MyIPScan
IP Ranges

FranTech Solutions IP Ranges

FranTech Solutions is the registered operator behind BuyVM, a host that rents virtual machines rather than selling access lines. Its addresses are announced from AS53667, named PONYNET and registered with ARIN to FranTech Solutions under the organisation handle SYNDI-5 on 19 November 2010. The IPv4 space is a run of ARIN direct allocations named PONYNET-01 to PONYNET-16 plus one called FRANTECH, the oldest being 199.19.224.0/22 as PONYNET-01 on 3 August 2010, three months ahead of the ASN itself; the IPv6 direct allocation 2605:6400::/28 is PONYNET-02, registered the day after it. FranTech now says it is not offering services under its own brand and points buyers at BuyVM, whose site files it as a division of Cloudzy.

Hosting
Provider
FranTech Solutions
Primary ASN
AS53667
Category
Hosting
Headquarters
Las Vegas, NV, USA
Announced IPv4 prefixes
42
Registry
ARIN

Known IP ranges

These prefixes are currently announced to the global routing table by AS53667 (PONYNET - FranTech Solutions). Prefix sets change over time - use WHOIS Lookup for the authoritative record on any specific address.

209.141.32.0/19
205.185.112.0/20
198.98.48.0/20
104.244.72.0/21
107.189.0.0/21
199.195.248.0/21
45.61.184.0/22
199.19.224.0/22
107.189.8.0/22
107.189.28.0/23
2a09:7500::/29
2605:6404::/32
2a0f:3044::/32 (IPv6)

What does a FranTech Solutions IP mean in a privacy test?

An address here is a machine somebody rents by the month, so the useful question is what the tenant is running, and the operator's own policy answers part of it outright. The acceptable use policy permits Tor relays, bridges and exit nodes, and obliges an exit operator to open a ticket, put reverse DNS on the address, and block TCP ports 25, 465 and 587 in the exit policy, with the IRC ports 6660 to 6667 and 6697 suggested as optional. An inbound connection from AS53667 is therefore a credible Tor exit as readily as a VPN endpoint or a scanner, and any reverse name you find was chosen by the tenant rather than assigned by the operator - sampled addresses returned tenant-set names such as mx24.songlige.com on 199.19.224.9 and nyc.ft.primeserver.net on 198.98.55.5, and nothing at all on most of the rest. Geolocation is the second trap: the ARIN records carry United States registrant details, yet one of the four sites is in Roost, Luxembourg, and no geofeed is published. A European machine on this network can be placed in the United States by any database that reads only the registry.

What BuyVM documents about AS53667, and what it leaves out

The operator documents its own network on a public wiki rather than in a registry file. That page names AS53667 and four sites - Las Vegas, New York, Miami and Roost in Luxembourg - each on a Juniper MX204 core, with transit from Cogent (AS174) and Hurricane Electric (AS6939) and DDoS filtering bought from Path.net (AS396998) as an IPv4-only option priced at three dollars per address per month. Per-site test endpoints are exposed at speedtest.lv.buyvm.net, speedtest.ny.buyvm.net, speedtest.mia.buyvm.net and speedtest.lu.buyvm.net. The PeeringDB entry adds an open peering policy, a global scope and the IRR object AS-FRANTECH.

What is missing is a location file. The ARIN records inspected here - PONYNET-01, PONYNET-04 and PONYNET-15 - carry no Geofeed comment and no RFC 8805 reference, so the only registry evidence of where a block runs is the reallocation layer beneath it. That layer does exist and is worth reading: 104.244.72.0/21 is reallocated out of PONYNET-14 to an organisation named BuyVM under the netname BUYVM-LUXEMBOURG-01, registered 1 October 2017. Where such a child record exists it beats the parent allocation for placing a machine, and where it does not, nothing in ARIN distinguishes a Nevada address from a Luxembourg one.

FranTech's own space, a tenant's machine, or another company's prefix

Nothing on this network is a subscriber line, so the separation to make is operator against tenant. The IPv4 side is registered in one name: PONYNET blocks held directly by FranTech Solutions, with the one reallocation naming BuyVM rather than any customer, which means the registry will not identify who rents a given address. Reverse DNS is the only per-machine signal and it is tenant-controlled - names like ixb.zircd.net on 104.244.72.10 and 7562ae15-c4-toc-alastor.front.tmtnw.net on 107.189.3.30 were set by whoever holds the machine, and most addresses sampled carried no name at all. Since the acceptable use policy makes reverse DNS a condition of running a Tor exit, a deliberately descriptive name on this space is more often a signal than an accident.

IPv6 works differently and this is where attribution goes wrong. AS53667 originates a number of prefixes registered to other organisations entirely: 2a09:7500::/29 is netnamed SC-RAPIDSEEDBOX-20181116 against a Seychelles entry and 2a0f:3044::/32 is NL-RAPIDSEEDBOX-20250105 against a Netherlands one, while 2a11:2304::/37 is registered as LSD-CAT in Luxembourg under maintainers with no FranTech connection. The ASN is the same; the holder of record is not. For any IPv6 address on this network, look up the specific prefix rather than trusting the ASN, because the company named in the routing table and the company named in the registry are routinely different here.

Related tools

Frequently asked questions

What IP ranges does FranTech Solutions use?

The address space is announced from AS53667, whose ARIN name is PONYNET and whose registrant is FranTech Solutions under the handle SYNDI-5. The blocks above are the largest currently announced. The IPv4 allocations are named PONYNET-01 to PONYNET-16 in ARIN, with occasional child records such as BUYVM-LUXEMBOURG-01 covering 104.244.72.0/21.

Why does a FranTech or BuyVM IP show up in my privacy test?

An address here is a machine somebody rents by the month, so the useful question is what the tenant is running, and the operator's own policy answers part of it outright. The acceptable use policy permits Tor relays, bridges and exit nodes, and obliges an exit operator to open a ticket, put reverse DNS on the address, and block TCP ports 25, 465 and 587 in the exit policy, with the IRC ports 6660 to 6667 and 6697 suggested as optional. An inbound connection from AS53667 is therefore a credible Tor exit as readily as a VPN endpoint or a scanner, and any reverse name you find was chosen by the tenant rather than assigned by the operator - sampled addresses returned tenant-set names such as mx24.songlige.com on 199.19.224.9 and nyc.ft.primeserver.net on 198.98.55.5, and nothing at all on most of the rest. Geolocation is the second trap: the ARIN records carry United States registrant details, yet one of the four sites is in Roost, Luxembourg, and no geofeed is published. A European machine on this network can be placed in the United States by any database that reads only the registry.

Could an address on this network be a Tor exit node?

Yes, and the operator says so. Its acceptable use policy explicitly permits Tor relays, bridges and exit nodes, requiring the operator of an exit to notify support, set reverse DNS on the address, and block TCP 25, 465 and 587 in the exit policy. That makes a connection from this space a plausible Tor exit rather than an unusual one.

Why does a BuyVM server in Luxembourg geolocate to the United States?

Because the IPv4 blocks are ARIN registrations with United States registrant details and no geofeed is published to correct them, while one of the four sites is in Roost, Luxembourg. Databases that follow the registry alone will place the machine in the US. The ARIN reallocation named BUYVM-LUXEMBOURG-01 is the exception that does record a European site.

Why does an IPv6 lookup on this ASN return a different company?

Because AS53667 announces prefixes registered to other organisations. Two of the IPv6 blocks it originates are netnamed for Rapidseedbox in RIPE, against Seychelles and Netherlands entries, and another is registered as LSD-CAT in Luxembourg. The routing table shows FranTech as the origin while the registry shows the block's actual holder, so check the prefix rather than the ASN.