K root route leak by AS49505 – Selectel, Russia

There seems be an ongoing route leak by AS49505 (Selectel, Russia) for K root server.
K root server’s IP:
Origin Network: AS25152
Here’s trace from Airtel Looking Glass, Delhi PoP

Mon Oct 26 16:21:18 GMT+05:30 2015
Mon Oct 26 16:21:22.053 IST
Type escape sequence to abort.
Tracing the route to
 1   * 19 msec  4 msec
 2 14 msec  3 msec  1 msec
 3 ( 7 msec  3 msec  2 msec
 4 26 msec  45 msec  26 msec
 5 ( 151 msec  153 msec  152 msec
 6 ( [MPLS: Label 383489 Exp 0] 160 msec  163 msec  155 msec
 7 ( [MPLS: Label 595426 Exp 0] 161 msec  162 msec  162 msec
 8 ( [MPLS: Label 399436 Exp 0] 149 msec  151 msec  155 msec
 9 ( 164 msec  163 msec  159 msec
 10 153 msec  151 msec  160 msec
 11 ( 190 msec  192 msec  189 msec
 12 ( 185 msec  185 msec  185 msec
 13 ( 183 msec  204 msec  196 msec

The routing information (show route output) from their looking glass doesn’t seems useful since it shows that it’s learning K root Noida route via NIXI. This is likely because routing information is different from actual forwarding information in that device.
So the trace looks extremely weird. It’s leading traffic to K root which does has anycast instance in Noida, landing into Russia!
Why is that happening?
Let’s look at what Tata Communications (AS6453) routing table has for K root’s prefix. I am looking at feed of AS6453 which it’s putting into RIPE RIS RRC 03 collector.

anurag@server7:~/temp$ awk -F ‘|’ ‘$5==6453’ rrc03-table-26-Oct-2015.txt|grep
TABLE_DUMP_V2|10/26/15 08:00:03|A||6453||6453 20485 49505 25152|IGP

Let’s analyse this AS_PATH

  1. AS25152 is orignating prefix to AS49505 (Selectel Russia)
  2. AS49505 is “leaking” route to it’s upstream AS20485 (Trans Telecom, Russia)
  3. AS20485 is further propagating route to Tata Communications AS6453 making route visible globally via Tata Communications IP backbone

What impact of it?
Impact is much higher latency with K root from India. Here’s how RIPE Probe 170111 hosted at my home finds latency to K root:
As per graph change, leak started on 24th Oct at 9am UTC and this resulted in jump of latency of over 180ms.
    1. Dear RS – thanks for the article and pointing their blog post out.
      I have checked it in detail and seems like they host what RIPE refers to as “remote site” and by design these sites should limit the BGP announcement. They should limit announcements to their clients only.
      Quoting from RIPE’s FAQ on hosted nodes:
      “The K-root server will advertise the K-root anycast prefixes from AS25152 to your router. Your router needs to propagate the K-root prefixes to your clients”
      I hope this clarifies what’s wrong.

