How to create Route Object and ROA-records

How to create Route Object and ROA-records

For our IP Announcement product, we expect every prefix we announce to have a valid Route Object and ROA-record with the RIR (RIPE, ARIN, RDB or APNIC).

How to Check Your Current Status Right Now

You can instantly verify if your IP ranges that you have announced by Leaseweb, have valid Route Objects and ROAs using the public tools like NLNOG IRR Explorer and Arelion looking Glass

RR Status: Must display an active ‘route’ or ‘route6’ object.

PKI Status: Must display ‘Valid’. (If it reads “No (covering) RPKI ROA found”, you must issue a ROA).

How to create valid Route Object and ROA-record for your prefix

To prevent your prefixes from receiving warnings or being withdrawn from being announced on the internet, please complete the following steps with your RIR, see below for detailed information:

1. Create/Update IRR Route Objects:
Ensure every IP subnet announced has a valid ‘route’ or ‘route6’ object in an authoritative IRR registry (e.g., RADB, RIPE, APNIC, ARIN) referencing our correct regional ASN.

2. Publish RPKI ROA Records:
Log into your RIR portal (ARIN, RIPE NCC, or APNIC) and create a signed ROA for all IP ranges binding them to the correct Leaseweb ASN. Ensure your ‘maxLength’ accommodates all announced subnets e.g., ‘/24’ or ‘/48’ (for IPv6 prefixes).

Documentation

Direct links to official documentation and portal instructions for creating RPKI ROA records (Route Origin Authorizations) and IRR Route Objects (route / route6) across RIPE, APNIC, ARIN, and RADB:

1. RIPE NCC (Europe, Middle East, Central Asia)

  • ROA Records (Hosted RPKI):
    • Documentation: RIPE NCC Hosted Certificate Authority Management
    • How to create: Log in to my.ripe.net, navigate to the RPKI Dashboard, and under the BGP Announcements or ROAs tab, click New ROA. Enter your prefix, origin Autonomous System Number (ASN), and set the maxLength (leaving it default/equal to the prefix length is recommended).
  • Route Objects (RIPE Database / IRR):
MAINT-ID for RIPE
Leaseweb UKleaseweb-uk-mnt
Leaseweb NLleaseweb-nl-mnt
Leaseweb DEleaseweb-de-mnt

2. ARIN (North America & Caribbean)

3. APNIC (Asia-Pacific)

  • ROA Records & Route Objects (MyAPNIC One-Stop Creation):
    • Documentation: APNIC Resource Certification & RPKI Overview | Creating Route Objects Guide
    • How to create: APNIC allows creating both simultaneously. Log in to MyAPNIC, go to ResourcesRoute Management, click Create Route, enter the IP prefix and Origin ASN, and tick the ROA and/or Whois Route Attributes options to generate both the RPKI ROA and IRR route/route6 objects together.

4. RADB (Routing Assets Database – IRR)

  • Note: RADB is an independent Internet Routing Registry (IRR) and does not host RPKI CAs for creating ROAs directly; it is strictly used for IRR route/route6 objects.
  • Route Objects (IRR):
mnt-by for RADB
Leaseweb UKleaseweb-uk-mnt
Leaseweb NLleaseweb-nl-mnt
Leaseweb DEleaseweb-de-mnt

Leaseweb ASNs per datacenter

EntityDatacenterASN
Leaseweb NetherlandsAMS-01AS60781
AMS-02AS60781
Leaseweb GermanyFRA-01AS28753
Leaseweb UKLON-01AS205544
LON-11AS205544
Leaseweb USCHI-11AS27411
DAL-13AS394380
LAX-12AS395954
MIA-11AS393886
NYC-01AS396362
PHX-01AS19148
SEA-11AS396190
SFO-12AS7203
WDC-02AS30633
Leaseweb SingaporeSIN-01AS59253
SIN-12AS59253
Leaseweb Hong KongHKG-12AS133752
Leaseweb AustraliaSYD-10AS136988
SYD-12AS136988
Leaseweb JapanTYO-11AS134351
Leaseweb CanadaMTL-01AS32613
MTL-02AS32613