-
Notifications
You must be signed in to change notification settings - Fork 5
Examples
Herve Hildenbrand edited this page Jan 20, 2026
·
1 revision
This page shows common queries and their expected output patterns.
> Who originates 8.8.8.0/24?
Expected output:
**Prefix: 8.8.8.0/24**
**Origin ASN(s):** AS15169
**Visible from:** 23 collectors (rrc00, rrc01, rrc03, rrc04, rrc05...)
**Unique AS paths:** 47
**Sample paths:**
1. AS15169
2. AS6939 → AS15169
3. AS3356 → AS15169
> What prefixes does AS15169 announce?
Expected output:
**AS15169 Announcements**
**Total prefixes:** 1,234
- IPv4: 456
- IPv6: 778
**IPv4 prefixes (sample):**
- 8.8.8.0/24
- 8.8.4.0/24
- 8.34.208.0/21
... and 453 more
> Give me details about AS13335
Expected output:
**AS13335 Details**
**Announcements:**
- Total prefixes: 2,847
- IPv4: 1,523
- IPv6: 1,324
**Upstream Providers:** 12
AS174, AS2914, AS3356, AS6939...
**Downstream Customers:** 156
AS209242, AS211298, AS212238...
**Routing Behavior:**
- Appearances in paths: 15,847
- As origin: 12,456
- As mid-path transit: 3,391
> Analyze the AS paths to 1.1.1.0/24
Expected output:
**AS Path Analysis: 1.1.1.0/24**
**Path Diversity Metrics:**
- Unique paths: 89
- Unique origins: 1
- Collectors: 23
- Min path length: 1
- Max path length: 6
- Avg path length: 2.45
**Upstream ASNs (direct peers of origin):** 47
AS174, AS2914, AS3356, AS6453, AS6939...
**Transit ASNs (middle of paths):** 23
AS1299, AS3257, AS5511, AS6762...
**Path Prepending Detected:** 3 routes
- AS13335 prepended 2x in path via rrc00
> Compare how different collectors see 8.8.8.0/24
Expected output:
**Collector Comparison: 8.8.8.0/24**
**Total collectors:** 23
**Unique paths:** 47
**Unique origins:** 1
**Consistent origin:** Yes
**View by Collector:**
**rrc00:** AS6939 → AS15169 (len=2)
**rrc01:** AS3356 → AS15169 (len=2)
**rrc03:** AS15169 (len=1)
...
> Check RPKI status for 1.1.1.0/24 from AS13335
Expected output:
**RPKI Validation**
**Prefix:** 1.1.1.0/24
**Origin:** AS13335
**Status:** ✅ VALID
The route announcement is covered by a valid ROA and matches the expected origin.
> Check if 203.0.113.0/24 is being hijacked
Expected output:
**Prefix Anomaly Check: 203.0.113.0/24**
**Risk Level:** 🟢 LOW
**Single Origin:** AS64496
**RPKI Validation:**
- AS64496: ✅ VALID
**Visibility:** 21 collectors
**Origin History:** Stable (no changes in last 7 days)
**No risk factors detected.** Prefix appears to be routing normally.
**Prefix Anomaly Check: 192.0.2.0/24**
**Risk Level:** 🔴 HIGH
**⚠️ MOAS Detected (Multiple Origin AS)**
Origins: AS64496, AS65001
**RPKI Validation:**
- AS64496: ✅ VALID
- AS65001: ❌ INVALID
**Visibility:** 18 collectors
**⚠️ Recent Origin Changes (last 7 days):**
- New: AS65001
**Risk Factors:**
- MOAS: Multiple origins (2 ASes)
- RPKI Invalid: AS65001 not authorized
- New origin(s) in last 7 days: AS65001
> Show routing history for 8.8.8.0/24 from 2024-01-01 to 2024-01-31
Expected output:
**Routing History: 8.8.8.0/24**
**Period:** 2024-01-01 to 2024-01-31
**Origins observed:** 1
**AS15169:**
- 8.8.8.0/24: 1 timeline(s)
> What are the upstream providers for AS64496?
Expected output:
**AS64496 Upstream Providers**
**Total upstreams:** 3
- AS174 (Cogent): 95.2% visibility
- AS3356 (Lumen): 89.7% visibility
- AS6939 (Hurricane Electric): 78.3% visibility
> Show me all peers of Cloudflare
Expected output (after search_asn resolves Cloudflare to AS13335):
**AS13335 Peers**
**Total peers:** 847
**Top peers (by visibility):**
- AS6939 (Hurricane Electric): 98.5% visibility
- AS3356 (Lumen): 97.2% visibility
- AS174 (Cogent): 96.8% visibility
...
> Who do I contact about AS15169?
Expected output:
**AS15169 Contact Information**
**Network:** Google LLC
**Contacts (4):**
**NOC:**
- Email: noc@google.com
- Phone: +1-650-253-0000
**Abuse:**
- Email: network-abuse@google.com
**Website:** https://peering.google.com
> Ping 8.8.8.8 from multiple locations worldwide
Expected output:
**Global Ping Results: 8.8.8.8**
**Measurement ID:** abc123-def456
**Probes:** 10
**Latency Summary:**
- Min: 1.23 ms
- Max: 156.78 ms
- Avg: 45.67 ms
**Results by Location:**
- San Francisco, US: 12.34ms
- New York, US: 18.56ms
- London, GB: 8.92ms
- Frankfurt, DE: 6.45ms
- Tokyo, JP: 45.67ms
...
> Run a traceroute to cloudflare.com from Europe
Expected output:
**Global Traceroute Results: cloudflare.com**
**Measurement ID:** xyz789
**Probes:** 5
**From London, GB:**
1. 192.168.1.1 (0.45ms)
2. 10.0.0.1 (2.34ms)
3. ae-1.r00.londen01.uk.bb.gin.ntt.net (5.67ms)
4. 104.16.132.229 (8.12ms)
**From Frankfurt, DE:**
1. 192.168.1.1 (0.52ms)
2. 10.0.0.1 (1.89ms)
3. de-cix.cloudflare.com (4.23ms)
4. 104.16.132.229 (5.67ms)
> Our customers can't reach our prefix 203.0.113.0/24
Claude will automatically:
- Look up the prefix to check visibility
- Check RPKI validation
- Analyze AS paths for anomalies
- Compare collector views
- Check for recent origin changes
- Provide actionable diagnosis
> Should we peer with AS64496?
Claude will:
- Get ASN details and announcements
- Check IXP presence for co-location opportunities
- Analyze connectivity (upstreams, peers, downstreams)
- Look up network contacts
- Provide a summary with peering considerations
- Tools Reference - Full list of available tools
- Real-time Monitoring - Set up anomaly detection
- Troubleshooting - Common issues and solutions