Bring a RIPE IPv6 PI /48 to AWS (VPC IPAM BYOIP)

AWS lets you advertise your own IPv6 range from EC2, VPC and CloudFront using Bring Your Own IP (BYOIP), managed through VPC IP Address Manager (IPAM). A RIPE IPv6 PI /48 is the exact minimum AWS will advertise to the internet, so it drops straight in. This guide covers the RIPE-side prerequisites GetIPv6 handles and the AWS-side steps you run.

Note: /48 is the smallest IPv6 block AWS advertises to the internet from a Region. For non-advertised (VPC-only) space the minimum is /60. Set your ROA max length to /48 so you can split and place the block across Regions.

What you need

What GetIPv6 does (your sponsoring LIR)

AWS-side steps (VPC IPAM)

  1. Generate the material. Create the self-signed X.509 key + certificate (RDAP method), or create an IPAM verification token (create-ipam-external-resource-verification-token) for the DNS-TXT method.
  2. Send us the certificate / token. We publish the certificate in RDAP, or you add the TXT record under the reverse zone of the /48. AWS uses nibble-aligned records for IPv6 (e.g. token-name.<nibbles>.ip6.arpa TXT "token-value").
  3. Sign the authorization message. Produce the text_message / signed_message proving you authorize AWS to advertise the range.
  4. Provision into IPAM. Bring the /48 into a publicly advertisable pool with the CIDR authorization context. Wait until the state is provisioned (can take a few hours; IPv6 sometimes longer).
  5. Withdraw any other advertisement, then advertise the /48 in your Region (e.g. us-east-2) with advertise-byoip-cidr.

After provisioning

Order of operations that matters

New to BYOIP? Start with the overview: Using Your RIPE IPv6 PI with Cloud BYOIP.

Get a routable IPv6 PI /48 for AWS BYOIP

Order RIPE IPv6 PI
← All guides