Why and How I Got My Own ASN
chown.me
chown.me
We have too many people who don't like stuff like this, who say it's "too hard", and that people shouldn't do hard things (just see any thread on the Internet about people running their own email servers). It's wonderful to see someone sharing something non-trivial in a way that makes it ever so slightly more attainable to the rest of us.
I'm sure you'd agree that it's also easier to scale your experiments/interest if you only do small experiments rather than go all the way in every dimension.
What I do instead (instead of running an antispam server) is checking all stuff that a proper mail admin would do, that is:
- greylisting (postgrey)
- reject hosts not listed in spf records for the sender (spf-policyd)
- verifying dkim signatures, if present (opendkim)
Also f#@k spamhaus and those people, they will mark you as a spam host on pure prejudice.
That's said, most of my spam senders match SPF and have proper DKIM records. Only few absolutely outrageous spammers ignore it.
Setting DKIM and SPF is not a rocket science and I'd be extremely surprised if spammers wouldn't do that.
You should ALSO be checking dkim signatures on incoming e-mails (opendkim does that IIRC).
Also, I forgot to mention that I REQUIRE tls for incoming smtp connection. That's another thing rising the bar for spammers.
If you're using postfix, it's very open by default, in the sense that it doest not come with spf and/or dkim/dmarc tooling and it's not going to, for example, require (or even allow) ssl/tls for incoming smtp connections (and won't use it for outgoing smtp connection).
One last thing: a little bit of spam leaks trough... But it's like less than a single spam email per two weeks.
This would cut quite a number of legitimate emails for me. Surprised it works for you.
I also require SSL/TLS for incoming smtp/submission connections.
Equinix owns PAIX on 529 Bryant St. as SV8.
It's interesting how racks still aren't so much volume-, mass-, or network bandwidth-/transit-constrained, but power-constrained.
Even with what is now a "small" 5kW thermal power budget per 44U cabinet, measuring 24 inches wide x 48 inches deep, you can easily exceed that 5kW long before you physically fill the cabinet with servers.
You can only get so much cooling density. And loading up a rack can use a signifigant portion of cooling.
Its pretty easy now-a-days to get 18kW into a rack, which will require 5 tons of cooling. Ie. enough cooling to handle a 3,000 ft^2 house.
For software, I'm using Bird, because I couldn't get OpenBGPd insert routes into my FIB. (I'm using OpenBSD, not the portable one)
Regarding the routes in the FIB, I had the problem as well. Hopefully claudio@'s answer may help you (provided you want to test again) https://marc.info/?l=openbgpd-users&m=161510661928340&w=2 (ctrl-f "1. Why the FIB isn't filled?")
If you want to be serious about having and using an ASN for its intended purpose, you're looking at a minimum of a couple hundred dollars a month anyways for a 1U system in colocation with a hosting company that will set up a router-to-router BGP relationship with you. Even if to start, just singlehomed to one IP transit provider sending you full tables. And ideally also a connection to an IX that exists at the same location.
In US dollars, budget something like $2400-3000 a year to be serious about it what I described above...
The ARIN minimum bar to meet is actually not that high - you need to register an LLC or the local equivalent in your state or province, though of course something like a C-corp is perfectly acceptable as well. Other corporate legal entities like a US state's 501c3 or a Canadian non-profit society or registered charity are also acceptable.
They are not set up for individual persons to get an ASN.
One of the main purposes of having an ASN is to be truly multihomed, to 2 or more transit providers sending you full BGP tables, and you announce your own IP space to your upstream(s), as small as at least one /24 of ipv4, and whatever size you have for ipv6 such as a /32, or /36 or /48, and to join peering exchanges. The number of individual persons who really need to have a BGP-to-BGP full tables relationship with more than 1 ISP are really small. If you need such a thing you are almost certainly some sort of corporate entity (see above) and doing the ARIN membership joining paperwork should be very straightforward.
Couldn't you achieve this with a simpler/cheaper setup (a single Vultr server set up with their BGP service), and your home devices tunneling everything through it?
And doesn't this use case warrant your own address space?
If you actually do find a cooperative fiber based last mile ISP that will set up bgp with you in your house, I'd be shocked if the service quotation for such a custom weird thing doesn't start from a floor price of $400 a month.
Backhaul over tunnels is really the only viable solution to "BGP at home."
Companies like Vultr can provide cheap BGP services (free in the case of Vultr) which can be combined with cheap VPS instances as gateways that back-haul your subnet to a home or office server. This type of setup is mentioned down thread. You could easily end up paying more in ARIN fees than infrastructure costs.
> One of the main purposes of having an ASN is to be truly multihomed
For me the main interest in having my own ASN is IP portability across hosting providers. Unfortunately, IP reputation is a thing, especially for e-mail. If I had a portable subnet I wouldn't need to sweat how and where I host my infrastructure. In my case, I could change my office ISP from Cogent to AT&T without worrying about losing e-mail.
EDIT: I'm probably overblowing the risk of being blocked by GMail, Office365, etc, after an IP migration. Don't let me dissuade any aspiring SMTP admins. Nonetheless, my overarching concern is maintaining control of my digital presence (personal and business), no matter how hard Google, Amazon, and others try to squeeze all the small players out of the space.
ARIN really needs the concept of sponsoring LIRs, because right now everyone has to deal directly with ARIN and that means ARIN has to fit their policies to try to fit everyone. While it's technically possible to get IPv6 PI space from ARIN as an individual person end user, and it's gotten easier than in the past, it still looks really daunting to the hobbyist or small network operator.
As for LIRs handing them out like candy, I joined RIPE as an LIR and RIPE will allocate an IPv6 /29 to an LIR for the low cost of zero Euro (well, except for the membership, which is a bit spendy) and that's 524,288 /48s so no reason for me to not slap up a web page and see if I can earn back a few of the EUR I will be paying to RIPE. I'm glad people do it for the pittance we see here.
Last time I checked it was a /32.
More than that requires justification (and potential Euro payments depending on context/cirumstances).
Edit to add: Grrr... I see there was a policy change after $myco received its IPv6 allocation [1]. Typical. ;-(
[1] https://www.ripe.net/participate/policies/proposals/2012-10
Most IPv4 space also isn't portable. Even if you have a /24 (enough IPv4 space that it could be portable) it usually isn't, if you actually need portable space you need to make sure that's what you're actually getting, it will probably cost more.
If it's portable then you can just take it with you to another provider.
But you can instead request /48 PI range in 'sponsoring LIR' mode, which would be independent allocation from RIPE (and subject to small yearly fee), just processed by the LIR. Then you could keep it if you change LIRs.
That's an odd way of saying "spurring innovation in the realm of internet routing implementations!
Damn middleboxers. Always trying to keep the little guy off the net!
The steps to getting an ASN essentially entail setting up some objects over at the RIPE database and then letting us know what these are, we will then send you some paperwork to print, sign & return to us. From here, we submit this application to RIPE (along with company documents, if applying as a company) and they will then request ID verification from you directly (if applying as an individual) or seek to validate your Company, if applying as a company. A few days later, RIPE will give you an ASN. This is the short version but it is essentially just a bit of paperwork and that's all.
The /48 is PA space we give to you in order for you to announce via BGP, with your fresh new ASN. This is included for the life of your ASN (or the heat death of the universe, whichever comes first) and you are free to take that and announce it wherever you want. We do make a polite request that you peer with us but it's not a requirement. If you do peer with us we can help get you up & running and your prefix announced.
Hope that helps a little & if not, feel free to find me on Discord (link is in the footer of the website) and I'll be happy to walk you through it.
He mentions one of his VMs is in Toronto, but not with whom...
edit: Looks like https://xenyth.net/products/vps-hosting/ Xenyth Cloud. Curious if there's any VM hosts in e.g. California that would do this.
Everything broke and support wasn't willing to explain what happened. It felt like they decided my account was suspicious and they routed all my traffic through some firewalled/monitored egress to inspect my traffic. I couldn't even SSH in, I had to go the the dashboard and grab the IP they had reassigned to my host.
You'd be doing everyone a service by continuing to dig out a reason for why that happened, and if they don't provide it, lambast them over social media or something so they do provide some sort of justification.
Surely the account was being paid via cryptocurrency however it was already verified through the linking of an actual traditional credit card like they required.
They have Vegas, Miami, NY and Luxembourg and do BGP, Anycast, DDoS protection etc.
A few years ago someone gave a talk "anycast on a shoestring": https://ripe69.ripe.net/wp-content/uploads/presentations/36-...
The author explained how they found hosting services.
I understand what an ASN is at a super high level, but have to admit that the vast majority of the acromyns in this article were new to me.
Any good resources to read on this subject?
* There are a bunch of organizations responsible for distributing all IP ranges (i.e. ARIN and RIPE);
* Each of these ranges they assign, get a unique ASN;
* Once I have such an ASN, I can go to an ISP and say, “please broadcast this for me and route it to my network”
* ISP will verify whether you speak the truth (hopefully);
* They will add an entry in their route tables for your range, so that any traffic they receive is correctly routed to your port:
* They will start broadcasting your routes, using protocols such as RIP;
* They will then start broadcasting your IP ranges with their uplinks they peer with using BGP;
* The internet has now learned how to reach your servers behind your IP ranges.
This is a bit simplified, but in general is how I understand things work.
Would love it if someone with more knowledge on the matter can elaborate a bit on the BGP broadcasting part, and how ISPs protect against bad actors / scammers / whatever. I know there are recent improvements in BGP security, but it all still seems very insecure to me, and humans are still a critical factor here?
Additionally, I understand that BGP is necessary because typical route table entries being broadcasted using RIP etc are too narrow, too smal, and you want to be able to aggregate a whole bunch of routes into large blocks, which is what BGP is for? Did I get that right?
Question: so if I want to host a web application at hosting provider X, and I have my own ASN and want to use my own IP addresses - I assume then that the hosting provider needs to "support BGP"? Is that accurate?
Indeed, one way or another, they need to support BGP which if they are using their own ASN and data center, they most likely already do but it's not 100% they allow their customers to use their own. Sometimes they advertise that they support BGP for their customers (like Vultr: https://www.vultr.com/docs/configuring-bgp-on-vultr/), sometimes they can provide the service to you if you ask nicely and sometimes they don't want anything to do with customer BGP.
Everything you wanted to know about BGP from the Network Startup Resource Center (NSRC):
Congratulations on your network setup! It's impressive for such a low budget
A relevant snippet:
> This means that we feel comfortable about the prospect of allocating 178 billions /48 prefixes under that scheme before problems start to appear. To understand how big that number is, one has to compare 178 billion to 10 billion, which is the projected population on earth in year 2050
Edit: oh, wow I misread that completely. It's 17.8 /48 ranges per person on average. Yep, that should be enough for quite a while.
/48 is actually a relatively standard allocation even for home connections, although /56 is more common.
This was later revised to "/56 by default, /48 if you ask with no justification needed"
A /48 is considered one "site" in current thinking. Since IPv6 subnets are /64, you have 16 bits between the /48 and the /64. This is the equivalent of using 10/8 for your network and using /24 IPv4 subnets: in both cases you can have upto 2^16 subnets.
The main difference being that a /24 can have ~250 hosts, but a /64 IPv6 subnet can hold the equivalent of four billion Internets (2^32 * 2^32).
But one of the selling points of IPv6 is reducing/eliminating the mental math about worrying about if you have "enough" addresses (and then carving things into /26, /30, etc).
This is the really important part. As they continue to hand out IPv6 like candy, the minimum prefix length will get shorter.
No ISP wants a hundred million+ routes in their routing table, so people will start to drop anything shorter than a /42, /40, /38, etc. until the table gets small enough and shunt everyone elses traffic off to Hurricane Electric or the like as a default route.
People have this mindset of "we added a bunch of zeros, its an infinite resource now!" which is how we ended up in this mess to start with.
Unlikely.
> No ISP wants a hundred million+ routes in their routing table […]
Too late. IPv4 are set to hit 1024K (2^20) in January 2024 at current trends:
* https://blog.apnic.net/2021/03/03/what-will-happen-when-the-...
Already close to 10^6:
> I see 904560 IPv4 prefixes. This is 30 fewer prefixes than 6 hours ago and 416 more than a week ago. 59.10% of prefixes are /24.
* https://twitter.com/bgp4_table
What is your basis for this opinion? Network operators are already talking about it.
> Too late. IPv4 are set to hit 1024K (2^20) in January 2024 at current trends
Allow me to expand that number for you: 1,048,576
One million. A reasonable upper bound for max announced v4 prefixes is somewhere around two million. You can handle that in a few GB of RAM. IPv6 could see 100x or 1000x that number based on how we are handling allocations, at which point prefix trimming will happen.
By handing out /48s the routing table stays manageable. This is the smallest address block you can announce via BGP for this reason.
Given the utter vastness of IPv6 we are also able to do things like carve out an entire /7, fc00::/7, for unique local addresses, and still tell people they shouldn't actually need these addresses at all.
As to the actual process of getting a PI block, I think it is likely to involve some questions. A similar objection exists to handing out smaller than /48s: more people having their own block implies more routing entries. Much better if an existing provider carves you a /48 out of their allocation and routes you traffic. This is probably balanced against the fact that by requiring you to deal with an existing LIR and set up BGP (and your LIR won't want you to muck that up) the number of people who will actually do this just for fun is limited.
The standard /48 assignment size from ISP's to end-users was targeted mainly at stingy residential ISP's that were only assigning one IP per customer. They wanted any customer to have as many publicly routable subnets as they would ever need or want, but 65k is a lot of subnets. This was later updated to a default of /56 (256 subnets) but you could still get at /48 just for asking.
It got even weirder on RIR to ISP portable allocations. One of the original schemes would have RIR's allocating a "TLA" /16 (!) to only a few mega ISP's. Most ISP's/hosts would have to get their "NLA" address blocks from and be subservient to the 800 pound gorillas in the industry. https://www.rfc-editor.org/rfc/rfc2450.txt, https://www.rfc-editor.org/rfc/rfc2374
This was loosened somewhat in 2000 with RFC2928 which designated a "Sub-TLA" /29 as the initial ISP size. This would open it up to many more potential registrants, at least in theory. https://www.rfc-editor.org/rfc/rfc2928.html
The TLA/Sub-TLA/NLA system was abandoned in 2003 with RFC3587 after panic set in that nobody was deploying IPv6. https://www.rfc-editor.org/rfc/rfc3587.txt. ARIN had only made 30 Sub-TLA assignments by the end of 2002.
While RFC3587 wisely punted allocation policy to the RIR communities, the RIR's still had very restrictive policies inherited from RFC2450. Only around 2004 did they loosen to the point that ordinary networks could start requesting addresses. Google for example got their first IPv6 allocation in 2005. The problem is by then few networks were interested or just assumed they wouldn't qualify. When I got my first /32 in late 2004 there were less than 1000 routes in the global IPv6 table! Today there are ~135,000.
These more permissive rules only applied to ISP's/Hosts. End user orgs of any size were not allowed to start requesting portable /48's directly from RIR's until 2006 after much debate in RIR communities and vocal objections from IETF members and certain large ISP's.
Today router silicon and RIR policies have converged to a reasonably functional state. Too bad it took 20 years to get here or IPv6 might actually be on it's way to replacing IPV4. Instead that is still about 20 years away.
Probably cheaper and less bothersome than acquiring an ASN and setting up BGP. :)
I always spot those small things, but I always feel silly submitting them on github since sometimes they feel so minor.
However to submit a patch you have to email a diff to their mailing lists. They even prefer it inline vs as an attachment.
The GitHub repo linked in the post is just a read only mirror, not used by the OpenBSD project for development.
Not sure what magic I'm pulling off but I run OSPFv2 and OSPFv3 between 3 routers in a triangle using WireGuard and FRR on VyOS and it's working fine. I just set allowedIPs to everything on the interfaces to let the multicast address traffic go through.
Besides, I wonder what the threat model is; you will still want end-to-end encryption on top of it, so why bother with encrypting the traffic below as well?
Why? The colon character is not a special character in shell commands.
Tab-completion is probably being conservative about escaping it in case you're using it as a path separator, like when setting a `$PATH`-like var.
: is special on NTFS for alternative data streams, and I think HFS+ named forks? (The mac syntax is foo/..namedfork/rsrc, I don't know how that translates to linux)
"foo\:bar" is a file name with a colon in it. "foo:bar" is an ADS named bar on the file foo.
bash added `:` to the list of completion word break characters with bash 2.0 [1][2]. Bash 2.0 was released in 1996. NTFS-3G started in 2006 but it was "forked from the Linux-NTFS", and I can't find any history for this project. NTFS itself was released in 1993.
HFS+ seems to have been released in 1998, so it can't be the reason. But even regular HFS had resource forks and it was released in 1985.
No idea where to look in ksh's source.
[1]: https://github.com/bminor/bash/commit/ccc6cda312fea9f0468ee6...
[2]: https://github.com/bminor/bash/commit/ccc6cda312fea9f0468ee6...
That does not make sense. The shell does not itself know anything about ADSs, and therefore, in both cases, sends the string "foo:bar" as arguments to commands.
I'm running bash I have to escape it otherwise the shell doesn't autocomplete.
But ls/vim seems to be fine with the path without escaping so I guess I'm wrong.
Anyway, another problem is: ~/git/git.chown.me/ipam (master %=)$ vim ipv6/2a0e\:f43\:\:-48/2a0e\:f43\:<tab><tab> I get: 2a0e:f43:0:100:-56/ 2a0e:f43:0:fd00::-56/ 2a0e:f43:0:fe00::-56/ 2a0e:f43:0:ff00::-56/ 2a0e:f43::-56/
it's a mess to find the difference between the possibility haha
https://stackoverflow.com/questions/7444504/explanation-of-c...
Contrast this with the characters $, [, (, etc.