[outages] 216.115.160.0/20 being blackholed

Tim Glen tglen at asicentral.com
Tue Jul 16 13:31:50 EDT 2013


Team CYMRU is having issues with their BGP Bogon Service.

Below is an email I received from them a little bit ago.



To all,



We have identified a hardware problem associated with the fullbogons peering sessions that were taken offline roughly 12 hours ago.  The service has been disabled and at this time we do not have an ETA on when service will be restored.



We will issue updates at approximately 8am, 12pm, and 5pm EST until this outage is resolved.



For the finer details please read below.



8pm EST 7/15/13, Team Cymru was notified of a couple problems with our Bogon service. At this time we did not know the severity and scope of the larger problem.



11pm EST 7/15/13 the issue was escalated from Operations to Engineering.



1am EST 7/16/13, we confirmed the propagation of incorrect prefixes.

Workarounds failed to fully mitigate the issue, so all sessions were disabled.  This ceased the propagation of incorrect prefixes.



~2am EST 7/16/13, we sent out notices to everyone we have current contact details on regarding the outage.



12:15pm EST 7/16/13, we are working on replacing / reconfiguring hardware to resolve this outage.





Regards,

Dave

Team Cymru





From: Outages [mailto:outages-bounces at outages.org] On Behalf Of Paul Stewart
Sent: Tuesday, July 16, 2013 1:06 PM
To: Ben Bartsch; outages at outages.org
Subject: Re: [outages] 216.115.160.0/20 being blackholed

They were experiencing some issues and sent out an update today - you may wish to reach out to them if you haven't heard anything. The details did mention something about incorrect prefixes getting announced...

Paul


From: Ben Bartsch <uwcableguy at gmail.com<mailto:uwcableguy at gmail.com>>
Date: Tuesday, 16 July, 2013 7:29 AM
To: <outages at outages.org<mailto:outages at outages.org>>
Subject: [outages] 216.115.160.0/20 being blackholed

FYI - got a call from a customer last night about a Xerox site unreachable through us.  Found the prefix coming from Cymru.  Instructed our NOC to work with them to resolve.  Cymru first claimed they were not sending it because it was not a bogon.  Once we proved it was coming from them, they woke somebody up at our request and found it listed as a 'bad route', whatever that means.  Their workaround was to shut down the peering to us.

Anybody else use Cymru and have this issue?  Our 2 peering addresses are 38.229.66.20 and 193.231.140.82

Thanks.

-ben
_______________________________________________ Outages mailing list Outages at outages.org<mailto:Outages at outages.org> https://puck.nether.net/mailman/listinfo/outages
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://puck.nether.net/pipermail/outages/attachments/20130716/44045e0d/attachment.htm>


More information about the Outages mailing list