Creating public address ranges

You can create a public address range by defining its size and optionally, specifying a VPC to associate with it in any availability zone within the account.BYOIP (IPv4) Beta Addresses can be allocated from IBM-managed IP pools or from a custom authorized CIDR if you want to use your own publicly routable IP range.

If the VPC is deleted while it is bound to a public address range, the address range continues to exist and can be bound later to a different VPC in any availability zone.

You can create public address ranges with the console, CLI, API, and Terraform.

Before you begin

Make sure to review planning considerations for public address ranges.

Creating public address ranges in the console

To create public address ranges in the IBM Cloud console, follow these steps:

  1. From the IBM Cloud console, select the Navigation menu Menu icon, then click Infrastructure VPC icon > Network > Public Address Ranges. The Public Address Ranges for VPC page appears.

  2. Click Create to go to the provisioning page.

  3. In the Location section, indicate the region where you want the public address range created.

  4. In the Details section, complete the following information:

    • Size: Select the size (number of IPs) of the address range. You can choose from 1, 2, 4, 8, or 16 IPs to include in the block.

      After you create a public address range, you can't change its size.

    • Name: (Optional): Enter a name for the public address range, such as my-public-address-range.

    • Resource group: Select a resource group for the public address range.

      After you create a public address range, you can't change the resource group.

    • Tags: (Optional) Add tags to help you organize and find your resources. You can always add more tags later. For more information, see Working with tags.BYOIP (IPv4) Beta

    • Public address source: Select one of the following:

      • IBM CIDRs: Select from IBM-managed IP address pools. Then, select the size (number of IPs) of the address range. You can choose from 1, 2, 4, 8, or 16 IPs to include in the block.

        After you create a public address range, you can't change its size.

      • Custom authorized CIDRs: From the Authorized CIDR list, select the custom authorized CIDR that you want to allocate addresses from. The available CIDR blocks are limited to valid, unallocated ranges within the selected custom authorized CIDR.

        When you select a custom authorized CIDR, you allocate addresses from your own IP range instead of IBM-managed pools. If no authorized CIDRs exist in the menu, you can enter IPs from an authorized CIDR. The new CIDR becomes available immediately for selection.

        For more information, see Provisioning a custom authorized CIDR.

      For zonal authorized CIDRs, only CIDRs associated with the selected zone are available.

  5. (Optional) If you want to bind your public address range to an existing VPC, toggle the Bind switch to On. Then, select the VPC and availability zone that you want to bind to.

    You can bind a public address range to any VPC in a single availability zone that already exists in your account. You can also bind the address range to a VPC later. For more information, see Binding a public address range.

  6. Click Create. The public address range is requested for use.

On the Public address ranges for VPC page, your address range appears in the table. It takes a few minutes for the status of the public address range to change from Updating to Stable. When in Stable status, the address range is ready for use.

Creating public address ranges from the CLI

To create public address ranges from the command line, follow these steps:

  1. Set up your CLI environment.

  2. Log in to your CLI environment. After you enter the password, the system prompts which account and region that you want to use:

    ibmcloud login --sso
    
  3. Run the following command:

    ibmcloud is public-address-range-create --ipv4-address-count IPV4_ADDRESS_COUNT [--name NAME] [--vpc VPC --zone ZONE] [--resource-group-id RESOURCE_GROUP_ID | --resource-group-name RESOURCE_GROUP_NAME] [--output JSON] [-q, --quiet]
    

    BYOIP (IPv4) Beta

    ibmcloud is public-address-range-create (--ipv4-address-count IPV4_ADDRESS_COUNT | --cidr CIDR) [--name NAME] [--vpc VPC --zone ZONE] [--resource-group-id RESOURCE_GROUP_ID | --resource-group-name RESOURCE_GROUP_NAME] [--output JSON] [-q, --quiet]
    

    Where:

    --ipv4-address-count
    The total number of public IPv4 addresses required. Must be a power of 2.BYOIP (IPv4) Beta Mutually exclusive with --cidr.

    BYOIP (IPv4) Beta --cidr : The public IPv4 range for this public address range expressed in CIDR format. Must be an unallocated block within a custom authorized CIDR in your account. Mutually exclusive with --ipv4-address-count.

    --name
    A name for the public address range. Names beginning with ibm- are reserved for provider-managed resources and are not allowed.
    --vpc
    The VPC to bind this public address range to. Requires --zone.
    --zone
    The zone where this public address range resides. Requires --vpc.
    --resource-group-id
    ID of the resource group. Mutually exclusive with --resource-group-name.
    --resource-group-name
    Name of the resource group. Mutually exclusive with --resource-group-id.
    --output
    The output format, only JSON is supported. One of: JSON.
    -q, --quiet
    Suppress verbose output.

Command examples

Create a public address range named public-address-range-1 with an address count of 8:

ibmcloud is public-address-range-create --name public-address-range-1 --ipv4-address-count 8

Create a public address range that is named public-address-range-2 with an address count of 4 and a resource group named Default:

ibmcloud is public-address-range-create --name public-address-range-2 --ipv4-address-count 4 --resource-group-name Default

Create a public address range named public-address-range-3 with an address count of 8, bound to VPC cli-test-vpc in zone us-south-1 with resource group ID 72b27b5c-f4b0-48bb-b954-5becc7c1dcb3:

ibmcloud is public-address-range-create --name public-address-range-3 --ipv4-address-count 8 --vpc cli-test-vpc --zone us-south-1 --resource-group-id 72b27b5c-f4b0-48bb-b954-5becc7c1dcb3

BYOIP (IPv4) BetaCreate a public address range from a custom authorized CIDR, bound to a VPC and zone:

ibmcloud is public-address-range-create --name public-address-range-3 --cidr 46.16.186.112/28 --vpc cli-test-vpc --zone us-south-2 --resource-group-name Default

Create an unbound public address range from a custom authorized CIDR:

ibmcloud is public-address-range-create --name public-address-range-4 --cidr 46.16.186.128/28 --resource-group-name Default

Creating public address ranges with the API

Before you begin, set up your API environment.

Select one of the following options:

  • Create a public address range from IBM-managed IPs, bound to a VPC:

    curl -sX POST \
    "$vpc_api_endpoint/v1/public_address_ranges?version=$api_version&generation=2" \
    -H "Authorization: Bearer $iam_token" \
    -H "Content-Type: application/json" \
    -d '{
          "ipv4_address_count": 8,
          "name": "my-public-address-range",
          "target": {
             "vpc": {
                "id": "r006-4727d842-f94f-4a2d-824a-9bc9b02c523b"
             },
             "zone": {
                "name": "us-south-1"
             }
          }
       }'
    
  • Create an unbound public address range from IBM-managed IPs:

    curl -sX POST \
    "$vpc_api_endpoint/v1/public_address_ranges?version=$api_version&generation=2" \
    -H "Authorization: Bearer $iam_token" \
    -H "Content-Type: application/json" \
    -d '{
          "ipv4_address_count": 8,
          "name": "my-public-address-range"
       }'
    

BYOIP (IPv4) Beta

  • Create a public address range from a custom authorized CIDR (requires is.public-address-range.authorized-cidr.operate IAM action on the authorized CIDR):

    curl -sX POST \
    "$vpc_api_endpoint/v1/public_address_ranges?version=$api_version&generation=2" \
    -H "Authorization: Bearer $iam_token" \
    -H "Content-Type: application/json" \
    -d '{
          "cidr": "192.168.3.192/28",
          "name": "my-par-from-cidr"
       }'
    

If you need to change the size of the address range or the resource group, you must delete and recreate the address range.

Next steps