BGPalerter - Real-time BGP and RPKI Monitoring

AWS Networking

self-hosted BGP and RPKI monitoring, secure by default, alerting on hijacks and route leaks in real time

Base
Hardened build
minimal ports, security patches applied at build time
Access
Unique credentials
generated on first boot, readable only by root
Verified
Boots working
services pass a health gate before release
Support
24/7, 365 days
by email and live chat, 24 hour response SLA

Overview

BGPalerter is a self-hosted, open source BGP and RPKI monitoring and alerting daemon from NTT. It connects to real-time BGP data and continuously watches your prefixes and autonomous systems for visibility loss, prefix hijacks, unexpected more specific announcements, RPKI invalid routes and ROA misconfiguration, so you learn about a routing incident affecting your network in minutes rather than hours. This image delivers it installed behind an nginx reverse proxy and running under systemd, so a monitoring appliance is operational within minutes of launch with no package installation or proxy configuration.

Why the cloudimg image

The cloudimg image never exposes the monitoring API unauthenticated: the daemon binds its REST status API to loopback behind nginx, an unauthenticated health endpoint is left open for load balancer probes, and every other path requires a unique status API password that is generated on each instance's first boot and never baked into the image. The appliance refreshes to the newest BGPalerter release on first boot, the OS ships fully patched, and every deployment is backed by a paired step-by-step guide and 24/7 cloudimg support.

Common uses

  • Detect prefix hijacks and unexpected more specific announcements of your networks in real time
  • Monitor prefix visibility and withdrawals and validate RPKI and ROA changes across your autonomous systems
  • Route alerts to a log file, email, Slack, syslog or webhooks so on-call teams learn about routing incidents in minutes

Key features

  • Self-hosted BGP and RPKI monitoring daemon preinstalled behind an nginx reverse proxy and running under systemd, detecting prefix hijacks, visibility loss, more-specific announcements and RPKI-invalid routes in real time within minutes of launch
  • Secure by default: the monitoring API is never exposed unauthenticated - it binds to loopback behind nginx, a unique status API password is generated on first boot and never baked into the image, and only an unauthenticated health endpoint is left open for load balancer probes
  • Refreshes to the newest BGPalerter release on first boot, ships a ready to edit prefixes and ASN watch list with flexible alerting to log file, email, Slack, syslog and webhooks, a fully patched OS and 24/7 cloudimg support

Description

This is a repackaged open source software product wherein additional charges apply for cloudimg support services.

BGPalerter is a self-hosted, open source BGP and RPKI monitoring and alerting daemon from NTT. It connects to real-time BGP data and continuously watches your prefixes and autonomous systems for visibility loss, prefix hijacks, unexpected more-specific announcements, RPKI-invalid routes and ROA misconfiguration, so you learn about a routing incident affecting your network in minutes rather than hours. This image delivers it fully installed and reverse proxied behind nginx and managed by systemd, so a production ready monitoring appliance is operational within minutes of launch, with no manual package installation, no dependency troubleshooting and no proxy configuration required.

Unlike a bare deployment, this image never exposes the monitoring API unauthenticated. The daemon binds its REST status API to loopback and it is served through an nginx reverse proxy that is ready for your TLS certificate: an unauthenticated health endpoint is available for load balancer probes, while the status API and all other paths require a password. There are no shared or default credentials: a unique status API password is generated on each instance's first boot and written to a root only file, so the API requires your password from the very first request. On first boot the appliance also refreshes itself to the newest BGPalerter release, so every launch runs current software, and systemd manages the daemon for automatic restarts and clean logging. The operating system ships fully patched with unattended security updates enabled.

Monitoring capabilities include real-time hijack detection, prefix visibility and withdrawal monitoring, RPKI validation and ROA change tracking, path and neighbour analysis, and flexible alerting to a rotating log file, email, Slack, syslog, HTTP webhooks, Kafka and more, all configured through simple YAML files. Point it at your own prefixes and autonomous systems and BGPalerter does the rest. The security group opens only SSH and the nginx health and status port. The current release available is BGPalerter 2.0.1.

This is a repackaged open source software product with additional charges for cloudimg support services. BGPalerter is distributed under the BSD 3-Clause permissive license. cloudimg is not affiliated with or endorsed by NTT or the BGPalerter project. All product and company names are trademarks or registered trademarks of their respective holders. Use of them does not imply any affiliation with or endorsement by them.

Related technologies

bgpalerterbgpbgp monitoringrpkiroute hijacknetwork monitoringrouting securityprefix monitoringnetworkingcloudimg