Your IPv4 block behind Cloudflare, on every service.
Cloudflare BYOIP puts your own address space in front of Magic Transit, Spectrum or the CDN. The way it works is that your prefix is announced by Cloudflare from its global anycast network, AS13335, and you then map individual addresses to services by means of what Cloudflare calls service bindings. It is worth knowing from the outset that onboarding here is a guided process run together with your Cloudflare account team rather than a self-service API you work through on your own. What the process involves, and what you would do well to have ready before it starts, is laid out below.
Prerequisites
Cloudflare onboards prefixes of /24 or larger that your organization is authorized to use, and that authorization is backed by a Letter of Authorization together with RPKI. There is one point we would emphasize more strongly here than in our other guides. Because your addresses will be fronting production traffic on a shared anycast edge, reputation matters doubly: a blocklisted range sitting behind a CDN is, to put it plainly, a support nightmare that can take months to untangle. This is why the sourcing matters so much. Prefixx delivers vetted, escrow-secured space from the marketplace, or you can lease IPv4 addresses from us instead, in which case the LOA and the registry records are coordinated by us with the address holder on your behalf.
LOA in. Anycast out.
Below is the flow as we have seen it play out for our own clients. The exact steps are run through your Cloudflare account team, and we would suggest reading the official Cloudflare BYOIP documentation alongside this page as well.
Secure the block
It all begins with a clean /24 or larger, acquired through Prefixx. The block arrives vetted and escrow-secured, and it comes with the registry authority you will need in order to issue an LOA for it later on.
Authorize Cloudflare
Next, a Letter of Authorization is provided so that Cloudflare may announce the prefix, and an RPKI ROA is published authorizing AS13335 as the origin. Both documents are prepared by our team if the block came through us.
Onboard & announce
Cloudflare then validates the LOA and the ROA, provisions the prefix, and begins announcing it from its anycast network around the world. There is not much for you to do at this stage besides keeping in touch with your account team.
Bind to services
Finally, service bindings are created to map your addresses onto Magic Transit, Spectrum apps or CDN zones. Usefully, different parts of one and the same prefix can be made to serve different products.
Clean space, clean paperwork, clean launch.
In our experience, Cloudflare's onboarding is only ever as smooth as the block behind it. Prefixx has been brokering IPv4 since 2007, we are registered with ARIN, RIPE NCC and APNIC, and over the years we have developed a fairly settled routine for this: space with a verifiable clean history is sourced, the deal is closed through escrow, and the LOA and the AS13335 ROA are prepared by our team ahead of time. When it is done in that order, Cloudflare's validation tends to be a formality rather than a project of its own.
Pair it with included BYOIP
Something we see many teams do is put one subnet behind Cloudflare while running their origin servers on their own space somewhere else. For that origin block, BYOIP is natively included on Netrouting bare metal, which is to say that the LOA, ROA and IRR work is handled by our team and the announcement is coordinated for you as well.
Netrouting BYOIP guide →Cloudflare BYOIP: common questions
BYOIP is a paid add-on to Cloudflare's Magic Transit, Spectrum and CDN offerings. It is priced through their sales team on enterprise agreements, and it is quoted per prefix, so the honest answer is that the Cloudflare side of the cost depends on your particular arrangement with them. The block itself is the part we can speak to: you buy or lease it through Prefixx with zero buyer fees, since it is the seller who pays our 3-8% commission.
We generally tell clients to plan for a few weeks, though it does vary from case to case. There is the RIR transfer or the lease setup to get through first, then the LOA and ROA preparation, where ROA propagation alone takes up to about 24 hours, and after that come Cloudflare's validation, provisioning and announcement, plus the service-binding configuration at the end. When the registry side has been prepared by Prefixx in advance, the Cloudflare phase quite often turns out to be the shortest part of the whole move.
Yes, and this portability is one of the main reasons people bring their own space in the first place. You offboard the prefix with your account team so that the announcement is withdrawn by Cloudflare, you update the ROA, and you then announce the very same addresses anywhere else you please: Netrouting bare metal, one of the cloud BYOIP flows, or your own network. There is no re-IP involved and no renumbering either, which means your allowlists, your reputation and your customers' configurations all simply keep working.
Put addresses you control on the edge.
Just tell us the size you need and which Cloudflare product it is for. We will source the block, and the LOA and ROA will be prepared by us along with it.
Explore related services
BYOIP
Deploy your own or leased IPv4 addresses on bare metal or cloud. We prepare the LOA, ROA and route objects for you.
Learn more →Lease IPv4
Short- and long-term IPv4 rentals provisioned in as little as 24 hours with LOA, RPKI and reverse DNS support.
Learn more →Buy IPv4
Source vetted IPv4 blocks with zero buyer fees. Prefixx manages the entire transfer process across ARIN, RIPE, APNIC and LACNIC.
Learn more →Contact us to discuss your IPv4 needs today
No hidden fees, free consult. A broker replies within one business day.