Prefix hijack by INDOSAT AS4795 / AS4761
Christian Teuschel
christian.teuschel at ripe.net
Thu Mar 26 15:02:00 UTC 2015
Hi Randy,
Assuming that your prefix is 198.98.180.0/22 (AS29889 - FSNET-1 - Fast
Serv Networks, LLC) none of the mentioned more specifics are currently
seen from the RIPE NCC's RIS network, see the Looking Glass widget:
https://stat.ripe.net/198.98.180.0/23#tabId=routing
https://stat.ripe.net/198.98.182.0/23#tabId=at-a-glance
though there has been some BGP activity going on since 11:49:42, see the
BGPlay and BGP Update Activity widget. In both cases the originating ASN
was AS29889.
Cheers,
Christian
On 26/03/15 15:46, Randy wrote:
> All,
>
> Info gathered off-list indicates this may be a couple of issues in our
> case - possible routing leak by 18978 (check your tables!) and more
> specifics on our prefixes from 4795 that we couldn't see before the leak
> hence the apparent hijack.
>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: christian_teuschel.vcf
Type: text/x-vcard
Size: 342 bytes
Desc: not available
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20150326/9de6eabc/attachment.vcf>
More information about the NANOG
mailing list