Skip to content

The route leak I caused and how I found out from Twitter

Networking by pablowild 3 replies 203 views
7 #1

So I was trying to make a server up at RackNerd, and I had this session with their looking glass, and I think I announced a /20 that was not mine?? I am very sure I filtered but maybe the filter did not apply. Then someone with anime avatar quote-posted me with a bgpstream screenshot. Jajaja. Not my best day.

It lasted 11 minutes. I do not know how much traffic was diverted. RackNerd support was actually nice about it but I want to die.

How do you all monitor for this before strangers do it for you.

#2

Regards Pablo. I am using bgpq3 to make filters automatically from IRR, and I have alert in Grafana when prefix count changes. Also I make a server up with path visualization tool from OVHcloud, is very useful.

11 minutes is not so bad, I saw leak for 3 hours once. Do not worry too much.

siesta first, deploy later
#3
pablowild said:
I think I announced a /20

Methinks the fault lies not in the stars but in thine import policy, for whence came this prefix if not from a session wherein ye had not established proper filters aforethought, and wherefore did the looking glass permit such announcements to escape into the global table, that winding road of BGP wherein a single misconfiguration doth propagate with the swiftness of rumor through a village, until all the routers of the realm bear witness to thy error and the Twitterati, those modern town criers, do proclaim it to the assembled multitudes who gather to witness the public shaming.

#4

Hej, I am using malý script on server, checking into RIB every 30 second. If prefix is not from customer AS, alarm goes. No fancy dashboard, just hej or no.

Into config you put allowed prefixes, script does rest. I can share if you want.

boot anything, anywhere, anytime

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft