lucgone
Member
OP
Le Baguette
- Joined:
- Jul 2024
- Posts:
- 296
- From:
- Lyon, FR
Hello, I have make a bad discovery since 2 days. My /24 subnet was hijacked for 20 minutes, someone has announce it on another ASN and my traffic was redirect. I check RIPE (https://www.ripe.net) and my ROA was... not there? I have make it in 2023, I am sure.
It is possible to do that? The RPKI is not supposed to prevent this? I am confused lol. My provider is KnownHost, they say "not our problem, contact RIPE". Mdr.
What I should do now? I don't want this repeat
Vive la résistance... électrique
debDebi
Member
- Joined:
- Jan 2025
- Posts:
- 28
- From:
- Gdansk, Poland
The Vorld Is Full Of Surprises.
I Have Checked The Certificate Transparency Logs And The Roa For Your Prefix Is Not Visible. The Rir Interface Sometimes Fails Silently; This Is A Known Issue Since The "Upgrade" In January.
You Should Validate In The Ripe Ncc Web Interface Directly. Do Not Trust The Api Response Alone.
apt-get install everything
tomchan
Member
- Joined:
- Jul 2024
- Posts:
- 202
- From:
- Bristol, UK
The actual published manifest was empty. Took me ages to spot.
$ rpki-client -t | grep 203.0.113.0/24
# nothing. absolutely nothing.
It actually works once you re-sign, but their "save" button doesn't always save. Hit it twice, check the.roa file downloads.
What RIR are you with?
works on my bench ¯\_(ツ)_/¯
RAJ
Member
- Joined:
- Jul 2024
- Posts:
- 294
- From:
- Mumbai, IN
January upgrade broke more than it fixed, typical
your margin is my opportunity
lucgone
Member
OP
Le Baguette
- Joined:
- Jul 2024
- Posts:
- 296
- From:
- Lyon, FR
Thank you all. I have login to RIPE again and... the ROA is there now? I have not touch anything since 2023. But the "last modified" say 2023, so it was always there? I am more confused.
I have download the .roa file, it is valid. So why rpki-client show nothing before? Maybe the problem is not RIPE but the publication server?
KnownHost say again "not our problem" but they are my upstream, they should filter invalid routes no? Or at least validate? I am on their Amsterdam datacenter — https://www.knownhost.com.
Vive la résistance... électrique
GeorgeNmp
Member
AS64512
- Joined:
- May 2024
- Posts:
- 218
- From:
- Ashburn, US
They should filter invalid routes no?
No. Your provider is a transit customer, not a peer. They receive the hijacked route from their upstreams or peers, and unless they run RPKI validation on *all* received routes and drop RPKI-invalid, the leak propagates. Most providers don't do strict RPKI filtering because it breaks things during partial deployments.
You want IRR filters plus RPKI, and you want your provider to at least do RPKI-based tagging. But "should" and "does" are different continents on this internet.
Check your ROA's max length. If you announced a /24 and the ROA says /24, fine. If it says /22, someone can hijack a more-specific.
iBGP, eBGP, don't care, just peer
tomchan
Member
- Joined:
- Jul 2024
- Posts:
- 202
- From:
- Bristol, UK
The "last modified" say 2023
The object was there. The manifest wasn't serving it. Classic RIPE rsync lag, their new publication infrastructure has gaps.
Run this from two different vantage points:
$ dig +short txt 113.0.203.rpz-ip.ripe.net
If you get NXDOMAIN from one resolver and a record from another, their anycast is split-brain again. Happened in March too.
works on my bench ¯\_(ツ)_/¯