Information

Information about Routing policy, BGP Communities and ROA

Routing Policy
BIRD is used as the routing daemon with ROA and dn42 subnet filtering enabled.
The following metrics are automatically examined in the described order to choose through which peer a prefix is routed:
  1. Direct routes to prefixes belonging to peers are always chosen
  2. The network with the lowest BGP path length
  3. If the prefix BGP path length is the same accross multiple peers, the network with the lowest latency is chosen
BGP Communities
The following BGP Communities are supported:
ROA Validation
Route Origin Authentication (ROA) is used to validate if the originating AS is allowed to advertise a prefix.
Frequently asked questions

Peering with Kioubit

There are a couple of things you can verify:
  1. If you just recently registered with the registry, wait about a day until the ROA filtering is updated across all DN42 nodes
  2. Ping the BGP-Endpoint address which can be found on the Dashboard to see if the OpenVPN/WireGuard connection is working
  3. Check if the BGP Session is established
  4. Check if your source address is set correctly. You can do this for example with the command: ip route get 172.20.14.33 and by looking at what "src" address is shown there. It should be an IP address that you are advertising via BGP
  5. Make sure you have set the systctl rp_filter value to 0 (required)
  6. Check the network troubleshooting tool which you can find on the services page

WireGuard will not attempt a handshake with the remote side if no traffic needs to be sent. For testing, try to ping the remote tunnel IP to generate some traffic and force the handshake process.

Yes, people have successfully peered with the Kioubit network using:
  • Mikrotik routers (confirmed with RouterOS v7 and higher)
  • Ubiquiti routers (confirmed with Ubiquiti EdgeRouter-X)
  • FRR bgp daemon software
  • BIRD bgp daemon software
  • OPNsense software in combination with FRR
  • Quagga bgp daemon software (not recommended)

Yes, peers from dynamic IP addresses are fully supported.

Check the traceroute and the troubleshooting tool which you can find on the services page. If you find that an address is not reachable, it does not mean that there is a problem with the Kioubit Network. Sometimes there might be routing issues elsewhere or the IP address may not be online.

Due to the nature of the DN42 network, which is built on top of the public internet using VPN technologies, high ping times are common. The Kioubit Network is constantly trying to optimize latency and maitains the lowest latency metrics across dn42.

Router setup

Find the tutorial here: Learn more

Find the tutorial here: Learn more

Find the registry here: Learn more