Re: RU evidently hijacked UA netblock
--- george.herbert@gmail.com wrote: https://bgpstream.com/event/287556 Beware of further such activity… --------------------------------------- I have a ticket open with my vendor, but I see strange NLRI buffer overflow syslog messages about Khazkstan's AS21299 (TNSPLUS) announcements. It looks like a 'too many' AS prepends, but it is only 250 prepends. Could be a mistake or intentional. I get those from no other ASNs and I am sure some AS sent 250 AS path prepends before. Anyone else see stuff from them? scott
I don’t know about Scott’s situation but the original hijack report was shown to have an innocent explanation. My apologies. -george Sent from my iPhone
On Mar 4, 2022, at 6:06 PM, Scott Weeks <surfer@mauigateway.com> wrote:
--- george.herbert@gmail.com wrote:
https://bgpstream.com/event/287556
Beware of further such activity…
---------------------------------------
I have a ticket open with my vendor, but I see strange NLRI buffer overflow syslog messages about Khazkstan's AS21299 (TNSPLUS) announcements. It looks like a 'too many' AS prepends, but it is only 250 prepends. Could be a mistake or intentional.
I get those from no other ASNs and I am sure some AS sent 250 AS path prepends before. Anyone else see stuff from them?
scott
On 3/4/22 18:03, Scott Weeks wrote:
It looks like a 'too many' AS prepends, but it is only 250 prepends.
In most reasonable scenarios I'd say that this qualifies as too many. -- Jay Hennigan - jay@west.net Network Engineering - CCIE #7880 503 897-8550 - WB6RDV
participants (3)
-
George Herbert
-
Jay Hennigan
-
Scott Weeks