<div dir="ltr">Hi all,<div><br></div><div>A short follow-up to my post from earlier this month, since the feedback I got (here and elsewhere) directly shaped what changed:</div><div><br></div><div>- The checker now flags overly loose ROAs: maxLength beyond the actually announced length (the classic /24 covered "up to /32"). A forged more-specific with the right origin would be RPKI-VALID and win longest-prefix match; the tool lists the affected prefixes and points to RFC 9319 (maxLength = announced length). Flagged as a preventive note, no impact on the grade.</div><div>- The continuous-monitoring version is now live in production: real-time RIS Live feed, email/Telegram alerts, with a permanently public status page (dead man's switch): <a href="https://sentinelle-backend-production.up.railway.app/status">https://sentinelle-backend-production.up.railway.app/status</a></div><div>- A sample of the monthly routing-security report (NIS2/MANRS preparation angle) is online, generated on a fictional network (AS64496, documentation prefixes, nobody real gets graded publicly): <a href="https://sentinelle-routage.fr/rapport-exemple.pdf">https://sentinelle-routage.fr/rapport-exemple.pdf</a> — in French for now, English version coming.</div><div><br></div><div>Since June: ~500 analyses across 300+ distinct ASNs. Thanks to everyone who tested and criticized.</div><div><br></div><div>Still keen on feedback, especially if the tool gets your AS wrong: <a href="https://sentinelle-routage.fr">https://sentinelle-routage.fr</a></div><div><br></div><div>Abdelaziz</div></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">Le jeu. 2 juil. 2026 à 21:54, N&R consulting <<a href="mailto:netrconsulting@gmail.com">netrconsulting@gmail.com</a>> a écrit :<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">Hi all,<br><br>French network engineer here (MPLS backbone operations). I built a small free tool that gives any ASN a routing health check in about 30 seconds, in the browser, no signup:<br><br><a href="https://sentinelle-routage.fr/en/" target="_blank">https://sentinelle-routage.fr/en/</a><br><br>What it checks (data from RIPEstat, via a caching proxy):<br>- RIS visibility of your announced prefixes<br>- RPKI/ROA coverage and invalid originations<br>- BGP neighbors overview<br>- an overall grade, with a warning when low visibility may be legitimate (anycast, regional networks)<br><br>It started on the FRnOG list three weeks ago, where the feedback (including a few sharp reviews) led to fixes: edge caching against RIPEstat rate-limits, false-positive warnings, and an English version. About 200 distinct ASNs have been checked so far.<br><br>Known limitations, to be upfront: the RPKI check runs on a prefix sample, and there is no IRR consistency check yet (needs a backend, planned).<br><br>I'm now building the continuous monitoring version (hijack/leak/ROA alerts by email/Telegram + a monthly routing compliance report aimed at NIS2/MANRS) and looking for a handful of founding networks to shape it in beta. If that's interesting, there's a form on the site, or just reply here.<br><br>Feedback on the scoring logic is very welcome, especially edge cases where the grade feels wrong.<br><br>Thanks,<br><br>Abdelaziz EL-BORGI</div>
</blockquote></div>