Skip to content
bgplookup.io

July 29, 2026

When the origin ASN changes overnight

origin ASN

The alert is one line: origin for 203.0.113.0/24 moved from AS64500 to AS64511. No traceroute poetry. No customer yet. Just a new origin ASN. This is either boring or a fire. The first ten minutes decide which.

Do not start with a theory

I do not start with “we are being hijacked.” I start with “is this real in more than one view?” Three collectors. If only one RIS peer shows the new origin, I wait and I watch. Collectors lie, sessions reset, someone dumps a stale RIB. If three continents show AS64511, I proceed as if the world moved.

Then I ask whether we moved it. Check the change calendar, the last git commit to the route-maps, the ticket queue. I have paged people for a hijack that was a scheduled ASN migration someone put in a Slack thread I muted. That is a me problem. It is also a process problem. Write the migrations down where the on-call actually looks.

The five lookups

  1. BGP lookup on the prefix and its parent. Is the whole aggregate gone, or a child?
  2. RPKI for old origin and new origin. If the new origin is invalid, I am already writing the incident doc.
  3. IRR for a route object pointing at the new ASN. Fresh object + new origin is either planned or prepared.
  4. ASN explorer on AS64511. Age, prefixes, upstreams, PeeringDB. A year-old transit with a real NOC is a different call than an ASN created last month with a Gmail in WHOIS.
  5. WHOIS on the prefix. Did the holder change? A transfer looks like an origin change if you only watch BGP.

Migrations have manners

A clean migration dual-originates for a while, or it moves after a ROA for the new ASN exists. You will see both origins in the glass, then the old one fades. The new ASN will have a PeeringDB page that is not empty. Someone will have emailed the peering list.

A leak has manners too, just worse ones. The new origin is often a customer of the old transit, the path is short, and the ROA is invalid or unknown. A phone call to the transit fixes more leaks than any blog post.

A hijack is rude. More-specific, short path, invalid ROA, empty PeeringDB, and a looking glass that disagrees with itself by region. You already read that article. Go do the drill.

Write the before/after down

Whatever it is, paste the old path and the new path into the ticket with timestamps. Future you will not remember which collector you trusted. Future legal will not accept “I think it flipped on Tuesday.” The glass is free. Screenshots are cheap. Origin changes are how prefixes get lost in the filing cabinet of a tired NOC.

A new origin ASN is a fact. The story is optional. Collect the fact from more than one pair of eyes, then pick the story that still stands.

Leave a Reply

Your email address will not be published. Required fields are marked *

BGPLOOKUP.IO ACCOUNT

Sign in or create an account

Continue with an account you already use.

Your provider password is never shared with bgplookup.io.