Autonomous system detail

AS377

Announced

Operated by SNLA-NET-AS - Sandia National Laboratories.

Summary

// analyst note
Active low-numbered legacy ASN registered to a DOE/NNSA national laboratory. First-party ARIN RDAP is authoritative (allocated 1989-08-01, last changed 2024-12-20); a third-party '1994-12-11' last-updated claim was rejected in favor of RDAP. Topology from canonical CAIDA: AS rank 12965, cone 1 ASN / 7 prefixes / 136,960 addresses, AS-degree 1 (provider 1, peer 0, customer 0), cliqueMember true. The single upstream provider ASN, per-peer sample, and RPKI status are not enumerated in the canonical records and are left null rather than fabricated; announced-prefixes count is approximate (RIPEstat routing-status shows 10 IPv4 prefixes / 137,728 addresses).
// security note
NEUTRAL/DATED: no notable public abuse signal found for AS377 as of 2026-07-02; not in Spamhaus, AbuseIPDB, or Cisco Talos.
IPv4 prefixes
10
~137.7K addresses
IPv6 prefixes
1
announced
Peer networks
1
1 up · 0 down
IANA block
1-1876
Assigned by ARIN
[ 01 ] — Context

About this ASN.

Updated  ·  Confidence: High

AS377 is a low-numbered, legacy autonomous system number registered under ARIN to Sandia National Laboratories, a U.S. Department of Energy national laboratory. Sandia is a Federally Funded Research and Development Center (FFRDC) operated on a government-owned, contractor-operated (GOCO) basis; it is currently managed and operated by National Technology and Engineering Solutions of Sandia, LLC (NTESS), a wholly owned subsidiary of Honeywell International, under DOE/NNSA contract DE-NA-0003525. The ASN's low handle reflects its age: the ARIN autnum top-level registration event dates to 1989-08-01, placing it among the early Internet-era allocations, with the registry record last changed 2024-12-20. AS377 is an active, in-use network — RIPEstat reports it as announced, carrying a small, stable footprint of roughly eight prefixes anchored on 134.253.0.0/16 and 132.175.0.0/16 (IPv4) plus at least one IPv6 block (2620:106:6008::/48), on the order of ~137,000 IPv4 addresses. This is an end-user institutional/mission network rather than a commercial ISP or transit provider: there is no PeeringDB record (peeringdb.com/asn/377 returns 404), no published peering policy, and Sandia's primary DOE/NNSA mission WAN connectivity runs over ESnet, the DOE's dedicated national-laboratory network, rather than through commercial public/private peering. The network supports national-security science and engineering work — nuclear-weapons stewardship, high-performance computing, and related research — and a "Sandia Anywhere" remote-access portal for staff. No notable public abuse signal was found for AS377 as of 2026-07-02 across Spamhaus, AbuseIPDB, and Cisco Talos; the only security-relevant history concerns Sandia (the operating organization) as a *target* of the 2003–2004 Titan Rain espionage campaign and the 2020 SolarWinds compromise — intrusions into Sandia's network, distinct from abuse originating from this ASN's address space.

Operator
Sandia National Laboratories (ARIN org handle SNL-Z; SNLA-NET-AS) — DOE/NNSA national laboratory, an FFRDC operated GOCO by NTESS (a Honeywell subsidiary) under contract DE-NA-0003525 [Confirmed] — ARIN RDAP, sandia.gov/about
Country / RIR
US, ARIN [Confirmed] — RIPEstat abuse-contact-finder (authoritative_rir: arin); ARIN RDAP autnum
Allocated
1989-08-01 (ARIN registry autnum top-level registration event — a first-party RIR fact, NOT an IEEE date); last changed 2024-12-20 [Confirmed] — ARIN RDAP autnum top-level events (https://rdap.arin.net/registry/autnum/377). Entity/POC-level dates (HELLE40-ARIN 2015-05-18, SNLN-ARIN 2018-05-24, SNL-Z 2023-04-27) are correctly excluded as decoys — they are nested contact/org records, not the autnum allocation event.
Org status
FFRDC, government-owned contractor-operated national laboratory under DOE/NNSA; not a commercial entity; operated by NTESS (Honeywell subsidiary) under contract DE-NA-0003525 [Confirmed] — sandia.gov/about
Contacts
the abuse POC is a named individual, Jeff Heller (HELLE40-ARIN), whose personal mailbox is not reproduced here; admin/technical is the departmental workgroup alias wg-snl-arin-technical@mailgate.sandia.gov (Sandia National Laboratories Networking); registrant address Kirtland AFB, PO Box 5800, Albuquerque, NM 87185
[Confirmed] — ARIN RDAP autnum entities

Security/abuse context (NEUTRAL, DATED)

no notable public abuse signal found for AS377 as of 2026-07-02 — not in Spamhaus (DROP/SBL/check), AbuseIPDB, or Cisco Talos reputation center. Sandia (the operating organization) has a documented history as a TARGET of the 2003–2004 Titan Rain espionage campaign and the 2020 SolarWinds supply-chain compromise — intrusions into Sandia's network, distinct from abuse originating from this ASN's announced space

[Likely] — check.spamhaus.org, abuseipdb.com, talosintelligence.com, en.wikipedia.org/wiki/Shawn_Carpenter

Network & routing

Network type
government/research institution network (national laboratory) — not a commercial ISP or transit provider; active/announced [Confirmed for org type; Likely for non-commercial classification] — sandia.gov/about, peeringdb.com/asn/377 (404, no public peering record)
Size
~8 announced prefixes; observed IPv4 blocks include 134.253.0.0/16, 132.175.0.0/16, 198.102.152.0/22, 198.102.151.0/24, 192.160.227.0/24, 205.137.80.0/20 (~137,000 IPv4 addresses per bgp.he.net) plus IPv6 2620:106:6008::/48; the RIPEstat announced-prefixes list was truncated in the fetched snapshot so the exact total is approximate
[Likely] — RIPEstat announced-prefixes, bgp.he.net/AS377
Routing/peering
announced/active per RIPEstat as-overview; no PeeringDB listing and no published peering policy. CAIDA AS rank is 12965, with a customer cone of 1 ASN / 7 prefixes / 136,960 addresses and an AS-degree of 1 (provider 1, peer 0, customer 0; cliqueMember true) — a single-upstream, end-user topology with no downstream customers, consistent with an institutional network. The single upstream provider's ASN is not enumerated in the canonical CAIDA/RDAP records (RIPEstat likewise reports 1 observed neighbour); it is left unnamed rather than fabricated [Confirmed for rank/cone/degree; upstream ASN identity Unknown] — asrank.caida.org/asns/377 (CAIDA), RIPEstat as-overview/routing-status
RPKI
not assessed — RIPEstat rpki-validation was skipped (requires a specific prefix); no per-prefix ROA check was performed [Unknown]
Notable usage
Sandia's internal/institutional mission network for national-security science and engineering (nuclear-weapons stewardship, HPC, DOE/NNSA research); "Sandia Anywhere" remote-access portal for staff; primary mission WAN runs over ESnet (DOE dedicated national-lab network). No evidence of third-party transit or commercial hosting from AS377 [Confirmed for mission/ESnet; Likely for absence of transit] — sandia.gov/about, anywhere.sandia.gov, es.net/engineering-services
Analyst note
Encountered as an active, low-numbered legacy ASN registered to a DOE/NNSA national laboratory. First-party ARIN RDAP is authoritative; one third-party aggregator claimed a "1994-12-11" last-updated date, but the direct RDAP fetch (last changed 2024-12-20) is authoritative and used. Topology (AS rank 12965, cone 1 ASN / 7 prefixes / 136,960 addresses, AS-degree 1) is taken from canonical CAIDA; the specific upstream provider ASN, per-peer sample, and RPKI status are not enumerated in the canonical records and are left Unknown rather than fabricated.
[ 02 ] — Announced prefixes

What this network routes.

11 prefixes total · RIPEstat data · cached, not real-time
// IPv4 prefixes10
  1. 134.253.0.0/16/16
  2. 132.175.0.0/16/16
  3. 205.137.80.0/20/20
  4. 198.102.152.0/22/22
  5. 198.102.151.0/24/24
  6. 198.178.170.0/24/24
  7. 198.178.169.0/24/24
  8. 192.160.227.0/24/24
  9. 198.178.168.0/24/24
  10. 198.206.223.0/24/24
// IPv6 prefixes1
  1. 2620:106:6008::/48/48
[ 03 ] — Notable peers & upstreams

Who it talks to.

1 observed neighbour
// Notable connectionsTop 1 of 1
ASNOperatorRole
AS293 ESNET - ESnet upstream
Neighbours observed via public BGP collectors; not a complete peering list.