Summary

  • The prefix 194.0.132.0/24, registered to DATAMATIX Datensysteme GmbH's AS210973, is RPKI-valid and visible as an announced best route at an AMS-IX route server — yet it is absent from CIDR Report's snapshot and shows as received-but-not-exported at a Netnod route server (RIPEstat; CIDR Report; AMS-IX looking glass).
  • The divergence has a documented mechanism: RIPEstat's announced-prefixes API defaults to a two-week window and a minimum-ten-peers filter that explicitly excludes low-visibility announcements (RIPEstat).
  • No single monitor's output is complete evidence of what a network announces; corroboration across monitors, registry records and RPKI state is required.

The chain that closed — and the monitor that did not

Prior reporting on DATAMATIX Datensysteme GmbH closed the chain from registry record to operating business: AS210973 is a RIPE NCC allocation registered 2021-07-30 in Austria, held by DATAMATIX-AS under organisation ORG-DDG16-RIPE, and its 2026-09-26 coverage flagged one unresolved anomaly — that the prefix 194.0.132.0/24 "splits the public monitors themselves." This investigation establishes the mechanism behind that split.

The registry and RPKI layers agree

The prefix is registered. A RIPE route object for 194.0.132.0/24 with origin AS210973, created 2025-11-13 with max-length 24, carries rpki-ov-state valid in IRR mirrors (RIPE RPKI CA). Independent rpki-client validation shows a ROA covering 149.62.35.0/24, 194.0.132.0/24 (max-length 24) and 2a10:fd00::/32 (max-length 32), plus a second ROA covering 212.236.9.0/24 and 212.236.10.0/24 (rpki-client console). The underlying RIPE RPKI CA certificate lists AS210973's subordinate resources and shows validation OK, valid from 2026-01-01 to 2027-07-01 (rpki-client console, RIPE repository mirror).

What each monitor actually says

  • RIPEstat: its RIS-based overview lists four originated IPv4 prefixes — 149.62.35.0/24, 194.0.132.0/24, 212.236.9.0/24, 212.236.10.0/24 — treating the disputed prefix as announced (RIPEstat).
  • AMS-IX looking glass: at route server nl-rs2-v4, neighbor 80.249.209.53, 194.0.132.0/24 appears as "RPKI Valid Best Route" with AS path 8218 210973, roughly six days old at snapshot (AMS-IX).
  • Netnod looking glass: route server 8, neighbor as49292_1, receives the prefix with path 8220 24953 210973 but lists it under "Routes not exported" (Netnod).
  • CIDR Report: its AS210973 snapshot lists only three prefixes (768 addresses) and omits 194.0.132.0/24 entirely (CIDR Report).
  • A third-party ASN listing corroborates five originated prefixes including the disputed one and the IPv6 block; it is low-authority and used only for corroboration (bestcheapvps.org).

The mechanism: thresholds and export policy

Two mechanisms explain the split without invoking any anomaly. First, RIPEstat's own documentation states that the announced-prefixes API defaults to a two-week window and a min_peers_seeing=10 filter that "excludes low-visibility/localized announcements" (RIPEstat). A prefix seen by fewer than ten RIS peers is legitimately absent from default API output while still genuinely announced. Second, route-server behaviour is per-IXP: at Netnod the prefix is received but not re-exported, which limits downstream visibility from that vantage; the reason — export policy or a route-server configuration choice — is not visible in the retrieved data. CIDR Report's snapshot date is unknown, so its omission could be sampling lag or filtering.

What this means for evidence

The disagreement between monitors is not noise to be averaged away; it is a boundary of the method. A registration proves an administrative claim; a ROA proves an authorisation to originate; a single looking glass proves visibility at one vantage; an aggregated monitor proves visibility above its own threshold. In this case the four layers converge on the same conclusion — 194.0.132.0/24 is registered, RPKI-valid, and announced — but each monitor alone would have produced a wrong answer. The prefix directory entry for DATAMATIX records the entity; the routing evidence describes only its network resources, not its commercial operation, which remains unproven.

What remains open

  • How many RIS peers currently see 194.0.132.0/24 — the min_peers_seeing threshold effect is documented but unquantified for this prefix.
  • Whether Netnod's non-export reflects route-server export policy or an export-target choice by the upstream.
  • Whether CIDR Report's omission is sampling lag or a deliberate filter.