INTEGRITY Cloudflare Docs

Manage IRR entries

You must keep your Internet Routing Registry (IRR) entries up to date so that it is public information that Cloudflare has permission to advertise your prefix or prefixes, and to ensure that your traffic can be properly routed on the Internet.

Configure an IRR entry

You can add or update an IRR entry by following the directions of your routing registry. Each routing registry has its own set of instructions to configure an IRR entry.

The recommended registries are AFRINIC, APNIC, ARIN, LACNIC, and RIPE. Refer to the table below for more information.

Route registry URL
AFRINIC https://afrinic.net/internet-routing-registry#guide
APNIC https://www.apnic.net/manage-ip/apnic-services/routing-registry/
ARIN https://www.arin.net/resources/manage/irr/quickstart/
LACNIC https://lacnic.zendesk.com/hc/articles/360038667154-What-are-a-route-and-a-route-6-objects
RIPE https://www.ripe.net/manage-ips-and-asns/db/support/managing-route-objects-in-the-irr

Verify an IRR entry

Verify your Internet Routing Registry (IRR) entries to ensure that the IP prefixes Cloudflare advertises for you match the correct autonomous system numbers (ASNs).

Each IRR entry record must include the following information:

Add or update IRR entries when they meet any of these criteria:

Subnet prefix verification

Use IRR Explorer to verify which ASN is associated with a subnet prefix.

Method: Search for the subnet prefix IP, for example, 162.211.156.0/24.

Output: List of ASN numbers, source (route registry), and any associated errors.

ASN verification

Use IRR Explorer to verify which prefixes are associated with an ASN.

Method: Search for the ASN, for example AS13335.

Output: List of prefixes, source, and any associated errors.

WHOIS lookup

Use WHOIS lookup to verify your origin ASN and routing data.

Method: In a terminal, use the following whois command, replacing <NETWORK_PREFIX> with your network prefix. The host rr.ntt.net is the primary server for the Global IP network.

whois -h rr.ntt.net <NETWORK_PREFIX>

Output: IRR route, origin, and source information.

WHOIS output example

The <IRR entry section> in the WHOIS output shows the correct IRR entry information for the specified network. In this example, the network prefix is 1.1.1.0/24, and the output includes the route, origin ASN, and route registry, which in this example is APNIC:

Example
user@xxt32z conduit-qs-config % whois -h rr.ntt.net 1.1.1.0/24
route:          1.1.1.0/24
<RPKI section>
descr:          RPKI ROA for 1.1.1.0/24
remarks:        This route object represents routing data retrieved from the RPKI
remarks:        The original data can be found here: https://rpki.gin.ntt.net/r/AS13335/1.1.1.0/24
remarks:        This route object is the result of an automated RPKI-to-IRR conversion process.
remarks:        maxLength 24
origin:         AS13335
mnt-by:         MAINT-NTTCOM-RPKI
changed:        job@ntt.net 20200913
source:         RPKI  # Trust Anchor: apnic

<IRR entry section>
route:          1.1.1.0/24
origin:         AS13335
descr:          APNIC Research and Development
                6 Cordelia St
mnt-by:         MAINT-AU-APNIC-GM85-AP
last-modified:  2018-03-16T16:58:06Z
source:         APNIC