GOpenCNR hosted ASN and public pool terms
How GOpenCNR meets the public internet through hosted ASNs, public pools of PA space from sponsoring LIRs and public exposure granted by GOpenCNR Community Council motion, what each pool's policy decides, and what a member owes for what it announces.
What these terms cover
GOpenCNR is a private network. Its own ranges are not routed on the public internet, and its hubs forward only packets whose source and destination both lie inside GOpenCNR ranges or a named interconnect. These terms cover the public-internet package, the part of GOpenCNR that the public internet can reach:
- Hosted ASNs: a member's public ASN and the public address space it holds, announced to the public internet through GOpenCNR.
- Public pools: public IPv6 and IPv4 address space, from which members receive public addresses.
- Public exposure: a public address routed one to one through GOpenCNR to a member's router, so that services the member chooses can be reached from the internet.
Reaching the internet from GOpenCNR's private addresses is not part of this package. It goes only through a licensed exit operator, for members who opt in, under the licensed exit operator terms.
You accept these terms when you apply for any of the three, in addition to the GOpenCNR terms, the acceptable use policy and the network participation agreement. They sit under the general terms of service, which carry warranty, the limits of liability and the governing law.
The announcement edge
Every public announcement leaves GOpenCNR at one edge, through one BGP-capable provider in the EU that carries it to the rest of the internet. Tier 0 holds no public ASN for members. A hosted member brings its own public ASN, and GOpenCNR carries that ASN's BGP session through to the provider. Public pool space is announced from the same edge, with the origin its sponsoring LIR's ROAs authorise.
The edge is single. When it or the provider fails, public reachability fails with it. Traffic inside GOpenCNR is not affected.
Hosted ASNs
- Who. A member that holds a public ASN and public address space of its own. The ASN is recorded in the registry once the member has proved it holds it, by an RPKI Signed Checklist or a token in its aut-num object. A recorded ASN stays the member's: it is recorded, never allocated.
- What we do. We carry the BGP session of the member's own ASN through GOpenCNR to the provider at the announcement edge, which announces the member's prefixes to the public internet with the member's ASN as their origin, and we carry their traffic through GOpenCNR between the provider and the member's routers.
- What is announced. Only prefixes that are registered to the member, or that it is authorised to announce, and that a valid ROA in the public RPKI covers. A route that is RPKI-invalid is not announced.
- PI space is routed, never shared. A member that holds PI space may have it routed through GOpenCNR. It cannot donate any of it, because RIPE policy does not let PI space be sub-assigned to other organisations, and no public pool asks it for a share.
- Ending it. The member may stop hosting at any time, and its announcements are withdrawn. We may end it on the grounds under "Suspension and withdrawal" below.
Public pools
- What they are. Pools of public IPv6 and IPv4 address space. A public pool is created only by a motion of the GOpenCNR Community Council, and the same council makes each pool's policy by motion.
- Where the space comes from. Only from PA space that sponsoring LIRs provide under the LIR sponsorship agreement. RIPE policy lets an LIR assign PA space to others, with the LIR registering each assignment; it does not let PI space be sub-assigned to other organisations. So PI space never enters a public pool.
- Every assignment is registered. Before an address from a public pool is routed to a member, the sponsoring LIR registers the assignment in the RIPE Database. What the entry contains is set by RIPE policy, and the RIPE Database is public.
- The share. A public pool may ask members whose space GOpenCNR hosts for a share of that space. How large the share is, and how it can be reduced, is set by each public pool's policy, made by GOpenCNR Community Council motion and shown to you before you apply. These terms set no share. A share can only come from space that RIPE policy allows to be assigned to others, which is PA space, contributed through its LIR under the LIR sponsorship agreement.
- Addresses from a public pool reach members through public exposure, below.
Public exposure
- Applying. A member applies for a public address for services of its choice, and names them in the application.
- Each grant is a motion of the GOpenCNR Community Council. The council decides it under the GOpenCNR charter rider and the shared part of the charter, and it is recorded in the transparency log. Like every governance record, the motion stays public for good.
- One to one. The public address, from a public pool or from space GOpenCNR hosts, is routed through GOpenCNR to the member's router, one address to one router. Nobody else's traffic shares it.
- Your abuse contact is published for every public address you hold: in GOpenCNR's registry and in the RIPE Database entry for its assignment.
- It is not an exit. Public exposure makes your services reachable from the internet. It gives your private GOpenCNR addresses no way out to the internet; that goes only through a licensed exit operator you opt into. You may still expose your own services on your own internet uplink, outside GOpenCNR; that is not an exit and needs nothing from these terms.
A public address does not become yours
Like all address space in GOpenCNR, a public address is allocated for use, never owned and never sold. The PA space stays the sponsoring LIR's, and the RIPE NCC remains the registry for it. Your assignment lasts as long as the grant does, and RIPE policy, the sponsor's duties as an LIR and these terms decide what happens to it.
Your duties
For everything announced or exposed for you under these terms:
- Abuse. Keep the abuse contact published for it working. Act on reports within 48 hours, or within 12 hours for an active attack (active phishing, malware, scanning, a live leak). Reports are acknowledged within 24 hours, and Tier 0 steps in where you do not act, under the abuse and sanctions policy.
- RPKI. Keep the ROAs for your hosted space current and exact, with no maxLength wider than what is announced, as RFC 9319 recommends.
- No spoofing. Send to the internet only packets whose source address is yours under these terms. GOpenCNR's per-tunnel source checks enforce this as well.
- Your own routes only. Announce through GOpenCNR only your own prefixes, never routes learned from another network.
- The RIPE and upstream policies. Keep RIPE's policies for your space and your ASN, the policies of the provider at the announcement edge, and the acceptable use policy.
- Accurate data. Keep your contacts and the data the sponsoring LIR needs for your assignment current, and tell Tier 0 at once if you lose the right to an ASN or to space you have had announced.
- What you expose. Open only the services you applied for, and keep them secure and patched. Whatever you expose is reachable from the whole internet.
Suspension and withdrawal
- The sanctions ladder. The steps of the abuse and sanctions policy apply to what is announced or exposed under these terms as to any route: a warning, a reduced max-prefix, routes suppressed at the hubs, depeering from all Tier 0 nodes, reclamation. Each step lasts at least 7 days before the next. Routes suppressed inside GOpenCNR are no longer announced to the internet either.
- Emergency suspension. Tier 0 may suspend public exposure or a hosted announcement at once only in the cases where the general terms of service let us act first, such as an attack on GOpenCNR or on other networks, malware or phishing, or a binding order of a court or an authority. An emergency suspension only suspends or tightens. It lapses after 90 days unless it is reaffirmed, and after one year at the latest.
- When the RIPE NCC or the announcement edge requires it. If the RIPE NCC or the provider at the announcement edge requires an announcement to stop, it stops when they require, and you receive a statement of reasons no later than then.
- Withdrawal by motion. Public exposure is withdrawn as it is granted, by a motion of the GOpenCNR Community Council.
- When the space leaves its pool. If a sponsoring LIR withdraws space or its agreement ends, the addresses in that space are withdrawn at the end of the notice the sponsor gives. You are told as soon as we know, and you may apply for an address in another public pool.
- Reasons and appeal. You receive a statement of reasons for every measure, no later than when it takes effect, unless the law forbids telling you. A step of the ladder or an emergency suspension may be appealed within six months to the GOpenCNR Registry Council, and whoever took the decision does not vote on the appeal. While Tier 0 still holds that council's seats, Tier 0 reviews the appeal itself and says so in its answer. The courts remain open to you whatever the outcome.
- Afterwards. When an announcement or an exposure ends, it is withdrawn from the internet first; the sponsoring LIR then removes the assignment from the RIPE Database.
What is public, and what we pass on
- Public: hosted prefixes with their origin ASN, the grants of public exposure, your abuse contact for public space, and the RIPE Database entries for assignments. Your handle is shown, and a person's name only by their choice, as the registry data policy sets out. What is announced to the internet is also visible in the routing tables and route collectors of the internet. Public registry data, its history and the motions that grant exposure stay public for good.
- Passed to the sponsoring LIR: what an assignment needs under RIPE policy, including your handle, the prefix and your abuse contact (Art. 6(1)(b) GDPR). The LIR is the controller for what it registers, and the RIPE NCC for the RIPE Database.
- The rest of what we process about you is in the GOpenCNR privacy notice.
Fees and service levels
These terms set no fee. Anything a public pool asks in return, the share and the ways to reduce it, is in that pool's policy.
No service level applies. Reachability from the internet depends on one edge and one provider. No availability, latency or reachability from any particular network is owed.
Everything else
Warranty and the limits of our liability are as the GOpenCNR terms and the general terms of service set them out. These terms change only as the general terms set out under "New versions of these terms": a material change is emailed to your address at least six weeks before it takes effect, and at your next sign-in you are asked to accept the new version, which is shown to you in full and linked in the document archive, without a list of what changed. A new version applies to you only once you accept it. What applies if you have not accepted it when the six weeks are over is set out in the GOpenCNR terms, under "Your content, your account and these clauses"; the restriction does not itself end what is announced or exposed for you. Every version stays in the document archive.