Welcome to the HEADSCARF175 DN42 network — public tunnel peering across eight POPs in Brisbane (AU), Los Angeles (US), New Jersey (US), Frankfurt (DE), Tokyo (JP), Hong Kong, Singapore, and Coventry (GB), plus direct IX presence in Frankfurt and San Jose.
| ASN | AS4242420842 |
| IPv4 Prefix | 172.20.159.128/27 |
| IPv6 Prefix | fdfd:27b9:f174::/48 |
| Domain | headscarf175.dn42 |
| Contact | [email protected] |
| BGP Software | BIRD 2.x / BIRD 3.x (per-node) |
| MP-BGP / ENH | Supported (RFC 4760, RFC 8950) |
| RPKI | Validated locally on every POP; ROA-invalid routes rejected |
| Anycast IPv4 | 172.20.159.128 (served on au-bne01, us-lax01, de-fra01, and us-ewr01; other POPs forward internally) |
| Anycast IPv6 | fdfd:27b9:f174::1 |
| Link-Local (peers) | fe80::842/64 |
| MTU | 1420 |
| au-bne01 | Brisbane, AU | au-bne01.headscarf175.net | manual peering only |
| us-lax01 | Los Angeles, US | us-lax01.headscarf175.net | autopeer + manual |
| us-lax02 | Los Angeles, US | us-lax02.headscarf175.net | autopeer + manual; IPv4 underlay |
| de-fra03 | Frankfurt, DE | de-fra03.headscarf175.net | autopeer + manual |
| us-ewr01 | Piscataway (NJ), US | us-ewr01.headscarf175.net | autopeer + manual |
| de-fra01 | Frankfurt, DE | de-fra01.headscarf175.net | autopeer + manual |
| jp-tyo01 | Tokyo, JP | jp-tyo01.headscarf175.net | autopeer + manual; v6-only origin (RFC 8950 ENH carries v4 NLRI for transit) |
| hk-hkg01 | Hong Kong | hk-hkg01.headscarf175.net | autopeer + manual |
| sg-sin01 | Singapore | sg-sin01.headscarf175.net | autopeer + manual |
| gb-cvt01 | Coventry, GB | gb-cvt01.headscarf175.net | autopeer + manual |
| nl-ams01 | Amsterdam, NL | nl-ams01.headscarf175.net | autopeer + manual |
Nodes use geographic names; former sN.headscarf175.net endpoints remain valid permanently as aliases, so existing tunnels need no change.
Per-node WireGuard public keys, tunnel addresses, and assigned ports are shown by the peering portal (below). For au-bne01 (manual only), they are sent in the peering email reply.
The self-service portal serves us-lax01, de-fra01, jp-tyo01, us-ewr01, hk-hkg01, sg-sin01, and gb-cvt01:
DN42: https://peer.headscarf175.dn42 clearnet: https://peer.headscarf175.net
Sign in with your DN42 mntner (OIDC via iedon's auth42 / oauth.dn42 — password, email, PGP, or SSH). Create and remove sessions at any portal POP; the portal shows the node identity, tunnel addressing, peer configuration, and live session status.
Transports: WireGuard is available at every portal POP and remains preferred. Every portal POP also offers IKEv2 route-based XFRM/IPsec and GRE/IPsec. Raw RSA public-key authentication is recommended; pinned certificates, CA validation, and 32-byte PSKs are available for compatibility. Private keys are generated and retained on each router and must never be uploaded.
Ports: portal-managed tunnels use UDP 30001-39999; your exact port is shown on the session page. (The legacy SSH autopeer on port 4242 is retired — existing sessions were migrated unchanged.)
Members of Yukisino IX and SVIX can establish a direct bilateral BGP session with us across the shared IX fabric, without a WireGuard tunnel.
| Yukisino IX | Frankfurt, DE (de-fra02) | fe80::1266:6aff:fe14:abf2 | IPv4 fabric address: 242.99.55.196 |
| SVIX | San Jose, US (us-sjc01) | 2607:3fc0:42:e19::1 |
MP-BGP over IPv6 with RFC 8950 Extended Next Hop is supported. Email [email protected] with your ASN, IX name, and on-fabric BGP address to request a session.
au-bne01 (Brisbane) is manual-peering only — residential link, no autopeer. WireGuard, OpenVPN, and GRE/Plain are all accepted.
OpenVPN remains email-only. The portal manages WireGuard and supported IPsec transports, plus plain GRE on us-lax01.
GRE/Plain is available through the portal on us-lax01 and by email at other POPs. No encryption — community (64511, 31) is set on routes via that session instead of (64511, 34) for WG. Encrypted GRE/IPsec is available through the portal at every portal POP.
Ports: au-bne01 uses sequential UDP 200xx (we'll assign the next free one). us-lax01, de-fra01, jp-tyo01, us-ewr01, hk-hkg01, sg-sin01, and gb-cvt01 manual WireGuard peers use last 5 digits of your ASN (e.g. AS4242422189 → UDP 22189).
Send the following template to [email protected]:
I would like to peer with AS4242420842. ASN: Preferred POP (au-bne01/us-lax01/de-fra01/jp-tyo01/us-ewr01/hk-hkg01/sg-sin01/gb-cvt01/multi): Transport (WireGuard, OpenVPN, or GRE/Plain): WireGuard Endpoint: (if WG) WireGuard Public Key: (if WG) OpenVPN Endpoint + config: (if OpenVPN) GRE Public IP: (if GRE/Plain) -- protocol 47, no port Tunnel IPv6 Link-Local: (preferred for BGP session) Tunnel IPv4 Address: (if using IPv4 BGP)
/27 and IPv6 /48 anycast aggregates. Per-node IPv6 /58s are advertised externally with home-aware steering; per-node IPv4 /32s stay inside our iBGP/Babel underlay and are never advertised externally. jp-tyo01 has no per-node v4 origin, but carries v4 NLRI via RFC 8950 ENH for transit. See /details.html/27 → 27, /48 → 58(64511, 1..9) | latency tier (set per-peer from measured RTT) |
(64511, 21..29) | bandwidth tier (we set 23, <100Mbps) |
(64511, 31..34) | encryption tier (34 = WireGuard / PFS, 31 = no encryption / GRE) |
(64511, 41..53) | region (per-POP: au-bne01 53 Pacific, us-lax01 44 NAM-W, us-ewr01 42 NAM-E, de-fra01/de-fra02/gb-cvt01 41 EU, jp-tyo01 52 East-Asia, hk-hkg01 52 East-Asia, sg-sin01 51 Asia-Southeast) |
(64511, 10NN) | ISO-3166-1 country (per-POP: 1036 AU, 1840 US, 1276 DE, 1392 JP, 1344 HK, 1702 SG, 1826 GB) |
We also stamp our own informational large communities at ingress (in our import filters); they pass through unchanged on re-export, so peers and looking glasses see them:
(4242420842, 1, <peer-ASN>) | learned via eBGP from this peer — value is the immediate eBGP neighbour’s ASN |
(4242420842, 120, N) | POP this route entered our network at — 1 au-bne01 (Brisbane), 2 us-lax01 (Los Angeles), 3 de-fra01 (Frankfurt), 4 jp-tyo01 (Tokyo), 6 us-ewr01 (New Jersey), 7 hk-hkg01 (Hong Kong), 8 sg-sin01 (Singapore) |
(4242420842, 130, 1) | learned directly from the origin AS (1-hop AS path at ingress) |
(4242420842, 140, R) | DN42 region we learned it in — same region codes as (64511, 41..53) above |
We have a DN42 phone number via the registry-managed tel.dn42 ENUM project — +04240842 (formatted +042-4-0842: the +042- prefix, the 424242xxxx block digit, plus the last four digits of our ASN).
| Number | +04240842 (+042-4-0842) |
| ENUM domain | 2.4.8.0.4.2.4.0.tel.dn42 |
| NAPTR → | sip:[email protected] |
| SIP / PBX | Asterisk 18 (chan_pjsip) on au-bne01 — codecs opus / g722 / ulaw, UDP 5060 |
Any PBX doing ENUM lookups against tel.dn42 can dial 04240842, or call sip:[email protected] directly. Quick check: dig 2.4.8.0.4.2.4.0.tel.dn42 NAPTR.
No one’s home — the number answers with a short recorded greeting and hangs up.
whois -h whois.headscarf175.dn42 AS4242420842 — serves our local clone of the DN42 registry (refreshed hourly). whois42d, anycast from au-bne01 + de-fra01 + sg-sin01 + nl-ams01 + us-lax02.