How do ISPs assign IP addresses?
An ISP assigns or delegates an IP address or prefix when it provisions a customer connection. The address space comes from a larger Internet number-resource chain: IANA manages the top of the global pool, Regional Internet Registries maintain regional allocations and assignments under community policies, and ISPs or their upstream providers hold address resources that can be used for customer service.
The ISP then combines address management with access authentication, routing, DHCP or PPP, Carrier-Grade NAT where used, DNS, monitoring, and subscriber records. These are separate functions. A registry record does not configure a customer's router, a DHCP lease does not create an Internet route, and a public IP address alone does not identify a person.
| Layer | Typical responsibility | What it does not do by itself |
|---|---|---|
| IANA | Manages the top of the global IP address and AS number allocation hierarchies and allocates large resource blocks to the RIR system. | Assign an address to a household, activate a circuit, or route customer traffic. |
| RIR, LIR, or upstream resource provider | Maintains number-resource registration and distributes resources under the applicable policy and contractual framework. | Guarantee that a prefix is routed, reachable, accepted, or attached to a specific subscriber. |
| ISP | Plans pools and prefixes, provisions access, assigns or delegates customer addressing, routes traffic, and operates the related records and controls. | Assign every address inside a customer's LAN or make a shared CGNAT address uniquely identify one connection. |
| Customer router and LAN | Uses its WAN address or delegated IPv6 prefix and provides addressing to local devices through mechanisms such as DHCP, SLAAC, or manual configuration. | Change the ISP's registry authority, public route, or subscriber-account records. |
Allocation, assignment, lease, registration, and routing
These words describe different evidence. In registry policy, an allocation commonly makes a block available for further distribution, while an assignment commonly identifies space intended for use by a network or end site. Exact policy terms vary by RIR and resource type, so check the current regional policy instead of treating one definition as universal.
- DHCP lease: a time-bounded address binding maintained by a DHCP server. It is a protocol state, not a purchase or commercial lease of Internet number resources.
- Commercial IP lease: a contract granting temporary use of an address block under stated authority, routing, operating, renewal, and return conditions.
- Registration: the applicable registry or RDAP data describing a number-resource record and its contacts. It does not prove current reachability or every downstream customer binding.
- Routing: the control and data-plane work that makes a prefix reachable. BGP announcements, route filters, an origin ASN, and routing policy are separate from the subscriber assignment.
For the general registry and local-network definitions, use the IP address allocation guide. This page focuses on the operational steps an ISP performs after it has authority to use the address space.
The ISP address-provisioning workflow
- Establish address authority. The ISP records the exact IPv4 or IPv6 prefixes it may use, the holder or upstream relationship, registry region, contractual limits, renewal or return conditions, and the parties that may change the relevant records.
- Plan pools and routed prefixes. IP address management links each pool or prefix to an access network, service type, routing domain, capacity limit, exclusion, reservation, owner, and retirement state. Overlap and unintended reuse must be prevented.
- Prepare routing and policy. The provider configures internal reachability and an approved Internet route, directly or through an upstream. Route filters, origin ASN, IRR objects and RPKI ROAs may be part of this work, but none replaces testing of the live path.
- Authenticate and provision the service. An access platform associates a subscriber or circuit with a service profile. DHCP, PPP, static configuration, access-network policy, and AAA systems such as RADIUS may participate; the exact design depends on the provider.
- Assign IPv4 and delegate IPv6. The customer may receive a dynamic or static public IPv4 address, a private or shared WAN address behind CGNAT, an IPv6 address, an IPv6 prefix, or a dual-stack combination.
- Operate DNS, logs, and abuse contacts. Forward DNS, reverse DNS, subscriber session records, NAT logs where needed, monitoring, security controls, privacy retention, and incident response each need an explicit owner and lawful operating basis.
- Change or retire the binding safely. When a session ends, a customer changes plan, or a resource is returned, the ISP updates pools, routes, ROAs, IRR, reverse DNS, geofeed, allowlists, monitoring, and records that depend on the old address.
Static, dynamic, CGNAT, and IPv6 assignment methods
| Model | What the subscriber receives | What can change | Operational consequence |
|---|---|---|---|
| Dynamic public IPv4 | A public IPv4 address from an ISP pool, often bound to a session for a finite time. | The address may change after reconnect, lease expiry, equipment change, pool movement, or provider policy. | Ordinary outbound and return traffic can work directly; inbound use still depends on firewalls, provider policy, and the customer service. |
| Static public IPv4 or routed prefix | A stable public address or prefix associated with the customer service. | The value should remain stable during the agreed service, but renumbering can still occur under the contract or network change process. | Useful for services, VPN peers, and allowlists; it still needs routing, security, DNS, monitoring, and documented ownership. |
| Shared public IPv4 through CGNAT | A private or shared WAN address; many subscribers use one or more public IPv4 addresses through provider translation. | Public address and source port mappings can change by flow or session. | Inbound connections and protocols that need stable end-to-end address or port control may require an alternative service. |
| IPv6 prefix delegation | A routed IPv6 prefix for the customer router to subdivide across local links, often alongside IPv4 during migration. | The delegated prefix may be stable or dynamic according to the provider service. | The LAN can use globally unique IPv6 addresses without IPv4-style address sharing, but firewall policy, DNS, monitoring, and dual-stack testing remain necessary. |
The WAN address is different from addresses inside the LAN
A home or office router normally has an ISP-facing WAN connection and one or more customer-facing LANs. With IPv4, the ISP may assign one WAN address while the router uses private RFC 1918 space and NAT for local devices. The phone or laptop can therefore have a private address that is different from the public source address seen by an Internet service.
With IPv6, the ISP often delegates a prefix to the customer router. The router can advertise a separate subnet on each LAN, and hosts can form addresses through Stateless Address Autoconfiguration, use DHCPv6 where appropriate, or use both. The ISP does not need to choose every individual host address, but it remains responsible for routing the delegated prefix to the customer connection.
Dynamic IP assignment and DHCP leases
DHCPv4 lets a server offer configuration to a client and maintain a lease record for the selected address. A lease lifetime controls protocol renewal; it does not promise that the subscriber will keep the same public address after every disconnect or service change. Providers can use DHCP directly at the customer edge or combine it with relays, access concentrators, subscriber policy, and address-management systems.
A DHCP reservation or a static service profile can improve stability, but the commercial service definition still matters. Ask whether the address is public, exclusive, fixed for the contract term, routed to customer equipment, portable between circuits, and supported for reverse DNS or inbound service. For protocol detail, see the DHCP lease and IP allocation guide.
How CGNAT changes public IPv4 assignment
Carrier-Grade NAT allows multiple subscriber networks to share public IPv4 addresses. RFC 6598 reserves 100.64.0.0/10 as shared address space for service-provider use, although provider designs may also involve other internal addressing. A subscriber behind CGNAT usually does not control the public mapping and cannot assume that unsolicited inbound traffic will reach the customer router.
One public IPv4 address can represent many subscribers at the same time, so the address alone is not enough to attribute a connection. Operational investigation can require a precise timestamp, time zone, source and destination address, protocol, source and destination ports, and the provider's corresponding session and translation records. Retention and disclosure must follow applicable law and provider policy. See the CGNAT guide for architecture, limits, and migration choices.
How ISPs assign IPv6
IPv6 service commonly separates the address used on the WAN link from a prefix delegated for customer LANs. DHCPv6 supports prefix delegation, while IPv6 Router Advertisements and SLAAC can configure host addresses on a LAN. A provider may also use DHCPv6 for other configuration. The delegated prefix size, stability, renewal behavior, and supported LAN count are service choices that customers should verify.
IPv6 does not remove the need for security policy. Customer routers and hosts still need stateful firewall rules or other appropriate controls, DNS and reverse-DNS decisions, logging, monitoring, and tested failure behavior. During dual stack, troubleshoot IPv4 and IPv6 independently because an application can succeed over one protocol and fail over the other.
Registry, routing, RPKI, and DNS are separate controls
Registry data supports uniqueness and operational contacts. BGP carries reachability between autonomous systems. An IRR route object expresses routing policy data used by some operators, while an RPKI ROA authorizes an origin AS for a prefix and maximum length. A valid ROA does not prove that the route is visible, preferred, secure, reputable, or attached to the intended subscriber.
Forward DNS maps a name to address data selected by the domain operator. Reverse DNS maps an address to a name under the authority for the reverse zone. Neither process assigns the address or creates reachability. An ISP offering static service should document who can change reverse DNS and how long changes normally take; customers should test the result from independent resolvers.
What to verify for an ISP address service
| Question | Evidence to request or test | Why it matters |
|---|---|---|
| What exactly is delivered? | Public, private, or shared addressing; exact address or CIDR; IPv4, IPv6, or dual stack; static or dynamic behavior; usable LAN prefixes. | Prevents a shared or changing service from being mistaken for an exclusive fixed address. |
| Who has authority? | Current RIR or RDAP record, holder or upstream relationship, contract scope, permitted use, term, renewal, return, and change contacts. | Separates number-resource authority from a reseller label or network configuration. |
| How is it routed? | Origin ASN, upstream path, accepted prefix length, IRR and ROA state, activation window, monitoring, withdrawal, and rollback. | A registered or configured address is not useful until the intended networks can exchange traffic with it. |
| What inbound behavior is supported? | CGNAT status, firewall and port policy, static mappings, DDoS controls, blocked ports, service terms, and synthetic inbound tests. | A public-looking address or successful outbound request does not prove inbound reachability. |
| Who operates dependent records? | Reverse DNS, geofeed, abuse contact, subscriber and NAT logs, privacy retention, incident escalation, maintenance, and change receipts. | These records affect operations and attribution but are maintained through different systems. |
| How does the service end? | Notice, renumbering overlap, route and record cleanup, equipment return, data handling, prefix return, and continuity plan. | Applications, allowlists, peers, certificates, and documents may depend on the old address. |
Troubleshooting ISP address assignment
| Symptom | Inspect first | Do not assume |
|---|---|---|
| No WAN address or prefix | Access link, subscriber authentication, DHCP or PPP exchange, VLAN or circuit mapping, pool capacity, and customer equipment state. | That a registry or DNS change will fix the access session. |
| Outbound works but inbound fails | CGNAT, customer and provider firewalls, NAT state, route direction, blocked ports, listening service, and DNS target. | That any public address automatically accepts inbound traffic. |
| Address changed unexpectedly | Service plan, lease and session history, reconnects, pool migration, equipment identifier, failover, and provider change notice. | That “dynamic” guarantees a particular stability period. |
| Some sites or networks cannot connect | IPv4 versus IPv6 path, prefix filters, BGP visibility, RPKI validity, MTU, DNS answers, reputation controls, and return route. | That one successful ping proves application reachability everywhere. |
ISP IP address allocation FAQ
Who assigns public IP addresses?
IANA manages the top of the global allocation hierarchy, RIRs distribute and register resources under regional policy, and ISPs or other network operators provision addresses or prefixes for customer services. The customer-facing assignment comes from the provider operating that connection, not directly from IANA.
Does every ISP customer get a unique public IP address?
No. A customer may receive a dynamic public IPv4 address, a static public address or prefix, a private or shared WAN address behind CGNAT, an IPv6 prefix, or a dual-stack combination. Check the exact service rather than inferring it from a router status label.
What is the difference between a static and dynamic IP address?
A static service is intended to keep the same address or prefix under the agreed service conditions. A dynamic address comes from a pool and may change after a lease, session, equipment, failover, or provider-policy event. Neither label alone defines routing, inbound access, DNS, or security.
Is a DHCP lease the same as leasing IPv4 address space?
No. A DHCP lease is a protocol binding between a client and server for a stated lifetime. A commercial IPv4 lease is a contract for temporary use of a prefix and may include authority, routing, RPKI, IRR, DNS, abuse, renewal, and return obligations.
Can an ISP change my public IP address?
A dynamic service normally permits changes, and even a static service can require renumbering under documented contract or network-change conditions. If stability matters, obtain the service definition, notice terms, change process, DNS support, and continuity plan in writing.
Does an ISP give one IPv6 address or a prefix?
Many fixed-access services delegate a prefix so the customer router can create subnets for local networks. The WAN link may also use its own IPv6 address. Prefix size, stability, renewal, and the number of supported LANs vary by provider.
Can a public IP address identify a subscriber?
Not by itself. Attribution can require a precise time and network-flow details matched against provider session and, for shared addresses, NAT translation records. An address also does not identify which person used a device. Access to provider records is governed by applicable law and policy.
Can an organization use its own address space through an ISP?
Sometimes. A provider may support customer-owned or leased prefixes under a BYOIP or BGP service. Confirm the exact prefix, holder or lease authority, origin ASN, LOA, IRR, ROA, accepted prefix length, routing policy, DDoS handling, monitoring, and withdrawal process before migration.
Primary sources
- RFC 7020: The Internet Numbers Registry System
- RFC 2131: Dynamic Host Configuration Protocol
- RFC 1918: Address Allocation for Private Internets
- RFC 6598: IANA-Reserved IPv4 Prefix for Shared Address Space
- RFC 6888: Common Requirements for Carrier-Grade NATs
- RFC 8415: DHCP for IPv6 and Prefix Delegation
- RFC 4862: IPv6 Stateless Address Autoconfiguration
- RFC 4271: Border Gateway Protocol 4
- RFC 9582: Route Origin Authorization Profile
Where i.lease fits
i.lease is not an ISP, IANA, or an RIR. It supports organizations that need temporary public IPv4 capacity through managed IPv4 leasing, and it helps teams define authority, routing, RPKI, IRR, reputation, abuse, renewal, return, and continuity responsibilities within the agreed service scope.
ISPs and telecom operators can start with the ISP and telecom solution. Teams planning address capacity, records, and operating ownership can use strategic IP address management and the IPv4 operating knowledge base. Bring the exact prefix size, regions, origin model, start date, term, use case, and acceptance tests so the service can be evaluated against a concrete requirement.



