The Internet is a vast collection of interconnected infrastructures, mainly routers, organized into Autonomous Systems (ASes). To forward packets between networks, a routing protocol is often required; the Border Gateway Protocol (BGP) is a widely adopted inter-domain routing protocol, while within an administrative network boundary, other protocols are used.
Nevertheless, Internet routing is not free of potential anomalies; one of them is a routing loop. A routing loop happens when a packet cannot reach its destination because it gets repeatedly forwarded across a path segment until it is discarded to prevent unnecessary consumption of network resources.
Routing loops represent a significant threat to routing stability in the region, as they can negatively affect network performance by causing packet loss, generating unnecessary traffic, and increasing transmission latency.
(Free access, no subscription required)
In this article, we explore routing behaviour in the Dominican Republic. To this end, we analysed 1,476 IPv4 prefixes announced by 197 ASes operating in the country, with the aim of identifying potential routing loops.
Can routing loops be observed in Internet paths within the Dominican Republic?
In this study, we consider a potential routing loop to be present when our traceroute measurements reveal repeated and periodic sequences of hops. To collect the measurements, we adopted the following methodology.
First, for each of the 1,476 IPv4 prefixes announced by 197 ASes registered in the Dominican Republic, we sent ICMP probes to at least 40 different IP addresses within the prefix. These probes were generated by means of the Scapy library. For each scanned prefix in which at least one IP address generated an ICMP Time Exceeded response, we recorded the IP address that triggered the response and randomly selected another IP address from the same prefix. Following this procedure, we obtained a set of 234 IP addresses for further traceroute measurements.
In this article, we explore routing behaviour in the Dominican Republic. To this end, we analysed 1,476 IPv4 prefixes announced by 197 ASes operating in the country, with the aim of identifying potential routing loops.
Can routing loops be observed in Internet paths within the Dominican Republic?
In this study, we consider a potential routing loop to be present when our traceroute measurements reveal repeated and periodic sequences of hops. To collect the measurements, we adopted the following methodology.
First, for each of the 1,476 IPv4 prefixes announced by 197 ASes registered in the Dominican Republic, we sent ICMP probes to at least 40 different IP addresses within the prefix. These probes were generated by means of the Scapy library. For each scanned prefix in which at least one IP address generated an ICMP Time Exceeded response, we recorded the IP address that triggered the response and randomly selected another IP address from the same prefix. Following this procedure, we obtained a set of 234 IP addresses for further traceroute measurements.
Second, we scheduled a set of traceroutes in RIPE Atlas. Specifically, we used RIPE Atlas probe 60205, connected through AS6400 (Claro Dominicana), one of the best-connected ASes in the country, according to Eyeball Rank. We also tested from probe 32174, connected through AS267705. This provided two distinct vantage points and allowed us to evaluate whether a routing loop was observable only from specific source networks.
Third, we performed both ICMP and TCP-based traceroutes. Using two distinct traceroute probe mechanisms allowed us to compare the observed paths and identify loops that may depend on the type of traffic being forwarded. This is particularly useful for detecting cases potentially associated with Policy-Based Routing (PBR), where forwarding decisions may differ according to traffic characteristics.
Finally, we double-checked loop candidates using custom traceroutes, executed by means of different sites such as NetKitBox, and DNS-checker; we also repeated tests at different times to check whether the loop persisted.
What the Measurements Reveal.
Based on the collected measurements, we identified at least 138 cases exhibiting forwarding patterns consistent with potential routing loops. Of these cases, 24 exhibited an intra-AS loop cycle and 14 an inter-AS loop cycle. The remaining 100 cases contained either private IP addresses within the observed cycle, which cannot be directly mapped to an AS, or intermediate timeout responses that prevented reliable AS identification.
Nevertheless, if we adopt the criterion that a loop is intra-AS when the last public hop before the private-address portion of the cycle and the destination prefix belong to the same ASN, the number of intra-AS cases increases to 83. Under this criterion, 41 cases remain unclassified.
On the other hand, based on the loop cycle topology, we categorized the cases as Ping-Pong, Circuit or Unclassified. Ping-Pong refers to the cases in which the packets oscillated between two hops, whereas Circuit loops contain cycles with more than two hops. The vast majority of the cases are ping-pong loops. Loop topology is important because it helps to infer the potential cause of the loop.
The results are summarized in the following Figures.
Finally, the following figure illustrates the distribution of the observed loops based on the destination ASN. This shows that the observed potential loops are not confined to a single destination AS.
In the following table, we provide Representative RIPE Atlas measurement IDs.
Categories
RIPE Atlas Measurement ID
Intra-AS
215333649 (dst: 186.120.15.1)
Inter-AS
215329771 (dst: 45.186.15.13)
Unclassified Domain Scope
215329032 (dst: 45.85.180.20)
Ping-Pong
215329771 (dst: 45.186.15.13)
Circuit
215330052 (dst: 45.186.14.16)
Unclassified Loop Topology
215326566 (dst: 38.127.196.12)
What This Means for Internet Routing in the Dominican Republic
The observed results show that forwarding anomalies can persist over time rather than appearing only as short-lived convergence events.
For network operators within the region, this study can support their troubleshooting by identifying the routers, prefixes, and paths involved in anomalous forwarding behavior. For Internet researchers, it provides a practical methodology for studying routing resilience and operational failures at regional scale.
The views expressed by the authors of this blog are their own and do not necessarily reflect the views of LACNIC.