IP Address Allocation
Depending on your routing configuration, your Internet Access service needs the following subnets.
-
Static, Direct, and BGP routing all require a LAN subnet.
Your LAN subnets can be:
-
Equinix-owned IP Addresses - Lease public IP addresses owned by Equinix.
-
Customer-provided IP Addresses - Onboard public IP addresses that you own or are authorized to use.
-
Mixed IP Addresses - Use both your own and Equinix-assigned public IP addresses.
-
-
If you are using Static or BGP routing, you also need a Peering subnet.
Peering subnets use Equinix-assigned IP Addresses and are automatically assigned when you create the service at no additional cost. Peering subnets do not support customer-provided IP addresses.
Equinix-owned IP Addresses
Equinix-owned IPv4 and IPv6 address blocks can be used with the Internet Access service.
When you order internet access, you select a subnet of Equinix-owned IP addresses from your IP Blocks inventory to use for your LAN subnet. You can also order a new Equinix-owned IP Block.
The following subnet sizes are available:
- IPv4 subnets –
/30,/29,/28,/27,/26,/25,/24 - IPv6 subnets –
/64,/48
If you are using Static or BGP routing, your service is automatically assigned a peering subnet of Equinix-owned IP addresses. The minimum subnet size depends on the selected routing configuration.
Customer-provided IP Addresses
Equinix Internet Access supports the use of customer-owned or authorized, publicly routable IP address space.
When using customer-provided IP addresses, a Route Object (RO) must be created in the Internet Routing Registry (IRR) associated with the Regional Internet Registry (RIR), or another IRR such as the Routing Assets Database (RADb). (Equinix recommends using a Regional Internet Registry’s IRR.)
If you’re using a public ASN the Route Object must match the public ASN your public prefix. If you’re using a private ASN the Route Object must match Equinix’s public ASN (15830) and your prefix. The Route Object is required for the internet access service to accept a prefix received from you, or used on a Direct service, and advertise that prefix to upstream peers and providers.
Equinix recommends, but not require, you create a Resource Public Key Infrastructure (RPKI) Route Origin Authorization (ROA) for your prefix and relevant ASN as well. When creating an ROA it is important to make sure it’s properly configured. An Invalid ROA will cause the matching prefix to be dropped by the service.
Internet Routing Registry (IRR) Requirements
-
Exact‑match route objects must be created for every prefix that will be announced. For example, announcing
198.51.100.0/24requires a route object for198.51.100.0/24exactly. -
Route objects should be created in the IRR associated with the Regional Internet Registry (RIR), such as:
- ARIN IRR – American Registry for Internet Numbers
- RIPE Database – RIPE NCC
- APNIC IRR – Asia-Pacific Network Information Centre (APNIC)
- LACNIC IRR – Latin America and Caribbean Network Information Centre (LACNIC)
- AFRINIC IRR – African Network Information Center (AFRINIC)
-
You may also announce IP address space obtained from third parties, provided the announcing organization is the legitimate holder or an authorized user of the ASN and/or IP address space. Being a “legitimate holder” and “authorized user” requires an Route Object matching the IP prefix and relevant ASN. Letter of Agency (LOAs) are not an acceptable or valid method of to prove legitimacy or authorization.
Using RPKI and Route Origin Authorization
Resource Public Key Infrastructure (RPKI) enables IP prefixes and Origin ASNs to be cryptographically validated by networks worldwide.
Equinix recommends, but does not require, an Route Origin Authorization (ROA) for a prefixed advertised to Internet Access at this time. If an ROA does exist the tuple of Prefix/ASN/maxLength must match the Origin ASN and prefix being advertised to Internet Access. An invalid ROA will result in the prefix being dropped. If Equinix is the Origin AS for your prefix and you want to use an ROA, you need to create an ROA that authorizes Equinix to announce the prefix as with an origin AS of 15830.
For example:
- Origin ASN:
15830(Equinix) - Prefix: The exact prefix to be announced (for example,
198.51.100.0/24) - Prefix lengths that exactly match the intended announcement (for example, a
/24announcement requires maxLength = 24)
ROAs must be created through the Regional Internet Registry (RIR) where the prefix is registered. Equinix cannot create or manage RPKI ROAs for customer subnets.
Prefix Size Requirements
Equinix Internet Access requires the following minimum prefix sizes:
- IPv4:
/24 - IPv6:
/48
Internet Routing Registry Route Objects should match, and RPKI Route Origin Authorizationss must match, the intended announcements and meet the minimum size requirements.
ASN Requirements and Local‑AS Support
Dedicated Internet Access ports support routing with customer public Autonomous System Numbers (ASNs).
EIA delivered via Fabric Port or to Network Edge currently requires the use of a private ASN provided by Equinix for BGP peering.
To retain the use of a public ASN, for the routing process or as an origin ASN, in these scenarios, the BGP Local‑AS feature may be used, subject to support by the network equipment vendor. This allows the public ASN to be maintained internally while satisfying the private ASN requirement for peering with Equinix.
Refer to the router vendor documentation or contact an Equinix account team for guidance on configuring and using Local‑AS.
Propagation Time Before Service Activation
After creating the required IRR Route Object, you must wait for global propagation. Allow up to 36 hours before creating an Internet Access service. This ensures that Equinix systems can validate the prefixes and accept the route announcements.
Mixed IP Addresses
Internet Access supports using both Equinix-owned and customer-provided IP addresses on the same service. Mixed IP addresses are supported for the following routing configurations:
| Configuration | Internet Access Over Fabric | Internet Access to Network Edge |
|---|---|---|
| Single Static Routing | Supported | Supported |
| Dual Static VRRP | Supported | NOT Supported |
| Single Direct Routing | NOT Supported | NOT Supported |
| Dual Direct VRRP | NOT Supported | NOT Supported |
| Single BGP | Supported | Supported |
| Dual BGP | Supported | Supported |
Mixed IP addresses are not available on Internet Access over Dedicated Ports.