The autonomous system of Whisper Security.
We hold the IPv6 allocation 2a04:2a00::/31 from the RIPE NCC and run
AS219419 to originate and route it directly. The addressing, the routing policy, the DNS,
and the per-agent identity space all run on infrastructure we operate, under numbers registered to us.
None of it is rented from a platform.
| ASN | AS219419 (whisper-as) |
|---|---|
| Operator | Whisper Security |
| Holder | viaGraph b.v. (ORG-VB155-RIPE) |
| RIPE LIR | nl.viagraph |
| Allocation | 2a04:2a00::/31 |
| Originated | 2a04:2a00::/32 · 2a04:2a01::/32 |
| Ping | 2a04:2a00::1 (anycast, answered by both edges) |
| IP version | IPv6 only |
| RPKI | ROAs, origin AS219419, maxLength 32 |
| IRR | as-set AS219419:AS-WHISPER |
| Transit | Vultr AS20473 · Route64 AS212895 |
| Peering | open |
| Look us up | RIPE · PeeringDB · bgp.tools · RIPEstat |
The allocation is a single /31, operated as two routed /32 halves:
2a04:2a00::/32 | Infrastructure. Edge routers, anycast service addresses (authoritative DNS, the DNS64/NAT64 resolver), and our own office and staff access. |
|---|---|
2a04:2a01::/32 | Identity. One /128 per agent, assigned and registered individually in the RIPE database. |
The plan is published because it is, by construction, public. It can be read straight from the routing table and the registry. The specific assignments within it are not.
We originate 2a04:2a00::/32 and 2a04:2a01::/32, and nothing else. Every
announcement carries a matching RPKI ROA pinned to maxLength /32 (RFC 9319); there is
no slack for a more-specific to be forged under our origin. Each edge runs a validating resolver and discards
RPKI-invalid routes on import. The prefixes are originated from more than one independent edge; the loss of
any single one is not visible from the outside.
That is the full set of MANRS actions: prefix filtering (the IRR as-set plus RPKI), anti-spoofing (we source only the registered space we announce), coordination (a published security contact and PeeringDB), and global validation (a Routinator ROV cache on every edge).
The network is IPv6-only. There is no IPv4 to announce, and acquiring some is not on the roadmap. The agent estate is native v6, and the legacy v4 Internet is reached through NAT64.
The two /32s are originated from two independent edges. The readout below is taken
live off BIRD on each router — not a status page kept by hand.
| ams · NL | yto · CA | |
|---|---|---|
| Session | — | — |
| Originated | — | — |
| Received | — | — |
| RPKI ROV | — | — |
ns1.whisper.online and ns2.whisper.online are authoritative for our zones and for
the reverse of the entire /31 (delegated as the two /32 zones a /31
requires). An anycast resolver provides DNS64, paired with NAT64, so IPv6-only hosts reach the remaining
IPv4 Internet without carrying any IPv4 of their own.
Our policy is open, though we are transit-only today (Vultr AS20473,
Route64 AS212895) and not yet on an IXP fabric. Build filters from the as-set
AS219419:AS-WHISPER — it expands to {AS219419} only, no customer cone —
published in PeeringDB. To bring up a session, write to
peering@whisper.security.
On a session you will see at most two prefixes — 2a04:2a00::/32 and
2a04:2a01::/32, origin AS219419, both RPKI-valid (ROA maxLength 32) — and no
IPv4, so set max-prefix 2. We drop RPKI-invalids on import and ask the same of you;
MD5 and BFD on request.
AS219419 is operated by Whisper Security. Reach the right desk:
| Peering | peering@whisper.security |
|---|---|
| NOC / ops | noc@whisper.security |
| Abuse & security | security@whisper.security · security.txt · disclosure policy |
Run day-to-day by Kaveh Ranjbar (kaveh.org) and Alireza Saleh; the role addresses above reach us both.