AWS AWSEC2: Clarify ASN authorization requirements for sovereign clouds
Summary
Specified distinct ASN authorization rules for AWS GovCloud and European Sovereign Cloud during ROA creation.
Security assessment
Explicitly defines authorized ASNs for sovereign cloud regions to prevent IP prefix hijacking through misconfiguration.
Evidence
+Create a ROA object to authorize the Amazon ASNs 16509 and 14618 to advertise your address range, as well as the ASNs that are currently authorized to advertise the address range. For the AWS GovCloud (US) Regions, authorize only ASN 8987. For the AWS European Sovereign Cloud, authorize ASNs 16509 and 214101\. You must set the maximum length to the size of the CIDR that you are bringing in. The most specific IPv4 prefix you can bring is /24. The most specific IPv6 address range that you can bring is /48 for CIDRs that are publicly advertisable and /60 for CIDRs that are not publicly advertisable.
Diff
diff --git a/AWSEC2/latest/UserGuide/prepare-for-byoip.md b/AWSEC2/latest/UserGuide/prepare-for-byoip.md index 3f24abc81..ea4669209 100644 --- a//AWSEC2/latest/UserGuide/prepare-for-byoip.md +++ b//AWSEC2/latest/UserGuide/prepare-for-byoip.md @@ -252 +252 @@ You can remove the certificate from your RIR's record after the provisioning sta -Create a ROA object to authorize the Amazon ASNs 16509 and 14618 to advertise your address range, as well as the ASNs that are currently authorized to advertise the address range. For the AWS GovCloud (US) Regions, authorize ASN 8987 instead of 16509 and 14618. You must set the maximum length to the size of the CIDR that you are bringing in. The most specific IPv4 prefix you can bring is /24. The most specific IPv6 address range that you can bring is /48 for CIDRs that are publicly advertisable and /60 for CIDRs that are not publicly advertisable. +Create a ROA object to authorize the Amazon ASNs 16509 and 14618 to advertise your address range, as well as the ASNs that are currently authorized to advertise the address range. For the AWS GovCloud (US) Regions, authorize only ASN 8987. For the AWS European Sovereign Cloud, authorize ASNs 16509 and 214101\. You must set the maximum length to the size of the CIDR that you are bringing in. The most specific IPv4 prefix you can bring is /24. The most specific IPv6 address range that you can bring is /48 for CIDRs that are publicly advertisable and /60 for CIDRs that are not publicly advertisable.