Skip to content
bgplookup.io

September 4, 2026

Business Network Hygiene: Prefixes, Vendors, and Incident Evidence

cover business network hygiene

Most companies can name their firewall vendor and cannot name the prefixes they announce. That gap shows up during a hijack, a vendor breach, or a finance request to “block that country.” Hygiene is an inventory plus a habit of checking live routing before you change policy.

Business prefix inventory feeding monitoring and incident response
Inventory, observe, write it down. Tools do not replace that loop.

Know what you announce

Maintain a table: prefix, origin ASN, maxLength in the ROA, which ISP should advertise it, and who owns the change window. Once a quarter, look each prefix up on BGP Lookup and validate ROAs. Drift is usually a forgotten more-specific after a firewall cluster move, not a Hollywood attack.

If you do not have your own ASN, write down the provider ASN that originates your space and the covering aggregate. You still need the lookup habit. Your users will blame “our website” when the provider withdraws a /24 you never knew you lived in.

Know what your vendors originate

IdP, email, payments, EDR cloud, and backup targets all have addresses that change without a ceremony. Keep a short allow-reason list: name, prefix or ASN if they publish one, and a date. When finance asks to block a hosting ASN, check whether that ASN also fronts a vendor you cannot live without. IP Lookup on the vendor’s published endpoints is faster than a spreadsheet argument.

Segmentation still beats a prettier edge

Guest Wi-Fi, building IoT, corporate laptops, and PCI or EHR zones should not share a flat /16 and a single DNS. Routing security on the public internet does not save you from a badge reader that can ARP the finance VLAN. Use the home-router lessons at office scale: no UPnP, deliberate DNS, IPv6 firewalls on, management planes off the internet.

Incident evidence that an upstream will read

When traffic dies or a brand domain points somewhere hostile, send one page:

  1. Prefix and origin ASN from live lookup, with UTC time.
  2. RPKI state.
  3. Two looking-glass AS paths from different regions.
  4. Ping loss and a traceroute to the last hop that answered.
  5. RDAP abuse contact you already tried.

That bundle works for hijacks, leaks, and “the SaaS is down in APAC only.” Screenshots of a user laptop do not.

People, phones, and the office edge

Phones on the guest SSID should not reach the printer that talks to AD. Laptops should not use café DNS the moment they roam. MDM and always-on VPN exist because the office router is no longer the only border. Teach staff one trick: if the VPN light is on, the public IP’s origin ASN should be the company or the VPN vendor — check it on this site when something feels off.

Start with your corporate prefix on BGP Lookup, then validate it, then save a looking-glass path. That is the whole program’s first hour.

What “block that ASN” really does

One ASN can cover a national ISP, a CDN, and a cloud region that hosts your CRM. Look the ASN up, sample vendor IPs, then ping the vendors you must keep. Country blocks built from geo IP are worse: anycast and travelers both suffer. If regulation forces a control, put it where you can log exceptions.

FAQ

FAQ

We are all-in on one cloud. Do we still care about BGP?

Yes. Your users still reach the cloud over other people’s ASNs. Outages and hijacks happen on the path, not only in the VPC.

Should we drop RPKI-invalid on our edge?

Yes, after you inventory customer and partner prefixes. Invalid-drop without inventory is a self-inflicted outage.

Leave a Reply

Your email address will not be published. Required fields are marked *

BGPLOOKUP.IO ACCOUNT

Sign in or create an account

Continue with an account you already use.

Your provider password is never shared with bgplookup.io.