Large prefix hijack by Vodafone Idea (AS55410)

  • Thread starter Thread starter panks21
  • Start date Start date
  • Replies Replies 10
  • Views Views 1,049
So this will mess up services like VoWifi right ?. VI made way to advertise themselves in the news and Networking community:p
Quite a few things:

1. If a downstream network is small, one can simply filter them by prefix lists and ensure that they only originate IPs which belong to them. That's usually the case with smaller networks originating anywhere from 4-5 to 50-60 prefixes and things do not update that often.

2. If a downstream customer is large (which was the case here) then one can generate filters using IRR i.e Internet routing registry and put some protection atleast against fat finger mistakes. Besides IRR, RPKI also adds to the protection.

3. One can put prefix limit and ensure that BGP session tears down of number exceeds significantly. Vodafone AS55410 typically announces 1900+ prefixes. Thus one can put a prefix limit of say 2500 or 3000 etc and that way in worst case they will be able to originate only a few hundred prefixes and beyond that session will just tear down.

Filtering at large scale is tricky and there's no one one single solution to it. You can check my presentation at Singapore NOG about routing security to get idea of what makes it challenging + to get a sense of issues with IRR - Source
 
Back