at around 12:00 am on 4th December 2024, our monitoring system alerted us to over 60 BGP sessions keep going up and down (Flapping)
Our on-call network engineer Phil was then alerted and found that the BGP Daemon keep crashing and that is what caused the BGP sessions to keep flapping.
A remote reboot of Sov Router did not resolve the issue and after investigating further, we found this to be likely a remote BGP DDOS Attack, which took advantage of a vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS (Router)
Juniper released a fix for this which Phil attended both Data Centres to apply the software update. This could not be done remotely due to the BGP Daemon not being stable and a fear of software updating failing. So had to be done via a USB Drive to load on the software.
Phil arrived at the first Data Centre at 1:53am of 4th December 2024 and attempted to load the new firmware. Following the update a few manual reboots was needed for the new software to fully apply.
At 3:50am of 4th December 2024, the first Router then become stable again following the completed software upgrade.
At 3:58 of 4th December 2024, we noticed the other router had also been stable for around 3 hours.
Phil thought it best to also upgrade the software on the second router of which started at 4:32am of 4th December 2024.
At 4:57am of 4th December 2024, the software had been fully upgraded and router rebooted and all the remaining BGP Sessions came up and no further alerts showing on our monitoring.
Both upgrades fixed the vulnerability in the Juniper routing protocol daemon (RPD) and our network returned back to being stable.
whilst it took from around 12:00am to 4:57am to fully resolve all the issues, the whole network would not have been completely down for this amount of time.
Affected Services
Hosted 3CX at Volta - around 3 Hours and 50 minutes
Hosted 3CX at Sov House, few small outages but largely remained up and in service.
SIP Trunks, Some customers would have been offline, depending on where the Customer 3CX was hosted,
Internal network remained stable and fully functional during the Router issues,