Summary

  • Historical coverage associated AS210837 with 22 IPv4 prefixes and 29 IPv6 prefixes in July 2022, while a later source-specific lookup reported no prefixes. That difference is a signal, not a finding of withdrawal or closure.
  • The current continuity state remains unresolved because the research run did not retrieve live payloads from the identified registry, measurement and BGP aggregation endpoints.

ROYA Communications and Internet Services Company Ltd’s AS210837 sits at the intersection of three different systems that are often treated as one. A number-resource registry records administrative identity. A routing measurement system records what participating collectors observe. A network directory can describe a self-reported operating surface. None of those layers, alone, proves that an autonomous system is currently originating routes.

That distinction matters because the public record contains a genuine visibility gap. Historical coverage associated AS210837 with 22 IPv4 prefixes and 29 IPv6 prefixes in July 2022. Later coverage reported no prefixes in a source-specific lookup. The first observation describes a historical operating surface; the second describes an observation from another point in time and through another retrieval context. It does not, by itself, establish withdrawal, cessation, reassignment, migration or a technical outage.

The central question for operators and infrastructure readers is therefore narrower and more useful: what mechanism could produce the gap, and what evidence would be needed to distinguish the competing explanations?

Registry identity is not route continuity

The RIPE Database search record is evidence that AS210837 has a registry entry. It is not evidence that the ASN is currently announcing routes, that its prefixes remain reachable, or that ROYA continues to operate the same network surface. The registry snapshot supports that boundary directly: registry presence does not establish current announcements, prefix reachability, withdrawal, cessation, reassignment or continued operation (RIPE Database search for AS210837).

This is not a defect in the registry. Registration and routing are different institutional functions. A registry maintains number-resource and Internet-number records. Routing measurements observe announcements and paths through a collector system. An operator may retain an administrative record while changing upstreams, ceasing announcements, transferring operational responsibility or allowing resources to become inactive. Conversely, a route can be visible through a measurement system while other administrative records are incomplete, delayed or maintained by a different party.

For continuity analysis, the registry is therefore the identity layer. It helps identify the object under investigation and provides the starting point for interpreting later measurements. It cannot substitute for those measurements.

The historical footprint is informative but bounded

The historical observation of 22 IPv4 prefixes and 29 IPv6 prefixes in July 2022 is material because it establishes that AS210837 was associated with a non-trivial public routing footprint at that time. It also gives the investigation a baseline: a later absence or reduction should be compared with a known earlier state rather than treated as an unexplained blank.

But the historical count is not a continuous telemetry stream. It does not reveal whether all prefixes were originated by ROYA itself, whether some were announced through a provider, whether the set changed seasonally, or whether the count reflected a particular collector’s view. It also does not establish what happened after July 2022. The appropriate conclusion is limited: a historical operating surface was documented, and the later continuity question remains open.

A route-history series would be more informative than two isolated counts. It could show the first and last observed announcements, periods of intermittent visibility, changes in origin, and whether IPv4 and IPv6 followed the same pattern. Without that time series, a before-and-after comparison risks turning a measurement gap into an operational narrative.

What RIPEstat could establish

The identified RIPEstat endpoints are relevant because they address different parts of the continuity problem. The AS overview, routing-status, announced-prefixes, BGP-state, first/last-seen and routing-history endpoints are designed to support time-bounded observations of routing visibility. The research run identified those endpoints, but did not retrieve their live payloads. That limitation is recorded in the fact package and means the run cannot state current prefix values, route counts or observation timestamps (RIPEstat AS overview; RIPEstat routing status; RIPEstat announced prefixes; RIPEstat BGP state; RIPEstat first/last seen; RIPEstat routing history).

The distinction between these measurements is operationally important. A current AS overview may establish whether RIPE’s data service has a current object-level view. Announced-prefix data can identify prefixes observed as originated by the ASN. Routing status can indicate whether routes are currently visible in the service’s measurement base. BGP-state data can provide a point-in-time view. First/last-seen and routing-history data can show whether the apparent gap is persistent, recent or intermittent.

Even a successful query would not answer every question. RIPEstat endpoints share RIPE RIS as their routing-data foundation. They are therefore not independent collector families from one another. Agreement across several RIPEstat views would strengthen the measurement result, but would not constitute the same kind of independent confirmation as agreement between RIPE RIS and a separate collector or aggregation service.

PeeringDB adds operating-surface context

PeeringDB is useful for understanding how a network identifies itself and describes its interconnection surface. Its record can contain information about network type, points of presence, facilities, Internet exchanges and contacts. It is a context layer rather than an authoritative route monitor.

For AS210837, the relevant PeeringDB endpoint is the network record for the ASN (PeeringDB network record). The fact package treats PeeringDB’s presence or absence as bounded evidence: it may inform network identity and operating-surface context, but it does not prove current BGP activity. PeeringDB is voluntary and self-maintained. A stale record can persist after a network changes. An incomplete record can coexist with a functioning network. A missing record can reflect non-participation rather than non-operation.

That makes PeeringDB particularly valuable when used comparatively. If an ASN has a stable registry record, a maintained PeeringDB record and current route visibility, the three layers reinforce one another without becoming interchangeable. If the directory record remains while route visibility disappears, the result is a discrepancy to investigate, not a conclusion that the operator has stopped.

Independent BGP sources are cross-checks, not automatic truth

Public BGP aggregation services can provide a second measurement family, but their results depend on collector coverage, filtering, freshness and presentation choices. The identified cross-checks include bgp.tools, Hurricane Electric, CAIDA AS Rank and BGPView (bgp.tools AS210837; Hurricane Electric AS210837; CAIDA AS Rank AS210837; BGPView AS210837).

A source-specific absence is therefore ambiguous. It could reflect route withdrawal. It could reflect a change in origin or upstream propagation. It could reflect a collector blind spot, filtering difference, stale cache or a query that does not expose the relevant address family. It could also reflect temporary inactivity. The practical test is not whether one website displays zero prefixes, but whether multiple independent sources show a consistent, time-stamped change and whether that change persists.

The same principle applies to route counts. A lower count does not necessarily mean that capacity or customers disappeared. Prefix aggregation can reduce the visible number of routes without reducing the underlying service footprint. More-specific announcements can be withdrawn while an aggregate remains. A network can move announcements to another ASN or provider. A collector can see one path and miss another. Route visibility is a measurement of reachability and propagation from a vantage point, not a complete inventory of the operator’s commercial or physical network.

The causal mechanism: four layers of continuity

Continuity in this case is controlled through the interaction of four layers.

First is number-resource registration: the administrative identity linking AS210837 to a recorded entity and resource history. Second is route origination: whether the ASN is announcing prefixes into BGP. Third is upstream propagation: whether transit providers and peers carry those announcements outward. Fourth is collector visibility: whether measurement systems receive and retain the routes in the form queried.

A break in any layer can produce apparent absence. If an operator stops originating routes, collectors may see the ASN disappear while the registry record remains. If routes are originated but not propagated beyond a restricted upstream, some collectors may miss them. If collectors filter, expire or fail to retrieve observations, a functioning announcement can appear absent in one service. If the registry record changes after operational control moves, administrative continuity can diverge from routing continuity.

The reverse is also possible. A registry or historical directory record can persist after routes disappear. A route can remain visible after the named company’s operating role changes. That is why the article does not infer an institutional event from a technical visibility gap.

What would resolve the question

A defensible continuity determination would require a fresh, time-stamped retrieval package rather than another unsourced summary. At minimum, that package should include the RIPE Database object, RIPEstat route-status and announced-prefix results, a first/last-seen or routing-history interval, and contemporaneous results from at least one independent BGP aggregation source. IPv4 and IPv6 should be checked separately. The observed origin ASN, prefix set, timestamps and collector or service identity should be preserved.

The comparison should then classify the result into one of several bounded outcomes:

  1. Continued visibility: routes are currently observed across multiple sources, with no evidence in the retrieved interval of a sustained disappearance.
  2. Sustained withdrawal: the ASN or its prefixes are absent across independent sources for a defined interval, with historical last-seen evidence supporting a route-level change.
  3. Reassignment or origin change: the prefixes remain visible but are originated by a different ASN or through a changed operational arrangement.
  4. Intermittent or partial visibility: some prefixes or address families remain visible while others disappear, or observations vary by collector and time.
  5. Unresolved measurement gap: the sources disagree, are stale, or cannot provide the required timestamps.

Only the fifth outcome is supportable from this research run. The endpoints and cross-checks were identified, but their live payloads were not retrieved. Current prefix values, route counts and observation timestamps therefore remain unverified.

Implications for operators and investors

For operators, the lesson is procedural. A registry entry, a PeeringDB profile and a historical route count should be maintained as separate evidence classes. Incident response and continuity planning should not rely on a single public view. When an ASN appears to disappear, the first task is to establish whether the change is in origination, propagation, collector visibility or administrative identity.

For investors and public-interest infrastructure readers, the same separation prevents over-reading thin public evidence. A historical route footprint can establish that a network once had an observable operating surface. It cannot establish current customer count, physical capacity, financial health or cessation. A current absence can raise a diligence question without answering it.

The risk is asymmetric. Treating a registry record as proof of operation can create false confidence. Treating a single source-specific absence as proof of failure can create false alarm. Both errors arise from collapsing different layers into one status label.

The bounded conclusion is therefore straightforward: AS210837 has a documented historical operating surface, but the available evidence in this run does not establish what happened to that surface afterward. The continuity question remains open until time-stamped live route observations are independently retrieved and compared.