Cloudflare blames recent outage on BGP hijacking incident

Share:

Internet giant Cloudflare reports that its DNS resolver service, 1.1.1.1, was recently unreachable or degraded for some of its customers because of a combination of Border Gateway Protocol (BGP) hijacking and a route leak.

The incident occurred last week and affected 300 networks in 70 countries. Despite these numbers, the company says that the impact was “quite low” and in some countries users did not even notice it.

Incident details

Cloudflare says that at 18:51 UTC on June 27, Eletronet S.A. (AS267613) began announcing the 1.1.1.1/32 IP address to its peers and upstream providers.

This incorrect announcement was accepted by multiple networks, including a Tier 1 provider, which treated it as a Remote Triggered Blackhole (RTBH) route.

The hijack occurred because BGP routing favors the most specific route. AS267613’s announcement of 1.1.1.1/32 was more specific than Cloudflare’s 1.1.1.0/24, leading networks to incorrectly route traffic to AS267613.

Consequently, traffic intended for Cloudflare’s 1.1.1.1 DNS resolver was blackholed/rejected, and hence, the service became unavailable for some users.

One minute later, at 18:52 UTC, Nova Rede de Telecomunicações Ltda (AS262504) erroneously leaked 1.1.1.0/24 upstream to AS1031, which propagated it further, affecting global routing.

This leak altered the normal BGP routing paths, causing traffic destined for 1.1.1.1 to be misrouted, compounding the hijacking problem and causing additional reachability and latency problems.

Cloudflare identified the problems at around 20:00 UTC and resolved the hijack roughly two hours later. The route leak was resolved at 02:28 UTC.

Remediation effort

Cloudflare’s first line of response was to engage with the networks involved in the incident while also disabling peering sessions with all problematic networks to mitigate the impact and prevent further propagation of incorrect routes.

The company explains that the incorrect announcements didn’t affect internal network routing due to adopting the Resource Public Key Infrastructure (RPKI), which led to automatically rejecting the invalid routes.

Long-term solutions Cloudflare presented in its postmortem write-up include:

  • Enhance route leak detection systems by incorporating more data sources and integrating real-time data points.
  • Promote the adoption of Resource Public Key Infrastructure (RPKI) for Route Origin Validation (ROV).
  • Promote the adoption of the Mutually Agreed Norms for Routing Security (MANRS) principles, which include rejecting invalid prefix lengths and implementing robust filtering mechanisms.
  • Encourage networks to reject IPv4 prefixes longer than /24 in the Default-Free Zone (DFZ).
  • Advocate for deploying ASPA objects (currently drafted by the IETF), which are used to validate the AS path in BGP announcements.
  • Explore the potential of implementing RFC9234 and Discard Origin Authorization (DOA).

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:39 pm, Jan 19, 2025
weather icon 3°C
L: 2° | H: 4°
overcast clouds
Humidity: 83 %
Pressure: 1019 mb
Wind: 5 mph S
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:55 am
Sunset: 4:26 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
2° | 4°°C 0 mm 0% 3 mph 83 % 1019 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 4 mph 92 % 1019 mb 0 mm/h
Tue Jan 21 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 4 mph 95 % 1017 mb 0 mm/h
Wed Jan 22 9:00 pm
weather icon
4° | 5°°C 1 mm 100% 4 mph 98 % 1010 mb 0 mm/h
Thu Jan 23 9:00 pm
weather icon
3° | 6°°C 1 mm 100% 13 mph 92 % 1003 mb 0 mm/h
Today 6:00 pm
weather icon
3° | 4°°C 0 mm 0% 3 mph 83 % 1019 mb 0 mm/h
Today 9:00 pm
weather icon
3° | 4°°C 0 mm 0% 3 mph 78 % 1019 mb 0 mm/h
Tomorrow 12:00 am
weather icon
3° | 4°°C 0 mm 0% 2 mph 75 % 1019 mb 0 mm/h
Tomorrow 3:00 am
weather icon
4° | 4°°C 0 mm 0% 2 mph 74 % 1019 mb 0 mm/h
Tomorrow 6:00 am
weather icon
4° | 4°°C 0 mm 0% 2 mph 75 % 1019 mb 0 mm/h
Tomorrow 9:00 am
weather icon
5° | 5°°C 0 mm 0% 2 mph 76 % 1019 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
5° | 5°°C 0 mm 0% 4 mph 84 % 1019 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
7° | 7°°C 0 mm 0% 4 mph 79 % 1017 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€101,755.62
0.54%
Ethereum(ETH)
€3,319.24
3.99%
XRP(XRP)
€3.05
-1.34%
Tether(USDT)
€0.97
-0.03%
Solana(SOL)
€261.30
5.99%
Dogecoin(DOGE)
€0.379265
-0.67%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000021
-4.55%
Pepe(PEPE)
€0.000017
-5.78%
Peanut the Squirrel(PNUT)
€0.448559
-11.46%
Scroll to Top