Whisper whisper

AS219419

The autonomous system of Whisper Security.

We hold the IPv6 allocation 2a04:2a00::/31 from the RIPE NCC and run AS219419 to originate and route it directly. The addressing, the routing policy, the DNS, and the per-agent identity space all run on infrastructure we operate, under numbers registered to us. None of it is rented from a platform.

The numbers

ASNAS219419 (whisper-as)
OperatorWhisper Security
HolderviaGraph b.v. (ORG-VB155-RIPE)
RIPE LIRnl.viagraph
Allocation2a04:2a00::/31
Originated2a04:2a00::/32  ·  2a04:2a01::/32
Ping2a04:2a00::1  (anycast, answered by both edges)
IP versionIPv6 only
RPKIROAs, origin AS219419, maxLength 32
IRRas-set AS219419:AS-WHISPER
TransitVultr AS20473  ·  Route64 AS212895
Peeringopen
Look us upRIPE · PeeringDB · bgp.tools · RIPEstat

Addressing

The allocation is a single /31, operated as two routed /32 halves:

2a04:2a00::/32Infrastructure. Edge routers, anycast service addresses (authoritative DNS, the DNS64/NAT64 resolver), and our own office and staff access.
2a04:2a01::/32Identity. One /128 per agent, assigned and registered individually in the RIPE database.

The plan is published because it is, by construction, public. It can be read straight from the routing table and the registry. The specific assignments within it are not.

Routing & origin security

We originate 2a04:2a00::/32 and 2a04:2a01::/32, and nothing else. Every announcement carries a matching RPKI ROA pinned to maxLength /32 (RFC 9319); there is no slack for a more-specific to be forged under our origin. Each edge runs a validating resolver and discards RPKI-invalid routes on import. The prefixes are originated from more than one independent edge; the loss of any single one is not visible from the outside.

That is the full set of MANRS actions: prefix filtering (the IRR as-set plus RPKI), anti-spoofing (we source only the registered space we announce), coordination (a published security contact and PeeringDB), and global validation (a Routinator ROV cache on every edge).

The network is IPv6-only. There is no IPv4 to announce, and acquiring some is not on the roadmap. The agent estate is native v6, and the legacy v4 Internet is reached through NAT64.

DNS

ns1.whisper.online and ns2.whisper.online are authoritative for our zones and for the reverse of the entire /31 (delegated as the two /32 zones a /31 requires). An anycast resolver provides DNS64, paired with NAT64, so IPv6-only hosts reach the remaining IPv4 Internet without carrying any IPv4 of their own.

Peering

Our policy is open, though we are transit-only today (Vultr AS20473, Route64 AS212895) and not yet on an IXP fabric. Build filters from the as-set AS219419:AS-WHISPER — it expands to {AS219419} only, no customer cone — published in PeeringDB. To bring up a session, write to peering@whisper.security.

On a session you will see at most two prefixes2a04:2a00::/32 and 2a04:2a01::/32, origin AS219419, both RPKI-valid (ROA maxLength 32) — and no IPv4, so set max-prefix 2. We drop RPKI-invalids on import and ask the same of you; MD5 and BFD on request.

Operational contacts

AS219419 is operated by Whisper Security. Reach the right desk:

Peeringpeering@whisper.security
NOC / opsnoc@whisper.security
Abuse & securitysecurity@whisper.security  ·  security.txt  ·  disclosure policy

Run day-to-day by Kaveh Ranjbar (kaveh.org) and Alireza Saleh; the role addresses above reach us both.