wikiroute

networking recipes

User Tools

Site Tools


who_is_using_this_ip_address

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revisionBoth sides next revision
who_is_using_this_ip_address [2014/01/11 15:24] samerwho_is_using_this_ip_address [2014/01/11 15:26] samer
Line 17: Line 17:
 [{{ :bgp-table.png?direct&600 | Figure 1. Active BGP entries}}] [{{ :bgp-table.png?direct&600 | Figure 1. Active BGP entries}}]
  
-However, having access to a DFZ BGP router is not easy in practice. Alternatively, it is possible to find similar routing information on looking glasses or route servers that are made public by network operators (see for example a list of servers on [[routeserver.org]]. Such devices are originally deployed in order to contribute to the monitoring or the tracking of BGP anomalies in the Internet. +However, having access to a DFZ BGP router is not easy in practice. Alternatively, it is possible to find similar routing information on looking glasses or route servers that are made public by network operators (see for example a list of servers on www.routeserver.org. Such devices are originally deployed in order to contribute to the monitoring or the tracking of BGP anomalies in the Internet. 
-Let us try for example to log on the Allstream route server in Canada and identify the origin AS of 148.60.0.0/16. The output of the ''show ip bgp command'' shows the AS path "15290 3356 1273 2200" in the BGP announcements. Therefore, the first AS, *i.e.*, 2200 is the origin AS of the studied prefix.+Let us try for example to log on the Allstream route server in Canada and identify the origin AS of 148.60.0.0/16. The output of the ''show ip bgp command'' shows the AS path "15290 3356 1273 2200" in the BGP announcements. Therefore, the first AS, //i.e.//, 2200 is the origin AS of the studied prefix.
  
  $ telnet route-server.east.bb.allstream.net   $ telnet route-server.east.bb.allstream.net 
Line 42: Line 42:
        Community: 15290:3356 15290:64995 15290:65050 15290:65506        Community: 15290:3356 15290:64995 15290:65050 15290:65506
  
-Despite its availabitlity, this method remains cumbersome, especially if you want to quickly look up something or if you have a large number of addresses that you want to analyze with a script. Fortunatly, RIPE NCC and Team Cymru have already answered these questions: they provide solutions that combine the versatility of the whois protocol with the accuracy of the BGP information. In other words, you keep on using the legacy whois command by you get BGP-based results. Let us examine these solutions: +Despite its availability, this method remains cumbersome, especially if you want to quickly look up something or if you have a large number of addresses that you want to analyze with a script. Fortunately, RIPE NCC and Team Cymru have already answered these questions: they provide solutions that combine the versatility of the whois protocol with the accuracy of the BGP information. In other words, you keep on using the legacy whois command by you get BGP-based results. Let us examine these solutions: 
  
 1- Team Cymru implements the `whois.cymru.com` server  1- Team Cymru implements the `whois.cymru.com` server 
who_is_using_this_ip_address.txt · Last modified: 2014/02/15 23:31 by samer