[179050] in North American Network Operators' Group
Re: Prefix hijack by INDOSAT AS4795 / AS4761
daemon@ATHENA.MIT.EDU (Christian Teuschel)
Thu Mar 26 11:11:04 2015
X-Original-To: nanog@nanog.org
Date: Thu, 26 Mar 2015 16:02:00 +0100
From: Christian Teuschel <christian.teuschel@ripe.net>
To: nanog@nanog.org
In-Reply-To: <78c55aee9b1853c827c78adb8527fafb@mailbox.fastserv.com>
Errors-To: nanog-bounces@nanog.org
This is a multi-part message in MIME format.
--------------080802080409030908050908
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: 7bit
Hi Randy,
Assuming that your prefix is 198.98.180.0/22 (AS29889 - FSNET-1 - Fast
Serv Networks, LLC) none of the mentioned more specifics are currently
seen from the RIPE NCC's RIS network, see the Looking Glass widget:
https://stat.ripe.net/198.98.180.0/23#tabId=routing
https://stat.ripe.net/198.98.182.0/23#tabId=at-a-glance
though there has been some BGP activity going on since 11:49:42, see the
BGPlay and BGP Update Activity widget. In both cases the originating ASN
was AS29889.
Cheers,
Christian
On 26/03/15 15:46, Randy wrote:
> All,
>
> Info gathered off-list indicates this may be a couple of issues in our
> case - possible routing leak by 18978 (check your tables!) and more
> specifics on our prefixes from 4795 that we couldn't see before the leak
> hence the apparent hijack.
>
--------------080802080409030908050908
Content-Type: text/x-vcard; charset=utf-8;
name="christian_teuschel.vcf"
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
filename="christian_teuschel.vcf"
begin:vcard
fn:Christian Teuschel
n:Teuschel;Christian
org:RIPE Network Coordination Center (NCC);Research & Development
adr:;;Single 258;Amsterdam;;1016AB;The Netherlands
email;internet:christian.teuschel@ripe.net
title:Senior Software Engineer
tel;work:+31 20 535 4373
tel;fax:+31 20 535 4445
url:http://www.ripe.net
version:2.1
end:vcard
--------------080802080409030908050908--