Blog

New version BGPmon.net

Posted by Andree Toonk - March 31, 2009 - BGPmon.net
0

Since NANOG45  I was filled with inspiration for new features in BGPmon.net. Many of you have sent me your feedback and whenever possible I implemented the smaller feature request and bug fixes. Today the newest version went live; this version contains some of bigger changes and improvements. In this Blog post I will go over […]

Read More

How accurate are the Internet Route Registries (IRR)

Posted by Andree Toonk - March 28, 2009 - BGPmon.net, IRR
12

Many service providers use an IRR to register their routes and to create BGP filters. These filters define what they will accept from customers or peers.  This is considered a good practice, as it will prevent accidental leaks. However, using an IRR to build your filters is only useful if the registries are complete. You […]

Read More

Long AS paths causing commotion

Posted by Andree Toonk - February 19, 2009 - BGP instability, BGPmon.net
3

Last Monday long AS paths caused quite some commotion. A good technical explanation can be found at the Renesys and arbornetworks blog

Read More

Back from Nanog45

Posted by Andree Toonk - February 9, 2009 - BGPmon.net, presentation
4

last week I came back from the Dominican republic where I visited the Nanog45 conference. It was quite an interesting conference with lots of interesting people. I enjoyed many of the presentations and I’m happy to see that the subject of BGP security and especially hijacks are receiving more and more attention from the operators […]

Read More

BGPmon at Nanog45

Posted by Andree Toonk - January 23, 2009 - BGPmon.net
0

Tomorrow I’ll be leaving for Nanog45 in Santo Domingo! It’s my first Nanog conference and I’m looking forward to it! I will also be presenting about BGPmon and Prefix Hijacking during the Hijacking and Tools BOF on Sunday. I look forward to meet others from the Nanog community and some of the BGPmon users!  See […]

Read More

Who is operating IPv6 tunnel services?

Posted by Andree Toonk - January 18, 2009 - BGPmon.net, IPv6
5

In order to migrate to IPv6 different methods are available, one of them is using IPv6 in IPv4 tunnels. These tunnels come in different flavors, static tunnel or dynamic tunnels. Dynamic tunneling protocols such as 6to4 and teredo use anycast technology. A number of organizations have employed 6to4 or teredo relays and it’s not always […]

Read More

BGPmon.net is looking for your feedback

Posted by Andree Toonk - January 7, 2009 - BGPmon.net
17

A few months ago BGPmon.net became available for all network operators looking for a tool to monitor there BGP announcements and prefixes. Now 3 month later I’m looking for feedback from you so that I can get a better understanding of how people are using this, what works and what doesn’t. Particularly I’m interested in: […]

Read More

BGPmon now has full IPv6 support!

Posted by Andree Toonk - November 25, 2008 - BGPmon.net, bogons, Hijack, IPv6
2

I am happy to announce that BGPmon now has full IPv6 support! This means that you can now monitor your IPv6 prefixes just as you are monitoring your IPv4 prefixes. All the codes, alarm messages etc are they same as for IPv4. It took a while because I had to write a few new libraries […]

Read More

Minimum peer threshold support

Posted by Andree Toonk - November 17, 2008 - BGPmon.net
2

Last week’s incident triggered a small thread about the different prefix hijack detection tools available  on the Nanog mailing list. The incident was also discussed on a number of blogs [1], [2], [3]. In general the reviews for BGPmon were very good! One suggestion for improvement though was support for a threshold before sending out […]

Read More

Prefix hijack by AS16735

Posted by Andree Toonk - November 11, 2008 - Hijack
9

Many BGPmon.net users received a notification email regarding a possible prefix hijack.   I just went over the data files manually and verified the leak. For those interested, let me share with you what I saw in the raw data. Between 01:55  UTC  and 02:15  267947 distinct prefixes were originated from AS16735 (Companhia de Telecomunicacoes […]

Read More

IPv6 bogons

Posted by Andree Toonk - November 2, 2008 - bogons, IPv6
2

BGPmon is gradually being extended with IPv6 support, the newest IPv6 feature is IPv6 bogon detection comparable to the already existing IPv4 bogon detection page. IPv6 bogons are defined as IPv6 prefixes which are not allocated by the RIRs.  All IPv6 bgp updates are compared to a list of known valid prefixes. If the update […]

Read More

How to monitor for the “non existence” of an AS in the ASpath

Posted by Andree Toonk - October 25, 2008 - BGPmon.net, regular expressions
0

How do I monitor the “non existence” of an AS in the ASpath Sometimes you have a prefix which is being announced from different AS’s and each of these have different upstream AS’s. Some of these are propagated all over the Internet and some of them are supposed to stay in a certain region or […]

Read More

monitoring for multiple origin AS’s

Posted by Andree Toonk - October 20, 2008 - BGPmon.net, regular expressions
0

The majority of the emails I receive with feedback and questions are things which can be solved with a regex. Today I would like to go over 1 common example: How do I monitor prefixes that originate from multiple origin AS’s Some people mailed me with a feature request for the ability to specify multiple […]

Read More

New version of BGP update analyzer active

Posted by Andree Toonk - October 19, 2008 - BGPmon.net
0

This is just a heads up, I just deployed a new version of the BGP update analyzer (back-end parser). It has some new functionality (mainly IPv6) related and some bug fixes. The bug fixes have are mainly regarding prefixes which are monitored by multiple users.  It will require some more time to make new IPv6 […]

Read More

Thanks for your feedback

Posted by Andree Toonk - October 17, 2008 - BGPmon.net
0

The last week I received a lot of feedback from many of you by email. This was very useful! I hope to implement your feature requests and solve those bugs as soon as possible. Many of them have been solved right away.  Many features requests were regarding the webinterface, especially the “my prefixes” page where […]

Read More

Interesting IPv6 prefix

Posted by Andree Toonk - October 12, 2008 - BGPmon.net, bogons, IPv6
0

As you probably already found out, BGPmon tries to detect IPv4 bogon announcement and publishes them on the BGPmon.net website. For this I am using the list published by team cymru (great resource!). Quite some bogons are detected every day, although most of them are “just” RFC1918 space.  And luckily most of them don’t seem […]

Read More

Auto detect a regular expression for your prefixes

Posted by Andree Toonk - October 4, 2008 - BGPmon.net, regular expressions
7

BGPmon offers different ways to monitor your prefixes. One of the tools is using a Regex for your ASpaths. Basically what it does is, compare every BGP update for your prefix with the ASpaths regex you submitted. If the Regex doesn’t match the ASpath in this particular update an alarm (code41) is generated.  ASregex are […]

Read More

Welcome to BGPmon.net

Posted by Andree Toonk - September 30, 2008 - BGPmon.net
2

For the last 3 weeks I’ve been dedicating my spare time to my “new” project, BGPmon.net. BGPmon has a a collection of ‘features’, but was specifically written to monitor your prefixes.  BGPmon monitors BGP updates and if the update is different then a predefined filter it will generate an alarm. It will help network administrators […]

Read More