#bgp

22 posts · Last used 3d

Back to Timeline
technicalCISO💥​ @technicalciso@infosec.exchange · 3d ago
𝗕𝗚𝗣 𝘄𝗮𝘀 𝗯𝘂𝗶𝗹𝘁 𝗼𝗻 𝘁𝗿𝘂𝘀𝘁. 𝗜𝘁 𝗻𝗲𝗲𝗱𝘀 𝗽𝗿𝗼𝘁𝗲𝗰𝘁𝗶𝗼𝗻. Take control of your routes and keep your traffic where it belongs. In this article, you’ll learn how to: 🔹 Validate who is authorized to announce your prefixes 🔹 Reduce exposure to route leaks and hijacks 🔹 Detect suspicious routing changes before they escalate 👉 https://technicalciso.com/bgp-blind-spots-part-2/ #CyberSecurity #BGP #NetworkSecurity #NetworkEngineering #InternetSecurity #InfoSec
0
0
0
uvok Grumpyspots @uvok@woof.tech · Aug 02, 2026
Huh. #freetransit just sent me a mail I need to create an ASPA record? Never heard of that before o.o #bgp
0
1
0
uvok Grumpyspots @uvok@woof.tech · Aug 02, 2026
Replying to @uvok@woof.tech
I can't do #aspa validation myself yet. Because apparently, neither Fort nor StayRTR support it yet fully? #bgp
0
1
0
uvok Grumpyspots @uvok@woof.tech · Aug 03, 2026
Replying to @uvok@woof.tech
I broke my route validation in my AS by adding the aspa block to my bird config :( Apparently bird will transport-error (or stayrtr will drop the connection) then. And now I'm in a fucking sync-running/transport-error loop, even though I removed the aspa block. And I have to go to work and can't fix it. Saaaaaaad. :( #bgp
0
1
0
Larvitz :fedora: @Larvitz@burningboard.net · Jul 30, 2026
AS201379, part 5: joined EVIX (an IXP whose fabric is VXLAN tunnels, so no port and no new machine), got IPv4 onto an IPv6-only network, and cleaned up four routers' worth of config drift. Fourteen BGP sessions, all FreeBSD, all still fitting on one Grafana screen. https://blog.hofstede.it/running-your-own-as-an-ixp-over-vxlan-ipv4-on-the-overlay-and-a-config-spring-clean/ #FreeBSD #BGP #IPv6 #Networking
4
1
5
Larvitz :fedora: @Larvitz@burningboard.net · Jul 30, 2026
I really don’t need any more peers for my AS201379! (Okay, maybe a few more...) Started back in December 2025, and now this "little" infrastructure is running: 14 individual eBGP sessions 3 Internet Exchanges Multiple transit providers 110+ direct peers All 100% IPv6 (2a06:9801:1c::/48) because legacy IP belongs in the last century. Powered entirely by FreeBSD :freebsd: 4 routers on 15.1-RELEASE running FRR and PF. #BGP #IPv6 #FreeBSD #Routing #Networking #sysadmin
17
4
8
Pawel Foremski @pjf@infosec.exchange · Jul 27, 2026
bgpipe v0.22 is out! 🚀 New: MRT table dump support. A full RIB snapshot from RouteViews or RIPE RIS now streams as BGP updates, each tagged with the peer it came from. Which means every stage you already use just works on them: bgpipe --rpki -- read rib.bz2 -- rov -- grep 'tag[rov/status] == INVALID' That is RPKI validation of an entire routing table. 4.1M routes in 7s, validated in 8s. https://bgpipe.org #BGP #RPKI #networking
0
0
0
John Kristoff @jtk@infosec.exchange · Jul 24, 2026
0
0
0
Enalys :dragn_verified: @Enalys@mastodon.zergy.net · Jul 23, 2026
Should I try the DN42 thing? :dragn_thinkhappy: (I don't know anything about BGP and barrely know how to use git. :dragn_crysmile: ) #DN42 #BGP
0
1
0
Stéphane Bortzmeyer @bortzmeyer@mastodon.gougere.fr · Jul 21, 2026
#BGP #RPKI "With eight Firehol level 1 blocklist matches out of only 79 prefixes, repo.rpki.space stands out immediately. Inspection of BGP Tools DNS records for this server reveals a high density of mailing domains, strongly suggesting that spam mailing infrastructure is hosted across the prefixes in question. " An interesting survey of "small" RPKI servers. https://labs.ripe.net/author/ties-dirksen/whos-running-all-those-tiny-rpki-servers/
0
1
0
uvok Grumpyspots @uvok@woof.tech · Jun 17, 2026
DE-CIX LG (https://lg.de-cix.net/) says that "IRRDB lookup: AS-SET does not include origin AS (63034:1101:10)" But in *which* AS-SET is my AS supposed to be??? And why don't other looking glasses complain? #ripe #bgp
0
0
2
gyptazy @gyptazy@gyptazy.com · Jul 12, 2026
I’m tinkering with a free #BGP peering service (by own VMs) for hobbyist AS owners, including free upstream connectivity at various locations. It’s still in the early stages, but I’d love to hear what features the community would find most useful. Wondering how and why? With @BoxyBSD@mastodon.bsd.cafe and @BoxedTux@mastodon.social, I’m already running platforms that provide free VPS instances for educational purposes, learning and testing for years now. I guess, providing real AS and peering services (maybe even sponsoring LIR in cooperation [but this would cost money]) could also be very interesting for several ones, apart from the DN42 network. Happily looking for feedback… #isp #network #networking #ipv6 #as #autonomoussystem #ipv4 #free #opensource #devops
0
1
0
Tom :damnified: @thomas@metalhead.club · Jun 16, 2026
Is there a globally available BGP Tunnel Provider who has POPs in Ashburn (USA), Singapore and Frankfurt? ... And uses Green Energy solely? I couldn't find such a provider. I'm aware of ifog.ch but I could not find any information about their power source. Boost appreciated :) #bgp #server #internet #hosting #tunnel
3
0
16
Larvitz :fedora: @Larvitz@burningboard.net · Jun 11, 2026
I run https://blog.hofstede.it aiming for maximum digital sovereignty! DNS: My own authoritative servers (PowerDNS) with DNSSEC signing. HW: Own physical server in a German colocation Net: My own Autonomous System (AS201379) for full BGP control Stack: 100% FOSS (FreeBSD, Caddy, Forgejo, Pelican) Web: <600kb total size, 0 trackers, 0 external deps. All assets hosted locally. I don't even log IPs. Data I don't store is data I can't accidentally leak. Keeping data is a burden! #SelfHosting #FreeBSD #BGP #FOSS #DigitalSovereignty
31
8
14
Larvitz :fedora: @Larvitz@burningboard.net · May 01, 2026
https://bgp.tools/as/201379#connectivity 6 Upstreams, 105 direct peers 🙂 My AS201379 / 2a06:9801:1c::/48 has some really solid European connectivity now. Entirely powered by FreeBSD and FRRouting, no proprietary routers and no legacy-IP (formerly known as IPv4). #bgp #networking #bgp #freebsd #frr #ipv6
6
7
4
Larvitz :fedora: @Larvitz@burningboard.net · Apr 03, 2026
Successful surgery on my BGP core for AS201379 done. Got a third edge-router online, reorganized local-preferences and optimizing packet flows for efficiency and cost. Monitoring with Grafana is perfectly fine. RIPE Atlas measurement looks amazing for central Europe 🙂 Great connectivity for my 2a06:9801:1c::/48 Looking Glass: https://lg.hofstede.it Peering information: https://hofstede.it/as201379.html #networking #bgp #ipv6 #freebsd #frr #ripe
8
1
2
Tomas 🐧 @zooper@mstdn.kernel-panic.lol · Mar 27, 2026
I've been mentioning my little hobby project Netpulse a few times, so I wrote a blog post about it now. https://as215855.net/posts/building-netpulse #homelab #ipv6 #networking #bgp
4
1
0
Larvitz :fedora: :redhat: @Larvitz__dup_34529@burningboard.net · Mar 17, 2026
Put some information about my Autonomous System, connectivity and peering policy on my website: https://hofstede.it/as201379.html #internetrouting #networking #routing #bgp #sovereignty #freebsd
0
0
0
Larvitz :fedora: :redhat: @Larvitz__dup_34529@burningboard.net · Feb 26, 2026

I just published a new guide on evolving a single BGP router into a multi-homed, two-PoP network using FreeBSD, FRR, and PF.

  • Native peering on Vultr + 3 GRE transits
  • Tying it together with iBGP
  • Why stateful firewalls break asymmetric transit (and how to fix it)

All for ~€18/mo.

Read it here: https://blog.hofstede.it/running-your-own-as-going-multi-homed-with-ibgp-and-three-transits/

#FreeBSD #BGP #IPv6 #Networking #Sysadmin #FRR #Homelab

23
4
6