Prefix hijack by INDOSAT AS4795 / AS4761

Christian Teuschel christian.teuschel at ripe.net
Thu Mar 26 15:02:00 UTC 2015


Hi Randy,

Assuming that your prefix is 198.98.180.0/22 (AS29889 - FSNET-1 - Fast
Serv Networks, LLC) none of the mentioned more specifics are currently
seen from the RIPE NCC's RIS network, see the Looking Glass widget:

https://stat.ripe.net/198.98.180.0/23#tabId=routing
https://stat.ripe.net/198.98.182.0/23#tabId=at-a-glance

though there has been some BGP activity going on since 11:49:42, see the
BGPlay and BGP Update Activity widget. In both cases the originating ASN
was AS29889.

Cheers,
Christian

On 26/03/15 15:46, Randy wrote:
> All,
> 
> Info gathered off-list indicates this may be a couple of issues in our
> case - possible routing leak by 18978 (check your tables!) and more
> specifics on our prefixes from 4795 that we couldn't see before the leak
> hence the apparent hijack.
> 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: christian_teuschel.vcf
Type: text/x-vcard
Size: 342 bytes
Desc: not available
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20150326/9de6eabc/attachment.vcf>


More information about the NANOG mailing list