Start typing to search across invoices, services, domains, tickets, and more...
Once a business reaches a certain scale, the same needs keep coming up: using its own IP addresses, moving between data centers without renumbering, or letting users around the world reach a single address through the nearest location. All of this depends on BGP, ASNs and Anycast. This article explains these concepts in plain language and walks through the full process of applying for an ASN and IP block and getting your routes announced.
This guide is for:
Prepare these in advance: company registration documents, a network plan (why you need an independent routing policy and which upstreams you plan to connect to), and technical contact details.
BGP (Border Gateway Protocol, currently BGP-4) is the protocol networks use to exchange routing information with each other across the internet. Each network uses BGP to tell its neighbors: "These IP blocks are here with me, and you can reach them through me." The global routing table is built from tens of thousands of networks making these announcements to one another.
An ASN (Autonomous System Number) uniquely identifies a network that manages its own routing policy. 4-byte ASNs are now the norm, giving a range of roughly 4.2 billion numbers. The ranges 64512–65534 and 4200000000–4294967294 are private ASNs: they can only be used internally and must not appear in the public global routing table.
Anycast means announcing the same IP block from multiple locations at once via BGP. When a user connects to that IP, routing sends them to the node that is closest in network terms. Public DNS, CDNs and DDoS scrubbing networks widely use Anycast. Its advantages include:
IANA allocates the world's IP addresses and ASNs to five Regional Internet Registries (RIRs):
| RIR | Service Region |
|---|---|
| APNIC | Asia-Pacific (including Hong Kong, Taiwan, Japan, Singapore, etc.) |
| RIPE NCC | Europe, the Middle East and Central Asia (including Russia) |
| ARIN | United States, Canada and parts of the Caribbean |
| LACNIC | Latin America and parts of the Caribbean |
| AFRINIC | Africa (including South Africa) |
You should generally apply to the RIR that covers the country where your company is registered or where most of your network is located.
When you apply for an ASN, RIRs usually ask you to demonstrate multihoming or an independent routing policy, meaning you plan to establish BGP sessions with two or more upstream networks.
IPv4 is essentially exhausted at every RIR. New members can usually obtain only a small allocation through a waiting list, or buy addresses on the IP transfer market or lease them from holders. IPv6 is plentiful and new requests are generally approved without much difficulty, so plan for IPv6 at the same time. Note that the smallest prefix normally accepted in global routing is /24 for IPv4 and /48 for IPv6.
Once you have an ASN and IP block, your upstream provider still needs to announce your routes to the rest of the world. This involves a few key steps.
An LOA is a document issued by the IP block holder authorizing a provider (or its upstream) to announce a specific prefix. Upstream networks usually check that the LOA matches the holder information in the RIR database.
The IRR (Internet Routing Registry) is a set of public routing databases. You need to create route / route6 objects in the RIR database or an IRR such as RADB, declaring that "this prefix is originated by this ASN". Many upstreams generate their filters automatically from the IRR, so a missing route object can get your announcement rejected. Lookup examples:
whois -h whois.radb.net 203.0.113.0/24
whois -h whois.radb.net -- '-i origin AS64500'
RPKI uses cryptographic certificates to verify who is allowed to originate a given prefix. In your RIR member portal, create a ROA (Route Origin Authorization) for the prefix, specifying the ASN allowed to originate it and the maximum prefix length. More and more operators now drop routes that fail RPKI validation as Invalid, so without a correct ROA, your routes may well be unreachable from parts of the internet. You can check who holds a prefix with:
whois -h whois.apnic.net 203.0.113.0
If your provider gives you a BGP session, you can announce your prefix from a Linux server using BIRD 2. The ASNs and IPs in this example are reserved documentation values; replace them with the actual parameters from your provider:
apt install -y bird2
Example /etc/bird/bird.conf:
router id 192.0.2.10;
protocol device { }
protocol static announce_v4 {
ipv4;
route 203.0.113.0/24 unreachable;
}
protocol bgp upstream {
local 192.0.2.10 as 64500;
neighbor 192.0.2.1 as 64496;
ipv4 {
import none;
export where net = 203.0.113.0/24;
};
}
Reload the configuration and check the session status:
systemctl restart bird
birdc show protocols
birdc show route export upstream
A session state of Established means BGP is up. Note that you still need to configure the addresses you actually use from the block on your network interface before your services can be reached.
Yes. Some providers can announce your IP block using their ASN. You just provide an LOA and set up the IRR and ROA records accordingly. This suits users who don't plan to apply for an ASN yet.
It depends on the RIR and how complete your documents are. With everything in order, it usually takes from a few business days to a few weeks. Becoming an RIR member takes longer.
Anycast works best for stateless or short-lived connections such as DNS, CDNs and API gateways. Long-lived or stateful services need extra design work so that routing changes don't shift connections to a different node.
First check that your ROA covers the correct ASN and prefix length and that your IRR objects have taken effect. Then use public tools such as bgp.tools or a Looking Glass to see how your routes are propagating worldwide.
BGP connects networks, an ASN identifies a network, and Anycast lets one address serve users from the nearest location worldwide. An LOA, IRR objects and an RPKI ROA are the three key preparations for getting your own IPs announced correctly. IMIDC is a member of RIPE NCC, APNIC, ARIN and AFRINIC and can provide consulting on ASNs and IP blocks, BGP announcement and Anycast solutions, with support for connecting servers and colocation across multiple data centers. Because the process requires manual review of documents, please submit a ticket in the Client Center if you need help, and our 24/7 technical team will confirm the details with you.