About custom authorized CIDRs for VPC
BYOIP for IPv4 is a beta feature that is available for evaluation and testing purposes to select customers. Access is restricted to allowlisted accounts.
You can bring your own publicly routable IPv4 address ranges to IBM Cloud VPC and use them alongside IBM-provided public IP addresses. Bring Your Own IP (BYOIP) is optional and applies to the public address ranges and floating IPs. This capability helps you maintain consistent IP addressing when migrating workloads, preserve existing allowlists, and retain IP reputation.
Customer-owned (BYOIP) authorized CIDRs are regional. Each CIDR is provisioned in a specific region and can only be used to allocate resources within that region. To use the same IP range in another region, you must deprovision it from the current region and provision it in the new region.
Use BYOIP when you need to:
- Keep the same public IPs when you migrate workloads to VPC.
- Maintain firewall rules, allowlists, or external dependencies that rely on specific IPs.
- Control how your address space is segmented and assigned across workloads.
How BYOIP works
BYOIP allows you to import a public IPv4 address range that you own into IBM Cloud VPC. After it is onboarded, the range is available in your account as an authorized CIDR.
An authorized CIDR acts as a pool of public IP addresses that you control and can allocate to VPC resources. Rather than having IP addresses assigned automatically from IBM-managed pools, you allocate addresses from this pool by creating public address ranges or floating IPs. Any unused IP addresses remain available in the pool for future use.
Understanding the allocation model
Think of your authorized CIDR as a single address pool that you subdivide based on your needs.
For example, from a /24 range (192.0.2.0/24) you might:
- Allocate
/26or/27blocks as public address ranges (for example,192.0.2.0/26,192.0.2.64/27,192.0.2.128/26) - Reserve individual IPs as floating IPs (for example,
192.0.2.224,192.0.2.225) - Leave the remaining IPs unallocated for future use
All allocations are tracked within the authorized CIDR, so you always know how your address space is being used. Available IP space includes all unallocated ranges plus any floating IPs that have not yet been assigned.
The following diagram shows how a /24 authorized CIDR (192.0.2.0/24) is divided into public address ranges, floating IPs, and unallocated space.
Using BYOIP with VPC resources
You can use BYOIP addresses with VPC resources that support public connectivity, including virtual server instances, bare metal servers, load balancers, VPN gateways, and network appliances.
You can allocate addresses from a custom authorized CIDR in two ways:
- Floating IPs: Reserve a single IP address (
/32) from your authorized CIDR and attach it to a virtual network interface (VNI) or a public gateway. This provides direct external connectivity to a specific resource without additional routing configuration. For more information, see Creating floating IPs from a custom authorized CIDR. - Public address ranges: Allocate a block of contiguous IPv4 addresses (a CIDR block) for use in your VPC. Public address ranges require ingress routing to be configured to direct traffic to the intended destination, such as a firewall or network appliance. They are bound to a VPC in a specific zone. For more information, see Creating public address ranges.
Common use case: Retaining your own public IP addresses
If your organization has existing public IP address ranges that are already known to your customers, partners, or DNS infrastructure, you can bring those IPs into IBM Cloud VPC. This approach eliminates the need to replace them with IBM-provided addresses.
By provisioning a custom authorized CIDR and then creating public address ranges or floating IPs from it, you:
- Retain your existing IP reputation
- Avoid updating firewall allowlists at your customers or partners
- Maintain continuity for services that depend on specific source or destination IPs
For example, an enterprise migrating workloads to VPC can bring a /28 block from their existing public range, bind it to a VPC zone, and configure ingress routing to direct traffic to a network appliance or application tier - all
without changing the public IPs their users already rely on.
Planning considerations
The following considerations highlight how BYOIP differs from IBM-provided public IPs and what to plan for when using your own address ranges:
- BYOIP is IPv4 only. You bring your own publicly routable IPv4 range. There is no equivalent for IPv6. IBM-provided IPv6 authorized CIDRs use the same authorized CIDR infrastructure but are not BYOIP. For more information, see About public IPv6 address ranges.
- BYOIP is optional. You can create public address ranges from IBM-managed IP pools without using BYOIP.
- Authorized CIDRs are scoped to a single region. To use the same IP range in another region, you must remove it and onboard it again in the new region.
- BYOIP uses a CIDR-based allocation model. Rather than having addresses assigned from an IBM-managed pool, you control how your address space is subdivided and allocated.
- Public address ranges require ingress routing to be configured after binding, unlike floating IPs which route traffic directly without additional configuration.
- A custom authorized CIDR cannot be self-provisioned. Provisioning is performed by IBM in response to an IBM Support case that you open. For more information, see Provisioning a custom authorized CIDR.
Getting started with BYOIP
Complete the following steps:
- Onboard your IP address range.
- View the authorized CIDR in your account.
- Allocate addresses from your authorized CIDR by using one of the following methods:
- Create public address ranges (block allocations).
- Create floating IPs (single IP allocations).
- Configure ingress routing so that traffic can reach your resources (required for public address ranges).
- Associate those allocations with VPC resources.
- Release allocations or deprovision the IP range when no longer needed.