[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Prefix hijack by INDOSAT AS4795 / AS4761
- Subject: Prefix hijack by INDOSAT AS4795 / AS4761
- From: christian.teuschel at ripe.net (Christian Teuschel)
- Date: Thu, 26 Mar 2015 16:02:00 +0100
- In-reply-to: <[email protected]>
- References: <[email protected]> <CAL9jLaY17-8nVwXDDs1dncU=252pBSEFpdi1QaGXq5ZEJ-AyvA@mail.gmail.com> <[email protected]>
Hi Randy,
Assuming that your prefix is 198.98.180.0/22 (AS29889 - FSNET-1 - Fast
Serv Networks, LLC) none of the mentioned more specifics are currently
seen from the RIPE NCC's RIS network, see the Looking Glass widget:
https://stat.ripe.net/198.98.180.0/23#tabId=routing
https://stat.ripe.net/198.98.182.0/23#tabId=at-a-glance
though there has been some BGP activity going on since 11:49:42, see the
BGPlay and BGP Update Activity widget. In both cases the originating ASN
was AS29889.
Cheers,
Christian
On 26/03/15 15:46, Randy wrote:
> All,
>
> Info gathered off-list indicates this may be a couple of issues in our
> case - possible routing leak by 18978 (check your tables!) and more
> specifics on our prefixes from 4795 that we couldn't see before the leak
> hence the apparent hijack.
>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: christian_teuschel.vcf
Type: text/x-vcard
Size: 342 bytes
Desc: not available
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20150326/9de6eabc/attachment.vcf>