Viewing custom authorized CIDRs

BYOIP for IPv4 is a beta feature that is available for evaluation and testing purposes to select customers. Access is restricted to allowlisted accounts.

After IBM approves your provisioning request, view your custom authorized CIDR to monitor how the address space is being used.

Viewing authorized CIDRs in the console

To view custom authorized CIDRs in the console:

  1. From the IBM Cloud console, select the Navigation menu Menu icon, then click Infrastructure VPC icon > Network > Public address ranges.
  2. Click the Custom authorized CIDRs (BYOIP) tab.

The Custom authorized ranges table displays the following information:

Custom authorized ranges table columns
Column Description
Name The name of the authorized CIDR. Click the name to open the details page.
CIDR The authorized IP prefix (for example, 46.16.185.48/28).
IP version The IP version (for example, IPv4).
Availability mode The availability scope: Regional (customer-provided BYOIP) or Zonal (IBM Classic migrated).
Allocated resources The number of resources currently allocated from this authorized CIDR.

To view details for a specific CIDR, click the CIDR name in the table. The details page includes two tabs:

Viewing CIDR details

On the Overview tab, you can review the following information in the CIDR details section:

  • Name: The name of the custom authorized CIDR.
  • ID: The unique identifier of the authorized CIDR. Click the copy icon to copy the ID to your clipboard.
  • IP range: The CIDR block allocated for this authorized range.
  • IP version: The IP version (IPv4).
  • Resource group: The resource group assigned to this authorized CIDR.
  • Availability mode: Regional or Zonal.
  • Location: The region (for example, us-south) or zone where the CIDR is provisioned.
  • Type: The CIDR ownership type (for example, User-provided or IBM-provided).
  • CRN: The Cloud Resource Name for the authorized CIDR. Click the copy icon to copy the CRN to your clipboard.

To deprovision the authorized CIDR, click the Actions... menu in the header and select Deprovision.

Viewing allocated resources

On the Allocated resources tab, you can view all resources allocated from the authorized CIDR.

Use the Resource type dropdown filter (options: All, Floating IP, Public address range) or the search field to filter the list of allocated resources.

The table displays the following columns:

Allocated resources table columns
Column Description
Resource The name of the allocated resource (for example, floating IP or public address range).
CIDR or IP The individual IP address (for floating IPs) or the CIDR block (for public address ranges).
Status The binding status (Bound with a green indicator or Unbound with a yellow warning indicator).
Resource type The type of resource allocated (Floating IP or Public address range).
Targeted resource The name of the targeted resource (such as a VNI or VPC) that the resource is attached to, or — if unbound.
Target type The target type (such as Virtual network interface), or — if unbound.

Creating resources from the authorized CIDR

You can reserve floating IPs and create public address ranges directly from the Allocated resources tab:

  1. Click Create on the Allocated resources tab.
  2. Select Floating IP or Public address range. The provisioning page opens with the custom authorized CIDR pre-selected.

This flow applies to both regional (customer-brought) CIDRs and zonal (IBM Classic migrated) CIDRs. For zonal CIDRs, only the zone that is associated with the CIDR is available during creation.

For more information, see Creating a public address range or Creating floating IPs from a custom authorized CIDR.

Public address ranges created from a custom authorized CIDR require ingress routing to be configured before traffic can reach your resources. For more information, see About routing tables and routes.

Viewing authorized CIDRs from the CLI

Before you can use the CLI, you must install the IBM Cloud CLI and the VPC CLI plug-in. For more information, see the CLI prerequisites.

To list all authorized CIDRs in your account, run the following command:

ibmcloud is public-address-range-authorized-cidrs

You can filter the list by allocation profile family or availability mode:

ibmcloud is public-address-range-authorized-cidrs --allocated-profile-family user
ibmcloud is public-address-range-authorized-cidrs --availability-mode regional --output JSON

Where:

--allocated-profile-family
Filters the collection to resources with a matching allocation profile family. One of: provider, user.
--availability-mode
Filters the collection to resources with a matching availability mode. One of: regional, zonal.

To view details of a specific authorized CIDR, run the following command:

ibmcloud is public-address-range-authorized-cidr AUTHORIZED_CIDR

Where AUTHORIZED_CIDR is the ID or name of the authorized CIDR.

To list all allocations for an authorized CIDR, run the following command:

ibmcloud is public-address-range-authorized-cidr-allocations AUTHORIZED_CIDR

You can filter allocations by resource type:

ibmcloud is public-address-range-authorized-cidr-allocations AUTHORIZED_CIDR --allocations-resource-type floating_ip

To view details of a specific allocation, run the following command:

ibmcloud is public-address-range-authorized-cidr-allocation AUTHORIZED_CIDR --allocation ALLOCATION_ID

Where ALLOCATION_ID is the ID of the allocation.

Viewing authorized CIDRs with the API

Before you begin, set up your API environment.

To list all authorized CIDRs in your account, send a GET request:

curl -sX GET "$vpc_api_endpoint/v1/public_address_range/authorized_cidrs?version=$api_version&generation=2" \
  -H "Authorization: Bearer $iam_token"

You can filter the list by allocation profile family or availability mode:

curl -sX GET "$vpc_api_endpoint/v1/public_address_range/authorized_cidrs?version=$api_version&generation=2&allocation.profile_family=user" \
  -H "Authorization: Bearer $iam_token"
curl -sX GET "$vpc_api_endpoint/v1/public_address_range/authorized_cidrs?version=$api_version&generation=2&availability_mode=regional" \
  -H "Authorization: Bearer $iam_token"

To view details of a specific authorized CIDR, send a GET request with the CIDR ID:

curl -sX GET "$vpc_api_endpoint/v1/public_address_range/authorized_cidrs/$authorized_cidr_id?version=$api_version&generation=2" \
  -H "Authorization: Bearer $iam_token"

To list all allocations for an authorized CIDR, send a GET request to the allocations endpoint:

curl -sX GET "$vpc_api_endpoint/v1/public_address_range/authorized_cidrs/$authorized_cidr_id/allocations?version=$api_version&generation=2" \
  -H "Authorization: Bearer $iam_token"

You can filter allocations by resource type:

curl -sX GET "$vpc_api_endpoint/v1/public_address_range/authorized_cidrs/$authorized_cidr_id/allocations?version=$api_version&generation=2&allocations[].resource_type=floating_ip" \
  -H "Authorization: Bearer $iam_token"

To view details of a specific allocation, send a GET request with the allocation ID:

curl -sX GET "$vpc_api_endpoint/v1/public_address_range/authorized_cidrs/$authorized_cidr_id/allocations/$allocation_id?version=$api_version&generation=2" \
  -H "Authorization: Bearer $iam_token"