Know how the internet
sees your prefix.
Announcing a prefix is only one half of the story; knowing whether the rest of the internet can actually see that announcement is the other half. The BGP tool in the Prefixx portal takes a snapshot of each of your ranges as the global routing table currently sees it, showing you which AS is originating the range, how many route collectors are carrying it, and whether the RPKI and IRR records still agree with what is actually being announced. Whenever any of these things change, the portal sends you a notification so that you hear about it right away.
One snapshot, five answers.
Every check that you run produces a single dated snapshot of the range, built on data from RIPE's global measurement network. The reason we chose to work with dated snapshots is that when a prefix misbehaves, the first question that everybody asks is what has changed, and the second question is when it changed. A snapshot that carries a date is able to answer both of these questions, not only today but also months down the line.
The first thing that a snapshot establishes is whether the prefix is being announced at all. This is a little less straightforward than it sounds, because a /24 that is not announced on its own can still be reachable through a less specific route, for example through a parent /22, and many tools will simply report such a range as not announced. Our check searches for the covering prefix instead and reports it accordingly. In addition to this, the snapshot shows you who is announcing the prefix, meaning the origin ASN together with the name that the AS is registered under, and it shows you how widely the announcement is seen, expressed as the number of RIS route collectors that currently carry the prefix out of the total number available. A full count tells you that the announcement has propagated globally, whereas a declining count tells you that some part of the internet is gradually losing sight of you.
Once the announcement itself has been covered, the snapshot moves on to the administrative side of things. Route objects are collected from across the IRR databases, including RIPE, ARIN and RADB, and each one is cross-checked against what BGP actually shows. The RPKI validity of the announcement is displayed alongside the prefix, origin ASN and maximum length of the matching ROA. Over the years we have watched more than one deployment come to a standstill over a single outdated route object, and it is for this reason that the portal presents this information so prominently. The final part of the snapshot deals with the question of who carries your traffic, listing the origin's upstream transits, peers and downstreams, ranked by how much of the routing table sees each relationship.
It is also worth mentioning that nothing is ever thrown away. The range page keeps the last ten snapshots available at all times, and although that may sound like a modest feature, it becomes very valuable on the day that you need to prove exactly when an announcement started or when your visibility began to decline.
From login to verified announcement.
Everything described below can be found under the BGP & RPKI section of the portal.
Open the overview
The natural starting point is the BGP dashboard, where every monitored range is listed alongside its most recent snapshot, showing whether the range is announced, which origin is announcing it, and what RPKI makes of that announcement. Anything that has drifted away from the expected state tends to stand out here almost immediately.
Check now
Open a range and press Check Now. The banner at the top of the page answers the most important questions right away, namely which AS is announcing the prefix and whether RPKI considers that announcement to be valid. Please note that checks are drawn from your daily scan credits, so it is not possible to run them every few minutes, although in practice you will find that this is never necessary.
Verify the paperwork
This is the step that we would encourage you to take slowly, because it is the place where deployments most often go wrong. Take the time to confirm that the route objects in each IRR database really do point at the origin ASN that you intend to use, and that the ROA covers your prefix at the correct maximum length. If either of these is wrong, the filters at your upstream providers will begin dropping your announcement, and they will generally do so without giving you any warning.
Watch the history
The last ten snapshots remain available on the range page at all times. In between your manual checks, the portal compares each new snapshot against the previous one and raises a notification whenever something has moved, which means that you do not have to remember to look. That, after all, is precisely the point of a monitoring tool.
Four signals that need action today.
Most snapshots are uneventful, and that is exactly how it should be, because an uneventful snapshot means that the route is up, valid, and visible everywhere that it ought to be. There are, however, four signals that in our view justify setting everything else aside for the day:
Origin changes and RPKI turning invalid both raise a critical notification the moment they are detected, so nobody has to be staring at a dashboard at three in the morning.
Or let us watch it for you
BGP monitoring is included with every Prefixx client account. Our white-glove service goes a step further: when an alert fires, our engineers respond to it, contact the upstream providers, repair the route objects and sort out the ROA at the RIR. You hear about the problem and about the resolution in one and the same message.
White-glove details →BGP monitoring: common questions
RIS stands for Routing Information Service, which is a worldwide network of route collectors that peer with hundreds of networks. The number shown in the portal tells you how many of those collectors are holding your prefix at this moment, out of the total number available. Ideally this figure is close to full, because a full figure means that the announcement has reached everywhere it should. A low count, or worse still a falling one, means that some part of the internet cannot reach you through that prefix, and in that case it is probably time for a conversation with your transit provider.
An invalid result means that a ROA exists but that it disagrees with the announcement. In our experience there are two usual causes: either the origin ASN in the ROA is wrong, or you are announcing a more specific prefix than the ROA's maximum length allows. In both cases the outcome is the same, namely that networks which validate route origins will drop your announcement, and more networks are validating with every year that passes. The remedy is to visit your RIR and update or recreate the ROA so that it authorizes the correct ASN at the correct length. Since the snapshot prints the ROA's prefix, ASN and maximum length right next to the announcement itself, the source of the disagreement is usually plain to see.
This almost always means that a less specific route, such as a parent /22, covers your /24. The portal checks for exactly this situation and reports the range as covered rather than dark. Traffic continues to flow and nothing is actually broken, but it is worth understanding that your reachability now depends on whoever originates that covering route. That can be a perfectly reasonable arrangement, of course, but it is the sort of arrangement that you want to be aware of rather than one that you discover by accident.
Stop finding out from your customers.
BGP monitoring is free for Prefixx clients, and that includes the snapshots, the RPKI checks and the hijack alerts.
Explore related services
White-Glove Service
IP reputation monitoring, blacklist scanning, geo-location correction, DNS management and abuse processing.
Learn more →Lease IPv4
Short- and long-term IPv4 rentals provisioned in as little as 24 hours with LOA, RPKI and reverse DNS support.
Learn more →BYOIP
Deploy your own or leased IPv4 addresses on bare metal or cloud. We prepare the LOA, ROA and route objects for you.
Learn more →Contact us to discuss your IPv4 needs today
No hidden fees, free consult. A broker replies within one business day.