05-05-2026

Securing Internet routing: a concrete commitment at ielo

At ielo, network security is an integral part of our commitment. Supported by a fibre infrastructure that we design, operate, and manage end-to-end, along with advanced monitoring tools, we work every day to ensure the performance, reliability, and integrity of our network.

Across the Internet, exchanges between operators rely on the Border Gateway Protocol (BGP), the protocol that enables networks to advertise and discover the paths used to route data to its destination. In practice, each operator announces the IP address ranges it is able to carry.
This declarative model is essential to the way the Internet functions, but it also relies heavily on trust between network operators.

 

BGP: Is Trust Enough ?

In practice, an incorrect or malicious route announcement can be accepted and propagated across large portions of the Internet.
The risk becomes even greater when IRR databases are incomplete, outdated, or inconsistent with RIPE NCC data.

The consequences can include :

  • Traffic hijacking (BGP hijacking) ;
  • Data leakage ;
  • Routing instability.

 

RPKI : Verifying Route Origin

To address these risks, several routing security mechanisms have been developed, including RPKI (Resource Public Key Infrastructure).
RPKI enables network operators to verify that an Autonomous System (AS) is authorised to announce a specific IP address range. In other words, it adds a validation layer to confirm the legitimacy of advertised route origins.
Within this framework, invalid announcements can be detected and blocked before they propagate through the network.
More specifically, RPKI verifies that an AS is authorised to advertise a given prefix through ROA (Route Origin Authorization) objects.
The model moves beyond declarative trust to verifiable validation.

 

The ielo Approach : Don’t Propagate What Cannot Be Verified

The ielo network incorporates RPKI validation to identify inconsistent announcements and prevent them from being propagated. The principle is straightforward: only verified and legitimate routes are accepted and relayed.

This approach is part of a broader routing hygiene strategy based on routing security best practices, including:

  • Validation of incoming routes ;
  • Filtering of inconsistent or unauthorised announcements ;
  • Supporting customers in the creation and management of ROAs (Route Origin Authorizations), allowing them to formally authorise the advertisement of their IP prefixes.

It also aligns with the recommendations of MANRS (Mutually Agreed Norms for Routing Security), the global initiative dedicated to improving the security and resilience of Internet routing.

 

A Shared Challenge and an Operator Responsibility

Today, the reliability of Internet routing can no longer depend solely on trust between operators.
By combining mechanisms such as RPKI with internationally recognised best practices, the industry can reduce routing errors, limit traffic hijacks, and strengthen the overall stability of the Internet.
At ielo, this approach contributes to building a safer, more robust, and more resilient Internet for all the organisations and businesses that depend on it.