BGP mistakes that looked like DDoS — how did you prove it was config drift?

Emerson Carter ⭐48 · Feb 28, 2026 20:44
We chased a traffic shift for hours before noticing a stale prefix advertisement from a secondary router. What forensic steps saved you the most time?
15 replies
Finley Tan ⭐191 · Feb 28, 2026 22:44
Collecting RIB snapshots on a schedule gave us a before picture — diffing against live state pinpointed the leak.
Quinn Carter ⭐143 · Mar 1, 2026 02:44
NetFlow alone misled us; combining it with BGP update logs from the peer edge finally correlated.
Quinn Walker ⭐171 · Mar 1, 2026 06:44
We now require maintenance windows to include explicit withdraw checks, not just 'ping looks fine'.
Drew Khan ⭐138 · Mar 1, 2026 10:44
Automated validation of IRR objects against what we actually announce caught a typo a human skimmed twice.
Hayden Le ⭐116 · Mar 1, 2026 14:44
Escalation playbook starts with 'who changed what in the last two hours' — boring but effective.
Parker Bennett ⭐153 · Mar 1, 2026 18:44
Some CDNs mask origin shifts — we tag synthetic probes with headers our routers log to separate provider noise.
Casey Pham ⭐38 · Mar 1, 2026 22:44
Training NOC staff to read AS paths cut mean-time-to-innocent for our upstream partners dramatically.
Quinn Tan ⭐20 · Mar 2, 2026 02:44
We learned the hard way that rollback scripts must include community strings, not just interface toggles.
Casey Hoang ⭐30 · Mar 2, 2026 06:44
Internal chatbots are cute; a single Grafana board with last-known-good metrics saved us more than any bot.
Reese Hoang ⭐68 · Mar 2, 2026 10:44
Peering coordinator now gets paged on unexpected path prepends — political and technical problem in one.
Parker Walker ⭐73 · Mar 2, 2026 14:44
Packet captures at two hops minimum — single-point capture lied about directionality once.
Emerson Nguyen ⭐112 · Mar 2, 2026 18:44
Documentation debt hurt us — no diagram meant the new hire guessed wrong during failover practice.
Jordan Nguyen ⭐34 · Mar 2, 2026 22:44
Vendor TAC was faster when we sent them concise timeline tables instead of hundred-meg PCAPs upfront.
Jordan Scott ⭐86 · Mar 3, 2026 02:44
We simulate fat-finger events quarterly in lab — cheaper than another 3 a.m. war room.
Cameron Walker ⭐187 · Mar 3, 2026 06:44
Honest postmortems without blame made people report near misses earlier — prevention beats heroics.

Join the conversation.

Log in to reply