kenji3
Member
OP
- Joined:
- Jul 2024
- Posts:
- 138
- From:
- Osaka, JP
I may be wrong, but I believe we hit a routing loop during activation of our new scrubbing service. Provider is Contabo, scrubbing center in Singapore. Clean traffic should return via GRE tunnel to our edge in Osaka.
Instead we saw our own prefixes re-announced with an unexpected community string. I have pcaps from both sides if anyone wants to look. Traffic never reached us, just looped between two scrubbing PoPs for about 90 seconds before their BCP kicked in.
I am not strong with BGP communities so I may be missing something obvious. Happy to share more details. This was yesterday 14:00 JST if it matters.
conbini > datacenter snacks
ana_mad
Member
- Joined:
- Jun 2024
- Posts:
- 298
- From:
- Madrid, ES
MeritBudi is right! I sent ticket yesterday to Contabo about this exact community leak in their Singapore-Sydney path. They acknowledged in 4 hours, fixed in 8. Made test order with them last month and saw same behavior.
The route reflector was attaching 64512:9999 to all routes learned from scrubbing centers, not just inbound. Their engineering confirmed it was a template error from a new PoP turnup.
Kenji3, mention ticket #2025-SIN-BGP-0441 if you want, might help them connect the dots. They were very responsive once I got past tier 1.
Cheers!
swimming upstream since 2019 🐟
kenji3
Member
OP
- Joined:
- Jul 2024
- Posts:
- 138
- From:
- Osaka, JP
Can you confirm whether the community is on the clean route or on the original announcement?
Clean route only. Original announcement from our router in Osaka has no communities attached, we don't use them.
GRE keepalives were dead the whole time. Tunnel interface stayed up because the loop was between their PoPs, not the path to us. We saw nothing.
Mention ticket #2025-SIN-BGP-0441
Thank you, I referenced this in my follow-up. Tier 1 actually escalated immediately when I did, now talking to someone who knows what a route reflector is.
Still no root cause given but they confirmed "a configuration issue affecting multiple customers in Singapore." No timeline.
conbini > datacenter snacks
ana_mad
Member
- Joined:
- Jun 2024
- Posts:
- 298
- From:
- Madrid, ES
They confirmed "a configuration issue affecting multiple customers in Singapore"
That's their script. I got the same line before they admitted the template error. Push for an incident number, not just a ticket. Makes it harder for them to bury.
Also check your next invoice carefully. I got 2 hours of "scrubbed traffic" billed to my account even though the traffic never reached me. Their metering doesn't know the loop happened. I disputed and won, but only because I had timestamps.
swimming upstream since 2019 🐟