Running Your Own As: BGP on FreeBSD with FRR, GRE Tunnels, and Policy Routing

blog.hofstede.it

113 points by todsacerdoti 8 hours ago


tw04 - 7 hours ago

Not to nitpick, but the title should have AS capitalized. It’s confusing with the current capitalization.

mark_round - 5 hours ago

If you'd like to experiment with running your own AS in private address space, connecting to a friendly network of geeks over wireguard tunnels, check out DN42 https://dn42.dev/Home.

It's a great way to explore routing technologies and safely experiment with your own AS, running the same protocols as the "real" Internet, just in private space.

If you do get set up, give me a shout (https://markround.com/dn42), I'd be happy to peer with you if you want to expand beyond the big "autopeer" networks :)

candiddevmike - 6 hours ago

I was hoping with IPv6, getting an address space as an individual would go back to how it was in the early IPv4 days, but alas you need to be a multihomed individual with tons of usage instead of just a sophisticated netzien that wants to own their block.

mvanbaak - 5 hours ago

`-rxcsum -txcsum -rxcsum6 -txcsum6 -lro -tso`

Why disable all offloading? It's not explained anywhere.

rmoriz - 6 hours ago

I do a "light" version of this, but without running a public AS and using WireGuard for tunneling my public IPv4 subnet into my homelab (proxmox cluster).

Just running bird on my VPS to announce my routes to the upstream over a private link.

DarkFuture - 6 hours ago

I looked into buying my own IP space from that IP auction site, an IPv4 C-class costs around $10,000. What stopped me was finding out I also to register with RIPE and pay the LIR annual fee, costing hundred Euros per month or so, even if I wasn't yet ready to use the IP space (I wanted to setup a basic Anycast IP without Cloudflare with help of VPS host who said they can help and had multiple locations around world).

rnhmjoj - 5 hours ago

> MSS clamping is non-negotiable with tunnels. Every layer of encapsulation eats into the MTU.

Can this tunnel be avoided somehow? If I have to choose between owning my prefix and having 1500 MTU, I'd probably take the latter: MTU issues are so annoying to deal with, and MSS-clamping doesn't solve all of them.

direwolf20 - 4 hours ago

iFog and Lagrange Cloud, naturally.

I am always very curious why these operations exist. ISPs for the very specific niche of hobbyists who want to run ASNs.

- 4 hours ago
[deleted]
rmoriz - 6 hours ago

Just a reminder, that the basic fees at RIPE are 2-3x the fees at ARIN which hurts individuals, SOHO and multihomed not-for-profit institutions.

fee schedules FYI

- ARIN 2026 PDF: https://www.arin.net/resources/fees/images/2026feeschedule.p...

- RIPE 2026 : https://www.ripe.net/membership/payment/

Enthusiasts, trainees and small orgs are paying a lot more with RIPE.

dorianmariecom - 6 hours ago

how much does it cost?

shon - 6 hours ago

[flagged]