Hi all, A short follow-up to my post from earlier this month, since the feedback I got (here and elsewhere) directly shaped what changed:
- The checker now flags overly loose ROAs: maxLength beyond the actually announced length (the classic /24 covered "up to /32"). A forged more-specific with the right origin would be RPKI-VALID and win longest-prefix match; the tool lists the affected prefixes and points to RFC 9319 (maxLength = announced length). Flagged as a preventive note, no impact on the grade. - The continuous-monitoring version is now live in production: real-time RIS Live feed, email/Telegram alerts, with a permanently public status page (dead man's switch): https://sentinelle-backend-production.up.railway.app/status - A sample of the monthly routing-security report (NIS2/MANRS preparation angle) is online, generated on a fictional network (AS64496, documentation prefixes, nobody real gets graded publicly): https://sentinelle-routage.fr/rapport-exemple.pdf — in French for now, English version coming. Since June: ~500 analyses across 300+ distinct ASNs. Thanks to everyone who tested and criticized. Still keen on feedback, especially if the tool gets your AS wrong: https://sentinelle-routage.fr Abdelaziz Le jeu. 2 juil. 2026 à 21:54, N&R consulting <[email protected]> a écrit : > Hi all, > > French network engineer here (MPLS backbone operations). I built a small > free tool that gives any ASN a routing health check in about 30 seconds, in > the browser, no signup: > > https://sentinelle-routage.fr/en/ > > What it checks (data from RIPEstat, via a caching proxy): > - RIS visibility of your announced prefixes > - RPKI/ROA coverage and invalid originations > - BGP neighbors overview > - an overall grade, with a warning when low visibility may be legitimate > (anycast, regional networks) > > It started on the FRnOG list three weeks ago, where the feedback > (including a few sharp reviews) led to fixes: edge caching against RIPEstat > rate-limits, false-positive warnings, and an English version. About 200 > distinct ASNs have been checked so far. > > Known limitations, to be upfront: the RPKI check runs on a prefix sample, > and there is no IRR consistency check yet (needs a backend, planned). > > I'm now building the continuous monitoring version (hijack/leak/ROA alerts > by email/Telegram + a monthly routing compliance report aimed at > NIS2/MANRS) and looking for a handful of founding networks to shape it in > beta. If that's interesting, there's a form on the site, or just reply here. > > Feedback on the scoring logic is very welcome, especially edge cases where > the grade feels wrong. > > Thanks, > > Abdelaziz EL-BORGI >
_______________________________________________ NLNOG mailing list [email protected] https://mailman.nlnog.net/listinfo/nlnog
