Q: A major ISP accidentally misconfigures a BGP route, announcing to the world that they are the optimal path to reach Google's IP addresses. Suddenly, millions of users' traffic meant for Google is blackholed or severely degraded. What is this phenomenon called?
This is called a BGP Route Leak (or BGP Hijacking, if malicious).
🛠️ Production Runbook & Step-by-Step Resolution
Production Solution & Architecture
This is called a BGP Route Leak (or BGP Hijacking, if malicious). Because the Border Gateway Protocol (BGP) was designed in an era of mutual trust, when the ISP incorrectly advertises a more specific prefix or a shorter path to Google's IPs, neighboring global routers dynamically update their tables and redirect traffic toward that ISP. If the ISP isn't actually Google, the traffic hits their edge and is dropped (blackholed), or it artificially bottlenecks their infrastructure causing massive outages. Modern networks mitigate this using RPKI (cryptographic route validation) and strict route filtering, refusing to accept Google announcements from untrusted Tier-3 ISPs.
- Immediate Triage: This is called a BGP Route Leak (or BGP Hijacking, if malicious).
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.