KPN IP Ranges
KPN is the Dutch incumbent, and AS1136 is its national network - the RIPE object is named KPN with the description KPN National. It is flagged LEGACY, meaning the number predates RIPE NCC allocation policy, and the database object recording it was created on 28 December 2004. It is held by ORG-KOVN1-RIPE, KPN B.V. of Wilhelminakade 123 in Rotterdam, and PeeringDB carries the network as KPN NL with the AS-SET RIPE::AS1136:AS-KPNNL.
- Provider
- KPN
- Primary ASN
- AS1136
- Category
- ISP
- Headquarters
- Rotterdam, Netherlands
- Announced IPv4 prefixes
- 429
- Registry
- RIPE
Known IP ranges
These prefixes are currently announced to the global routing table by AS1136 (KPN KPN B.V.). Prefix sets change over time - use WHOIS Lookup for the authoritative record on any specific address.
188.200.0.0/13
77.160.0.0/13
86.80.0.0/13
92.64.0.0/14
77.60.0.0/14
84.84.0.0/14
81.204.0.0/14
86.92.0.0/14
77.168.0.0/14
46.144.0.0/15
2a02:a400::/25
2a00:9a40::/32
2a0d:f0c0:e000::/40 (IPv6)
What does a KPN IP mean in a privacy test?
KPN sorts its subscriber space into reverse-DNS zones that name the product, and you can read them straight off a log line without any lookup service. A consumer fixed line answers as something like 86-80-5-5.fixed.kpn.net; a business connection takes the same shape in a different zone, as with 46-144-5-5.biz.kpn.net. The static-IP pool behaves differently again: addresses across 188.200.0.0/13 return the bare hostname static.kpn.net with no per-address label at all, and the RIPE allocation covering that space carries the remark Static IP KPN customers. So an address here is a Dutch line, and the zone settles whether it is a household, a business connection, or an assignment somebody paid to keep.
What KPN puts in the registry, and what it leaves out
KPN publishes no geofeed. None of the allocations checked here carries a geofeed attribute or a geofeed URL in its remarks - not 188.200.0.0/13, not 86.80.0.0/13, not 213.75.0.0/16, and not the 77.160.0.0/12 allocation that the announced 77.160.0.0/13 sits inside. Every city a lookup service attaches to a KPN address is therefore that service making its own guess. What the RIPE objects do carry is operational: an abuse address of abuse@kpn.com with a separate security@kpn.com, and on the aut-num a routing note stating that filtering on the /24 boundary is applied and that KPN does not reannounce any route more specific than a /24, plus an explicit instruction to run whois -h whois.peeringdb.com AS1136 for public peering detail.
The trap is that KPN is two RIPE organisations, both named KPN B.V. ORG-KOVN1-RIPE in Rotterdam holds the ASN and the static-customer allocation. ORG-WAPI1-RIPE, a separate LIR at Rontgenlaan 75 in Zoetermeer, holds the large consumer blocks under netnames that begin NL-WAPI-: NL-WAPI-20050323 covers 86.80.0.0/13, NL-WAPI-20000406 covers 213.75.0.0/16, and NL-WAPI-20061102 covers the 77.160.0.0/12 allocation. The two organisations even publish different abuse handles, KPN-RIPE against PT978-RIPE. Enumerating one organisation handle will not find the other, so a query built around a single org object misses most of the consumer space.
KPN's own machines versus a KPN customer
KPN keeps its infrastructure in a different domain from its subscribers. Subscriber lines live under kpn.net, in the fixed, biz and static zones, and every one of those names is generated from the address with dots replaced by dashes. KPN's own hosts answer under kpnis.nl instead, so 213.75.10.10 comes back as fe04-www.hi.kpnis.nl - a named host, not a generated one. If a name ends in kpnis.nl you are looking at KPN equipment sitting in a KPN pool, not at a customer assignment.
Among the customer zones the distinction that matters for a log is stability. A fixed.kpn.net or biz.kpn.net name is generated for whatever address the line currently holds, so it identifies the address and not the subscriber. A static.kpn.net address is a customer who bought a fixed assignment, and the registry says the same thing independently: the allocation behind that pool, 188.200.0.0/13, is netname NL-KPN-BBT-20090605 under ORG-KOVN1-RIPE with the remark Static IP KPN customers. PeeringDB files AS1136 as a regional NSP with a mostly inbound ratio, the shape of an access network delivering traffic to subscribers rather than serving it out.
Related tools
Frequently asked questions
Is AS286 also KPN?
Not any more, and the RIPE record says so itself. AS286 still carries the as-name KPN, but the object is held by ORG-GCI2-RIPE and carries a remark stating that AS286 is now owned by GTT. KPN's own Dutch network is AS1136, held by ORG-KOVN1-RIPE.
Why do KPN addresses resolve to just static.kpn.net?
Because that pool gets one shared hostname rather than a generated per-address name. Addresses sampled in 188.200.0.0/13 return the bare string static.kpn.net, and the RIPE allocation covering that space, netname NL-KPN-BBT-20090605, is remarked Static IP KPN customers, so the flat hostname and the registry are saying the same thing.
What is the difference between fixed.kpn.net and biz.kpn.net?
They are product zones. Consumer fixed lines are generated into the fixed zone, as with 86-80-5-5.fixed.kpn.net, and business connections into the biz zone, as with 46-144-5-5.biz.kpn.net. The hostname shape is otherwise identical, so the zone label is the only part that distinguishes them.
Why does a KPN block show a netname starting NL-WAPI?
Because KPN operates two RIPE LIR organisations under the same company name. The NL-WAPI netnames belong to ORG-WAPI1-RIPE, registered at Rontgenlaan 75 in Zoetermeer, which holds most of the consumer address space. The ASN and the static-customer allocation sit under a different object, ORG-KOVN1-RIPE in Rotterdam.
Does KPN publish a geofeed?
No. No geofeed attribute or geofeed URL appears in the RIPE objects covering its main consumer, business and static allocations. The registry does publish abuse@kpn.com and security@kpn.com for reporting, but nothing that maps a prefix to a town.