nanog mailing list archives

Re: RU evidently hijacked UA netblock


From: "Scott Weeks" <surfer () mauigateway com>
Date: Fri, 4 Mar 2022 18:03:35 -0800



--- george.herbert () gmail com wrote:

https://bgpstream.com/event/287556

Beware of further such activity…

---------------------------------------


I have a ticket open with my vendor, but I see strange NLRI buffer overflow syslog messages about Khazkstan's AS21299 
(TNSPLUS) announcements.  It looks like a 'too many' AS prepends, but it is only 250 prepends.  Could be a mistake or 
intentional. 

I get those from no other ASNs and I am sure some AS sent 250 AS path prepends before.  Anyone else see stuff from them?

scott

Current thread: