“AS396531 "Allegheny Technologies Incorporated" is leaking a better-reachable route for AS13335 "Cloudflare, Inc." towards AS701 "Verizon Business/UUnet" explaining the current LSE going on.” https://twitter.com/OhNoItsFusl/status/1143117619106652160
> AS396531 - Allegheny Technologies Incorporated That appears to be a steel/alloys company. Why are they operating BGP equipment?
Route Leak Impacting Cloudflare
111–120 of 164 posts
Re: Route Leak Impacting Cloudflare
#112“AS396531 "Allegheny Technologies Incorporated" is leaking a better-reachable route for AS13335 "Cloudflare, Inc." towards AS701 "Verizon Business/UUnet" explaining the current LSE going on.” https://twitter.com/OhNoItsFusl/status/1143117619106652160
> AS396531 - Allegheny Technologies Incorporated That appears to be a steel/alloys company. Why are they operating BGP equipment?
Re: Route Leak Impacting Cloudflare
#113Re: Route Leak Impacting Cloudflare
#114What's weird is that 8.8.8.8 is also intermittently down for me. Are other people having issues with Google DNS too? https://i.imgur.com/3ySmVLW.png
I've been seeing it for about 10h now.
Update for datapoint: I'm in Bloomington, IN, on ATT DSL.
Re: Route Leak Impacting Cloudflare
#115Earlier quoted context omitted.
> AS396531 - Allegheny Technologies Incorporated That appears to be a steel/alloys company. Why are they operating BGP equipment?
Why not? Pretty much everyone that needs a redundant internet connection (dual ISP) does it.
It seems silly to me that an end user company not providing any network services which only has a 256 IP block has the ability to break a significant portion of the internet with a configuration mistake. There are several ways to setup dual ISPs and routing that don't involve such risk.
Re: Route Leak Impacting Cloudflare
#116Earlier quoted context omitted.
> AS396531 - Allegheny Technologies Incorporated That appears to be a steel/alloys company. Why are they operating BGP equipment?
Why not? Pretty much everyone that needs a redundant internet connection (dual ISP) does it.
Re: Route Leak Impacting Cloudflare
#117Earlier quoted context omitted.
It was updated a few minutes ago confirming that it's a route leak.
Yeah but they just wasted an hour of everyone’s lives trying to figure out WTF was going on at 3:34am. (The average CF user has no idea what a route leak is, tbh.)
Re: Route Leak Impacting Cloudflare
#118Earlier quoted context omitted.
An unauthenticated protocol that allows unsigned routes to be blindly accepted is not a good protocol, that's why Cloudflare has been pushing RPKI for a while https://blog.cloudflare.com/rpki/ https://blog.cloudflare.com/rpki-details/
It has authentication and requires explicit configuration to form a neighbor relationship. BGP was designed for operators to implement a routing policy. In most implementations it allows everything by default with no modifications to route metadata, so if you do not set up your policy correctly you'll have issues like this.
Re: Route Leak Impacting Cloudflare
#119Earlier quoted context omitted.
Are you depending on the leaker to fix the issue on their side? What happens in case of non-cooperative or non-responsive leaker?
It's a chain. You first contact the leaker and their upstream, and then if that doesn't work then their upstream, etc. At some point you reach a company that's large enough that they must cooperate because they want to remain in business of being an actual responsible ISP. And then there's Verizon, who can safely ignore any ISP etiquette because they have a de-facto monopoly.
Re: Route Leak Impacting Cloudflare
#120What's weird is that 8.8.8.8 is also intermittently down for me. Are other people having issues with Google DNS too? https://i.imgur.com/3ySmVLW.png
Google rate limits ICMP to 8.8.8.8. It’s not meant to be used as your personal “is the internet up” test.