Note: /48 is the smallest IPv6 block AWS advertises to the internet from a Region. For non-advertised (VPC-only) space the minimum is /60. Set your ROA max length to /48 so you can split and place the block across Regions.
What you need
- A RIPE IPv6 PI /48 (or a /48 from a larger allocation) that you control.
- Two RPKI ROAs authorizing Amazon's ASNs, both with max length /48:
- AS16509 — all commercial AWS Regions.
- AS14618 — the us-east-1 (N. Virginia) Region.
- Proof you control the range, using either method AWS accepts:
- X.509 certificate in RDAP — a self-signed certificate published in your RIPE Database object (works because RIPE supports RDAP), or
- DNS TXT record — an IPAM-generated verification token placed in the reverse DNS zone of the /48 (works with any registry).
- The /48 must not be advertised elsewhere when AWS begins advertising it.
What GetIPv6 does (your sponsoring LIR)
- Creates and maintains the two ROAs (AS16509 + AS14618, max length /48) in RIPE RPKI.
- Publishes the AWS X.509 certificate in your RDAP / RIPE Database object, or helps add the reverse-DNS TXT token for the IPAM path.
- Provides a Letter of Authorization (LoA) if requested.
- Keeps the /48 un-advertised during onboarding.
AWS-side steps (VPC IPAM)
- Generate the material. Create the self-signed X.509 key + certificate (RDAP method), or create an IPAM verification token (
create-ipam-external-resource-verification-token) for the DNS-TXT method. - Send us the certificate / token. We publish the certificate in RDAP, or you add the TXT record under the reverse zone of the /48. AWS uses nibble-aligned records for IPv6 (e.g.
token-name.<nibbles>.ip6.arpa TXT "token-value"). - Sign the authorization message. Produce the
text_message/signed_messageproving you authorize AWS to advertise the range. - Provision into IPAM. Bring the /48 into a publicly advertisable pool with the CIDR authorization context. Wait until the state is provisioned (can take a few hours; IPv6 sometimes longer).
- Withdraw any other advertisement, then advertise the /48 in your Region (e.g.
us-east-2) withadvertise-byoip-cidr.
After provisioning
- Allocate addresses from the pool to VPC subnets, EC2, Elastic IPs and CloudFront in the Region.
- You control advertisement — you can withdraw the /48 and move it elsewhere at any time.
Order of operations that matters
- ROAs and the RDAP certificate (or TXT record) must exist before you provision in IPAM.
- Stop advertising the /48 from anywhere else before you call advertise in AWS — two origins for the same prefix will conflict.
New to BYOIP? Start with the overview: Using Your RIPE IPv6 PI with Cloud BYOIP.
Get a routable IPv6 PI /48 for AWS BYOIP
Order RIPE IPv6 PI