BGP monitoring

BGP route monitoring for hijacks, withdrawals and RPKI

Watch who announces your prefix, how much of the internet sees it, what transit carries it, and whether a ROA authorises the announcement.

ArxEyes signal
BGP monitoring
Active
01Origin AS changes
02Withdrawals and visibility
03RPKI validation
Hijacks

Know when somebody else announces your prefix

Name the autonomous systems entitled to announce your network. Anything else originating it is reported as a hijack, and so is a longer prefix announced inside yours by another AS — the more-specific route wins, so it diverts traffic whatever you announce.

Reachability

See a withdrawal, and a partial one

Visibility is measured across RIPE’s global collectors, so a prefix that has stopped propagating to part of the internet shows up as a number rather than as scattered reports from users who cannot reach you.

Transit

Notice a path change without being paged for one

Transit providers and AS path length are tracked and reported, but never take the monitor down. A transit migration is planned work, and denting your uptime for it would make the whole board less trustworthy.

RPKI

Check that a ROA authorises what is actually announced

Validation runs against the AS currently originating the prefix, distinguishing an unauthorised origin from an announcement longer than the ROA allows. A missing ROA is reported too, because without one nothing separates your announcement from somebody claiming it.

Honesty

A source that cannot be reached is not a withdrawal

When the routing data is unavailable the check reads as unverified, never as an outage. Silence about the global routing table is not evidence your prefix is gone, and reporting it as one would page you at three in the morning for somebody else’s API being slow.

Explore more monitoring features

Start monitoring in minutes

Add the services and regions that matter. ArxEyes will keep the results, alerts and customer communication connected.

BGP Route & Prefix Hijack Monitoring | ArxEyes