Summary

  • AS210973 (DATAMATIX-AS), held by DATAMATIX Datensysteme GmbH since its allocation by the RIPE NCC on 30 July 2021, originates four IPv4 /24 prefixes and one IPv6 prefix: 149.62.35.0/24, 194.0.132.0/24, 212.236.9.0/24, 212.236.10.0/24 and 2a10:fd00::/32, according to RIPEstat's AS detail, which classifies the network as a stub originator that is not seen in RIS as transiting.
  • 149.62.35.0/24 — the one AS210973 prefix prior BTW reporting never examined — is registered to DATAMATIX itself: the RIPE inetnum AT-DATAMATIX-20180831 is held by organisation ORG-DDG16-RIPE (DATAMATIX Datensysteme GmbH, a Local Internet Registry in Vienna) with status ALLOCATED PA and maintainer lir-at-datamatix-1-MNT.
  • A valid ROA authorizes AS210973 to originate the exact /24 at maximum length /24, and independent route-server vantages at AMS-IX and Netnod both see the prefix announced by AS210973 as an RPKI-valid best route — one through AS8218, the other through AS24953.
  • Yet the routing-registry layer remains internally inconsistent: NLNOG IRR Explorer records two RIPE route objects for the prefix with different origins, AS210973 and AS24953, and flags the object set as RPKI-invalid because the AS24953-origin object contradicts the ROA that only authorizes AS210973.
  • The composite finding: registry ownership clarity and routing-registry consistency are separate problems. Even where the registry unambiguously names the holder, the layered control planes that actually govern reachability can disagree with each other and with the cryptographic authorization — and it is the cryptographic layer, not the database entries, that currently disciplines what reaches the global routing table.

What this report adds

Prior BTW coverage of DATAMATIX established four things. First, the company's product catalogue describes industrial wireless data-transmission equipment engineered to work without external networks or cloud services, while the same company holds an autonomous system with 768 routed IPv4 addresses — a gap between commercial description and routing footprint that the earlier report treated as evidence about the limits of routing data, not as a contradiction to be resolved.

Second, the network's reachability depends on a layered structure of mutually entangled upstreams — AS8218 (Zayo Infrastructure France SA), AS8245 (Video-Broadcast GmbH) and AS24953 (NETPLANET GmbH) — rather than on independent transit contracts. Third, the ownership of two of the four IPv4 prefixes, 212.236.9.0/24 and 212.236.10.0/24, could not be established on the public record: their route objects are maintained by AS8245-MNT, a maintainer belonging to a third party, and mirror databases disagree about the registrant.

Fourth, monitoring infrastructure does not agree about what the network announces: 194.0.132.0/24, RPKI-valid and present in RIPEstat's originated set, was absent from several major monitors' views, a divergence BTW documented as structural rather than accidental.

All four findings remain accurate against the current record. The route objects for the two 212.236.x prefixes are unchanged — created and last modified on 16 August 2021, still maintained by AS8245-MNT, as Hurricane Electric's reproduction of the RIPE route object for 212.236.9.0/24 shows. The aut-num for AS210973 was last modified on 5 June 2023 and its import/export policy still names only AS8245 and AS24953, even though bgp.tools lists AS8218 as a third upstream through which the network's prefixes propagate.

And the monitor divergence on 194.0.132.0/24 persists: Qrator Radar's announced-prefix table for AS210973 omits the prefix from its analysis window, while CIDR Report's AS6447 view likewise excludes it — the same omission pattern prior reporting documented.

The delta is 149.62.35.0/24. RIPEstat's AS detail lists four originated IPv4 prefixes, each at 25 percent of announced space, and 149.62.35.0/24 is the one that none of BTW's previous DATAMATIX articles examined. Where the 212.236.x prefixes are registry-ambiguous, this one is registry-clear. Where 194.0.132.0/24 is visibility-fragile, this one is globally visible from multiple independent vantages. And yet it exhibits a routing-registry inconsistency of its own. That combination — clean registration, dirty IRR — is what makes the prefix worth a report of its own.

The registry layer: a block that is demonstrably DATAMATIX's

The registration question for 149.62.35.0/24 has an unambiguous answer. The mirrored RIPE whois record shows an inetnum covering 149.62.35.0 through 149.62.35.255, with netname AT-DATAMATIX-20180831, country AT, organisation ORG-DDG16-RIPE, status ALLOCATED PA, maintainers lir-at-datamatix-1-MNT and RIPE-NCC-HM-MNT, and a created timestamp of 8 June 2023. ORG-DDG16-RIPE is DATAMATIX Datensysteme GmbH, registered as a Local Internet Registry at Märzstraße 1, 1150 Wien, Austria.

BigDataCloud's independent network-lookup view corroborates the picture: registry status assigned, registered country Austria, and the prefix associated with AS210973.

This is the first prefix in the AS210973 set for which the registry layer names the operating company itself as the holder. The contrast with the 212.236.x space is sharp. There, the operating company and the route-object maintainer diverge, and registrant labels rendered on aggregators — Clemens Schmikal for 212.236.9.0/24, Rapid Solution Development for 212.236.10.0/24, per Hurricane Electric's prefix views — match neither DATAMATIX nor each other. BTW's earlier attribution report concluded that operational control was attributable to AS210973 while ownership was attributable to no party on the public record.

For 149.62.35.0/24, ownership is attributable: it is DATAMATIX's own allocation, maintained by its own LIR handle.

One cosmetic discrepancy deserves note without being resolved: the inetnum's netname embeds the date 2018-08-31, while the record's created timestamp reads 2023-06-08. A third-party registration-date listing for the block shows 2018-08-31. Whether the netname preserves an earlier association with the number range that was re-registered or re-issued under the current record is not determinable from the public record examined here, and this report treats the discrepancy as observed, not adjudicated.

The announcement layer: visible from two independent vantages

Registration proves holdership; announcement proves reachability. For 149.62.35.0/24 both layers are independently confirmable, and they point at each other.

The AMS-IX route server nl-rs2-v4 shows 149.62.35.0/24 as an RPKI-valid best route with an AS path of 8218 210973 and a next hop of 80.249.209.53 — the route reaching Amsterdam through Zayo's upstream and being originated by DATAMATIX's AS. The Netnod route server 7 in Stockholm shows the same prefix, originated by the same AS, but reached through a different path: 8220 repeated four times, then 24953 repeated five times, then 210973 repeated four times — a heavily prepended path through NETPLANET, the Austrian upstream named in the aut-num's own policy.

Two independent internet exchange vantages, in two countries, through two different upstreams, both confirm the same origin.

Qrator Radar's prefix table for AS210973 corroborates the announcement at scale: over its analysis window from 20 May 2026 to 20 August 2026 it lists 149.62.35.0/24 with RPKI ROA status Valid, route object status Valid, and propagation of 548 probes at 100 percent — the highest-visibility entry in the set, alongside 212.236.9.0/24, 212.236.10.0/24 and 2a10:fd00::/32, and conspicuously without 194.0.132.0/24, which the same window omits entirely.

CIDR Report's AS6447 view independently places 149.62.35.0/24 on a path reading 2914 24953 210973 210973 210973 210973 — visible globally through NTT's transit backbone and NETPLANET's upstream — while again excluding the sibling prefix. bgp.tools attributes the prefix's description directly to DATAMATIX Datensysteme GmbH.

Taken together, the announcement layer for 149.62.35.0/24 is the healthiest in the AS210973 set: multiply confirmed, RPKI-valid, propagated at full visibility according to Qrator's own probe accounting, and reachable through at least two distinct upstream paths — evidence that the layered upstream dependency BTW previously documented is not a single point of failure at the level of individual vantage points.

The IRR layer: two route objects, one of them invalid

If the registry layer is clean and the announcement layer is healthy, the routing-registry layer is where the fourth prefix reproduces — in miniature and with a twist — the pattern of contested space that defines the rest of the AS210973 set.

NLNOG IRR Explorer's report for AS210973 records, for 149.62.35.0/24: RIR RIPE NCC, BGP origin 210973, RPKI origin 210973 with maxlen /24, and IRR origins 24953 and 210973 — with the advice line "RPKI-invalid route objects found: Multiple route objects exist with different origins, but DFZ only has one." In plain terms: two RIPE route objects exist for this prefix. One declares origin AS210973 and matches the ROA. The other declares origin AS24953, the NETPLANET upstream, and because the ROA authorizes only AS210973 at maximum length /24, that second object is RPKI-invalid.

The global routing table carries only the AS210973 origin. The same dual-origin pattern, IRR Explorer notes, appears for the IPv6 prefix 2a10:fd00::/32.

RIPE NCC's own documentation on BGP origin validation describes exactly the framework in which this conflict resolves: RPKI origin validation checks observed BGP routes against ROAs — cryptographically signed authorizations issued by the resource holder — so a route object in an IRR database that contradicts the ROA does not merely express a different opinion; it describes a filter-eligibility state that ROV-enforcing networks will reject. On this prefix, the object with origin AS24953 is a database entry with no cryptographically authorized counterpart and no presence in the DFZ.

Qrator Radar nonetheless labels the route object for 149.62.35.0/24 as Valid in its own table. The divergence between Radar's verdict and IRR Explorer's is a reminder that different monitors apply different matching rules to the route-object question — Radar appears to credit the existence of a valid-origin object, while IRR Explorer flags the coexistence of an invalid-origin object as a defect. Neither is wrong about its own rule; the disagreement is itself the finding.

Reading the planes separately

The four control planes that govern 149.62.35.0/24 now answer four different questions, and for this prefix they answer three of the four in agreement:

  • Registry: who is the registered holder? DATAMATIX Datensysteme GmbH, via ORG-DDG16-RIPE and lir-at-datamatix-1-MNT — unambiguous.
  • Announcement: who is propagating the prefix? AS210973, confirmed at AMS-IX, Netnod, CIDR Report's collector and Qrator Radar — unambiguous.
  • Authorization: which origin is cryptographically authorized? AS210973, at maximum length /24, per the RIPE-hosted ROA shown in rpki-client console output — unambiguous.
  • IRR objects: which origins will operators' filters accept? Both AS210973 and AS24953, per the dual route objects — inconsistent, with the AS24953 object RPKI-invalid and absent from the DFZ.

The strongest control evidence is therefore the ROA plus the sole DFZ origin: whoever holds DATAMATIX's key material can authorize or de-authorize origins, and RPKI-invalid announcements are dropped by ROV-enforcing networks regardless of how many IRR objects exist. The weakest layer is the duplicated IRR entry — and it is worth being precise about what that entry is not. A route object is a declarative database record, typically created so that upstream filters can be built; it is not proof of announcement and not proof of ownership.

Two conflicting objects describe two competing claims about who should be accepted as origin, not two ownership records. On 149.62.35.0/24, the ownership record is settled; only the filter-eligibility layer is noisy.

The most plausible reading of the AS24953-origin object — and this is inference, flagged as such — is stale documentation or an upstream's operational convenience: a filter-permitting record left in place from a prior or contingent routing arrangement, of a kind operators rarely clean up because deletion carries operational risk and leaving it costs nothing. AS24953 appears in the current announcement path itself (Netnod and CIDR Report both show the prefix transiting it), which makes a residual upstream-facing object more likely than a hostile claim.

Competing explanations — a deliberate competing claim, a misconfiguration, or a genuine historical announcement by AS24953 — are not excluded by the evidence examined here, and the IRR record examined carries no object-level timestamps or maintainer attribution in the retrieved material that would distinguish them.

What the evidence does establish is a methodological point that generalizes beyond this block: assess who controls announced space by asking, per plane, who can effect which change and with what observable consequence. Registration changes require the registry record to move. Reachability requires the DFZ to carry the announcement. Filter eligibility requires an IRR object. Cryptographic origin authority requires the resource holder's key chain. On 149.62.35.0/24, control is demonstrable at the strongest three planes by DATAMATIX and its AS; the fourth plane records an ambiguity that no observed routing consequence follows from.

The composite picture for AS210973

With the fourth prefix examined, the set reads as follows. 149.62.35.0/24: DATAMATIX's own, ROA-valid, fully propagated, one stale or upstream-convenient IRR object. 194.0.132.0/24: ROA-valid alongside the fourth prefix in the same ROA, originated according to RIPEstat and Hurricane Electric, but missing from Qrator Radar, CIDR Report and other monitor views — the divergence BTW documented and which persists in the current record. 212.236.9.0/24 and 212.236.10.0/24: origin attributable to AS210973, ownership attributable to no one on the public record, route objects maintained since 2021 by a third party's maintainer.

2a10:fd00::/32: ROA-valid, carrying the same dual-origin IRR pattern as the fourth prefix.

The earlier attribution report's open question — who, if anyone, holds AS210973's space — is now partially answerable, and the partial answer is instructive: one of the four IPv4 prefixes is unambiguously the operating company's own allocation. That makes the registry ambiguity of the 212.236.x space look less like a uniform property of the network and more like a question specific to those two blocks. It also confirms that registry clarity buys nothing at the IRR layer: the cleanest block in the set carries the same class of object conflict as the murkiest.

For a company whose own catalogue describes products designed to work without external networks — licensed-frequency radios for open-pit mining fleets, fleet-management systems explicitly independent of cloud, LoRaWAN field terminals — the routing footprint continues to outgrow the commercial description. Prior reporting treated that gap as evidence about the limits of routing data as business proof.

The fourth prefix sharpens the lesson from the other side: even where the routing data can be tied to a named, registry-verified holder, the layers beneath the announcement remain independently fallible, and only the cryptographic layer has teeth.