Bring your IPv4 block to AWS, the right way.
AWS BYOIP is the name Amazon gives to the feature that lets you allocate Elastic IP addresses out of a /24 or larger block of your own, instead of taking whatever happens to come out of Amazon's shared pool. There is a fixed order to the process. First a ROA is published, then an X.509 proof is placed in the RDAP record, then provision-byoip-cidr is run, and it is only after a validation wait that advertise-byoip-cidr can be run as well. That may sound like a good many steps, and the registry half of it genuinely is a fair amount of work, but the registry half is also the part that is taken care of by Prefixx on your behalf. What is left on your side, in the end, is the running of two EC2 commands.
Prerequisites
Amazon asks for a /24 or larger, registered to your organization at ARIN, RIPE NCC or APNIC, and the range needs to come with a clean history behind it. This last point deserves some emphasis. The reputation of every block is screened by Amazon during provisioning, and blocks with a troubled past do get rejected outright, so in a very real sense the outcome of your BYOIP project is decided at the sourcing stage, before a single command has been typed. It is here that we come in. Prefixx has been brokering IPv4 space since 2007, we are registered with all three of the registries mentioned above, and every block we sell is checked for blocklist entries, reputation problems and a sound chain of custody before the transfer is allowed to complete. Have a look at the live inventory on our marketplace, or, should buying not be the right fit for your situation just now, leasing IPv4 addresses is a perfectly good alternative. When you lease, the necessary updates to the holder's RIR records are coordinated through us as well.
Six steps from RIR record to Elastic IP.
Below is the flow as we walk our own clients through it. For the exact command syntax, and for the details that differ from one region to another, it is best to keep the official AWS BYOIP documentation open in another tab while you work.
Secure the block
It all begins with a /24 or larger that has a verifiable clean history and is registered to your organization at your RIR. Since the escrow and the transfer paperwork are taken care of by Prefixx, this first step is, from where you sit, mostly a conversation with us.
Create the ROA
Next, an RPKI ROA is published that authorizes Amazon's ASNs, AS16509 and AS14618, to originate your prefix. Propagation can take up to 24 hours, so we like to get this one out of the way as early as possible.
Prove ownership
Generate a self-signed X.509 certificate and add its public key to the remarks or comments field of the block's RDAP record at the RIR. A somewhat unusual mechanism, admittedly. It is, however, the way Amazon satisfies itself that the range really is yours to bring.
Provision
Now run aws ec2 provision-byoip-cidr together with a signed authorization message. This is where the validation happens: the ROA and the RDAP certificate are checked by AWS against your signature at this point.
Wait for validation
Provisioning happens asynchronously, and in some cases it takes up to a week, so a little patience is called for at this stage. Poll the status with describe-byoip-cidrs until the state reads provisioned.
Advertise & allocate
Finally, run aws ec2 advertise-byoip-cidr. From that point on you are free to allocate Elastic IPs out of your own pool and attach them to instances, NAT gateways or load balancers however you see fit. This part, at least, works just like it always has.
We do the registry half. You keep the CLI half.
If you look back at the walkthrough, you will notice that steps 1 through 3 are really registry work rather than AWS work: the ROA for AS16509 and AS14618, the X.509 keys in the RDAP remarks, and the transfer records themselves. That happens to be our side of the fence. All of it is prepared or executed by Prefixx on your behalf, with escrow protecting the purchase, and the aim, quite simply, is that provision-byoip-cidr validates on the very first attempt rather than after a round of corrections. We have seen provisioning requests held up for days by a single malformed remarks field, which taught us long ago to double-check these details before anything gets submitted at all.
Compare the included route
One more option we should mention before you commit to anything. On Netrouting bare metal, BYOIP is natively included in the service, meaning the ROA and the IRR objects are prepared by our team and the announcement is coordinated with Netrouting's NOC directly. There are no certificates to generate and no self-service queue to sit in, which for some teams is reason enough to compare the two routes before settling on the manual flow described above.
Netrouting BYOIP guide →AWS BYOIP: common questions
The good news is that Amazon does not charge anything for the BYOIP feature itself. Better still, space that you bring is not subject to the public IPv4 charge that is applied to Amazon-supplied Elastic IPs, and if you run a fleet of any size, that saving alone can quietly pay for the block over time. What does it cost, then? Really just the block itself, which you can buy or lease through Prefixx with zero buyer fees, since it is the seller who pays our 3-8% commission, plus whatever AWS resources you were going to be running anyway.
We generally tell clients to plan for two to three weeks from start to finish, though it does vary from case to case. The RIR transfer depends on which registry is involved, the ROA needs up to 24 hours to propagate, the AWS provisioning can take up to a week all on its own, and then the final advertisement step is quick by comparison. One thing we do to help is run the registry phase in parallel with your AWS preparation, which in most cases brings the total down by a useful margin.
Yes, and this portability is one of the main reasons people go the BYOIP route in the first place. You withdraw the advertisement, deprovision the CIDR, update the ROA, and then announce the very same range from Netrouting bare metal, from another cloud, or from your own network. The addresses stay yours, whatever reputation you have built on them comes along too, and at no point is any renumbering involved.
The block is the hard part. We've done it many times.
Just let us know the size you need and the region you have in mind, and we will come back to you with a quote for an AWS-eligible block. The whole registry side of the project, as described above, is taken off your hands by us.
Explore related services
BYOIP
Deploy your own or leased IPv4 addresses on bare metal or cloud. We prepare the LOA, ROA and route objects for you.
Learn more →Lease IPv4
Short- and long-term IPv4 rentals provisioned in as little as 24 hours with LOA, RPKI and reverse DNS support.
Learn more →Buy IPv4
Source vetted IPv4 blocks with zero buyer fees. Prefixx manages the entire transfer process across ARIN, RIPE, APNIC and LACNIC.
Learn more →Contact us to discuss your IPv4 needs today
No hidden fees, free consult. A broker replies within one business day.