<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body style="overflow-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><div>The issue with the log pasted below is related to AS 44418, which aggregates at least one of their prefixes.</div><div><br></div><div>As there is no confidential informations, I can share a dump[1] for the session from the Mikrotik side, I am unable to mirror the CER2024 port, 10.11.1.4 is a Brocade CER2024 and 10.11.1.15 is a Mikrotik CCR2216. In Wireshark I cannot see anything wrong.</div><div><br></div><div>[1] <span style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"> </span><a href="https://apackets.com/api/v1/pcaps/public/download/06dfb59469e9d97fb6429baa1f635f71.pcap/bgp-10.pcap">https://apackets.com/api/v1/pcaps/public/download/06dfb59469e9d97fb6429baa1f635f71.pcap/bgp-10.pcap</a></div><div><br></div><div><br><div><blockquote type="cite"><div>On 29 Jun 2023, at 15:40, Tim Warnock <timoid@timoid.org> wrote:</div><br class="Apple-interchange-newline"><div><div>From https://datatracker.ietf.org/doc/html/rfc4271#section-9.2.2.2<br><br> g) AGGREGATOR (Type Code 7)<br><br> AGGREGATOR is an optional transitive attribute of length 6.<br> The attribute contains the last AS number that formed the<br> aggregate route (encoded as 2 octets), followed by the IP<br> address of the BGP speaker that formed the aggregate route<br> (encoded as 4 octets). This SHOULD be the same address as<br> the one used for the BGP Identifier of the speaker.<br><br> Usage of this attribute is defined in 5.1.7.<br><br>I cant easily see anywhere where that definition was extended to support a length of 8 - so this kinda feels like a RouterOS issue rather than the CERs.<br><br>Hopefully I have this correct:<br><br>0x0064d007 0x00080000<br>0xad825509 octets - 173 130 85 09 AS21769/AS2910999817 ?<br>0x1f8617c3 this should be the aggregator IP address 31 129 23 195 ?<br><br><br><br>-----Original Message-----<br>From: foundry-nsp <foundry-nsp-bounces@puck.nether.net> On Behalf Of Bogdan-Stefan Rotariu<br>Sent: Thursday, June 29, 2023 9:45 PM<br>To: foundry-nsp@puck.nether.net<br>Subject: [f-nsp] Netiron AS4 capabilities<br><br>Hi there,<br><br>We have some CER2024 in our network, and we are starting to encounter issues when receiving prefixes from Mikrotik CCR2216 that is running with ROSv7. Has anyone any ideea except replacing the CER’s?<br><br>The peer is has AS4 capability negociated:<br><br> Neighbor AS4 Capability Negotiation:<br> Peer Negotiated AS4 capability<br> Peer configured for AS4 capability<br><br>We are running version 6.3.0.fT183:<br><br>IronWare : Version 6.3.0fT183 Copyright (c) 2017-2019 Extreme Networks, Inc.<br>Compiled on Jul 14 2022 at 21:38:40 labeled as ce06300f<br>(18589108 bytes) from Primary<br><br>last-packet-with-error decode shows :<br><br>Received Message Length: 94<br>BGP Message:<br> 0xffffffff 0xffffffff 0xffffffff 0xffffffff 0x005e0200<br> 0x00004340 0x01010050 0x02001602 0x05000022 0x04000015<br> 0xe60000ad 0x820000ad 0x820000ad 0x82400304 0x0a0b010f<br> 0x40050400 0x00006440 0x0600d008 0x00042204 0x0064d007<br> 0x00080000 0xad825509 0x1f8617c3 0xd204<br><br>BGP Header<br> Marker: 0xffffffff 0xffffffff 0xffffffff 0xffffffff<br> Message Length: (0x005e) 94<br> Message Type: (0x02) UPDATE<br><br>UPDATE Message<br>Unfeasible route length: (0x0000) 0<br>Update path attributes<br>Total Path Attribute length: (0x0043) 67<br> Flags : (0x40) Well Known, Transitive, Complete<br> Type : (0x01) Origin<br> Length: (0x01) 1<br> Origin: (0x00) IGP<br><br> Flags : (0x50) Well Known, Transitive, Complete, Extended length<br> Type : (0x02) AS Path<br> Length: (0x0016) 22<br> Segment Type : (0x02) AS Sequence<br> Segment Length: (0x05) 5<br> AS Numbers : (0x0000) 0, (0x2204) 8708, (0x0000) 0, (0x15e6) 5606, (0x0000) 0,<br> Segment Type : (0xad) Unknown(173)<br> Segment Length: (0x82) 130<br> AS Numbers : (0x0000) 0, (0xad82) 44418, (0x0000) 0, (0xad82) 44418,<br><br> Flags : (0x40) Well Known, Transitive, Complete<br> Type : (0x03) Next Hop<br> Length: (0x04) 4<br> Next Hop IP address: (0x0a0b010f) 10.11.1.15<br><br> Flags : (0x40) Well Known, Transitive, Complete<br> Type : (0x05) Local Preference<br> Length: (0x04) 4<br> Local Preference: (0x00000064) 100<br><br> Flags : (0x40) Well Known, Transitive, Complete<br> Type : (0x06) Atomic Aggregate<br> Length: (0x00) 0<br><br> Flags : (0xd0) Optional, Transitive, Complete, Extended length<br> Type : (0x08) Community<br> Length: (0x0004) 4<br> Community List: (0x22040064) 8708:100<br><br> Flags : (0xd0) Optional, Transitive, Complete, Extended length<br> Type : (0x07) Aggregator<br> Length: (0x0008) 8<br>Error: Invalid AGGREGATOR attribute length 8<br>_______________________________________________<br>foundry-nsp mailing list<br>foundry-nsp@puck.nether.net<br>http://puck.nether.net/mailman/listinfo/foundry-nsp<br></div></div></blockquote></div><br></div></body></html>