NATLAN
Green River Overlook at Island in the Sky, Canyonlands National Park — Ekker Butte upper left, Turks Head to the right
Canyonlands National Park

The terrain on this page is real: Island in the Sky, seen from Green River Overlook — the spot marked on the map.

Photo: au_ears · CC BY-SA 2.0

AS4242420028 · DN42

One operator.
One autonomous system.

Real BGP over WireGuard across three continents — run end to end by its own control plane.

10 nodes online 129 BGP sessions 2 485 routes
Sheet 01 · The territory

The lay of the land

Open in console →

This is the console's own fleet map, live against production data — every node, WireGuard tunnel and health state, exactly as we see it. Drag to pan, Ctrl-scroll to zoom, click a cluster to open it up.

Sheet 02 · Field notes

Why build a console for one AS?

Because the fleet outgrew every tool before it. Three eras, one lesson.

Nov 2025
wg-quick and SSH

Hand-written configs, keys in a notes app. Fine for two nodes — the third one broke the system.

Mar 2026
Templates and scripts

BIRD templates, deploy scripts. Better — until the question became “which node runs which version?”

Now
Agents + a control plane

Desired state in one place, an agent on every node, the console over it all. Drift died here.

Sheet 03 · The console

The whole network, one pane

A purpose-built control plane with an agent on every node. Everything below runs through the console — no SSH in the loop.

Nodes & sessions

Fleet state at a glance — every node, tunnel and BGP session, live.

Onboarding

Approve a registration, mint a token, provision the node — online in minutes.

DNS groups

Resolver sets pushed to the fleet by group — change once, land everywhere.

Agent releases

Roll the fleet forward — or back — by release channel, from one screen.

Flap analytics

Prefix and peer flap boards surface unstable routes before they become incidents.

Audit log

Every change on record, with who made it and when — even a one-person network deserves a paper trail.

Sheet 04 · Peering

Peer with NATLAN

Running an AS on DN42? Peering is self-service — prove the ASN is yours, pick a node, and the tunnel and BGP session come back live in the same response.

peering.natlan.io — what comes back

201 provisioned paste it as-is

# wireguard — the session is already up
[Peer]
PublicKey  = 9Fq1…Wc0H0A=
Endpoint   = hkg1.natlan.io:24028
AllowedIPs = ::/0, 0.0.0.0/0

# bird
protocol bgp natlan {
  local as 4242421234;
  neighbor fe80::28%'wg-natlan' as 4242420028;
}

One peering per AS per node. Keep the session stable — flapping ones may be torn down.

After it is up — the portal keeps working

Your session, as we see it

BGP state, last handshake, imported and exported route counts, traffic — from our side of the link.

Probes on demand

Path MTU and latency run against your endpoint whenever you want a number, not just at provisioning time.

The whole network

The same routing, traffic and flap boards the console runs on — including whether your own ASN is the one flapping.

Tear it down yourself

Remove a peering whenever you like and the slot frees up immediately. One peering per AS per node.

A small network, run properly.

Explore the console, read the docs, or bring your ASN over — there is always room for one more peer.

AS4242420028 DN42 WIREGUARD BGP-4 PEERING WELCOME