Points of presence

Two sites, one LAN.

Each site takes member connections, hosts one route server and runs its own RPKI validator. An encrypted link joins the two into a single broadcast domain, so a member on FSN and a member on HEL are neighbours on the same LAN. A third site follows once these two carry production traffic.

Sites

Where

SiteFacilityRoute serverPeeringDBState
FSNHetzner Online FSN1, Falkenstein, GermanyRS1 2a0b:4e07:42::1fac/3249in service
HELHetzner Online HEL1, Helsinki, FinlandRS2 2a0b:4e07:42::2fac/3886in service

Between sites

What the link costs you

The two sites are joined over the public internet with an encrypted link. To keep the LAN at its full 1300 bytes end to end, packets crossing between sites are fragmented on the outer layer, which costs CPU and can show up as a throughput anomaly somewhere above a gigabit of traffic between the two. Traffic that stays inside one site is unaffected, and the whole effect disappears when a dedicated circuit replaces it.

The peering LAN block

2a0b:4e07:42::/48 is not announced to the internet and never will be. Nothing in the routing registries authorises it to any network, ours included, and an AS0 ROA to make every announcement of it invalid is with our address holder. Reaching a member means peering with that member, not routing towards the LAN.