Daniel's been thinking about what happens after you cross the BGP threshold we talked about in the fiber episode — the moment a customer stops being a leaf node and becomes a mini ISP. His question is: how feasible is it to go all the way? Become a literal one-person operation with your own Autonomous System Number, your own IP space, your own place in the global routing table. He wants to know what the regulatory hurdles actually look like, whether they're as bad as they sound, and what you actually gain from upstream access to peering points where traffic moves across continents. He was surprised to discover there's apparently a whole underworld of hobbyists who do exactly this — run personal ASNs, peer at internet exchanges, announce their own prefixes. So the episode is: who are these people, what do they get out of it, and is the presumed headache real or overblown?
The short answer is the headache is real but front-loaded, and the benefits are tangible in ways that surprise people. An Autonomous System Number is your network's identity on the global internet — a sixteen-bit or thirty-two-bit number that identifies your network as a distinct entity participating in BGP, the Border Gateway Protocol. When you have an ASN, you're not just consuming routes anymore. You're announcing them. You're telling the entire internet: here is my IP space, here is how to reach me, and here is the path through me to other networks I'm connected to.
So it's the difference between renting and owning. Most people are tenants on someone else's network infrastructure. An ASN is a deed.
That's the metaphor. You flip from consumer to participant in the internet's routing fabric. A one-person ISP is the logical endpoint — someone with their own ASN, their own IP address space, and at least one upstream transit provider who accepts their BGP announcements and carries their traffic to the rest of the world.
Which sounds like an enormous amount of work for what is, at the end of the day, a hobby.
It does. But let me walk through what it actually takes, because the reality is more manageable than the reputation suggests.
All right, walk me through it. What's step one?
Step one is getting the ASN itself. You apply to one of the five Regional Internet Registries. ARIN covers North America, RIPE NCC covers Europe and the Middle East, APNIC for Asia-Pacific, LACNIC for Latin America, AFRINIC for Africa. Each has its own requirements and fee structure, and this is where the experience diverges sharply depending on where you live.
How sharply?
ARIN charges five hundred dollars a year for a small ASN, and they require you to demonstrate a real need — you have to show you're multi-homed or have a unique routing policy. They're not handing out ASNs to hobbyists who just want to learn BGP. RIPE NCC, on the other hand, lets you become a Local Internet Registry member for around fifty euros a year, and their justification requirements are looser. Europe is basically hobbyist-friendly territory.
Fifty euros versus five hundred dollars. That's not a small gap.
It's an order of magnitude, and it shapes where the hobbyist community clusters. You see far more personal ASNs in Europe than in North America, purely because the regulatory and cost barriers are lower.
So step one is pick your RIR and pay your money. What's step two?
Step two is IP address space. You need your own block of IP addresses to announce via BGP. There are two flavors: Provider Independent space — PI space — allocated directly to you by the RIR and staying with you regardless of which upstream provider you use. The other is Provider Aggregatable space, PA space, which comes from your upstream provider and is part of their larger block. PI space is the gold standard for independence, but it's expensive and requires justification. PA space ties you to your provider but is simpler to get.
And IPv4 versus IPv6?
IPv4 space is scarce and expensive. A slash twenty-four — two hundred fifty-six addresses — can cost thousands on the transfer market. IPv6, by contrast, is abundant. RIRs will happily allocate you a massive block for very little money. Most hobbyists running personal ASNs are primarily running IPv6, with maybe a tiny slice of IPv4 for legacy compatibility. The future is v6, and for a hobbyist, v6 is where the interesting work happens anyway.
So you've got your ASN, you've got your IP space. Now you need someone to actually carry your traffic.
Step three — and this is the hardest part. You need at least one upstream transit provider willing to peer with you and accept your BGP announcements. Most major transit providers have minimum commitments — they want to sell to businesses, not someone running a network out of their apartment. A typical contract might require a minimum commit of a hundred megabits or a gigabit per second.
Which a hobbyist is not.
Right. But there are smaller providers and hobbyist-friendly transit companies that specifically serve this niche. Companies like Hurricane Electric offer free IPv6 transit with BGP peering — they've been a major entry point for personal ASN operators for years. There are also virtual transit providers and tunnel brokers that let you establish BGP sessions over a GRE tunnel or VPN, meaning you don't even need a direct physical connection to your upstream. You can peer over your existing residential internet connection.
So you're running BGP over your Comcast cable modem.
In principle, yes. Though Comcast might have opinions. Which brings us to step four — the technical setup. You need a router capable of running BGP. This could be a used enterprise router, a MikroTik — popular in the hobbyist community because it's affordable with full BGP support — or you can run BGP on a Linux box using software like Bird or FRRouting. A lot of hobbyists go the Linux route because it's flexible, free, and lets you learn the protocol at a deeper level.
Bird and FRRouting. These are open source BGP daemons.
Yes. Bird in particular is widely used — it runs on a lot of internet exchange route servers. You configure it to establish BGP sessions with your upstream providers, announce your prefixes, and apply filtering policies. And that filtering part is critical. You need to make sure you're only announcing the prefixes you actually own. One wrong configuration and you could announce someone else's IP space — a route hijack, and it's a very big deal.
Which brings us to ongoing maintenance. Once it's set up, what does the day-to-day look like?
Once it's stable, the maintenance is surprisingly light. You monitor your BGP sessions, set up alerts if a session goes down, respond to abuse complaints — rare if you're the only user — and keep your RIR registration data current. You also deal with RPKI, the Resource Public Key Infrastructure, which is becoming mandatory at some RIRs.
RPKI — explain that.
RPKI is a cryptographic system that lets network operators prove they're authorized to announce specific IP prefixes. You create a Route Origin Authorization — a ROA — that says, this ASN is allowed to announce this prefix. Other networks can validate your announcements against the ROA database and reject anything that doesn't match. It's a defense against route hijacking, both accidental and malicious. ARIN now requires RPKI for new allocations, and RIPE is moving that direction. For a hobbyist, setting up RPKI is another step in the initial configuration, but once it's done, it mostly just works.
So let's put a number on this. Total cost, all in.
A few hundred to a few thousand dollars upfront for hardware, plus recurring fees. In Europe with RIPE, you're paying maybe fifty euros a year for the ASN, plus transit costs — which could be as low as zero if you're using a free IPv6 tunnel from Hurricane Electric. In North America with ARIN, you're paying five hundred dollars a year just for the ASN, plus transit, plus IP space fees. The time investment is significant up front — dozens of hours to get everything configured, tested, and stable — and then a few hours a month for maintenance.
Dozens of hours. That's not nothing.
It's not. But it's also not insurmountable. And this is where the hobbyist community comes in, because these are people who genuinely enjoy this work. The process itself is the point.
All right, so that's the process. Who are these people, and what's driving them?
The hobbyist community is small but surprisingly active. Ben Cox, who goes by benjojo online, has written extensively about running a one-person ISP — his blog posts are basically the canonical reference for anyone wanting to do this. There are communities on Reddit and on mailing lists like NANOG, where professionals and hobbyists mix. There's also a dedicated Personal ASN community that shares configuration tips and transit provider recommendations.
What's motivating them? From the outside, this looks like a lot of work for not much obvious payoff.
Three main drivers. The first is technical curiosity. BGP and interdomain routing are black magic to most people, even many network engineers. Running your own ASN is the best way to learn it hands-on. You can read about BGP in a textbook, but until you've configured a session, announced a prefix, and watched it propagate across the global routing table, you don't really understand it.
That tracks. What's the second?
The internet citizenship angle. Having your own ASN means your traffic isn't just consumed — you're part of the routing fabric. Your network has an identity. When someone runs a traceroute to your IP, they see your ASN in the path. There's a kind of sovereignty to it. You're not renting space on the internet anymore. You're a peer.
It's the ham radio license of the internet.
That's exactly the analogy. And like ham radio, it attracts people who want to understand infrastructure at a fundamental level, who get satisfaction from being part of the system rather than just a user of it. The third driver is practical benefits. Control over your own IP addressing — you're not tied to your ISP's address space, so you can switch providers without renumbering your entire network. The ability to multi-home across multiple ISPs for redundancy — if one upstream goes down, your BGP configuration automatically fails over to the other. And then there's the peering advantage, which is underappreciated.
This is what Daniel was asking about — upstream access to peering points where traffic moves across continents. What does that actually get you?
If you can get access to an Internet Exchange Point — an IXP — you can peer directly with major content providers. Netflix, Google, Cloudflare, Amazon, Microsoft — they all have presence at major IXPs. Instead of your traffic going through your upstream transit provider, then through maybe two or three more transit networks, then finally reaching Netflix's servers, it goes directly from your router to Netflix's router at the exchange. One hop.
Which means lower latency.
Dramatically lower. And higher throughput, because you're not sharing a congested transit link with thousands of other customers. Your Netflix streams don't go through a transit provider's overloaded peering link. Your latency to Google drops from maybe fifteen milliseconds through transit to two or three milliseconds over direct peering.
Two milliseconds. That's almost absurd for a home connection.
It is. And it's measurable. Hobbyists who peer at exchanges like AMS-IX in Amsterdam or LINX in London have posted traceroutes showing single-digit millisecond latency to major content providers. That's not something you get from a residential ISP, no matter how good their network is.
But there's a catch, because there's always a catch.
The catch is that most IXPs require physical presence at their facility. You need colocation space, a switch port, and a cross-connect to the exchange fabric. That adds cost — colo space might be fifty to a hundred dollars a month for a single rack unit, plus the cross-connect fee, plus the IXP membership fee. Some IXPs have remote peering options or virtual IXP services that lower the barrier, but it's still not trivial.
So the peering advantage is real, but it's not free, and it's not something you can do from your apartment without additional infrastructure.
Correct. And for a lot of hobbyists, the cost of colocation is where the budget starts to stretch. You're paying for rack space, power, and cross-connects. It's still not enormous — maybe a hundred to two hundred dollars a month all in — but it's real money.
What about people who want to learn BGP without any of this regulatory overhead? You mentioned a sandbox.
DN42. This is worth spending a minute on because it's how a lot of people start. DN42 is a fully decentralized, hobbyist-run network that mimics the global internet. It has its own ASN assignments, its own IP address space — private ranges, not public — its own BGP peering, its own DNS infrastructure. Over a thousand participants. You can set up BGP sessions, announce prefixes, configure filtering policies, peer with other participants — all without needing an ARIN approval or a transit provider or any real-world IP space.
So it's a flight simulator for BGP.
And it's useful. You can make all the mistakes you want in DN42 — announce the wrong prefix, break your BGP configuration, cause a routing loop — and the worst that happens is you annoy some hobbyists on a mailing list. You don't take down a bank's network. A lot of people spend months or years in DN42 before they make the jump to a real ASN.
Which brings us back to the central question. Is this worth it? You've laid out the costs, the complexity, the ongoing maintenance. You've also laid out the benefits — control, redundancy, direct peering, the satisfaction of being a first-class citizen on the internet. Where do you land?
It depends entirely on what you're optimizing for. If you just want faster Netflix, no — call your ISP and upgrade your plan. That's cheaper and easier. If you want to learn BGP at a deep level, or if you want control over your own addressing and routing in a way that no residential ISP will ever give you, then yes, it's worth it. The complexity is real but front-loaded. Once your ASN is set up, your BGP sessions are stable, your RPKI is configured, the day-to-day maintenance is minimal. The initial setup is the mountain. After that, it's a plateau.
The plateau being... you have your own little flag on the internet.
You have your own little flag on the internet. And for the kind of person who finds that appealing — and I count myself in this category — that's satisfying in a way that's hard to explain to someone who doesn't feel it.
I think I get it. It's the difference between visiting a country and having citizenship. Most people visit the internet. These people live there.
That's it.
So what about the risk side? We touched on route hijacking. How worried should a hobbyist be about accidentally breaking something?
Less worried than twenty years ago, thanks to RPKI and automated filtering. But the risk is not zero. If you misconfigure your BGP announcements and advertise a prefix that doesn't belong to you, and if your upstream provider isn't filtering properly, you could redirect traffic intended for someone else. Best case, your upstream notices and shuts down your session. Worst case, you cause a routing incident that affects real services.
And that's not theoretical.
It's not. Pakistan Telecom accidentally hijacked YouTube's prefixes in two thousand eight, and that was a national ISP with presumably competent engineers. A hobbyist operating from their apartment could absolutely make the same mistake. The difference now is that RPKI and route filtering at the upstream level make it much harder for a bad announcement to propagate widely. Most transit providers will reject announcements that don't match the ROA database. But you still need to be careful.
I think what's driving this community isn't really about practical benefits, even though those exist. It's about something more fundamental. The internet was originally designed as a network of peers — equal participants who could all originate and receive traffic on equal terms. Over time, it's become hierarchical. A few massive networks carry most of the traffic, and everyone else is a customer. Running a personal ASN is a way of reclaiming that original peer status, even if only symbolically. You're saying, I'm not just a consumer of the internet. I am the internet. Or at least a small piece of it.
That's a surprisingly philosophical take from someone who was just talking about BGP daemons.
The philosophy is part of it. You see it in the way these hobbyists talk about their networks. They're proud of their ASNs. They put them in their email signatures. They post traceroutes showing their own ASN in the path. It's a point of identity.
The ham radio operator with their call sign on a license plate.
And like ham radio, it's a shrinking niche. The regulatory trend is toward tighter controls. RPKI is becoming mandatory. RIRs are scrutinizing justification requirements more closely. IPv4 exhaustion means new entrants can't get meaningful IPv4 space. The window for hobbyist ASNs is narrowing, and I think that's part of why the community is so active right now — there's a sense of get in while you can.
Which makes it sound almost urgent.
Urgent might be too strong. But there's definitely a window. If you're in Europe, the window is wide open — RIPE's fee structure and policies are hobbyist-friendly, and that's not likely to change overnight. If you're in North America, ARIN's five-hundred-dollar annual fee is a real barrier, and it's not coming down. The DN42 route remains available to anyone, anywhere, and it costs nothing. But the experience of running a real ASN, with real IP space, peering at real exchanges — that's something that may get harder over time, not easier.
So the practical advice to someone listening who's intrigued by this is... what? Start with DN42?
Start with DN42. Spend six months there. Learn BGP, learn filtering, make your mistakes in the sandbox. If you're still interested after that, look at your RIR's requirements and fee structure. If you're in Europe, the path is straightforward. If you're in North America, you need to decide whether five hundred dollars a year is worth it for a hobby. And if you want the full experience — peering at an IXP, direct connections to content providers — be prepared to spend money on colocation and cross-connects. It's not a cheap hobby, but it's not outrageous either. A few hundred dollars a year for the basic setup, maybe a hundred to two hundred a month if you go the colocation route.
That's less than a lot of people spend on streaming services.
It is. And the satisfaction-to-dollar ratio is, in my opinion, extremely high.
All right, so we've covered the process, the community, the benefits, the risks. I want to circle back to something you said earlier about the initial setup being dozens of hours. What does that actually look like in practice? What's the hardest part?
The hardest part is probably the BGP configuration itself. Not because BGP is conceptually difficult — the protocol is actually fairly simple at its core — but because the consequences of getting it wrong are severe. You're configuring prefix filters, route maps, session parameters, and you need to get all of it right. One typo in a prefix list and you could announce something you shouldn't. The second hardest part is dealing with the RIR bureaucracy — filling out justification forms, waiting for approval, getting your IP space allocated. It's not technically difficult, but it's slow and frustrating. The third hardest part is finding an upstream transit provider who will take you seriously as a hobbyist. That's where the community really helps — there are lists of hobbyist-friendly providers, and people share their experiences.
And once it's all set up?
Once it's set up, it's mostly monitoring. You check your BGP sessions, look at your traffic graphs, respond to the occasional abuse complaint — which as a single user is almost always a false positive. You renew your RIR membership once a year, apply software updates. It's about as much work as maintaining a home server — a few hours a month if nothing goes wrong.
And if something goes wrong?
If something goes wrong, you're debugging BGP at two in the morning. But that's true of any serious hobby. The people who do this enjoy the debugging. That's part of the appeal.
Hilbert: The bank never noticed.
...What?
Hilbert: The bank. The one whose prefix we announced. They never noticed. Their upstream probably filtered it before it propagated far enough to cause real damage. But our transit provider noticed. They noticed immediately.
Wait, you actually did this? You ran an ASN?
Hilbert: Late nineties. Small ISP in Connecticut. Two people, a Cisco twenty-five hundred router, and an ASN we'd gotten from ARIN back when the fees were lower and the justification was basically a postcard. I was the one who configured the BGP sessions. The router was held together with zip ties. Literal zip ties. The chassis had cracked during a move and we didn't have budget for a replacement.
And you announced a bank's prefix.
Hilbert: Accidentally. I was updating the prefix list and I typed the wrong octet. Instead of announcing our slash twenty-four, I announced a slash twenty-four that belonged to a regional bank in Massachusetts. The upstream provider's NOC called us within about ninety seconds. The phone call was... memorable.
What did they say?
Hilbert: The exact wording was, and I quote, what are you doing. Not a question. A statement. What are you doing.
And you pulled the announcement.
Hilbert: Pulled it immediately. Total exposure was maybe two minutes. The bank's traffic probably didn't even blip. But our upstream put us on a watchlist. Every prefix announcement we made for the next six months got manually reviewed before they'd propagate it.
That's the risk we were talking about. It's real, and it happens fast.
Hilbert: These days, RPKI and ROAs make that specific mistake much harder to make. If I'd tried to announce a prefix without a valid ROA, the upstream would have rejected it automatically. The phone call never happens. But the fear is still there. The first time you announce a prefix, you sit there watching the looking glass servers, waiting to see if your route propagates correctly, and there's this moment of... I just told the entire internet something. If I told it the wrong thing, the entire internet is going to believe me.
That's a lot of weight for a zip-tied router.
Hilbert: The zip ties held. The router ran for another three years. I still have the configuration backup somewhere. Floppy disk. Probably unreadable by now.
The thing about that story is it captures something we've been dancing around. The terror of the first announcement is real, and it's not just about technical risk. It's about the responsibility of being part of the routing fabric. When you're a leaf node, your mistakes affect you. When you have an ASN, your mistakes can affect other people. That's the tradeoff for being a first-class citizen.
And yet people keep doing it. The hobbyist community is still there, still growing, still helping each other through the terrifying first announcement.
Hilbert: Because the moment after the terror, when you see your ASN in the traceroute, it's worth it. It's like... you know when you're a kid and you build something and it actually works? It's that feeling. But for adults. With routing protocols.
I think that's exactly right. Ham radio operators talk about the magic of making contact — hearing someone's voice come out of a box you built yourself, from thousands of miles away. Running a personal ASN is the digital equivalent. You build something, you connect it to the global internet, and it works. Your little network, with its little ASN, is talking to networks run by Google and Netflix and Comcast, and they're all treating it as a peer. That's magical.
The one thing I'd take from this whole discussion is that the complexity is real, but it's not the point. The point is that running a personal ASN changes your relationship to the internet. You stop being a consumer and start being a participant. And for the people who feel that distinction, the complexity is just the price of admission.
And the price is lower than most people think. Fifty euros a year in Europe. Free transit from Hurricane Electric if you're doing IPv6. A used router or a Linux box you probably already have. The barrier isn't money or even technical skill — it's the willingness to spend dozens of hours learning something that has no practical payoff unless you count the satisfaction of seeing your own ASN in a traceroute.
Which, to be fair, is a very specific kind of satisfaction.
It is. But for the people who feel it, there's nothing else like it.
The question we're left with is whether the regulatory window stays open. RPKI is becoming mandatory. RIRs are tightening justification requirements. IPv4 exhaustion is pushing new entrants toward IPv6-only networks, which is fine technically but complicates things if you want to reach the IPv4-only parts of the internet. The hobbyist ASN niche might look very different in five or ten years.
It might. But the tools are also getting better. Bird and FRRouting are mature, well-documented open source projects. The DN42 community has built an entire parallel internet for practice and experimentation. There are more tutorials, more blog posts, more community support than there were when benjojo first documented his setup. The knowledge barrier is lower than it's ever been, even as the regulatory barrier creeps up.
So the net effect might be a wash. Harder to get in, easier to learn once you're in.
That's my read. The window isn't closing so much as changing shape. And for someone who's interested, now is a perfectly good time to start. Start with DN42. Read benjojo's blog posts. Join the mailing lists. The community is there, and it's welcoming.
This has been My Weird Prompts. Thanks to our producer Hilbert Flumingtop for keeping the zip ties handy. We'll be back soon.