[114419] in North American Network Operators' Group
Re: Anomalies with AS13214 ?
daemon@ATHENA.MIT.EDU (Christopher Morrow)
Mon May 11 14:39:48 2009
In-Reply-To: <20090511182930.GA20954@toonk.nl>
Date: Mon, 11 May 2009 14:39:38 -0400
From: Christopher Morrow <morrowc.lists@gmail.com>
To: Andree Toonk <andree+nanog@toonk.nl>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On Mon, May 11, 2009 at 2:29 PM, Andree Toonk <andree+nanog@toonk.nl> wrote=
:
> .-- My secret spy satellite informs me that at Mon, 11 May 2009, Jay Henn=
igan wrote:
>
>> We're getting cyclops[1] alerts that AS13214 is advertising itself as
>> origin for all of our prefixes. =A0Their anomaly report shows thousands =
of
>> prefixes originating there.
>>
>> Anyone else seeing evidence of this or being affected?
>
> It seems it was picked up by route-views4. Non of the RIS peers seem to h=
ave seen this.
>
> Looking at the raw bgp data from route-views4:
> AS13214 leaked a full table (~266294 prefixes) with 13214 =A0as OriginAS =
to AS48285 which is a routeviews4 peer.
> Routeviews4 saw these announcements as: ASpath 48285 13214.
>
Since 48285 =3D=3D robtex, is it possible TPB was just setting up a
monitoring/route-feed session to robtex and either missed their
outbound policy or sent them the wrong form of outbound policy (full
routes not customer only routes)??
-chris