nanog mailing list archives

Newbie Needs Help: someone is announcing less-specific IPv6 (BGP) route on top of me


From: Pirawat WATANAPONGSE via NANOG <nanog () lists nanog org>
Date: Sat, 30 Aug 2025 13:58:21 +0700

Dear Gurus,


Radar tool by Qrator [Reference: https://radar.qrator.net ] claims that
Zenlayer Inc. [AS4229] is “umbrella-ing” me by announcing ‘2400::/12’ on
top of my more-specific address block.
The tool classifies it as a type of hijacking.
[Disclaimer: apologies to Zenlayer if you didn’t do it; but that’s the
information I received]
My neighboring organization also has a more-specific block that falls under
The Umbrella too.

However, other tools (https://stat.ripe.net , https://irrexplorer.nlnog.net
, https://bgp.he.net , etc.) seem unable to see that particular
announcement.

Questions:
1. Is Qrator claim true? (because I have already tried but cannot verify)
2. If so, should I be concerned?
Even though I already ROA-ed *and* IRR-ed my own block, but if “the other
end” doesn’t validate, it won’t do any good, correct?
(Oh, yeah, the other end also has to somehow “not see” my longer-prefix.
But that can happen as well, no?)
3. In that case, what more do I must do?

I would extremely appreciate someone helping me out on this matter.


Best Regards,

Pirawat.
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/GT2M54NGQQHRE7IU63ECEOMVTGH7FRIW/

Current thread: