BGP route hijack by AS10990

Aftab Siddiqui aftab.siddiqui at gmail.com
Fri Jul 31 01:57:24 UTC 2020


Not a single prefix was signed, what I saw. May be good reason for Rogers,
Charter, TWC etc to do that now. It would have stopped the propagation at
Telia.

On Fri, 31 Jul 2020 at 8:40 am, Baldur Norddahl <baldur.norddahl at gmail.com>
wrote:

> Telia implements RPKI filtering so the question is did it work? Were any
> affected prefixes RPKI signed? Would any prefixes have avoided being
> hijacked if RPKI signing had been in place?
>
> Regards
>
> Baldur - who had to turn off RPKI filtering at the request of JTAC to stop
> our mx204s from crashing :-(
>
> tor. 30. jul. 2020 18.59 skrev Töma Gavrichenkov <ximaera at gmail.com>:
>
>> Peace,
>>
>> On Thu, Jul 30, 2020, 5:48 AM Clinton Work <clinton at scripty.com> wrote:
>>
>>> We saw a bunch of our IP blocks hijacked by AS10990 from 19:15 MDT until
>>> 20:23 MDT.   Anybody else have problems with that.
>>>
>>
>> Here's what we discovered about the incident.  Hope that brings some
>> clarity.
>>
>> https://radar.qrator.net/blog/as10990-routing-optimization-tale
>>
>> --
>> Töma
>>
>>> --
Regards,

Aftab A. Siddiqui
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20200731/6123c4d3/attachment.html>


More information about the NANOG mailing list