AS138
Operated by DNIC-AS-00138 - United States Department of Defense (DoD).
Summary
- // analyst note
- Actively-routed U.S. DoD legacy ASN under DISA administration, in contrast with the dormant siblings AS132/AS136. The 1987-11-11 date is an ARIN database registration date, not IEEE-attributed. Prefix count reported as a range across sources (~18 per bgp.he.net/ipinfo vs ~32 per a security feed); 0 IPv6. Sole observed peer/upstream AS27064 (DoD NIC) reflects DoD internal aggregation and limited public-collector visibility, not necessarily true isolation; private DoD peering is likely undercounted. AS rank 12751 (CAIDA, 2026-06); customer cone is a single-homed stub (1 ASN / 18 prefixes), providing no transit. bgp.he.net flags bogon announcements (legacy DoD blocks).
- // security note
- NEUTRAL/DATED: no notable public abuse signal found as of 2026-06-13; absent from Spamhaus DROP/ASN-DROP, Scamalytics 0/100 fraud risk, no AbuseIPDB/ipapi.is abusive listing, no NANOG threads or BGP hijack/route-leak records surfaced.
About this ASN.
AS138 is a legacy two-digit Autonomous System Number registered through ARIN to the United States Department of Defense (DoD), under ARIN organization handle USDDD. The ARIN autnum carries the AS name DNIC-AS-00138 — the "DNIC" prefix marks it as part of the historic Defense Network Information Center (DoD NIC) block — with a registration date of 1987-11-11, placing it among the earliest ARIN-era allocations; the autnum record was last changed 2025-09-12 and its status is active. The registrant organization (USDDD) is listed at 3990 E. Broad Street, Columbus, OH, and the operational, technical, and abuse contacts all resolve to DISA-Columbus, the Defense Information Systems Agency office at 300 North James Road, Whitehall, Ohio (disa.columbus.ns.mbx.hostmaster-dod-nic@mail.mil), the same DISA-administered contact pattern seen across the DoD NIC ASN family. Unlike its dormant siblings AS132 and AS136, AS138 is operationally live: it actively originates IPv4 address space — roughly 18 announced prefixes covering on the order of 236,000 addresses (sources vary; see Size) — but announces no IPv6. Public BGP collectors see it as single-homed, with its sole observed peer being AS27064 (also a DoD NIC autonomous system), consistent with DoD's practice of routing through internal aggregation rather than commercial transit and keeping most interconnects off public route collectors. PeeringDB (net/36690) lists no IXP memberships and no peering policy, and Hurricane Electric notes the ASN carries no valid RPKI ROAs and flags it as announcing bogons. No notable public abuse signal was found as of June 2026 — a clean, actively-routed U.S. military legacy ASN.
- Operator
- United States Department of Defense (DoD), ARIN org handle USDDD; administered operationally via DISA-Columbus (Defense Information Systems Agency) [Confirmed] — ARIN RDAP (rdap.arin.net/registry/autnum/138)
- Country / RIR
- US, ARIN [Confirmed] — ARIN RDAP; RIPEstat as-overview (authoritative RIR = arin)
- Allocated
- ARIN autnum RegDate 1987-11-11 (ARIN database registration date — NOT an IEEE attribution); autnum last changed 2025-09-12 (registry values; original assignment not separately exposed) [Confirmed for shown dates] — ARIN RDAP
- Org status
- active ARIN registration (autnum last changed 2025-09-12) under United States Department of Defense / USDDD; operational and abuse contact DISA-Columbus, Whitehall, OH 43213. DISA is a DoD combat-support agency; the ASN is actively announcing prefixes[Confirmed] — ARIN RDAP, en.wikipedia.org/wiki/Defense_Information_Systems_Agency
- Website
- no dedicated AS138 site; the administering agency is DISA (disa.mil); the legacy DoD NIC site nic.mil is archived and no longer active [Likely] — A2 operator angle (disa.mil; archived nic.mil)
Security/abuse context (NEUTRAL, DATED)
no notable public abuse signal found as of 2026-06-13; not present in Spamhaus DROP / ASN-DROP, Scamalytics scores the DoD Network Information Center 0/100 fraud risk, no AbuseIPDB/ipapi.is "most abusive" listing, and no NANOG threads or BGP-hijack/route-leak records attributed to AS138 were surfaced. One academic note (a study of DoD prefixes' BGP behavior) concerns routing-update overhead, not abuse. Null findings from commercial feeds are not exhaustive — government/military networks rarely appear in such datasets
Abuse contact
disa.columbus.ns.mbx.hostmaster-dod-nic@mail.mil (NOC/technical/abuse; ARIN handle MIL-HSTMST-ARIN), +1-844-347-2457 ext.2; registrations via disa.columbus.ns.mbx.arin-registrations@mail.mil (REGIS10-ARIN)
Network & routing
- Network type
- U.S. federal government / military (enterprise/government) legacy backbone; single-homed stub AS that does not provide transit; part of the Defense Information Systems Network (DISN) / DoDIN under the DoD NIC umbrella [Confirmed] — ipinfo.io/AS138, bgp.he.net/AS138, ARIN RDAP
- Size
- ~18 IPv4 prefixes / ~236,288 addresses (bgp.he.net, ipinfo.io, 2026-06); a security-feed source reported ~32 prefixes / ~233,687 addresses — reported as a range; 0 IPv6 prefixes. Primary ranges in 131.x, 141.x, 144.183.x (e.g., 131.66.0.0/16, 131.67.0.0/16, 141.234.0.0/18, 144.183.32.0/22) — bgp.he.net/AS138, ipinfo.io/AS138, RIPEstat announced-prefixes
- Routing/peering
- single-homed; sole BGP peer observed in public collector data is AS27064 (DoD Network Information Center / DISA), which also serves as the only visible upstream — public visibility likely undercounts actual private/restricted DoD interconnects; ~713 AS paths observed, average path length ~6.17 hops [Confirmed for the single observed peer; private peering Likely] — bgp.he.net/AS138, ipinfo.io/AS138
- RPKI posture
- no valid RPKI-originated routes / 0 ROA-validated prefixes; bgp.he.net flags "AS138 announces bogons." RIPEstat RPKI-validation was skipped (endpoint requires a specific prefix, none supplied) — so the no-ROA finding rests on bgp.he.net, not RIPEstat [Confirmed for bgp.he.net finding; RIPEstat skipped] — bgp.he.net/AS138, RIPEstat rpki-validation (skipped)
- Notable usage
- one of ~20+ ASNs held by the U.S. DoD under the DoD NIC (org USDDD); an early ARIN-era ASN (registered 1987-11-11) predating the commercial Internet, carrying legacy class-B-scale blocks (131.66.0.0/16, 131.67.0.0/16) within the DISN/DoDIN infrastructure — bgp.he.net/AS138, icannwiki.org/Defense_Information_Systems_Agency
- Related ASNs
- AS27064 (DoD Network Information Center / DISA — sole observed peer/upstream); AS132 (WPAFB-CSD-NET-AS) and AS136 (AF-ASN-136), other dormant DISA-administered military legacy ASNs in the same family [Confirmed for AS27064 peering; AS132/AS136 as family] — bgp.he.net/AS138, ARIN RDAP
- IXP presence
- none listed (PeeringDB net/36690, last updated 2026-04-04: no exchange points, no policy/ratio/contract fields populated) [Confirmed] — peeringdb.com/net/36690
- Analyst note
- An actively-routed U.S. DoD legacy ASN under DISA administration — contrast with the dormant siblings AS132/AS136 which announce nothing. The 1987-11-11 date is an ARIN database registration date, not IEEE-attributed. The single visible peer (AS27064) reflects DoD's internal hub-and-spoke routing and limited public-collector exposure, not necessarily true topological isolation. The bogon flag is consistent with DoD's habit of announcing legacy blocks that modern bogon filters may flag. An IP "in" AS138 maps to DoD/DISA infrastructure.
What this network routes.
- 131.68.0.0/16
- 131.67.0.0/16
- 131.66.0.0/16
- 141.234.64.0/18
- 141.234.0.0/18
- 144.183.200.0/21
- 144.183.32.0/22
- 144.183.196.0/22
- 144.183.128.0/23
- 144.183.17.0/24
- 144.183.127.0/24
- 144.183.20.0/24
- 144.183.15.0/24
- 144.183.131.0/24
- 144.183.227.0/24
- 144.183.130.0/24
- 144.183.16.0/24
- 144.183.216.0/24
Who it talks to.
| ASN | Operator | Role |
|---|---|---|
| AS27064 | DNIC-ASBLK-27032-27159 - United States Department of Defense (DoD) | upstream |