Hi all, A short follow-up to my post from earlier this month, since the feedback I got (here and elsewhere) directly shaped what changed: - The checker now flags overly loose ROAs: maxLength beyond the actually announced length (the classic /24 covered "up to /32"). A forged more-specific with the right origin would be RPKI-VALID and win longest-prefix match; the tool lists the affected prefixes and points to RFC 9319 (maxLength = announced length). Flagged as a preventive note, no impact on the grade. - The continuous-monitoring version is now live in production: real-time RIS Live feed, email/Telegram alerts, with a permanently public status page (dead man's switch): https://sentinelle-backend-production.up.railway.app/status - A sample of the monthly routing-security report (NIS2/MANRS preparation angle) is online, generated on a fictional network (AS64496, documentation prefixes, nobody real gets graded publicly): https://sentinelle-routage.fr/rapport-exemple.pdf — in French for now, English version coming. Since June: ~500 analyses across 300+ distinct ASNs. Thanks to everyone who tested and criticized. Still keen on feedback, especially if the tool gets your AS wrong: https://sentinelle-routage.fr Abdelaziz Le jeu. 2 juil. 2026 à 21:54, N&R consulting <netrconsulting@gmail.com> a écrit :
Hi all,
French network engineer here (MPLS backbone operations). I built a small free tool that gives any ASN a routing health check in about 30 seconds, in the browser, no signup:
https://sentinelle-routage.fr/en/
What it checks (data from RIPEstat, via a caching proxy): - RIS visibility of your announced prefixes - RPKI/ROA coverage and invalid originations - BGP neighbors overview - an overall grade, with a warning when low visibility may be legitimate (anycast, regional networks)
It started on the FRnOG list three weeks ago, where the feedback (including a few sharp reviews) led to fixes: edge caching against RIPEstat rate-limits, false-positive warnings, and an English version. About 200 distinct ASNs have been checked so far.
Known limitations, to be upfront: the RPKI check runs on a prefix sample, and there is no IRR consistency check yet (needs a backend, planned).
I'm now building the continuous monitoring version (hijack/leak/ROA alerts by email/Telegram + a monthly routing compliance report aimed at NIS2/MANRS) and looking for a handful of founding networks to shape it in beta. If that's interesting, there's a form on the site, or just reply here.
Feedback on the scoring logic is very welcome, especially edge cases where the grade feels wrong.
Thanks,
Abdelaziz EL-BORGI