RONOG 11: We Replayed a Real BGP Route Leak, Then Stopped It in 11 Seconds
Four of us made the trip to RONOG – Romanian Network Operators Group 11 yesterday : Andrian Visnevschi, Nicolae Musteata, Struta Serghei and Ion Siretanu.
Andrian‘s talk had a blunt title: “The tooling exists, the filters don’t.” He took a real BGP route leak from a few years ago and replayed it in a lab with real ASNs, live RPKI, IRR and PeeringDB data. With no filters, the leak spread exactly as it did back then. With open-source tooling in place (bgpq4, Routinator, Peering Manager), the router was filtering it 11 seconds after the config push. The slowest part of the whole exercise was writing two templates, about an hour of work.
The point that sparked the most discussion afterwards was that no single layer catches everything. ROV misses leaks of valid routes. ASPA misses plain origin hijacks. IRR only works where you can build a list. You need all of them working together.
So if you run BGP at the edge, which one is still sitting on your team’s “next quarter” list: ROV, IRR prefix lists, max-prefix or ASPA? And what keeps it there?
Andrian wrote up the full story, including the lab mistake he put on his own slide and his checklist for operators. It’s linked in the comments.
Thanks to the RONOG – Romanian Network Operators Group team for another edition full of genuinely good technical content, and to everyone who stopped to talk shop with us between sessions. Events like this are where the useful conversations happen. See you at the next one.








