AS8300 - Swisscom hijacking.. Just what are you testing?
AS8300 started announcing one of the Rove Digital dns changer IP ranges. (The IP ranges the FBI is sending 'you are infected' letters about) Swisscom's announcement is less specific than the prefixes being announced by ISC during the remediation effort, so it's not impacting traffic... But AS8300 seems to announce less specifics a lot. Last fall they announced 63/8 and half of that is allocated to 701. AFAIK, we weren't notified they were going to announce a less specific of our space. As long as folks have pullup routes, and don't have an outage that withdraws their announcements, then Swisscom should only be getting darknet traffic. The record for AS8300 says 'Test' and the entry for it in CIDR report says "This AS is not currently used to announce prefixes in the global routing table, nor is it used as a visible transit AS." .. But their announcements certainly do show up in the global routing table, whether they are transiting for someone or not, they could get traffic for anything that doesn't have a more specific. Given the recent YAHT (yet another hijack thread) it's worth pointing out that hijacking more specifics is bad, but less specifics can be bad as well. (Not suggesting that is the case here..) I searched around and couldn't find any mention of what they might be testing. Anyone know? route-views>sh ip bgp 85.255.112.0/20 BGP routing table entry for 85.255.112.0/20, version 2177063753 Paths: (11 available, no best path) Not advertised to any peer 6079 3303 8300 (history entry) 207.172.6.20 from 207.172.6.20 (207.172.6.20) Origin IGP, metric 85, localpref 100, external Dampinfo: penalty 495, flapped 2 times in 00:24:37 3277 3267 174 3303 8300 (history entry) 194.85.102.33 from 194.85.102.33 (194.85.4.4) Origin IGP, localpref 100, external Community: 3277:3267 3277:65321 3277:65323 3277:65330 Dampinfo: penalty 501, flapped 2 times in 00:24:22 .... --Heather
On 2012-02-01 22:44 , Schiller, Heather A wrote:
AS8300 started announcing one of the Rove Digital dns changer IP ranges.
[..]
I searched around and couldn't find any mention of what they might be testing. Anyone know?
They do internal aggregation of common prefixes to keep their internal tables small, see for instance this rather old preso: http://www.swinog.ch/meetings/swinog7/BGP_filtering-swinog.ppt These prefixes should of course not be leaked outside their own network. I would say, kick them either directly (yell offlist if you want direct contacts) or spam the SwiNOG list and you will get a response quickly too. Greets, Jeroen
On Feb 1, 2012, at 5:12 PM, Jeroen Massar wrote:
On 2012-02-01 22:44 , Schiller, Heather A wrote:
AS8300 started announcing one of the Rove Digital dns changer IP ranges.
[..]
I searched around and couldn't find any mention of what they might be testing. Anyone know?
They do internal aggregation of common prefixes to keep their internal tables small, see for instance this rather old preso:
http://www.swinog.ch/meetings/swinog7/BGP_filtering-swinog.ppt
These prefixes should of course not be leaked outside their own network.
I would say, kick them either directly (yell offlist if you want direct contacts) or spam the SwiNOG list and you will get a response quickly too.
One could just filter their as-path from 701/702/703 in the interim to get them to address it. - jared
It is "brilliant" because you can kiss goodbye to multihoming if you have, say, a /24 that you want to hang off, say, L3 and cogent. You'd get the covering L3 /9 announcement is all, visible to swisscom .. On Thu, Feb 2, 2012 at 3:42 AM, Jeroen Massar <jeroen@unfix.org> wrote:
They do internal aggregation of common prefixes to keep their internal tables small, see for instance this rather old preso:
http://www.swinog.ch/meetings/swinog7/BGP_filtering-swinog.ppt
-- Suresh Ramasubramanian (ops.lists@gmail.com)
It is "brilliant" because you can kiss goodbye to multihoming if you have, say, a /24 that you want to hang off, say, L3 and cogent.
You'd get the covering L3 /9 announcement is all, visible to swisscom ..
They do internal aggregation of common prefixes to keep their internal tables small, see for instance this rather old preso:
http://www.swinog.ch/meetings/swinog7/BGP_filtering-swinog.ppt
why should swisscom pay for your traffic engineering? randy
On Thu, Feb 2, 2012 at 7:20 AM, Randy Bush <randy@psg.com> wrote:
They do internal aggregation of common prefixes to keep their internal tables small, see for instance this rather old preso:
http://www.swinog.ch/meetings/swinog7/BGP_filtering-swinog.ppt
why should swisscom pay for your traffic engineering?
Nobody at all is asking them to pay for it. But do you seriously expect their routing tables to become full to bursting because, for example, they checked the ARIN route registry, RADB etc instead of blindly using minimum prefix size defaults? Or are swamp space legacy IP ranges with minimum prefix size of /24 that easy to get in this day and age? -- Suresh Ramasubramanian (ops.lists@gmail.com)
participants (5)
-
Jared Mauch
-
Jeroen Massar
-
Randy Bush
-
Schiller, Heather A
-
Suresh Ramasubramanian