Bring Your Own IP (BYOIP)
Files.com offers Enterprise customers the ability to Bring Your Own IP (BYOIP), letting you use your own public IPv4 address range for both inbound and outbound traffic on your Files.com site. Files.com announces your range on the global internet and assigns addresses from that range to your site. Users connecting to your site reach your own addresses, and outbound connections from your site originate from them.
This feature is available exclusively to customers on Enterprise plans and requires approval and coordination with the Files.com team. Extra charges apply.
When to Use BYOIP
BYOIP is not the default way to get stable addresses, and most allowlist requirements do not need it. Adding a custom domain automatically provisions a pair of dedicated IP addresses for your site, giving your partners a stable pair to add to their allowlists. If stable addresses are all you need, that is the simpler path, and it is included on the Power and Enterprise plans.
BYOIP is the right choice when ownership of the addresses is itself the requirement:
- Compliance rules or corporate policy require that traffic originate from company-owned address space.
- External partners validate address ownership against your Regional Internet Registry (RIR) registration.
- Equipment in the field or counterparty connections with hardcoded addresses cannot be updated cheaply, so the address needs to belong to you rather than to any provider, including us. This is the case that most often justifies the cost: when reconfiguring endpoints means dispatching technicians or contacting hundreds or thousands of counterparties, owning the address becomes an operational necessity.
Benefits of BYOIP
Bringing your own IPs to Files.com offers several advantages:
- Firewall and allowlist compatibility. Your partners and internal systems allow traffic from addresses you already control, so your Files.com site fits security policies you have already written and distributed.
- Independence from provider IP changes. The range belongs to you, so your site's addresses cannot change when a provider renumbers its address space. Files.com's own addresses moved to a new range in March 2026; a BYOIP range sits structurally outside changes like that.
- Policy and brand continuity. Organizations with a policy that traffic must originate from company-owned address space can meet it without writing an exception for Files.com.
- Reputation continuity. Address space you have operated for years carries an established routing history, and you keep it.
Supported Traffic Types
Files.com supports BYOIP for both inbound and outbound traffic. Inbound traffic covers users accessing your site over FTP, SFTP, FTPS, WebDAV, and HTTPS — they connect to your own IP addresses. Outbound traffic covers connections originating from your site, such as webhooks and outbound connections to FTP/SFTP servers, which can optionally originate from your IPs.
The result is predictable, transparent network traffic in both directions.
Requirements
To participate in the BYOIP program, your organization must meet the following criteria:
- You must own a public IPv4 address range registered with a recognized RIR such as ARIN, RIPE, or APNIC.
- You must provide at least a /24 subnet (256 IPs). A /24 is the smallest block that can be announced on the global internet, because networks filter out anything smaller to keep the size of the global routing table under control. A single /24 covers every region you operate in.
- You must be able to publish a Route Origin Authorization (ROA) through your RIR and add a certificate to your registry record for the range. Both are required before your range can be announced.
- Your IP space must be eligible for BGP advertisement and not currently routed elsewhere, or you must be able to withdraw any existing announcements. When two networks announce the same prefix, the internet receives conflicting routes and reachability becomes unpredictable.
- You must dedicate the entire range to Files.com for as long as we announce it.
- All participating sites must be on an Enterprise Plan, and BYOIP requires prior coordination and approval.
Authorizing the Announcement
Announcing your range requires two separate authorizations, and they do different jobs. A Route Origin Authorization establishes which networks are permitted to advertise the prefix. A certificate published in your registry record proves that you control the range. Both are mandatory.
Files.com walks your network team through both steps. We supply the ASNs and the maximum prefix length for the ROA; the key pair and certificate are generated on your side, and the private key never leaves your network team.
Route Origin Authorization (ROA)
A ROA is a cryptographically signed record that you create through your RIR's Resource Public Key Infrastructure (RPKI) service. It names the Autonomous System Numbers (ASNs) authorized to originate a specific prefix, along with an expiration date. Because Files.com announces your range through Amazon Web Services, your ROA must authorize Amazon's ASNs — 16509 and 14618 — to advertise it, and the maximum prefix length must match the size of the range you are bringing in. Files.com confirms the exact values with you before you create it.
Networks across the internet validate ROAs automatically as part of route selection. If another network announces your prefix without authorization, validating networks reject the route outright rather than accepting it and leaving the conflict to be noticed later. The protection applies to your address space generally, not only to its use with Files.com.
Two things to plan around:
- A new ROA takes up to 24 hours to become visible to Amazon.
- If the range is announced today — by you, or by a carrier or hosting provider on your behalf — make sure a ROA already covers the ASN that originates it before you add the ROAs for Amazon's ASNs. Publishing those on their own makes the current announcement RPKI-invalid, and validating networks will begin dropping it. The two ROAs coexist safely, because a route is valid if any covering ROA matches its origin. Authorizing two ASNs is not the same as announcing from two — the range is still advertised from one place at a time. If you are not certain which ASN originates your prefix today, establish that before you publish anything.
Creating a ROA requires RPKI to be enabled on your RIR account. Registrations that predate your RIR's current agreements often need a Registration Services Agreement (RSA) or Legacy RSA in place before RPKI features become available. There is no way around this step, so start it early.
Proof of Ownership in Your Registry Record
A ROA authorizes the announcement, but it does not establish which account may bring your range in. A second authorization covers that, and it is performed once during provisioning:
- Your network team generates an RSA 2048-bit key pair and a self-signed X.509 certificate from it.
- The certificate is published in the RDAP record for your address range. At ARIN this is the Public Comments field on the network object; at RIPE it is a
descrfield on theinetnumobject; at APNIC it is the record remarks. - The private key signs an authorization message, which is submitted with the provisioning request and verified against the published certificate.
The certificate is only needed while provisioning is in progress. You can remove it from your registry record once your range is live.
A Note on Letters of Authorization
Authorizing a prefix announcement has historically meant sending a Letter of Authorization: a signed document that someone at the receiving network accepted on trust, with nothing validating it cryptographically. Our process is built on RPKI instead, so there is no LOA path and no document for us to send you to sign. If your internal process for authorizing prefix announcements is built around LOAs, the ROA and registry certificate above are what replace it.
Setup Process
The onboarding process for BYOIP involves close coordination with the Files.com team and proceeds as follows:
- Contact Files.com Support. Reach out via your Account Manager or Support contact to request BYOIP onboarding. We'll discuss your use case, regions, and confirm eligibility.
- Verification and review. We will verify your ownership of the IP range(s) and confirm they meet our technical criteria. You'll be asked to provide WHOIS or RDAP registration records, confirmation of current routing status, and ASN information (if applicable).
- Authorization. You publish a ROA authorizing Amazon's ASNs to originate your range, and publish a certificate in your registry record, which is used to verify the signed authorization message proving you control the range. We supply the ASNs and maximum prefix length; your network team generates the key pair and keeps the private key. We confirm the ROA is visible before going further — allow up to 24 hours for a new one to propagate.
- Deployment. Once authorization is confirmed, we provision your range, activate the addresses you have chosen, and configure your Files.com site to use them. Announcing the range is the last step, not the first. If your range is already carrying traffic somewhere else, everything up to that point happens without touching your current service — see If Your Range Is Already Announced Elsewhere.
- Testing and monitoring. After deployment, we work with your team to verify connectivity and confirm the IPs are functioning as expected. Monitoring and support continue throughout your use of the service.
How Your IPs Are Assigned
Your range is not provisioned as a subnet, and that is the single most useful thing to understand about how BYOIP behaves. Files.com advertises the prefix over BGP, then activates specific addresses from it and binds them to your site. Only activated addresses carry traffic; the rest of the block stays inert. There is no Layer 2 network, no gateway address, and no infrastructure addresses reserved out of your range — Files.com does not consume .1, .255, or anything else.
If you are used to planning address space as subnets, this is the assumption to drop. You do not set aside addresses for network overhead and you do not give us a usable-host range. You tell us which specific addresses you want live, and we activate those.
Each activated address serves every service on the site it is bound to — FTP, SFTP, FTPS, WebDAV, HTTPS, and the API — exactly as a dedicated IP does. There is no per-service binding.
Two addresses is the common case, matching a standard dedicated IP pair. If you need more, tell us how many and which ones.
Addresses can be reassigned between your sites. If you eventually split one site into regional child sites, we move addresses across without anything changing on your end, so equipment configured against a specific address keeps working.
You do not need to subdivide your range by region. Files.com treats the block as a single global range, and the same addresses serve your site regardless of where your users connect from.
While the announcement is active, the range serves Files.com only. The whole range is announced as one block, so every address in it routes to Files.com infrastructure whether or not we have activated it, and you cannot point part of the range at systems elsewhere.
Migrating to Your Own IPs
There are two ways to bring your range into service.
- Additive migration. Files.com adds your range alongside your existing dedicated IPs and keeps both in service. This is the more common approach, because external systems that reference your current addresses — partner firewalls, allowlists, embedded configurations in field equipment — can be updated on your own schedule instead of in a single cutover. Files.com keeps the original addresses in service indefinitely and removes them when you ask.
- Replacement migration. Files.com switches your site to the new range and retires the original dedicated IPs.
Files.com handles the address assignment on the backend. No DNS changes are required on your end, and your TLS certificate does not need to be reissued.
If Your Range Is Already Announced Elsewhere
Many ranges arrive already carrying production traffic, announced from your own data center or by a carrier or hosting provider on your behalf. Bringing one to Files.com does not mean taking it out of service first, and there is no outage while the range is validated.
Provisioning and announcing are separate steps, and only the second is visible on the internet. Files.com can provision your range, activate your addresses, and configure and test your site while your existing announcement stays up and serves traffic normally. The changeover at the end is the only timed event.
- You publish your ROA and registry certificate, following the ordering note in Authorizing the Announcement. Your current announcement is unaffected.
- Files.com provisions the range, and your ownership is validated against the ROA and certificate. Most provisioning finishes within about two hours, but it can take up to a week, so we start well ahead of any target date.
- Files.com activates the addresses you have chosen and configures your site to use them. Nothing has changed on the internet yet.
- Both teams test the site on its new addresses.
- Changeover. Your existing announcement is withdrawn, and Files.com then begins advertising the range. These are sequenced rather than simultaneous: a range advertised from two places at once is not guaranteed to route predictably, and the changeover itself may not complete until the earlier announcement has stopped.
The only interruption is the time the internet takes to converge on the new route. Your addresses themselves never change, so anything connecting to them — including field equipment configured with a hardcoded address — needs no reconfiguration.
Confirm reachability from several different networks after the changeover rather than from one. Propagation completes unevenly, and a route that is already live from one vantage point can still be invisible from another without anything reporting an error. Files.com verifies this from our side as well, and we treat the changeover as complete only once the range is reachable broadly.
One piece of preparation governs the schedule more than any other: everything else using the block has to be moved off it before the changeover, not after. Because the entire range is announced as one block, every address in it routes to Files.com from the moment we begin announcing, as described in How Your IPs Are Assigned. Any other service still using an address from the block — a proxy, a VPN concentrator, a mail server — loses reachability at that moment. Inventory the block early, and plan the changeover for after that work is complete.
If that cleanup will not be finished in time, the date does not have to move with it. Files.com can bring your site up on dedicated IP addresses now and add your range later as an additive migration, which separates your go-live from your network cleanup entirely.
Ongoing Usage and Management
- ROA validity. Your ROA carries an expiration date, and keeping it current is your responsibility. An expired or non-compliant ROA takes your site's addresses off the internet: validating networks reject the route, and the announcement may be withdrawn. Renew well ahead of the expiration date and keep those ASNs authorized for as long as you want the range announced.
- Exclusivity. While in use with Files.com, your IP range must not be advertised from any other provider or network.
- Routing visibility. Your IPs are globally visible and reachable, integrated with our high-availability infrastructure.
- Support. Files.com provides ongoing support for all announced ranges, including routing health, DNS, and protocol-specific integrations.
Continue to resolve your site by hostname rather than by address. Even with your own range in place, hardcoding IP addresses into client applications bypasses the DNS-based failover and Geo-DNS routing that Files.com relies on.
Reverting to Files.com-Assigned IPs
You can stop using BYOIP at any time.
If you kept your original dedicated IPs in service through an additive migration, those addresses are still assigned to your site and remain usable with no action required. If you fully replaced them, contact Support to coordinate the transition back to Files.com-assigned addresses before the announcement is withdrawn.
In either case, tell us when you want us to stop announcing your range. We typically cease announcements within 48 hours. Once we withdraw the announcement, the range is yours to route elsewhere.
Get Started
To request BYOIP, contact your Account Manager or Files.com Support. We confirm eligibility, review your range, and coordinate the registry steps with your network team.