AS4242420842 - HEADSCARF175

Notice: All nodes are currently degraded — some servers are unable to reach s1 (au-bne01). Peering sessions and services may flap or be intermittently unreachable while this is investigated.

Welcome to the HEADSCARF175 DN42 network — public tunnel peering across eight POPs in Brisbane (AU), Los Angeles (US), New Jersey (US), Frankfurt (DE), Tokyo (JP), Hong Kong, Singapore, and Coventry (GB), plus direct IX presence in Frankfurt and San Jose.

Network Information

ASNAS4242420842
IPv4 Prefix172.20.159.128/27
IPv6 Prefixfdfd:27b9:f174::/48
Domainheadscarf175.dn42
Contact[email protected]
BGP SoftwareBIRD 2.x / BIRD 3.x (per-node)
MP-BGP / ENHSupported (RFC 4760, RFC 8950)
RPKIValidated locally on every POP; ROA-invalid routes rejected
Anycast IPv4172.20.159.128 (served on au-bne01, us-lax01, de-fra01, and us-ewr01; other POPs forward internally)
Anycast IPv6fdfd:27b9:f174::1
Link-Local (peers)fe80::842/64
MTU1420

POPs

au-bne01Brisbane, AUau-bne01.headscarf175.netmanual peering only
us-lax01Los Angeles, USus-lax01.headscarf175.netautopeer + manual
us-lax02Los Angeles, USus-lax02.headscarf175.netautopeer + manual; IPv4 underlay
de-fra03Frankfurt, DEde-fra03.headscarf175.netautopeer + manual
us-ewr01Piscataway (NJ), USus-ewr01.headscarf175.netautopeer + manual
de-fra01Frankfurt, DEde-fra01.headscarf175.netautopeer + manual
jp-tyo01Tokyo, JPjp-tyo01.headscarf175.netautopeer + manual; v6-only origin (RFC 8950 ENH carries v4 NLRI for transit)
hk-hkg01Hong Konghk-hkg01.headscarf175.netautopeer + manual
sg-sin01Singaporesg-sin01.headscarf175.netautopeer + manual
gb-cvt01Coventry, GBgb-cvt01.headscarf175.netautopeer + manual
nl-ams01Amsterdam, NLnl-ams01.headscarf175.netautopeer + manual

Nodes use geographic names; former sN.headscarf175.net endpoints remain valid permanently as aliases, so existing tunnels need no change.

Per-node WireGuard public keys, tunnel addresses, and assigned ports are shown by the peering portal (below). For au-bne01 (manual only), they are sent in the peering email reply.

Auto-peering

The self-service portal serves us-lax01, de-fra01, jp-tyo01, us-ewr01, hk-hkg01, sg-sin01, and gb-cvt01:

DN42:      https://peer.headscarf175.dn42
clearnet:  https://peer.headscarf175.net

Sign in with your DN42 mntner (OIDC via iedon's auth42 / oauth.dn42 — password, email, PGP, or SSH). Create and remove sessions at any portal POP; the portal shows the node identity, tunnel addressing, peer configuration, and live session status.

Transports: WireGuard is available at every portal POP and remains preferred. Every portal POP also offers IKEv2 route-based XFRM/IPsec and GRE/IPsec. Raw RSA public-key authentication is recommended; pinned certificates, CA validation, and 32-byte PSKs are available for compatibility. Private keys are generated and retained on each router and must never be uploaded.

Ports: portal-managed tunnels use UDP 30001-39999; your exact port is shown on the session page. (The legacy SSH autopeer on port 4242 is retired — existing sessions were migrated unchanged.)

Direct IX peering

Members of Yukisino IX and SVIX can establish a direct bilateral BGP session with us across the shared IX fabric, without a WireGuard tunnel.

Yukisino IXFrankfurt, DE (de-fra02)fe80::1266:6aff:fe14:abf2IPv4 fabric address: 242.99.55.196
SVIXSan Jose, US (us-sjc01)2607:3fc0:42:e19::1

MP-BGP over IPv6 with RFC 8950 Extended Next Hop is supported. Email [email protected] with your ASN, IX name, and on-fabric BGP address to request a session.

Manual peering (au-bne01 and OpenVPN)

au-bne01 (Brisbane) is manual-peering only — residential link, no autopeer. WireGuard, OpenVPN, and GRE/Plain are all accepted.

OpenVPN remains email-only. The portal manages WireGuard and supported IPsec transports, plus plain GRE on us-lax01.

GRE/Plain is available through the portal on us-lax01 and by email at other POPs. No encryption — community (64511, 31) is set on routes via that session instead of (64511, 34) for WG. Encrypted GRE/IPsec is available through the portal at every portal POP.

Ports: au-bne01 uses sequential UDP 200xx (we'll assign the next free one). us-lax01, de-fra01, jp-tyo01, us-ewr01, hk-hkg01, sg-sin01, and gb-cvt01 manual WireGuard peers use last 5 digits of your ASN (e.g. AS4242422189 → UDP 22189).

Send the following template to [email protected]:

I would like to peer with AS4242420842.
ASN:
Preferred POP (au-bne01/us-lax01/de-fra01/jp-tyo01/us-ewr01/hk-hkg01/sg-sin01/gb-cvt01/multi):
Transport (WireGuard, OpenVPN, or GRE/Plain):
WireGuard Endpoint:           (if WG)
WireGuard Public Key:         (if WG)
OpenVPN Endpoint + config:    (if OpenVPN)
GRE Public IP:                (if GRE/Plain) -- protocol 47, no port
Tunnel IPv6 Link-Local:       (preferred for BGP session)
Tunnel IPv4 Address:          (if using IPv4 BGP)

Peering Policy

BGP

Communities tagged on announce

(64511, 1..9)latency tier (set per-peer from measured RTT)
(64511, 21..29)bandwidth tier (we set 23, <100Mbps)
(64511, 31..34)encryption tier (34 = WireGuard / PFS, 31 = no encryption / GRE)
(64511, 41..53)region (per-POP: au-bne01 53 Pacific, us-lax01 44 NAM-W, us-ewr01 42 NAM-E, de-fra01/de-fra02/gb-cvt01 41 EU, jp-tyo01 52 East-Asia, hk-hkg01 52 East-Asia, sg-sin01 51 Asia-Southeast)
(64511, 10NN)ISO-3166-1 country (per-POP: 1036 AU, 1840 US, 1276 DE, 1392 JP, 1344 HK, 1702 SG, 1826 GB)

We also stamp our own informational large communities at ingress (in our import filters); they pass through unchanged on re-export, so peers and looking glasses see them:

(4242420842, 1, <peer-ASN>)learned via eBGP from this peer — value is the immediate eBGP neighbour’s ASN
(4242420842, 120, N)POP this route entered our network at — 1 au-bne01 (Brisbane), 2 us-lax01 (Los Angeles), 3 de-fra01 (Frankfurt), 4 jp-tyo01 (Tokyo), 6 us-ewr01 (New Jersey), 7 hk-hkg01 (Hong Kong), 8 sg-sin01 (Singapore)
(4242420842, 130, 1)learned directly from the origin AS (1-hop AS path at ingress)
(4242420842, 140, R)DN42 region we learned it in — same region codes as (64511, 41..53) above

Telephony (tel.dn42)

We have a DN42 phone number via the registry-managed tel.dn42 ENUM project — +04240842 (formatted +042-4-0842: the +042- prefix, the 424242xxxx block digit, plus the last four digits of our ASN).

Number+04240842 (+042-4-0842)
ENUM domain2.4.8.0.4.2.4.0.tel.dn42
NAPTR →sip:[email protected]
SIP / PBXAsterisk 18 (chan_pjsip) on au-bne01 — codecs opus / g722 / ulaw, UDP 5060

Any PBX doing ENUM lookups against tel.dn42 can dial 04240842, or call sip:[email protected] directly. Quick check: dig 2.4.8.0.4.2.4.0.tel.dn42 NAPTR.

No one’s home — the number answers with a short recorded greeting and hangs up.

Resources