ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
Why IMIDC

IP Block Leasing for Hosting Providers: /24 Native Blocks, LOA and ROA Announcements

10 steps 27 min read 25 views 0
On this page

Anyone who runs host nodes to sell VPS, or operates site clusters, knows the story: you can always buy more hardware, but IP addresses are the real bottleneck. How many VPS a host node can carry, and how many sites a site cluster can host, depends on how many clean C-class (/24) blocks you hold. IPv4 has long been exhausted, so there are only two ways to get a block now: buy one through an RIR transfer, or lease one from a holder. This article covers leasing only, from the point of view of a bulk, long-term buyer: how to choose a block, what paperwork is involved, how to announce it, and what kind of upstream is worth a long-term relationship.

Key Takeaways

  • Because IPv4 has long been exhausted, hosting providers can obtain an IP block in only two ways: buying one through an RIR transfer or leasing one from a holder.
  • Announcing a leased IP block from your own ASN usually requires an LOA, an IRR route object and an RPKI ROA together, and a missing ROA or a wrong ASN in the ROA will get the route marked invalid on networks that enforce ROV.
  • Before leasing an IP block, check the whole block for RBL blacklist and abuse history, its geolocation database entries and whether it is a local native IP block.
  • Providers without their own ASN can use multiple IPs, up to a full /24, directly on IMIDC dedicated servers in Japan, Korea, Taiwan, the US or Moscow.
  • IMIDC is a member of the four RIRs (RIPE NCC, APNIC, ARIN and AFRINIC) and can help arrange authorization materials such as LOAs, route objects and ROAs.

Do the Math First: Lease, Buy, or Use the Data Center's IPs

Many providers on NodeSeek and HostLoc have debated the same question: when you are just starting out, should you buy dedicated servers with multiple IPs, or apply for your own ASN and lease a block to announce yourself? The right path depends mainly on your scale and whether you have network operations skills.

Option Best for Prerequisites Advantages Watch out for
Use multiple IPs directly in an IMIDC data center (up to a full /24) Providers just starting with host nodes, site cluster teams, and sellers without their own ASN None; usable as soon as the server is up Fast to launch; routing and rDNS are maintained by the upstream; Japan, Korea, Taiwan, US and Moscow nodes are ready to sell right away The IPs are tied to the data center and cannot be taken with you when you move
Lease an IP block and announce it from your own ASN via LOA Hosting providers that already have an ASN and network across multiple data centers Your own ASN, a BGP-capable upstream or equipment, plus LOA, IRR and ROA The IPs move with you between data centers; you control your brand and routing High operational bar; a small misconfiguration can get you treated as a hijack
Lease a block first, add BGP or Anycast later Teams growing from reseller to true network operator An upstream that can support ASN and BGP setup A gradual transition without a large upfront investment Make sure renewal and reclaim terms are spelled out in the contract

Our view: if you do not have an ASN yet, start by taking a full C-class block directly on an IMIDC dedicated server in Japan, Korea, Taiwan, the US or Moscow, and get your host node and site cluster business running at the lowest cost. Once the business grows, consider your own ASN and BGP announcements. IMIDC also provides BGP, Anycast and ASN-related services, so you can upgrade smoothly later.

LOA, IRR and ROA: What Each One Does

Many newcomers lump these three together, and end up with a block they cannot announce, or one that is reachable from some networks but not others. In short:

  • LOA (Letter of Authorization): a paper document in which the IP holder authorizes your ASN to announce a specific prefix. It usually states the holder, the authorized ASN, the exact CIDR and the validity period. Many upstreams check this document before setting up a BGP session for you.
  • IRR route object: a route or route6 object registered in a registry such as RIPE, APNIC or RADB, declaring that "a given ASN may originate a given prefix". Many carriers generate filters automatically from IRR data; without a registration, your route will simply be dropped by some networks.
  • RPKI ROA: a digitally signed authorization. More and more networks perform route origin validation (ROV) against ROAs. Without an ROA, or with the wrong ASN in the ROA, your route will be marked invalid on networks that enforce ROV.

As discussed repeatedly on LowEndTalk and NANOG: an LOA is a paper document and easy to forge, while an ROA is issued by the RIR and can be verified. A truly professional lessor sets up all three together instead of just handing you a PDF. The RIPE community has also discussed upstreams announcing customer prefixes on their behalf, and concluded that this is normal business as long as both the ROA and the IRR authorize the correct origin ASN. The same prefix can also have multiple ROAs with different origin ASNs at the same time, so during a migration you can bring up the new one before dropping the old one without any downtime.

This is where membership in the four RIRs matters. IMIDC is a member of RIPE NCC, APNIC, ARIN and AFRINIC, and its IP resources are allocated officially by the RIRs with a clear provenance. When you need authorization materials such as an LOA, route objects or ROAs, IMIDC can help arrange them, so you do not have to go through several intermediaries to find the actual holder.

What's Behind a Block: Reputation, Geolocation and History

The biggest complaint among providers on forums is not price but "dirty" blocks. The previous tenant sent spam or ran scans and left a trail of blacklist entries; or the geolocation in IP databases still points to another country and the fraud score is high, so sites in a site cluster get indexed poorly and VPS customers keep opening tickets.

Before taking a block, check three things:

  1. Blacklists and abuse history: bulk-check the whole block against major RBLs such as Spamhaus, and look at neighboring blocks too. Contamination elsewhere in the same /16 can also drag you down.
  2. Geolocation databases: databases such as MaxMind and IPinfo update with a delay, so a newly transferred block may show the old country for a while. A reputable upstream will submit corrections for you rather than leaving you to deal with the database vendors yourself.
  3. Native attributes: native IP blocks in Japan, Korea, Taiwan and the US are a plus for site clusters and host node customers that need a "local identity". IMIDC has data centers in all these regions and provides local native IPs; the Moscow node also has CN2 routes connected directly to mainland China, with a return route that works well for users in China. Native IP and home broadband IP resources in Indonesia and Vietnam are available as a complementary option.

Signs of a Reputable Upstream: It Handles Abuse and Does KYC

Some providers find strict upstreams a hassle: they require KYC and forward complaints to downstream customers. But look at it the other way: an upstream that never handles abuse will sooner or later have its blocks blacklisted wholesale by RBLs, or even reclaimed by the holder. When that happens, your host node customers all go offline at once, which is not much different from your upstream disappearing overnight.

An upstream that takes abuse and traceback complaints seriously is protecting the reputation of the entire C-class block; requiring KYC from downstream customers keeps your resale business compliant and stable over the long term. For site cluster teams, please also remember: a site cluster here means compliant multi-site operation that follows local laws and the rules of search engines and platforms, not scraped spam sites or black-hat SEO. Only clean content deserves a clean block.

Procurement / Acceptance Checklist (For Hosting Providers)

Once you receive a block or a dedicated server with a full block, go through the checklist below item by item and keep a record:

  • [ ] Check the prefix against the contract and confirm the CIDR, count and gateway details are correct
  • [ ] Use whois to check the RIR of record and confirm the inetnum or NetRange information is clear
  • [ ] Check whether a matching route object exists in the IRR and whether the origin ASN is correct
  • [ ] Use an RPKI validation tool to confirm the prefix's ROA status is valid
  • [ ] If you will announce from your own ASN, confirm the LOA's validity period and authorized ASN are correct
  • [ ] Bulk-check the whole block against RBL blacklists and spot-check neighboring blocks
  • [ ] Spot-check country and city in several geolocation databases and record fraud scores
  • [ ] Confirm rDNS can be self-managed or handled by the upstream on your behalf
  • [ ] On the host node side, test whether IPMI/KVM works, whether Virtualizor, PVE, SolusVM or Convoy can be installed, and whether multiple IPs bind correctly
  • [ ] Run mtr to check the outbound and return routes, and confirm the IPs are not blocked in mainland China
  • [ ] Understand how abuse tickets are forwarded and how responses are handled
  • [ ] Write renewal, reclaim and migration terms into the contract

FAQ

Can I announce a leased IP block from my own ASN?

Yes, provided you have your own ASN and the upstream is willing to set up BGP for you. The holder needs to provide an LOA and change the origin ASN in the IRR route object and RPKI ROA to yours. IMIDC can help prepare these authorization materials; contact our business team to assess your specific needs.

Site cluster servers need multiple C-class blocks. How many IPs can one server get?

IMIDC dedicated servers support multiple IPs, up to a full /24. Local native IPs are available in Japan, Korea, Taiwan and the US. Contact support for a custom combination of multiple C-class blocks based on your project.

What if a newly leased IP block shows up in another country?

This usually means the geolocation databases have not been updated yet. First confirm that the whois and geofeed information is correct, then submit corrections to databases such as MaxMind and IPinfo. Each vendor takes a different amount of time to apply changes, and a reputable upstream will help you follow up.

Why does my upstream require KYC for VPS resale?

KYC and abuse handling protect the reputation of the entire IP block. The stricter the upstream's controls, the lower the risk that your block gets blacklisted wholesale or reclaimed, which is exactly what you should look for in a long-term upstream.

Find an IP Upstream You Can Work With Long Term

IMIDC (Rainbow Network Limited) has been operating since 2014, has served more than 5,000 customers, operates 9 data centers, has IP resources covering 24 countries, and is a member of all four major RIRs. We offer SSD dedicated servers, 10Gbps uplinks and DDoS protection, in Tier3+ data centers with 2N power and a 99.9% availability commitment, along with 24/7 multilingual support and free migration. If you are looking for host node or site cluster servers in Japan, Korea, Moscow, Taiwan or the US, or need full C-class blocks, contact our business/support team to discuss bulk and long-term cooperation: https://www.imidc.com

Related Products

Related Articles

References

  • https://lists.ripe.net/pipermail/members-discuss/2019-November/003478.html
  • https://kb.leaseweb.com/kb/network-services/how-to-create-route-object-and-roa-records/
  • https://ipv4center.com/blog/what-are-roa-loa-ipv4-leasing-transfers
  • https://dev.to/kohanevich/the-ipv4-leasing-mistakes-that-will-cost-you-thousands-2i69
  • https://lowendtalk.com/discussion/comment/4820199/
  • https://ipinfo.io/compare/maxmind-alternative

Was this answer helpful?

Related Tutorials