Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE
Apps / GOpenCNR / GOpenCNR acceptable use policy

GOpenCNR acceptable use policy

What GOpenCNR's addresses, routers and tunnels may not be used for, what every holder owes the network when abuse is reported, and how a case moves from the holder to Tier 0.

Last updated 1 October 2026 Auf Deutsch lesen →

On this page

  1. What this covers
  2. No scanning between members
  3. Closed space stays within its audience
  4. Keep your abuse contact working
  5. Addresses and routing
  6. No attacks on the network
  7. Nothing unlawful
  8. What is not our business
  9. How abuse is handled
  10. Consequences

What this covers

This policy applies to every allocation, ASN, route, router, hosted router, device, service and audience in GOpenCNR, and to every account and API key used with it. You accept it together with the GOpenCNR terms. It adds to the GOpenCSR acceptable use policy and to the acceptable use section of the general terms rather than replacing them.

A holder may set stricter rules for its own network and its sub-holders. It may not relax these.

No scanning between members

  • Do not scan other members. No port scans, address sweeps or vulnerability scans of space you do not hold, from inside GOpenCNR or through an interconnect.
  • Check your own space instead. Tier 0 offers a scan of your own space from a hub, which you ask for yourself, so that you can see what is exposed without anybody scanning strangers.
  • Research needs consent. Measurement or research that touches another holder's space needs that holder's consent first. GOpenCNR's own measurement probes run only between members who opted in.

Scanning counts as an active attack for the times under "How abuse is handled".

Closed space stays within its audience

A closed prefix is reachable only by its audience, and keeping it so is every member's duty, not only the hubs'. The prefix itself, its holder's handle, its origin ASN and its ROA are public like any other; what is closed is who can reach it, and the audience and the routes to it stay private.

  • No traffic across the boundary. Do not pass traffic to a closed prefix from anybody outside its audience, or from it to anybody outside, whether by routing, a proxy, NAT, a port forward or a tunnel.
  • No leaked routes. Never pass on a closed route you receive: not on a direct session, not to a transit member, a community hub or an interconnect, and not into any other network.
  • No shared keys. Inner WireGuard keys reach only the members allowed to talk to each other. Do not copy, export or share them, or a configuration that carries them.

A closed route that appears outside its audience is cut by the hubs at once, a case opens, and the holder of the prefix is told. A live leak counts as an active attack.

Keep your abuse contact working

Every holder has a public abuse relay address in GOpenCSR, which forwards reports to the holder without showing anybody the holder's own address.

  • Keep it delivering to somebody who reads what arrives and acts on it.
  • Act on a report about your space within 48 hours, or within 12 hours where the attack is active: active phishing, malware being served, scanning, or a live leak.
  • Tell the case what you did. If you do not act in time, Tier 0 steps in.

Addresses and routing

  • Not fdc0:09ff::/32. It is reserved, and the hubs drop traffic to and from it.
  • No exit and no public exposure. GOpenCNR carries traffic only between GOpenCNR's ranges and named interconnects. Never use it to carry traffic between the internet and other members: do not offer other members a way out through your connection, and do not make other members' addresses or services reachable from the internet through yours. You may still expose your own service on your own internet uplink, outside GOpenCNR. Routing between the public internet and GOpenCNR is offered only under the hosted ASN and public pool terms and the licensed exit operator terms.
  • No spoofing. Send traffic only from addresses inside your own registered space.
  • Announce only what you hold. Announce only your own space, each prefix with its route object and from the origin it names. Announcing somebody else's space, quarantined space or Tier 0's service addresses is a hijack.
  • Nothing but GOpenCNR's ranges and named interconnects. Route no other prefix into GOpenCNR: no default route, no public space and no other private ranges.
  • Blackhole only your own prefixes.

The hubs enforce these rules and refuse what breaks them. Trying to get around them is a breach in itself, whether or not it works.

No attacks on the network

Do not attack, overload or probe the hubs, the registry, the RPKI repository and its RTR caches, the resolvers, the transparency log or other members, except as the GOpenCNR security and disclosure policy allows. Do not forge or replay registry changes, bundles or RPKI objects, and do not alter the agent to get around a filter, a limit or a sanction.

Do not open new holders, ask for sub-allocations or move space to get around a restriction, a sanctions hold or a limit. Do not harvest registry data beyond what the registry data policy allows.

Nothing unlawful

Do not use GOpenCNR for anything unlawful under the law that applies to you or to us, including phishing, distributing malware, controlling botnets, denial-of-service attacks and unsolicited bulk messages.

Child sexual abuse material is always reported to the police or the Bundeskriminalamt, with what we hold about it that is not telecommunications traffic data. Traffic data is passed on only under a legal order based on a law that expressly refers to telecommunications (Section 3(3) TDDDG).

What is not our business

Tier 0 does not police content. Holders answer for what they run and host on their addresses, and the network forwards it without looking. We act on unlawful use through cases: a report of unlawful content goes to the holder, and a holder who ignores a well-founded report can be restricted, as any upstream provider would restrict a customer. We do not act on content somebody dislikes, on disagreement, on criticism of anybody, including of us, or on lawful speech. Where a court or an authority orders us to act, we act.

How abuse is handled

The abuse and sanctions policy sets out the one case system GOpenCSR runs for names and addresses. For GOpenCNR:

  1. Report. Anyone may report abuse, by email to abuse@gplatform.org, to the holder's abuse relay address, or through the report form in GOpenCSR, which every public allocation page links to. Name the address or prefix, say what is happening and include what shows it. We acknowledge every report within 24 hours.
  2. The holder acts first, within 48 hours, or 12 hours where the attack is active.
  3. Tier 0 steps in when the holder has not acted in that time, and may take the steps of the sanctions ladder: a warning, a reduced max-prefix limit, routes suppressed at the hubs, depeering from all of Tier 0's nodes, and reclaiming an allocation. Each step lasts at least 7 days before the next.
  4. Emergencies. Where an active attack cannot wait, Tier 0 may suspend at once under its emergency power, which only suspends or tightens and lapses after 90 days unless it is reaffirmed.
  5. Every action is notified and can be appealed, as the GOpenCNR terms describe, and every sanction is recorded in the transparency log.
  6. A restriction is lifted once the abuse has stopped and its cause has been dealt with.

Investigating a case. The hubs keep per-member counters, fine-grained for 90 days and then as daily totals until 12 months, and no records of traffic. Only inside an open case may Tier 0 sample the traffic of the reported source, for at most 7 days: one packet in 1,000, recording source, destination, port and size, never content. The samples are deleted when the case closes. GOpenCNR and the secrecy of telecommunications explains the limits.

A reporter's identity is not passed to the holder unless the reporter agrees or the law requires it. Requests from courts and authorities follow the authority request policy. We disclose nothing of our own accord except to prevent an imminent danger to life or limb, and even then no telecommunications traffic data. Every request and its outcome are counted in the joint transparency report published every six months.

Consequences

Breaking this policy can lead to the steps of the sanctions ladder, up to reclaiming an allocation, to an emergency suspension where an attack is active, to API keys being revoked, and, where the breach is serious or repeated, to consequences for the account under the GOpenCSR terms.

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAdvisory
  • GControl
  • GPlatform Control
  • GPlatform SSO
  • GPlatform Billing

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany