Huawei Cloud IP Ranges
Huawei Cloud is Huawei's public cloud business, and AS136907 is specifically its international network. The APNIC record was registered on 7 August 2017 under the name HWCLOUDS-AS-AP with the description HUAWEI CLOUDS, a Hong Kong country code, and HUAWEI INTERNATIONAL PTE. LTD. of Singapore as the registrant rather than the Shenzhen parent, with abuse handled by IRT-HIPL-SG. PeeringDB calls the network Huawei Cloud Global. Huawei Cloud regions inside mainland China ride a separate APNIC number, AS55990, name HWCSNET, country CN, registered 9 October 2012 and remarked as a Huawei Cloud Service data center.
- Provider
- Huawei Cloud
- Primary ASN
- AS136907
- Category
- Cloud
- Headquarters
- Shenzhen, China
- Announced IPv4 prefixes
- 544
- Registry
- APNIC
Known IP ranges
These prefixes are currently announced to the global routing table by AS136907 (HWCLOUDS-AS-AP - HUAWEI CLOUDS). Prefix sets change over time - use WHOIS Lookup for the authoritative record on any specific address.
156.230.64.0/18
124.243.128.0/18
156.240.128.0/18
154.220.192.0/19
114.119.128.0/19
119.8.96.0/19
110.239.96.0/19
119.8.32.0/19
94.45.160.0/19
190.92.192.0/19
2405:f080:3000::/38
2405:f080:3400::/38
2405:f080:1800::/39 (IPv6)
What does a Huawei Cloud IP mean in a privacy test?
An address here shown as your visible IP means the session left through a rented instance in one of Huawei Cloud's international regions, which is what a VPN or proxy hosted on that infrastructure looks like from outside. The more common way to meet AS136907 is the other direction, in a website's logs, where the Huawei addresses are usually PetalBot, the crawler behind Huawei's Petal Search. The country a lookup returns for this space depends entirely on which source answered: APNIC records the main blocks as SG or HK, the AFRINIC parent above two of the largest is registered in the Seychelles, and Huawei's own geolocation file files 156.240.128.0/18 as country CN, region CN-HK, Hong Kong. Nothing on this number is a home connection, so a test that classifies it as residential has got it wrong. If you need to know which Huawei entity you are dealing with, the registrant on the APNIC record is the Singapore company, not the Shenzhen one.
Where Huawei Cloud states the location of its blocks
Huawei Cloud does publish a self-declared geolocation file, but you reach it from the registry rather than from a product page. The AFRINIC records for 156.230.64.0/24 and 156.240.128.0/24 each carry a single remark that is nothing but a URL, https://res-static.hc-cdn.cn/cloudbu-site/china/zh-cn/IP-location/google-geo-feed.csv. That file has no header or comment line at all and starts straight into RFC 8805 five-field rows, and unlike a country-only feed it fills the region and city in: 101.44.32.0/20,TR,TR-34,Istanbul, and 110.238.72.0/21,ZA,ZA-GP,Johannesburg,. IPv6 sits in the same file, with entries such as 2405:f080:1e12::/47, and the AFRINIC space is covered too, 156.240.128.0/18 appearing there as country CN, region CN-HK, Hong Kong.
What the file does not do is say which Huawei service an address runs. There is no published address list for PetalBot, since Huawei's own page for the crawler tells you to verify it by DNS instead, and the only other machine-readable handle is the IRR object named in the PeeringDB record, AS-HUAWEI. The registry is less tidy than the geofeed suggests: APNIC blocks appear as Huawei-Cloud-SG, Huawei-HK-Cloud or HIPL-SG, all allocated non-portable to Huawei International Pte Ltd, but two of the largest announced ranges, 156.230.64.0/18 and 156.240.128.0/18, fall inside 156.224.0.0/11, an AFRINIC allocation registered on 22 December 2015 to Cloud Innovation Ltd in the Seychelles. Query an address in those and AFRINIC answers Cloud Innovation Support at the /24 and Cloud Innovation Ltd at the /11, with the geofeed URL in the remark the only thing in either record that ties the space back to Huawei.
Telling Huawei Cloud infrastructure from a tenant machine
Reverse DNS sorts this ASN into clear groups, and the lookups below were resolved from public DNS while this page was written. The crawler names itself after its own address: 114.119.141.80 returns petalbot-114-119-141-80.petalsearch.com and sits in 114.119.128.0/19, while 114.119.166.230 returns petalbot-114-119-166-230.aspiegel.com and sits in a separate allocation, 114.119.160.0/21 - two blocks, both recorded by APNIC as Huawei-Cloud-SG. Both domains are in live use, which matters because Huawei's verification page tells you to check the name is in aspiegel.com while the worked example on that same page is a petalsearch.com hostname. Accept either, then run the forward lookup Huawei asks for and confirm it returns the address you started from. Tenant compute names itself differently: 119.8.100.1 returns ecs-119-8-100-1.compute.hwclouds-dns.com, the default hostname an elastic cloud server gets, built mechanically from its address.
That naming split is the whole test, because a request claiming PetalBot in its user agent but resolving to compute.hwclouds-dns.com, or to nothing, is not PetalBot and there is no published address list to check instead. Beyond the crawler this is rented infrastructure rather than a subscriber network: the blocks are marked allocated non-portable to Huawei International Pte Ltd and handed out to instances, so a server answering here is somebody's tenancy and not a household line. Whois will not name that tenant either, which is the practical difference between this network and a transit carrier that writes customer assignments into the registry - the APNIC record stops at Huawei International Pte Ltd, with no sub-record naming the company behind the machine. If the address you are looking at is in a mainland China region rather than an international one, check the origin ASN before assuming this page applies, because that space is carried under AS55990.
Related tools
Frequently asked questions
Is AS136907 Huawei Cloud in China?
It is Huawei Cloud's international network. APNIC registered AS136907 on 7 August 2017 under the name HWCLOUDS-AS-AP with a Hong Kong country code, and the registrant on the record is HUAWEI INTERNATIONAL PTE. LTD. of Singapore rather than the Shenzhen parent, with PeeringDB listing it as Huawei Cloud Global. Huawei Cloud regions inside mainland China are carried by a separate number, AS55990, registered at APNIC in October 2012 as HWCSNET with country code CN.
What are the 114.119 addresses crawling my site?
That is PetalBot, the crawler behind Huawei's Petal Search, running on space APNIC records as Huawei-Cloud-SG. Verify it by reverse DNS and then a forward lookup back to the same address, and note that both aspiegel.com and petalsearch.com hostnames are in live use even though Huawei's instructions name only aspiegel.com. The user agent alone proves nothing, since anyone can copy it, and Huawei publishes no address list.
Does Huawei Cloud publish a geofeed?
Yes, though you find it through the registry rather than the product documentation. Two AFRINIC records carry a remark that is just a URL for a CSV on res-static.hc-cdn.cn, in the standard five-field self-published geolocation format of prefix, country, region, city and postal code. The file has no header line, covers IPv6 as well as IPv4, and fills in region and city rather than country alone.
Why does whois on some Huawei Cloud addresses name a different company?
Because two of the largest ranges announced by AS136907 sit inside the AFRINIC allocation 156.224.0.0/11, registered in December 2015 to Cloud Innovation Ltd in the Seychelles. The more specific records under it are held by Cloud Innovation Support, so the only thing in the registry tying that space to Huawei is the geofeed URL in the remarks. Routing says Huawei Cloud and whois says Cloud Innovation, and neither is wrong.
Can a site tell I am on Huawei Cloud rather than at home?
Easily. The blocks are allocated non-portable to Huawei International Pte Ltd under netnames such as Huawei-Cloud-SG and Huawei-HK-Cloud and handed to tenants as instances, and the default reverse DNS for one of those instances is an ecs hostname under compute.hwclouds-dns.com built from the address itself. Any check that classifies address space by type reads that as hosting, which is why a streaming or banking site treats an exit here differently from an ordinary connection.