Following this thread. I had similar with my /23 last month, also RIPE, also "saved but not published." I thought I was crazy.
My subnet got hijacked for 20 minutes—how do I prevent repeat?
You are not. I have mtr dreams and now I have RPKI manifest dreams. This is a disease.
@lucgone I checked from Melbourne, your prefix looks clean now but the historical route collector data shows the hijack lasted 19 minutes 47 seconds, not 20. Close enough. The more-specific was only visible from 6 of 24 collectors, so it was partial propagation, probably a single upstream that didn't filter.
KnownHost's upstream in AMS is likely Cogent or Telia. Both do RPKI now, so maybe it was a smaller peer. You can check with "show ip bgp" if they give you a looking glass, which they don't.
This. The "save" button in RIPE is actually a suggestion.
Thank you all again. I have:
- Set max-length /24 in my ROA (it was already but I have verify)
- Install Routinator in my Lyon office, it is syncing now
- Write to CERT-FR with the ASN and time window
- Consider moving from KnownHost, but their price is 45 USD for my VPS and others want 80+ for same
I will monitor and come back if repeat. Maybe I make a script to alert me if my prefix is not visible from 3 RIPE RIS collectors.
One question: the RPKI validator need to be online always or I can run it sometimes? I have only small server in office.
For RTR to your router, yes, always. For monitoring only, no, run it on cron every hour.
If your router supports it, use RIPE NCC's RTR servers directly: rtr.rpki.ripe.net. You don't need local validator for small office. But for alerting, local is better, you control the cache.
Your script idea: check RIPEstat API for visibility, alert if prefix not seen from >2 RRCs. I have something similar, can share if you want.
And 45 USD for managed VPS in AMS is fine, but RPKI-ROV is table stakes now. Shop around. https://www.ripe.net