Provisioning a custom authorized CIDR
BYOIP for IPv4 is a beta feature that is available for evaluation and testing purposes to select customers. Access is restricted to allowlisted accounts.
You can provision a custom authorized CIDR to bring your own publicly routable IPv4 address range into IBM Cloud VPC. By using your own IP ranges, you can retain your established IP reputation and continue to pass through externally controlled allowlists. A custom authorized CIDR acts as a pool of IP addresses that you can subdivide and allocate to public address ranges.
Customer-owned (BYOIP) authorized CIDRs are regional. When you provision a CIDR, you specify a region, and that CIDR can be used only to allocate resources within that region. To use the same IP range in a different region, you must open a new support case to deprovision it from the current region and provision it in the new region.
Before you begin
Provisioning a custom authorized CIDR requires an IBM Support case. If you bring your own IP (BYOIP), you must also provide a signed Letter of Authorization (LoA); IBM-assigned CIDRs do not require an LoA. IBM reviews the request and provisions the CIDR in your account. The provisioning process typically takes a minimum of two weeks.
Before you request provisioning of a custom authorized CIDR, review the following requirements and constraints:
- A custom authorized CIDR can be provisioned only through an IBM Support case. You cannot provision an authorized CIDR yourself. To request provisioning, see Provisioning a custom authorized CIDR.
- You must own the public IPv4 address range that you want to use.
- The CIDR block must be within the supported size range: minimum
/24, maximum/8. - The CIDR block must not overlap with other address ranges that are already in use in your account.
- The authorized CIDR address space is allocated in blocks when you create public address ranges or floating IPs from it. You cannot create sub-authorized CIDRs; the CIDR itself is the single pool from which allocations are made. Size the address space appropriately for your workload needs.
- Each account can have up to five authorized CIDRs per region.
- An authorized CIDR cannot be moved from one region to another. To use the same IP range in a different region, you must open a new support case to deprovision it from the current region and then provision it in the new region.
- Authorized CIDRs are cloud resources and have a Cloud Resource Name (CRN) that includes
public-address-range-authorized-cidr. They are onboarded to the Resource Controller and Global Search, and can be tagged and searched. - To allocate a public address range from an authorized CIDR, the user must have the
is.public-address-range-authorized-cidr.authorized-cidr.operateIAM action.
Provisioning a custom authorized CIDR in the console
To request provisioning of a custom authorized CIDR:
-
Select the Navigation menu
, then click Infrastructure
> Network > Public address ranges.
-
Click the Custom authorized CIDRs (BYOIP) tab.
-
Click Provision custom CIDR.
-
In the Provision custom CIDR dialog, review the information about what is required for the request, then click Create support case. The system redirects you to the Support Center.
If you bring your own IP (BYOIP), ensure that you have a signed Letter of Authorization (LoA) on company letterhead ready to attach. Click Download template in the dialog to obtain the LoA template, or see Template: Letter of Authorization for IBM to announce IPv4 prefixes. An LoA is not required for IBM-assigned CIDRs.
The provisioning process can take at least two weeks. Track progress in your support case.
-
In the support case form, complete the following fields.
The fields differ depending on your support plan:
- Platinum, Premium, or Advanced support plan: Select Category:
Account, Topic:Account, Subtopic:Bring your own IP to VPC. - Basic support plan: Under Report an issue, select Topic:
Virtual Private Cloud (VPC), Subtopic:Bring your own IP to VPC. A two-way support case is opened to process your request.
Then complete the remaining fields:
- Subject: Enter
Authorize custom CIDR (BYOIP) - Description: Include the following details:
- Select Provision CIDR to indicate the request type.
- For the version, enter IPv4.
- For CIDR ownership, enter Customer or IBM.
- Specify the destination region where the CIDR must be provisioned.
- Add any additional information relevant to your request.
- Attachments: If the CIDR or CIDRs are customer-provided, attach your signed LoA file (for example,
LOA_BYOIP_company.docx)
- Platinum, Premium, or Advanced support plan: Select Category:
-
Complete any other optional information, then review the case summary and click Submit case.
After IBM approves your request and provisions the CIDR, it appears in the Custom authorized CIDRs (BYOIP) tab. You can then create public address ranges or reserve floating IPs from it.
For public address ranges, you must configure ingress routing before traffic can reach your resources. For more information, see About routing tables and routes.
Next steps
Provisioning a custom authorized CIDR from the CLI
Before you can use the CLI, you must install the IBM Cloud CLI and the VPC CLI plug-in. For more information, see the CLI prerequisites.
Before you can work with a custom authorized CIDR in the CLI, you must open an IBM Support case through the Public address range for VPC UI. If you bring your own IP (BYOIP), you must also attach a signed Letter of Authorization (LoA). For more information, see Provisioning a custom authorized CIDR in the console. IBM reviews the request and provisions the CIDR in your account.
After IBM provisions the custom authorized CIDR, you can verify that it is available in your account by running the following command:
ibmcloud is public-address-range-authorized-cidrs
For more information about viewing authorized CIDRs, see Viewing a custom authorized CIDR.
You can then create public address ranges or reserve floating IPs from the CIDR. Specify a CIDR block from the authorized CIDR when you run ibmcloud is public-address-range-create --cidr CIDR. For more information, see Creating a public address range.
You can also reserve floating IPs from the CIDR by using ibmcloud is floating-ip-reserve --address ADDRESS. For more information, see Reserving floating IPs from a custom authorized CIDR.
Next steps
Provisioning a custom authorized CIDR with the API
Before you begin, set up your API environment.
Before you can work with a custom authorized CIDR using the API, you must open an IBM Support case through the Public address range for VPC UI. If you bring your own IP (BYOIP), you must also attach a signed Letter of Authorization (LoA). For more information, see Provisioning a custom authorized CIDR in the console. IBM reviews the request and provisions the CIDR in your account.
After IBM provisions the CIDR, you can list all authorized CIDRs in your account by sending a GET request:
curl -sX GET "$vpc_api_endpoint/v1/public_address_range/authorized_cidrs?version=$api_version&generation=2" \
-H "Authorization: Bearer $iam_token"
You can filter the list by allocation profile family or availability mode:
curl -sX GET "$vpc_api_endpoint/v1/public_address_range/authorized_cidrs?version=$api_version&generation=2&allocation.profile_family=user" \
-H "Authorization: Bearer $iam_token"
curl -sX GET "$vpc_api_endpoint/v1/public_address_range/authorized_cidrs?version=$api_version&generation=2&availability_mode=regional" \
-H "Authorization: Bearer $iam_token"
To view details of a specific authorized CIDR, send a GET request with the CIDR ID:
curl -sX GET "$vpc_api_endpoint/v1/public_address_range/authorized_cidrs/$authorized_cidr_id?version=$api_version&generation=2" \
-H "Authorization: Bearer $iam_token"
To list all allocations for an authorized CIDR, send a GET request to the allocations endpoint:
curl -sX GET "$vpc_api_endpoint/v1/public_address_range/authorized_cidrs/$authorized_cidr_id/allocations?version=$api_version&generation=2" \
-H "Authorization: Bearer $iam_token"
You can filter allocations by resource type:
curl -sX GET "$vpc_api_endpoint/v1/public_address_range/authorized_cidrs/$authorized_cidr_id/allocations?version=$api_version&generation=2&allocations[].resource_type=floating_ip" \
-H "Authorization: Bearer $iam_token"
To view details of a specific allocation, send a GET request with the allocation ID:
curl -sX GET "$vpc_api_endpoint/v1/public_address_range/authorized_cidrs/$authorized_cidr_id/allocations/$allocation_id?version=$api_version&generation=2" \
-H "Authorization: Bearer $iam_token"
Using your CIDR with the API
After IBM provisions the custom authorized CIDR, you can create public address ranges or reserve floating IPs from it. Send a POST request to /v1/public_address_ranges and specify the cidr field with
a CIDR block from the authorized CIDR. For more information, see Creating a public address range. You can also reserve floating IPs from the CIDR by specifying an address from your range. For more information, see Reserving floating IPs from a custom authorized CIDR.
Public address ranges created from a custom authorized CIDR require ingress routing to be configured before traffic can reach your resources. For more information, see About routing tables and routes.