Ecosystem: Netrouting· DFDC· LayerSwitch
Registered broker · ARIN · RIPE NCC · APNIC +1 (305) 209-5007
Home/Knowledge Base/Google Cloud
[ KB · Deploy Guide ]

Your IPv4 block on Google Cloud, verified and announced.

Google Cloud BYOIP hands the announcement of your prefix over to Google's network while the addresses themselves stay registered to you. The flow runs through two resource types, the PublicAdvertisedPrefix and the PublicDelegatedPrefix, and there is an ownership check along the way that is done by means of a verification token. We have set out the whole path below, together with the places where the friction is taken out of it by Prefixx.

[ Before You Start ]

Prerequisites

Block size: /24 minimum RIR: registered to your org at ARIN · RIPE NCC · APNIC ASN: not required, Google announces from AS15169 Timeline: provisioning can take up to ~4 weeks

Google accepts prefixes of /24 or larger that are registered to your organization and free of reputation problems. One thing worth understanding early on is that you will need the ability to edit the block's RIR records, since that is where the verification token goes, as well as the ability to publish RPKI ROAs for it. A block you cannot fully control at the registry will stop you cold at the verification stage, and it is for exactly this reason that the sourcing step matters so much. Prefixx delivers blocks with a clean chain of custody behind them, and every registry update along the way is coordinated by us. You can find inventory on the Prefixx marketplace, or you can lease IPv4 addresses from us instead, in which case the record changes are arranged by us with the address holder on your behalf.

[ The Walkthrough ]

From RIR record to regional addresses.

Below is the flow as we walk our own clients through it. For the exact commands and the constraints that apply at the moment, it is best to keep the official Google Cloud BYOIP documentation open alongside this page while you work.

01

Secure the block

It all begins with a clean /24 or larger and a completed RIR transfer to your organization. The vetting, the escrow and the paperwork are all handled by Prefixx, so this step is mostly a conversation with us.

02

Create the ROA

Next, an RPKI ROA is published authorizing Google's origin ASN, AS15169, for your prefix, and AS396982 as well where Google's documentation calls for it. We like to get this done early, as propagation takes time.

03

Create the advertised prefix

Create a PublicAdvertisedPrefix in your project, either via gcloud or in the console. A verification token for the prefix is then issued by Google, and you will need it in the next step.

04

Prove ownership

Place the verification token in the block's RDAP or whois remarks at your RIR, or alternatively in the reverse DNS zone for the prefix, following Google's instructions on the matter.

05

Verification & provisioning

The token and the ROA are then validated by Google, after which the prefix is provisioned and announced from its network. In due course the status moves to announced. A little patience is called for here.

06

Delegate & use

Finally, the space is carved into PublicDelegatedPrefixes per region, and from those you create addresses for your VMs, load balancers and other resources however you see fit.

gcloud · byoipproject: prod-net
$ gcloud compute public-advertised-prefixes create pfx-block \
    --range=203.0.113.0/24 --dns-verification-ip=203.0.113.1
PublicAdvertisedPrefix created · token issued
  … token published in RDAP remarks · verification pending
status: VALIDATED → ANNOUNCED
→ create PublicDelegatedPrefixes per region
Where Prefixx Helps

The registry steps are our home turf.

ROAs, RDAP remarks, reverse DNS zones: if you look at where the Google Cloud flow actually spends its time, it leans hard on records that only the address holder, or their broker, is able to touch. That happens to be precisely the territory we live in day to day. Prefixx has been registered as a broker with ARIN, RIPE NCC and APNIC for many years now, and it is our team that sources the block, secures it in escrow, and prepares or executes every registry-side edit one by one. The aim, quite simply, is that verification passes the first time rather than coming back with corrections.

✓ GCP-eligible blocks, reputation-vetted ✓ Escrow-secured transfer ✓ ROA for AS15169 prepared ✓ Verification token placement handled ✓ White-glove aftercare
[ Prefer Handled-For-You? ]

Compare the included route

One more option we should mention before you settle on a platform. On Netrouting bare metal, BYOIP is natively included in the service, meaning the ROA and the IRR objects are prepared by our team and the announcement is coordinated with Netrouting's NOC directly. There are no tokens to place and no four-week queue to sit in, which for some teams is reason enough to compare the two routes.

Netrouting BYOIP guide →
[ FAQ ]

Google Cloud BYOIP: common questions

The good news is that Google does not bill the standard external IPv4 address charges for addresses you bring yourself, and if you run a fleet of any size that saving becomes meaningful rather quickly. Your real costs, then, are the block itself, which you can purchase or lease through Prefixx, and your normal Google Cloud resource usage on top of it. We would suggest checking Google's current pricing page for the specifics, as these things do change from time to time; on the Prefixx side there are zero buyer fees involved.

Google itself states that the provisioning of a PublicAdvertisedPrefix can take up to four weeks after verification, and that comes on top of the RIR transfer and the ROA propagation time. It is sensible to plan your migration around that window rather than against it. One thing we do to help is run the registry work in parallel with your preparation, so that the Google-side clock starts ticking as early as it possibly can.

Yes, and this portability is one of the main reasons people bring their own space in the first place. You delete the delegated and advertised prefix resources so that the announcement is withdrawn by Google, you update your ROA, and you then announce the very same space anywhere else you please: Netrouting bare metal, AWS, or your own network. There is no re-IP involved and no renumbering either; the addresses, and whatever reputation you have built on them, remain yours.

[ Next Step ]

Start the four-week clock with the right block.

Just let us know the size you need and the region you have in mind, and we will come back to you with a quote for GCP-eligible space. The registry side, as described above, is handled by us.

[ Get In Touch ]

Contact us to discuss your IPv4 needs today

No hidden fees, free consult. A broker replies within one business day.

Zero buyer fees: commission is seller-only
Registered with ARIN, RIPE NCC & APNIC
Escrow-secured transactions since 2007