Live BGP ASN Prefix, RPKI ROA & ISP Peering Looking Glass (2026)

Query live Border Gateway Protocol (BGP) announcements, Autonomous System Numbers (ASNs), RPKI Route Origin Authorizations (ROA), and upstream ISP transit paths via RIPEstat and Cloudflare Radar telemetry.

Live BGP ASN Prefix, RPKI ROA & ISP Peering Inspector — Interactive Console
Runs locally in your browser • Instant output
Loaded verified ASN BGP profile (Click Query Live RIPE Stat BGP API for real-time RIB dump).
Autonomous System Holder
CLOUDFLARENET - Cloudflare, Inc. (US)
Upstream: AS174 (Cogent)Upstream: AS1299 (Arelion)Upstream: AS3356 (Lumen)Upstream: AS2914 (NTT)
RPKI ROA Hijack Simulator
ROA VALID: MaxLength /24 matched
Announced IPv4 Prefixes (5)
1.1.1.0/24104.16.0.0/13162.158.0.0/15172.64.0.0/13188.114.96.0/20
Announced IPv6 Prefixes (3)
2606:4700::/322803:f800::/322a06:98c0::/29
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![Live BGP ASN Prefix, RPKI ROA & ISP Peering Inspector](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/live-bgp-asn-peering-looking-glass/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/live-bgp-asn-peering-looking-glass/">Live BGP ASN Prefix, RPKI ROA & ISP Peering Inspector — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: Live BGP ASN Prefix, RPKI ROA & ISP Peering Inspector

Quick Answer & 2026 Technical Summary (bgp asn looking glass rpki checker)Updated 2026 Standard

BGP routers always prefer the most specific prefix (Longest Prefix Match). If a legitimate organization announces 198.51.100.0/23 and an attacker announces the more-specific 198.51.100.0/24 from a rogue ASN, global routers without RPKI validation will divert traffic for that /24 subnet to the attacker. Use this interactive bgp asn looking glass rpki checker above to test bgp prefix hijack detector, rpki roa validation checker online, and asn upstream peering lookup locally in your browser with zero server uploads.

Target Keyword Spec: bgp asn looking glass rpki checker | Modules: Live RIPEstat BGP Prefix & Origin ASN Telemetry • Cryptographic RPKI ROA Validation Inspector • AS-Path Upstream Transit & Peer Topology Graph
Primary Focus: bgp asn looking glass rpki checker
Core Capability: bgp prefix hijack detector
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
Live RIPEstat BGP Prefix & Origin ASN Telemetrybgp prefix hijack detectorFetch real-time global routing table state for any IPv4/IPv6 address, CIDR ...Network Security & BGP Hijack Incident Response
Cryptographic RPKI ROA Validation Inspectorrpki roa validation checker onlineVerify whether an announced IP prefix and origin ASN pair is cryptographica...RPKI Route Origin Authorization (ROA) Deployment Auditing
AS-Path Upstream Transit & Peer Topology Graphasn upstream peering lookupVisualize Tier-1 transit providers, IXP peering relationships, AS-PATH prep...Threat Intelligence & Bulletproof Hosting ASN Profiling
Execution & Privacy Architecture100% Client-Side WebCrypto / JS Sandbox0 Bytes Sent to External ServersSafe for internal SOC & authorized lab artifacts
NIST SP 800-53 / OWASP AlignmentOWASP ASVS v4.0.3 / NIST CSF 2.0Deterministic Rule & Header VerificationMaps findings to actionable hardening controls
Cryptographic & Entropy StandardSHA-256 / AES-256-GCM / Argon2id≥ 128-bit Effective Security MarginMeets 2026 post-quantum & zero-trust baselines
In-Depth ZerosUniverse Tutorial

What is IP Spoofing, BGP Hijacking & RPKI Defense?

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use Live BGP ASN Prefix, RPKI ROA & ISP Peering Inspector

01

Enter an IP Address, CIDR Prefix, or ASN

Type any public IPv4/IPv6 address (e.g., 1.1.1.1), CIDR block (1.1.1.0/24), or ASN (AS13335), or click a quick-load Tier-1/Cloudflare/Google preset.

02

Query Live RIPEstat Routing & RPKI Collectors

Run the live query to retrieve announced prefixes, origin ASN holder metadata, geographical registry allocation, and RPKI ROA status.

03

Analyze AS-Path Peers & ROA MaxLength Compliance

Inspect the upstream/downstream ASN neighbor table and confirm that the announced prefix length does not exceed the RPKI ROA MaxLength ceiling.

04

Test Sub-Prefix Hijack Scenarios in the Simulator

Toggle the BGP Hijack Simulator to model longest-prefix-match (LPM) route capture and generate Cisco IOS-XR / FRRouting RPKI ROV config snippets.

Key Capabilities & Technical Architecture

Live RIPEstat BGP Prefix & Origin ASN Telemetry

Fetch real-time global routing table state for any IPv4/IPv6 address, CIDR block, or Autonomous System Number (e.g., AS13335, AS15169, AS16509) directly from RIPE RIS collectors.

Cryptographic RPKI ROA Validation Inspector

Verify whether an announced IP prefix and origin ASN pair is cryptographically Valid, Invalid (ASN mismatch or prefix length violation), or NotFound under global RPKI trust anchors.

AS-Path Upstream Transit & Peer Topology Graph

Visualize Tier-1 transit providers, IXP peering relationships, AS-PATH prepending depth, and origin AS consistency across multi-homed global route collectors.

Sub-Prefix Hijack & BGP Route Leak Simulator

Simulate how a rogue AS announcing a more-specific /24 sub-prefix hijacks traffic from an unguarded /16 supernet—and how RPKI MaxLength + MANRS filters block the hijack.

Practical Use Cases

Network Security & BGP Hijack Incident Response

Verify whether enterprise IP blocks are being legitimately originated by your authorized ASN or hijacked via unauthorized sub-prefix announcements.

RPKI Route Origin Authorization (ROA) Deployment Auditing

Check MaxLength parameters and ROA validity across ARIN, RIPE, APNIC, LACNIC, and AFRINIC RPKI repositories before enforcing ROV drop policies on border routers.

Threat Intelligence & Bulletproof Hosting ASN Profiling

Map the upstream transit providers and neighbor ASNs of suspicious infrastructure during DDoS mitigation, C2 tracking, or IP spoofing investigations.

Frequently Asked Questions (FAQs)

How does a BGP sub-prefix hijack work?+

BGP routers always prefer the most specific prefix (Longest Prefix Match). If a legitimate organization announces 198.51.100.0/23 and an attacker announces the more-specific 198.51.100.0/24 from a rogue ASN, global routers without RPKI validation will divert traffic for that /24 subnet to the attacker.

What is RPKI (Resource Public Key Infrastructure) and ROA?+

RPKI is a cryptographic framework operated by the five Regional Internet Registries (RIRs). A Route Origin Authorization (ROA) is an X.509-signed object stating which Autonomous System Number (ASN) is authorized to originate a specific IP prefix and the maximum sub-prefix length (MaxLength) allowed.

Why is setting a loose MaxLength in an RPKI ROA dangerous?+

If you only announce a /16 in BGP but configure your ROA with MaxLength /24, an attacker who spoofs your Origin ASN in the AS_PATH can announce a forged /24 sub-prefix that passes RPKI Origin Validation (ROV). Best practice is to set MaxLength equal to the exact prefix length you actively announce, or deploy ASPA/BGPsec.

What is the relationship between IP spoofing and BCP 38 / MANRS?+

IP spoofing occurs when an autonomous system allows packets with forged source IP addresses to exit its network (enabling DNS/NTP amplification DDoS attacks). BCP 38 (RFC 2827) and MANRS require ISPs to enforce Unicast Reverse Path Forwarding (uRPF) and ingress prefix filtering so customers can only send packets from their assigned prefixes.

Where does this Looking Glass fetch live BGP data from?+

Your browser queries the public RIPE NCC RIPEstat Data API (stat.ripe.net) directly over HTTPS, aggregating live routing tables from global RIS route collectors.