To run your own network in Europe in 2026 you need three things: an AS number from the RIPE NCC, IP addresses that are registered to you or leased to you, and at least one upstream that will run BGP with you. There are two ways to get them. You can become a RIPE NCC member (a "LIR"), which costs EUR 1,000 once plus EUR 1,800 a year in 2026. Or you can go through a sponsoring LIR, which costs roughly EUR 100 to 250 a year for the ASN and EUR 150 to 300 a year for an IPv6 /48. New IPv4 is no longer handed out freely, so most new networks lease or buy a /24.
Key facts, checked on 9 October 2026:
- ASN policy: "A network must be multihomed in order to qualify for an AS Number" (RIPE-679). In practice that means two upstreams, or one upstream plus peering.
- Smallest routable blocks: IPv4 /24 and IPv6 /48. Longer prefixes are "generally neither announced nor accepted" (RFC 7454).
- IPv4 waiting list: 757 LIRs were queued in August 2026, and the first one had waited 467 days (RIPE NCC Member Update).
- IPv4 prices: roughly $20 to $30 per address to buy, or $0.30 to $0.55 per address per month to lease. These are broker figures, and brokers have a commercial interest.
- Global routing table: 1,086,218 IPv4 prefixes and 257,139 IPv6 prefixes (CIDR Report, 8 and 9 October 2026).
Do you actually need your own ASN?
An ASN (autonomous system number) is your network's name in BGP, the protocol networks use to tell each other which addresses they can reach. You need one when you want to:
- Use two or more upstreams with the same IP addresses, so that losing one provider does not take you offline.
- Move providers without renumbering every server, customer and firewall rule.
- Protect your addresses upstream, for example with remote DDoS protection over a GRE tunnel, where a filtering network announces your prefixes for you.
- Peer at an internet exchange and swap traffic directly with other networks.
You do not need one to run a few servers, a website or a VPN. A VPS comes with its own IPv4 and IPv6 addresses, and the provider handles the routing. An ASN only starts to pay off when you route address space yourself.
What it costs in 2026: two routes compared
| Own LIR (RIPE NCC member) | Through a sponsoring LIR | |
|---|---|---|
| One-time | EUR 1,000 sign-up fee | EUR 0 to about 50 setup, depending on the sponsor |
| Yearly | EUR 1,800 in 2026, EUR 1,894 in 2027, charged pro rata by quarter in the first year | About EUR 100 to 250 for the ASN and EUR 150 to 300 for an IPv6 /48 |
| ASN | Your first ASN is included in the annual fee from 2027 (RIPE-867) | Included in the sponsor's price. The RIPE NCC charges the sponsor EUR 50 a year (RIPE-848) |
| IPv6 | A /32 to /29 allocation at no extra RIPE fee | A /48 PI assignment. The RIPE NCC charges the sponsor EUR 75 a year |
| IPv4 | Join the waiting list for one /24 (well over a year), or buy or lease | No new PI exists, and transferred PA space can only go to members, so in practice you lease |
| Best for | Hosting companies and ISPs that will hold more space and assign it to customers | One company, one ASN, an IPv6 /48 and a leased IPv4 /24 |
Sponsor prices come from public price lists; check the provider's page before you order. All amounts exclude VAT, IP transit and hardware.
For a small network, a sensible first year through a sponsor costs about EUR 250 to 550 for the ASN and IPv6, plus EUR 900 to 1,600 to lease a /24 of IPv4. The member route costs about EUR 2,800 in the first year before any IPv4, but it gives you your own allocation and a seat at the RIPE NCC General Meeting.
Step 1: get the ASN
- Pick your route. To become a member, apply on the RIPE NCC membership page. The Standard Service Agreement must be signed by hand, because "electronic signatures are not accepted". Your account goes live once the signed agreement and the payment have both arrived. To use a sponsor instead, sign an End User Assignment Agreement with them and they file the request.
- Prepare your routing policy. The request asks for your upstreams and peers, written in RPSL, the language of the RIPE Database. Name the ASNs of your two upstreams, or of one upstream and the exchange or network you will peer with.
- Expect a 4-byte number. Since 2010 the RIPE NCC has assigned from a single 32-bit pool, so your ASN will probably be above 65535. Every router sold in the last decade supports this (RFC 6793). The one thing to watch is BGP communities: use large communities (RFC 8092) if an upstream supports them.
The RIPE NCC publishes no processing time. Once the paperwork is complete, ASN requests are usually answered within days, but plan for a few weeks from first contact to a working number, especially for a new membership.
Step 2: get IP addresses
IPv6: easy and cheap
A new LIR gets a /32 up to a /29 just by planning to use it within two years (RIPE-738). Through a sponsor you get a /48 of PI space, which is the smallest block other networks will accept. A 2024 proposal to change the PI rules was withdrawn on 23 September 2026, so these rules stay as they are.
IPv4: wait, buy or lease
| Option | Cost for a /24 (256 addresses) | Catch |
|---|---|---|
| RIPE waiting list | No extra fee beyond membership | Only for LIRs that never received IPv4 from the RIPE NCC, at most one /24 ever, and a wait of over a year (RIPE-826) |
| Buy | About $5,000 to $7,700 plus broker fees; small blocks cost more per address | Members only. The block cannot be transferred again for 24 months (RIPE-807) |
| Lease | About $80 to $140 a month | You depend on the lessor. If they withdraw the ROA, your routes become invalid |
Prices come from broker reports: IPv4Center's H1 2026 report averaged $20.95 per address in the RIPE region, and i.lease puts leases at $0.25 to $0.55 per address per month. Prices fell in 2025 and have been creeping up since mid-2026 as supply tightened.
Before you lease a block, check it
- Reputation: look up the whole /24 at check.spamhaus.org, including the DROP list, which many networks use to drop traffic outright. Check again after the handover.
- History: RIPEstat shows which ASNs announced the block before. Many different origins in a short time is a warning sign.
- Paperwork: you need a Letter of Authorization (LOA) naming the prefix, your ASN and the dates. The holder must also create a route object and a ROA for your ASN.
- Abuse: agree in writing who answers abuse reports. Every block needs a working abuse contact (RIPE-705), and ignored reports end in blocklists.
- Contract: look for a clean-block warranty, a replacement if the block gets listed, and a notice period before the lessor can pull the ROA.
Step 3: make your prefixes routable (IRR and RPKI)
Upstreams build their filters from public databases. If your objects are missing or wrong, your announcement is ignored however correct your router is. Create these in the RIPE Database:
- aut-num: your ASN, with
importandexportlines for each upstream. - route and route6: one per prefix you announce, with
origin:set to your ASN. For leased space, the holder creates them or authorises you. - as-set: for example
AS-YOURNAME, listing your ASN and later your customers' ASNs. Upstreams expand it to build prefix lists.
Then sign your prefixes with RPKI. In the LIR Portal, a ROA (route origin authorisation) is free and states which ASN may announce which prefix. Make it match exactly what you announce. RFC 9319 advises against a loose maxLength, because a ROA that allows more-specific routes makes it easier to hijack them.
This matters because the large transit networks now drop RPKI-invalid routes. isbgpsafeyet.com lists Lumen, Arelion, Cogent, NTT, GTT, Hurricane Electric and Deutsche Telekom as filtering. A wrong ROA is worse than none: a route without a ROA is still accepted, while an invalid one disappears from most of the internet. About two thirds of routed prefixes had a ROA in mid-2026.
Check your objects from any Linux machine. These examples use the RIPE NCC's own network, so you can run them as they are and then swap in your prefix and ASN:
# install the tools once (Debian or Ubuntu, as root)
apt install -y whois curl jq
# the route object for a prefix: origin ASN and maintainer
whois -h whois.ripe.net -T route -r 193.0.0.0/21
# the aut-num policy and an as-set
whois -h whois.ripe.net -T aut-num -r AS3333
whois -h whois.ripe.net -T as-set -r AS-RIPENCC
# RPKI status of a prefix for a given origin ASN
curl -s "https://stat.ripe.net/data/rpki-validation/data.json?resource=AS3333&prefix=193.0.0.0/21" | jq -r .data.status
The last command prints valid for the right ASN. When we asked about the same prefix with a different origin, AS64500, it printed invalid_asn: that is the answer the big networks act on when they drop a route. Run it for every prefix before you contact an upstream.
Two more steps help other networks trust you. Register on PeeringDB; approval is fastest when your email domain matches the one in your RIPE objects. And follow the four MANRS actions: filter your announcements, block spoofed source addresses, keep your contacts current, and publish IRR objects and ROAs.
Step 4: your first BGP session
Exchange these details with your upstream:
| You send | You receive |
|---|---|
| Your ASN and as-set | Their ASN and the peer IPv4 and IPv6 addresses |
| The prefixes you will announce, with route objects and ROAs in place | Full table, default route, or both |
| The LOA, if the space is leased | Their max-prefix limit for your session and their BGP community list |
| Where you connect: a cross-connect in the data centre, or a tunnel endpoint | An MD5 password, if they use one |
Full table or default route?
With one upstream, a default route is enough and runs on almost any hardware. With two or more, take full tables so the router can pick the best path per destination and fail over quickly. A full table means over 1.08 million IPv4 and 257,000 IPv6 routes per feed. A BIRD developer measured about 137 MB of RAM for one IPv4 feed of 760,000 prefixes in 2019, so plan on at least 4 GB of RAM for two full dual-stack feeds. On MikroTik, that means a CCR2004 class router or better.
A minimal BIRD configuration
BIRD runs on any Linux machine, including a small VPS acting as your router. This configuration announces one IPv4 /24 and one IPv6 /48 and takes routes from one upstream. We tested it with BIRD 2.17.5 on Debian 13, between two lab machines: one played the upstream and sent a default route, the other was "you". The addresses below are documentation examples; replace them with yours.
# as root
apt install -y bird2
# then put this in /etc/bird/bird.conf
log syslog all;
router id 192.0.2.2;
define MY_V4 = [ 203.0.113.0/24 ];
define MY_V6 = [ 2001:db8:1000::/48 ];
protocol device { }
# Your prefixes exist as "blackhole" routes so BIRD has something to announce.
protocol static my_v4 {
ipv4;
route 203.0.113.0/24 blackhole;
}
protocol static my_v6 {
ipv6;
route 2001:db8:1000::/48 blackhole;
}
# Put the routes learned over BGP into the Linux routing table.
protocol kernel {
ipv4 { export where source = RTS_BGP; };
}
protocol kernel {
ipv6 { export where source = RTS_BGP; };
}
protocol bgp upstream4 {
description "Upstream IPv4";
local 192.0.2.2 as 64500;
neighbor 192.0.2.1 as 64496;
ipv4 {
import all;
import limit 1200000 action restart;
export where net ~ MY_V4;
};
}
protocol bgp upstream6 {
description "Upstream IPv6";
local 2001:db8:ffff::2 as 64500;
neighbor 2001:db8:ffff::1 as 64496;
ipv6 {
import all;
import limit 300000 action restart;
export where net ~ MY_V6;
};
}
Check the file, load it and look at the sessions:
# as root
bird -p -c /etc/bird/bird.conf
birdc configure
birdc show protocols
birdc show route export upstream4
birdc show route protocol upstream4
In our lab, bird -p printed nothing (no errors) and both sessions showed Established within five seconds. show route export upstream4 listed exactly one route, 203.0.113.0/24, and ip route showed the upstream's default route installed by BIRD. On the upstream side, its import filter and a limit of 10 prefixes received our /24 and /48 and nothing else. Your upstream will set a similar limit on you.
Three lines in this configuration keep you out of trouble:
export where net ~ MY_V4announces only your own prefixes. Exporting everything would leak a full table back to the internet, the classic cause of large outages. RFC 8212 makes "no policy, no routes" the default for this reason.- The blackhole routes stop traffic for unused addresses in your range from looping between you and the upstream.
- The import limits restart the session if the upstream suddenly sends far more routes than a full table holds.
For a second upstream, copy the two protocol bgp blocks with the new neighbour's addresses and ASN. Use the upstream's communities to steer traffic, for example to prepend your path toward one of them. If you prefer another router, FRRouting, VyOS and MikroTik RouterOS 7 do the same job, and all three can validate routes with RPKI.
Where RS Computers fits in
We are not a sponsoring LIR, and we do not sell ASNs or IP space. We sell what comes next: IP transit from AS213900 in Amsterdam and Skopje, with IPv4 and IPv6, full table or default route, and no setup fee. Your own or leased address space is welcome once its route objects and ROAs name your ASN, and most sessions are up the same day.
- Equipment in Amsterdam: IP transit in Amsterdam by cross-connect at Qupra or Nikhef.
- Equipment elsewhere: we run the session over a tunnel, so you can get a second upstream without moving hardware. That also helps you meet the multihoming rule.
- Prefixes under attack: remote DDoS protection over GRE announces your prefixes from a filtering network and hands you clean traffic. Our guide to spotting a DDoS attack on a Linux server shows when you need it.
Frequently asked questions
How much does an ASN cost in 2026?
Through a sponsoring LIR, about EUR 100 to 250 a year, of which EUR 50 is the RIPE NCC's own charge. As a RIPE NCC member, the ASN comes with the membership, which costs EUR 1,000 to join plus EUR 1,800 a year in 2026 and EUR 1,894 in 2027.
Can I get an ASN with only one upstream?
RIPE policy says a network must be multihomed to qualify for an ASN. One upstream plus peering at an exchange, or two upstreams, meets that. A second upstream over a tunnel is a common way to start.
What is the smallest IP block I can announce?
A /24 for IPv4 (256 addresses) and a /48 for IPv6. Smaller blocks are filtered by most networks, as RFC 7454 describes.
Can I use leased IPv4 with my own ASN?
Yes. The holder issues an LOA and creates a route object and a ROA naming your ASN as the origin. Check the block's reputation on Spamhaus and its routing history on RIPEstat before you sign.
How long does it take to get an ASN from RIPE?
The RIPE NCC publishes no fixed time. Through an existing sponsor, a complete request is usually done within days. A new membership adds the due diligence check and the signed paper agreement, so allow a few weeks.
Do I need a ROA?
It is not required, but it is strongly advised. Major transit networks drop RPKI-invalid routes, and a correct ROA protects your prefixes from being hijacked by someone announcing them with another origin.
The checklist
Decide between membership and a sponsor. Get the ASN with a routing policy that names two upstreams or an upstream plus peering. Take an IPv6 block, and lease or buy a /24 of IPv4 after checking its history. Publish aut-num, route and as-set objects, sign ROAs that match exactly, and confirm everything with whois and RIPEstat. Then bring up BGP with export filters and prefix limits. When you are ready for the session, message us on Telegram with your ASN and prefixes, and we will check your objects before anything is announced.