Back to blog

SKNK Technical Guide

IPv4 Leasing Below /24: Can a /25 Be Announced with Your Own ASN?

A sub-/24 IPv4 lease can be originated by your own ASN at the BGP layer, but that does not make the route globally reachable, registered, or portable. How to separate the four things sellers bundle into one word.

The short answer is a qualified yes: a /25 — or a /26, /27, /28 — can be configured and announced from your own ASN, and many routers will accept the configuration without complaint. What a single BGP session does on your side, however, is only one of several independent conditions that decide whether the address space actually works the way a lease listing implies. Announcement, acceptance, propagation, and authorization are four separate things. This guide pulls them apart, because the word "independent BGP" in a sub-/24 product page usually hides exactly where they stop being true.

Definition Box: A sub-/24 IPv4 lease is a routing arrangement, not automatically a portable Internet resource. It grants the right to use addresses under a provider's or LIR's authority; whether those addresses are globally reachable, who may originate them, and what happens when the lease ends are determined separately.


1. What "Independent BGP" Actually Means

Before comparing any product, split the sales phrase into its four possible claims. A seller can mean any one of them, and each one carries a different level of commitment:

Meaning What it really means
Own ASN Your ASN appears as the route origin for the prefix
Own BGP session You hold an eBGP relationship with an upstream
Global reachability Multiple independent networks accept and propagate the route
Portable resource The prefix survives a provider change

The first two live in your router configuration. The third lives in other networks' routing policies, and the fourth lives in the registry and your contract. Nothing in the first two guarantees the last two. When a listing says "announce with your own ASN," read it as a statement about origin, not as a promise of worldwide reachability or portability.

White-Face Xiaolu pulls one tangled cable apart into four separate routing conditions: local origin, upstream session, global reachability, and portability.

One sales phrase can hide four separate conditions: origin, session, reachability, and portability.


2. What a Smaller-than-/24 IPv4 Product Is

"Sub-/24 IPv4" is not one product. It is a family of arrangements that share almost nothing except the address count, and they cannot be compared on price alone:

  1. A standalone PA /25/28. A sub-allocation from an LIR's Provider Aggregatable space, routed over an upstream. This is the only member of the family where "your own ASN as origin" is even on the table.
  2. A sub-range inside the provider's own network. The provider keeps one big block; you receive a slice of it and are simply a customer of that network. No BGP, no origin of your own.
  3. GRE / tunnel / server-attached IPs. Addresses delivered over a tunnel or bound to rented servers. They look like "yours" to a socket, but they never touch the global table under your control.
  4. Provider announces the full /24, you manage a sub-range. The whole /24 stays with the provider's ASN; you administer a /25 or smaller inside it.

The BGP capability, migration path, and price of these four are different categories, not points on one scale. A /25 you can originate is a fundamentally different thing from a /25 that only works behind someone else's announcement.


3. Three Deployment Models

Once you insist on your own origin, three realistic topologies emerge. They differ in who originates the route, who manages the ROA and the IRR record, and what happens at the end of the term.

White-Face Xiaolu turns a three-way route valve, sending one cable through an aggregate path, one into a filtering gate, and one across several open gates.

Three deployment models can share the same address count while producing different origins, visibility, and exit paths.

Model A — the provider announces the aggregate /24. Stability is the highest here: the world sees one well-established route from the provider's ASN, and your sub-range rides inside it. You may administer the subnets, but the origin is not yours. The ROA is controlled by the resource certificate holder, and the IRR route object is maintained with the address holder's authorization. On exit, your addresses simply stop being announced — there is nothing of yours to carry away.

Model B — your ASN announces the /25. Technically possible, and this is the arrangement the title of this article is really about. The catch is the upstream's prefix-length filter: many networks enforce a maximum accepted prefix length and reject anything more specific than /24. A /25 is more specific than a /24, so your route can be Valid, your session can be Established, and the announcement can still stop at the first filter. Your ASN is the origin, but you cannot promise global reachability on your own. The ROA is normally controlled by the holder of the address resource certificate; creating the IRR route object still requires the address holder's authorization — a point expanded below.

Model C — you receive a full /24. This is the cleanest boundary if your own ASN and multi-upstream global BGP are genuine requirements. A /24 is the most-specific IPv4 prefix many networks accept for broad propagation. It is a common practical routing boundary, not an unconditional guarantee. It is also the most expensive, and the least likely to be offered as a casual "lease" without a real routing relationship.

Each model can be reduced to five facts you should pin down in writing:

Model A (aggregate) Model B (customer /25) Model C (full /24)
Origin ASN Provider Customer Customer
ROA controller Resource holder Resource certificate holder (often LIR) Resource certificate holder
IRR route object Provider / authorized maintainer Requires address-holder authorization Requires address-holder authorization
Upstream prefix filter Not your concern Decides visibility Often accepts /24, but policy still varies
Exit handling Addresses return to provider Return + renumber Re-negotiate or return

4. Why a Route Can Be Valid but Still Not Reachable

The most common disappointment is not that a /25 cannot be announced — it is that the announcement exists and yet the address space never becomes reachable to the world. Three gates stand between your router and the global table, and each one closes independently:

  1. Your BGP session is Established. This proves your control plane is talking to the upstream. It says nothing about what the upstream will accept.
  2. The upstream accepts your prefix length. If the upstream accepts prefixes only up to /24, a /25 is dropped at the edge, silently.
  3. The rest of the Internet propagates it. Even after acceptance, every downstream network applies its own filters. A network that only accepts up to /24 will not carry your /25, even if its upstream did.

RPKI and IRR sit beside these gates, not above them. A ROA Valid result only means the cryptographic authorization for your origin ASN matches; it does not instruct any network to accept the route. An IRR route object only means the intended origin is recorded. Both can be correct and the route can still be dropped by a prefix-length filter two hops away. The reverse is equally true: a route can propagate today with stale or missing records, depending on who filters and how.

The practical consequence is that a single Looking Glass cannot verify a sub-/24 announcement. One vantage point that sees your /25 says nothing about the many other networks. Check the prefix from several public BGP observation points across regions, and if the route is not visible from most of them, treat it as not globally reachable no matter what the local session reports. This gate-by-gate logic is covered from the troubleshooting angle in RPKI vs IRR.


5. Registry, IRR, and RPKI Authorization

This is where "my own ASN" collides with "whose addresses these are." The RIPE Database draws a hard line between the two:

  • Address space authorization is about the prefix. To create a route or route6 object, you authenticate against the address space — the covering inetnum/inet6num — not against the origin ASN. Authorization follows the order mnt-routes, then mnt-lower, then mnt-by.
  • The origin ASN is a separate layer. You do not authenticate against the origin AS Number to create a route object; any non-reserved ASN can be used, and it does not even need to exist in the database.

The practical meaning is important for the "own ASN" pitch: holding an ASN does not give you the right to create a route object for someone else's PA prefix. If a sponsoring LIR or provider holds the address space, the IRR route object normally requires their authorization, while the ROA is controlled by the holder of the resource certificate. You need the address holder's cooperation for the records you want to change. The full authorization model is documented by the RIPE NCC in Protection of Route Object Space.

The fact that an IRR database can accept a non-reserved origin ASN is only a database rule. It is not permission to originate a prefix in BGP, and it does not override an upstream's filtering policy.

On the RPKI side, the ROA binds a prefix to an origin ASN and optionally a maxLength. Two details matter for sub-/24 leases:

  • A ROA with maxLength: /24 that authorizes only the /24 will mark a more-specific /25 as Invalid under strict origin validation — a common reason a "valid-looking" lease still fails ROV.
  • Whoever holds the address resource certificate is the party that can create or modify the ROA. That is usually the LIR, not the lessee.

See What Is a ROA? and What Is an IRR Route Object? for the two records in full, and What Is an IP Prefix? for how the prefix itself sits under all of it.


6. PA vs PI: The Exit and Renumbering Problem

The exit is where a sub-/24 lease stops being a technical question and becomes a contract question. Provider Aggregatable space is, by policy, not portable. RIPE NCC's IPv4 policy states plainly that when an end user or downstream network changes providers, address space assigned or sub-allocated from the previous provider must be returned and the network renumbered. LIRs are also required to warn PA customers that the assignment lasts only as long as the service agreement and that the space can be reassigned afterward. The policy is RIPE-553.

Three consequences follow for a lessee:

  • PA depends on the provider or LIR. When the relationship ends, the address block typically goes back, and every device using it must be renumbered to something else.
  • A leased /25 is not a portable PI resource. "Your ASN can originate it" describes the routing identity, not the address ownership. The address space itself remains someone else's, and its portability follows the registry rules for PA space.
  • Keeping an ASN does not make PA addresses portable. Your organization can usually retain its ASN through the appropriate sponsoring-LIR or transfer process, while a PA prefix normally has to be returned when the provider relationship ends. The two have different migration conditions; neither transfer is automatic.

This is also why the honest answer to "can I move my /25 to another provider?" is usually "you will likely renumber." If not renumbering is a hard requirement, the conversation should shift toward Provider Independent space or a transferable resource — which is a different product, with different cost and a different routing profile.


7. Pricing and Technical Support Snapshot

Prices below are a dated market snapshot from public listings reviewed in August 2026, not a quote or a market average. The listings use different currencies, minimum terms, setup fees, and support packages, so treat the range as an order-of-magnitude reference only. Representative listings include iFog, Hostio Solutions, Voldeta's 2026 plans, and IPbnb.

A full /24 (256 addresses) in the reviewed listings runs roughly $0.30–$0.75 per IPv4 per month, or about $80–$190 per month for the block after approximate currency conversion. Annual prepayment is often cheaper than month-to-month. Clean-reputation blocks sit at the higher end; blocks with spam or abuse history are discounted. These figures vary by region, block size, reputation, currency, and included support. Outright purchase prices are a separate market and are not included in this rental comparison.

The number to be skeptical of is any "per-IP" price for a sub-/24:

Pricing factor What to check
/24 total price Is it annual, quarterly, or monthly, and what is the minimum term?
Per-IPv4 / month A /24 price ÷ 256 is only an amortized average — do not assume a /25 costs half a /24
Setup fee / deposit Often the hidden cost on small blocks
RPKI / ROA Who creates it, and is maxLength set correctly for your prefix length?
IRR / route object Who maintains it, and in which registry does the upstream read it?
rDNS / GEO Who controls reverse DNS and geolocation data?
RBL / abuse handling Who handles blacklist delisting, and how fast?
Server / hosting binding Does the cheap price require renting servers or a tunnel from the same provider?

The cheap listings often reflect a different delivery model. A low per-IP price may correspond to GRE delivery, server binding, or the provider originating the announcement — meaning you are not getting your own origin at all. Compare products on origin, authorization, and exit as well as the per-IP number.


8. Buyer Decision Matrix

Map your actual requirement to a model before you shop:

Your requirement Recommended model
Only need a handful of addresses Provider-routed sub-range or GRE
Need your own ASN for experiments Sub-/24 with a designated, filter-aware upstream
Need long-term global reachability A full /24
Need to change providers without renumbering Evaluate PI or a transferable resource
Need to send email from these addresses Verify RBL, PTR, SMTP/25, and abuse handling first

White-Face Xiaolu points from a simple fork toward four different routing paths: a server or tunnel, a filtering gate, a broad open route, and a bridge that is no longer tied to its original stake.

Choose the deployment model from the operational requirement, not from the lowest per-IP price.

If your own ASN and global routing are the goal, the article that matters next is How to Announce an IPv6 /48 via BGP — the same origin/authorization/acceptance chain applies to IPv4, and IPv6 sidesteps the scarcity that makes sub-/24 IPv4 awkward in the first place.


FAQ

Can a /25 be announced with my own ASN?

At the configuration layer, yes. Whether any upstream accepts it, propagates it, and whether you are authorized to originate it are separate questions — and usually the ones that decide the outcome.

Will a /25 be visible globally?

Not reliably. Many networks filter prefixes more specific than /24, so a /25 can be accepted by one upstream and dropped by others. Verify from multiple public vantage points rather than relying on one Looking Glass.

Is a sub-/24 lease a PI resource?

No. A sub-/24 lease is normally a slice of someone else's PA space. PA is not portable; when the relationship ends, the addresses are returned and you renumber.

Who creates the ROA?

The party that holds the address resource certificate — usually the LIR or provider, not the lessee. Confirm this in the contract, along with the maxLength.

Who controls the IRR route object?

Creating a route object requires authorization against the address space, not the origin ASN. If the provider or LIR holds the space, they hold the maintainers and you need their authorization.

Does a BGP session being Established mean the route works?

No. Established only means your control plane is up. Acceptance, prefix-length filtering, and downstream propagation are all separate gates.

Can I move the prefix to another provider?

For PA space, usually not without renumbering. RIPE-553 requires address space from a previous provider to be returned on a provider change.

Why is a cheap per-IP price misleading?

Because a sub-/24 is not a fraction of a /24. A low per-IP rate often reflects GRE delivery, server binding, or provider-originated announcement — not a route you originate yourself.


Key Takeaways

  • A sub-/24 route can be configured from your own ASN, but configuration is only the first of several independent conditions.
  • "Independent BGP" hides four claims — origin, session, reachability, portability — that do not imply one another.
  • ROA Valid and a present route object do not override upstream prefix-length filters; both can be correct and the route can still be dropped.
  • PA address space is non-portable by policy; a leased /25 is not a PI resource and will usually mean renumbering at exit.
  • Compare sub-/24 products on origin, authorization, and exit terms, not on a per-IP price.

In One Sentence

A sub-/24 IPv4 lease can be originated by your own ASN, but origin, authorization, global reachability, and portability are four separate facts — and a lease only guarantees the first.

Continue Reading

References