nanog mailing list archives
Re: BGPMON Alert Questions
From: Zachary McGibbon <zachary.mcgibbon+nanog () gmail com>
Date: Wed, 2 Apr 2014 16:34:50 -0400
Same here: ==================================================================== Possible Prefix Hijack (Code: 10) ==================================================================== Your prefix: 132.206.0.0/16: Prefix Description: MCGILL-NET-132-206 Update time: 2014-04-02 20:11 (UTC) Detected by #peers: 1 Detected prefix: 132.206.0.0/16 Announced by: AS4761 (INDOSAT-INP-AP INDOSAT Internet Network Provider,ID) Upstream AS: AS4651 (THAI-GATEWAY The Communications Authority of Thailand(CAT),TH) ASpath: 18356 38794 4651 4761 Alert details: https://portal.bgpmon.net/alerts.php?details&alert_id=41664976 Mark as false alert: https://portal.bgpmon.net/fp.php?aid=41664976 ==================================================================== Possible Prefix Hijack (Code: 10) ==================================================================== Your prefix: 142.157.128.0/18: Prefix Description: McGill Update time: 2014-04-02 20:11 (UTC) Detected by #peers: 1 Detected prefix: 142.157.128.0/18 Announced by: AS4761 (INDOSAT-INP-AP INDOSAT Internet Network Provider,ID) Upstream AS: AS4651 (THAI-GATEWAY The Communications Authority of Thailand(CAT),TH) ASpath: 18356 9931 4651 4761 Alert details: https://portal.bgpmon.net/alerts.php?details&alert_id=41664977 Mark as false alert: https://portal.bgpmon.net/fp.php?aid=41664977 On Wed, Apr 2, 2014 at 3:21 PM, Felix Aronsson <felix () mrfriday com> wrote:
Seeing the same here for a /21. This seems to have happened before with AS4761? See http://www.bgpmon.net/hijack-by-as4761-indosat-a-quick-report/from january 2011. On Wed, Apr 2, 2014 at 8:51 PM, Joseph Jenkins <joe () breathe-underwater com>wrote:So I setup BGPMON for my prefixes and got an alert about someone in Thailand announcing my prefix. Everything looks fine to me and I've checked a bunch of different Looking Glasses and everything announcing correctly. I am assuming I should be contacting the provider about their misconfiguration and announcing my prefixes and get them to fix it. Any other recommendations? Is there a way I can verify what they are announcing just to make suretheyare still doing it? Here is the alert for reference: Your prefix: 8.37.93.0/24: Update time: 2014-04-02 18:26 (UTC) Detected by #peers: 2 Detected prefix: 8.37.93.0/24 Announced by: AS4761 (INDOSAT-INP-AP INDOSAT Internet Network Provider,ID) Upstream AS: AS4651 (THAI-GATEWAY The Communications AuthorityofThailand(CAT),TH) ASpath: 18356 9931 4651 4761
Current thread:
- Prefix hijack by AS4761 (was Re: BGPMON Alert Questions), (continued)
- Prefix hijack by AS4761 (was Re: BGPMON Alert Questions) Stephen Fulton (Apr 02)
- Re: Prefix hijack by AS4761 (was Re: BGPMON Alert Questions) joel jaeggli (Apr 02)
- Re: Prefix hijack by AS4761 (was Re: BGPMON Alert Questions) Bob Snyder (Apr 02)
- Re: Prefix hijack by AS4761 (was Re: BGPMON Alert Questions) joel jaeggli (Apr 02)
- Re: BGPMON Alert Questions Rene Wilhelm (Apr 02)
- Re: BGPMON Alert Questions Bryan Tong (Apr 02)
- Re: BGPMON Alert Questions Bob Evans (Apr 02)
- Re: BGPMON Alert Questions Bryan Tong (Apr 02)
- Re: BGPMON Alert Questions Bret Clark (Apr 02)
- Re: BGPMON Alert Questions Bryan Tong (Apr 02)
- Re: BGPMON Alert Questions Felix Aronsson (Apr 02)
- RE: BGPMON Alert Questions Mike Walter (Apr 02)
- Re: BGPMON Alert Questions Zachary McGibbon (Apr 02)
- Re: BGPMON Alert Questions Erik Bais (Apr 02)
- Prefix hijack by AS4761 (was Re: BGPMON Alert Questions) Stephen Fulton (Apr 02)