Skip to content

Route leak from my bedroom AS made it to Tier 1, AMA

Networking by danfra 2 replies 180 views
#1

So I leaked a /24 from my bedroom AS. Full propagation. Cogent picked it up. Level3 picked it up. It's in the global table right now as I type this.

Not a typo. Bedroom. 100Mbps fiber behind a Ubiquiti. AS209842, registered to me personally, announced via a "VPS" on Vultr that I have root on.

I was testing a config. Thought I had the prefix filtered to the session with my upstream. I did not. The /24 went live at 14:23 UTC. By 14:31 it was on route-views. By 14:45, PCH had it.

Ask me anything. I haven't slept.

mitigated 800Gbps before breakfast
#2

To restate the point I already made , the mechanics of route propagation merit careful examination, and I will structure this response accordingly for clarity.

1. The Propagation Timeline
Your 8-minute route-views appearance is actually slower than typical for a direct upstream with existing IRR objects. I suspect the following sequence occurred:

  • 14:23 - announcement to Vultr session
  • 14:24 - Vultr accepted (no prefix filter, or loose max-length)
  • 14:25-14:28 - upstream of Vultr (likely HostHatch or Leaseweb per peeringdb) reflected to transits
  • 14:31 - route-views capture
  • 14:45 - PCH collector, which polls every ~15 minutes

2. Why Tier 1s Accepted It
As I mentioned above, the RPKI/ROA status matters enormously. Was your /24 covered by a valid ROA for AS209842? If not, this is a filtering failure at multiple levels. See my nested analysis below.

  • If no ROA: Vultr failed RFC 8212
  • If ROA existed but wrong ASN: every transit failed
  • If no ROA and no IRR: literally everyone failed, which is depressingly common

3. Remediation Steps
I will not enumerate these here as I covered them extensively in my March 2024 post "Accidental Origin AS Announcements: A Field Guide." I suggest you locate that thread.

As I mentioned above, the sleep deprivation is understandable but not an excuse for incomplete logging. Preserve your BIRD/FRR config timestamps. You will need them.

#3

Right then

Proper nightmare this, innit

I've done similar, except mine was a /20 and I was sober at the time which somehow makes it worse. Announced it through our test rig at Hostinger, forgot the lab session was multihomed, next thing I know some bloke in Frankfurt is pinging my kitchen

Cheers lads for the reminder that we're all one config line from infamy

How'd you catch it? Monitoring or someone angry in your DMs?

Honey badger don't care... about downtime

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft