Login
Login

Extra alert information for the "Prefix Hijack" alert


This alert is triggered when a prefix in your monitored prefix lists (that can be found in your monitoring settings) is seen to be originated by an ASN that the monitor is for (or is it not in your account)

For this alert type to remain reliable you must keep your prefix list up-to-date.

The following situations will suppress an alert from being generated if true:

  • The prefix has a valid RPKI ROA entry for the ASN that is now originating
  • The prefix has an authenticated IRR (typically made inside the your RIRs portal) route/route6 entry for the ASN that is now originating

A Authenticated IRR means RIPE/ARIN/APNIC/LACNIC/AFRINIC, as their IRR databases do not allow you to insert entries for IP prefixes that you do not have administrative control over.


← All knowledge base articles