granular Control: Blackhole specific /32 (IPv4) or /128 (IPv6) addresses
  • BGP Community Trigger: Simple BGP community activation
  • Peer-Specific: Blackhole from specific peers or all peers
  • Temporary Protection: Quick mitigation while implementing permanent fixes
  • No Traffic Charges: Blackholed traffic doesn't count toward billing

How It Works:

  1. Announce the target prefix/IP to route server with blackhole community
  2. Route server propagates announcement to all or selected peers
  3. Traffic to the target is dropped at the edge before reaching your network
  4. Remove announcement when attack subsides to restore connectivity

Blackhole Communities:

65000:666 - Blackhole to all peers

65000:<peer-asn> - Blackhole to specific peer

Pricing:

FREE - Blackhole routing available to all peering members at no charge.

Routing & Security

DDoS Protection

Advanced DDoS mitigation protects your infrastructure from volumetric attacks, protocol exploits, and application-layer threats.

Protection Layers:

  • Always-On Scrubbing: Automatic detection and mitigation of common attacks
  • Volumetric Protection: Up to 100+ Gbps mitigation capacity
  • Protocol Validation: TCP/UDP/ICMP anomaly detection
  • Rate Limiting: Automated rate limits for suspicious traffic
  • BGP Flowspec: Dynamic traffic filtering via BGP
  • RTBH Integration: Combine with blackhole routing for targeted drops

Pricing:

Service Level Protection Capacity Monthly Fee Included
Basic (Included) Up to 5 Gbps FREE All peering/transit customers
Enhanced Up to 20 Gbps $500/mo Advanced filtering + reporting
Premium Up to 100 Gbps $2,000/mo 24/7 SOC + custom rules
Routing & Security

Looking Glass & Monitoring

Real-time network diagnostics and monitoring tools for troubleshooting and visibility into routing behavior.

Available Tools:

  • BGP Route Lookup: Query routes for any prefix
  • Ping & Traceroute: Network reachability testing
  • AS Path Lookup: View routing paths to destinations
  • RPKI Validation Status: Check ROA validation results
  • Peer Status: View BGP session states
  • Route Statistics: Prefix counts and peer details
  • API Access: Programmatic access for automation

Access Looking Glass →

Pricing:

FREE - Looking Glass access available to all members and the public.

Routing & Security

BGP Communities

Use BGP communities to control route propagation and implement traffic engineering policies.

View full list of supported communities: BGP Communities Documentation →

Policies & Proof

Policies & Proof

Operational controls and published policies you can verify before onboarding.

RPKI + IRR Validation

Route server sessions validated against ROAs and IRR objects.

Routing policies

Max-Prefix Policy

Automatic limits with NOC review to prevent leaks.

Policy details

BGP Communities

Published community catalog for traffic steering and blackholing.

Community list

Looking Glass

Public route visibility for verification and troubleshooting.

Open looking glass

Status Page

Uptime, incidents, and maintenance windows published.

Status page

24x7 NOC + Escalation

Defined response paths and escalation contacts.

Contact NOC

Questions about our routing services?

Contact Support Looking Glass