BGP route hijack by AS10990

Baldur Norddahl baldur.norddahl at gmail.com
Thu Jul 30 22:37:35 UTC 2020


Telia implements RPKI filtering so the question is did it work? Were any
affected prefixes RPKI signed? Would any prefixes have avoided being
hijacked if RPKI signing had been in place?

Regards

Baldur - who had to turn off RPKI filtering at the request of JTAC to stop
our mx204s from crashing :-(

tor. 30. jul. 2020 18.59 skrev Töma Gavrichenkov <ximaera at gmail.com>:

> Peace,
>
> On Thu, Jul 30, 2020, 5:48 AM Clinton Work <clinton at scripty.com> wrote:
>
>> We saw a bunch of our IP blocks hijacked by AS10990 from 19:15 MDT until
>> 20:23 MDT.   Anybody else have problems with that.
>>
>
> Here's what we discovered about the incident.  Hope that brings some
> clarity.
>
> https://radar.qrator.net/blog/as10990-routing-optimization-tale
>
> --
> Töma
>
>>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20200731/55dce208/attachment.html>


More information about the NANOG mailing list