nanog mailing list archives

Re: Cogent Abuse - Bogus Propagation of ASN 36471


From: William Herrin <bill () herrin us>
Date: Thu, 20 Jul 2023 09:30:31 -0700

On Thu, Jul 20, 2023 at 8:06 AM Pete Rohrman
<prohrman () stage2networks com> wrote:
On 7/20/23 10:40, Ben Cox wrote:
Can you confirm what you mean by compromised here?
Compromised as in a nefarious entity went into the router and changed passwords and did whatever.

Hi Pete,

I think Ben is asking you to "be more specific." The information you
provided isn't really sufficient for someone who isn't you to
differentiate between the routes you consider legitimate and and the
ones you think bogus.

If you would provide the output of two runs of "show ip bgp," one
trimmed to show the routes you consider bogus and the other trimmed to
show the routes you consider legitimate, it would likely answer Ben's
questions. Routeviews has FRR instances you can log in to and fetch
the text output of "show ip bgp" which are outside your network.

Regards,
Bill Herrin



--
William Herrin
bill () herrin us
https://bill.herrin.us/


Current thread: