Peering via Layer 3 Tunnel
Configure Layer 3 tunnel peering with AS203314 using WireGuard, GRE, or SIT/ip6gre protocols. Encrypted BGP sessions over WireGuard with no physical presence required at any of our 16+ PoPs.
A Layer 3 tunnel carries IP packets between endpoints without extending an Ethernet broadcast domain. It is the usual choice for routed peering; encapsulation and encryption determine its overhead.
Layer 3 Tunnel Overview
Replace the placeholder addresses, interface names and keys with the agreed configuration before applying these examples.
{name}- Tunnel interface name{yourside ip}- Your public IP address{ourside ip}- Our endpoint IP address{yourside port}- Your source port (WireGuard){ourside port}- Our destination port (WireGuard){your tunnel ip cidr}- Your tunnel IP/subnet{our public key}- Our WireGuard public key{your private key}- Your WireGuard private key
Tunnel Profile Selection
WireGuard
WireGuard is a modern, lightweight VPN protocol that provides encrypted Layer 3 tunneling. It's our recommended choice for secure peering due to its simplicity and performance.
For a wg-quick deployment, use the following WireGuard configuration:
[Interface]
Address = {your tunnel ip cidr}
ListenPort = {yourside port}
PrivateKey = {your private key}
# Disable WireGuard's built-in routing table management when using
# an external routing daemon (e.g. BIRD, FRR)
Table = off
[Peer]
PublicKey = {our public key}
AllowedIPs = 0.0.0.0/0, ::/0
Endpoint = {ourside ip}:{ourside port}
PersistentKeepalive = 25GRE Tunnel
GRE (Generic Routing Encapsulation) operates at Layer 3 and is suitable for routing IPv4/IPv6 traffic over an IPv4 underlay. It's simple, widely-supported, and has minimal overhead.
ip tunnel add {name} mode gre local {yourside ip} remote {ourside ip} ttl 255
ip addr add {your tunnel ip cidr} dev {name}
ip link set dev {name} upSIT / ip6gre (IPv6 Tunneling)
SIT (Simple Internet Transition) tunnels IPv6 traffic over an IPv4 underlay and is commonly used for 6in4 connectivity.
ip6gre provides full GRE encapsulation for IPv6 and is preferred when you need GRE key support or multi-protocol capability.
# SIT: IPv6-in-IPv4
ip tunnel add {name} mode sit local {yourside ipv4} remote {ourside ipv4} ttl 255
ip addr add {your tunnel ipv6 cidr} dev {name}
ip link set dev {name} upProtocol Comparison
| Protocol | Encryption | IPv4 | IPv6 | Overhead | NAT Traversal |
|---|---|---|---|---|---|
| WireGuard | Yes | ✓ | ✓ | 32 bytes | Good (UDP) |
| GRE | No | ✓ | ✓ | 28 bytes | Limited |
| SIT | No | N/A | ✓ | 20 bytes | Limited |
| ip6gre | No | N/A | ✓ | 28 bytes | Limited |
Protocol Selection Guide
- WireGuard: Best for secure peering, supports both IPv4 and IPv6
- GRE: Simple, widely-supported, good for IPv4 peering
- SIT/ip6gre: Use when you only need IPv6 transport over IPv4
MTU Considerations
Encapsulation consumes part of the underlay MTU. Set the tunnel MTU to leave room for the chosen protocol's headers.
| Protocol | Overhead | Recommended MTU |
|---|---|---|
| WireGuard | 32 bytes | 1468 |
| GRE | 28 bytes | 1472 |
| SIT | 20 bytes | 1480 |
| ip6gre | 28 bytes | 1472 |
WireGuard MTU example:
ip link set dev {name} mtu 1468Next Steps
After configuring both endpoints, verify the following:
- Verify connectivity using
pingortraceroute - Configure your BGP daemon (BIRD, FRR, etc.) to use the tunnel interface
- Contact us to finalize the peering session
Once tunnel reachability is confirmed, contact the peering team to complete the AS203314 BGP session.
Peering via Layer 2 Tunnel
Configure Layer 2 tunnel peering with AS203314 using GRETAP or VxLAN protocols. No physical colocation required - establish BGP sessions over encrypted tunnels from any location.
IP Transit Services
IP-Transit from Hats Network Inc. (AS203314) across 16+ PoPs in Asia, Europe, and North America. Multi-homed via Cogent, NTT, Hurricane Electric, and PCCW Global with up to 200 Gbps committed capacity per location.