[185681] in North American Network Operators' Group
Re: Route leaks from AS9498 (BHARTI Airtel)?
daemon@ATHENA.MIT.EDU (Job Snijders)
Fri Nov 6 10:43:49 2015
X-Original-To: nanog@nanog.org
Date: Fri, 6 Nov 2015 16:43:42 +0100
From: Job Snijders <job@instituut.net>
To: Andrew Duey <andrew.duey@widerangebroadband.net>
In-Reply-To: <CAK8kncn13-UfXZt=H26_t4Huduw-AkmfhUtatkvpk9htrSqo5A@mail.gmail.com>
Cc: nanog@nanog.org
Errors-To: nanog-bounces@nanog.org
On Fri, Nov 06, 2015 at 09:38:52AM -0600, Andrew Duey wrote:
> Is anyone else seeing their routes leaked from AS9498 (BHARTI Airtel) in
> India?
>
> According to bgpmon.net they started leaking our Level 3 provided IP space
> at 2015-11-06 05:52 UTC. Oddly, they're not leaking our ARIN assigned IP
> blocks but our prefixes inside the 8.0.0.0/8 range they are (8.34.96.0/21
> and 8.33.2.0/24).
>
> BGPmon shows less of their probes are now showing the announcement and we
> haven't seen a noticeable hit in overall traffic levels.
>
> Has anyone else seen this route leak? Is it somehow specific to just the
> big Level 3 blocks? (4.0.0.0/8 and 8.0.0.0/8)? I figured NANOG would have
> a thread on it already but haven't heard a whisper (unless all the new guys
> like me are being modded thanks to the spam incident).
Andree already did a good write-up:
http://www.bgpmon.net/large-scale-bgp-hijack-out-of-india/
Kind regards,
Job