How ISPs Acquire and Manage IP Addresses: Allocation, IPv4 Scarcity, and the Transition to IPv6
An explanation of how ISPs acquire and manage IP resources, tracing the evolution of Internet address allocation and the connections between IPv4 scarcity, subnetting, IPv6 deployment, address transfers, security, and Internet governance.

Internet service providers (ISPs) connect homes, businesses, and other organizations to the Internet. Behind this service, alongside fiber, routers, and interconnection links, lies an ongoing foundational task: acquiring suitable IP address resources and deploying them systematically across networks and customer connections.
Understanding this work requires a look at both the address allocation system and the way operators manage their own networks. The former determines where addresses come from and the rules governing their distribution and transfer; the latter concerns how addresses are configured, used, reclaimed, and protected. As IPv4 resources available for new allocations have grown scarcer, both aspects have become intertwined with the address transfer market and IPv6 deployment. This article traces that evolution to explain how ISPs address the tension between available address resources and network growth.
Editor's note (October 8, 2026): The original title and description incorrectly referred to the market challenges facing IP brokers. They have been corrected to reflect the article's content, and the wording on address allocation, IPv4 exhaustion, and security mechanisms has been revised. The historical events discussed here do not describe the specific allocation conditions in each region today.
1. Why Large Networks Depend on IP Address Management
ISPs are an important part of Internet infrastructure. A large operator's network may connect millions of users, maintaining existing connections while accommodating new customers, devices, and services. IP addresses provide logical identifiers for network interfaces, allowing packets to reach their destination networks using addressing and routing information. Conflicting or missing address configurations, or inconsistencies between addressing and routing, can disrupt communication even when the links and equipment themselves are working properly.
IP address management therefore involves more than taking an address from a pool and handing it to a customer. Operators need to know which addresses have been assigned, which remain available, which are reserved for future expansion, and which can be reclaimed after customers leave or the network changes. Different access regions, enterprise customers, infrastructure, and service systems also need clear address boundaries and consistent configuration records.
This is a complex, ongoing operational task. Good management can reduce configuration errors, help locate faults, and provide a firmer basis for expansion plans. Poor management can cause address conflicts, misjudgments about available resources, and service outages. Address management itself, however, does not increase the physical speed of a fiber link or port, nor can it guarantee end-to-end network speeds. Service performance also depends on link capacity, routing, equipment load, and other network conditions. Its contribution to reliability and scalability lies primarily in keeping resource planning aligned with the actual network.
2. RIRs and the Hierarchical Address Allocation System
Internet number resources are coordinated through a hierarchical system. As IANA's explanation of its number resource responsibilities describes, IANA generally allocates pools of address resources to Regional Internet Registries (RIRs), rather than allocating addresses directly to individual ISPs. Each RIR then handles subsequent allocation and registration under its regional policies.
From an operator's perspective, there is more than one way to obtain addresses. An ISP may receive resources directly from an RIR or obtain addresses through a National Internet Registry (NIR), a Local Internet Registry (LIR), or an upstream operator. Some ISPs themselves serve as LIRs. The specific route depends on regional arrangements, the organization's status, and its business arrangements. This hierarchy primarily describes resource coordination and registration relationships; it does not mean that Internet traffic must pass through each of these organizations in turn.
Once operators obtain an address block, they subdivide it according to their network structure, using different portions for customer access, service systems, or network infrastructure. Larger networks generally need to plan for more address resources, but customer numbers alone do not determine the size of the block required. How public addresses are used, address-sharing mechanisms, service types, and growth plans all affect demand.
Taking IPv4 prefix lengths as an example, a /24 block contains exactly 256 addresses, while a /16 block contains exactly 65,536 addresses. These are simply arithmetic examples of address space size. They do not establish that a /24 is sufficient to serve a small city or that a /16 can support a nationwide ISP, nor should they be understood as allocation sizes that registries promise to provide today. The total number of addresses may also differ from the number actually usable for a particular type of host or interface configuration, depending on subnet structure and purpose.
Allocation policies must balance support for justified demand, conservation of available resources, and accurate registration. Statements of need, usage records, and the relevant policy procedures help constrain unjustified resource holdings, but they do not guarantee that every ISP will obtain enough addresses. Nor can a hierarchical system alone eliminate the risk of hoarding.
3. Why IPv4 Exhaustion Is an Ongoing Operational Issue
IPv4 uses 32-bit addresses and has a finite address space. The portion available for general public allocation is further limited by special-purpose uses and existing allocations. As demand for Internet connectivity has grown, the supply of new addresses has increasingly become a constraint. This change has a clear historical milestone: on February 3, 2011, the Number Resource Organization (NRO) announced the exhaustion of IANA's central pool of unallocated IPv4 addresses.
Exhaustion of the central pool did not mean that all RIRs stopped allocating addresses on the same day, that previously obtained addresses became invalid, or that existing Internet connections stopped working. Each region has its own timeline and policies for using its remaining resources, handling reclaimed addresses, and arranging subsequent allocations. For ISPs, the central change is that a continuing supply of new IPv4 addresses can no longer be taken for granted. Expansion must account for both resource availability and acquisition costs.
Operators therefore need to combine several approaches: improving management of existing addresses, deploying IPv6, using address translation for suitable services, and obtaining IPv4 resources through transfers that comply with the relevant policies. These approaches address different problems. Reclaiming unused addresses can improve internal utilization, but it cannot enlarge the total IPv4 address space. Address transfers can redistribute existing resources, but they do not create new IPv4 addresses.
Address translation allows a limited number of public IPv4 addresses to support more connections, but it is necessary to distinguish basic NAT from Network Address and Port Translation (NAPT). RFC 3022's description of traditional NAT and NAPT explains that NAPT translates both addresses and transport-layer identifiers, allowing multiple internal nodes to share a single external address. Everyday references to “multiple devices sharing one public IPv4 address through NAT” usually include this port translation mechanism.
Sharing comes at a cost. Translation devices must maintain state, available ports and session capacity have limits, and externally initiated connections and certain application protocols may require additional handling. Troubleshooting and tracing activity back to users also become more complex. Translation changes the conditions for direct end-to-end communication, making it better suited to relieving IPv4 pressure than to expanding address capacity indefinitely.
IPv6 offers a long-term path for growth, but older devices, legacy applications, and networks that still depend on IPv4 prevent an overnight transition. Operators must maintain existing services while investing in the next generation of networks. That is why address scarcity remains an operational issue over time, rather than something resolved by a single technical switch.
4. How IPAM and Subnetting Improve Resource Use
IP Address Management (IPAM) systems help operators record address blocks, subnets, usage status, and related configurations, and can integrate with automated configuration workflows. They make it easier for operations staff to see how network resources are distributed, reconcile allocation records with actual use, identify conflicts or resources that have remained unused for long periods, and inform capacity planning.
These capabilities can reduce the omissions and inconsistencies associated with manually maintained spreadsheets, but their effectiveness still depends on data quality, system integration, and everyday operations. Outdated records, incomplete reclamation processes, or errors in automated configuration can all leave the management system out of step with the actual network. IPAM can therefore improve utilization, but it cannot guarantee that no addresses are wasted. Nor can an address marked “free” in a database automatically be treated as safe to reassign.
Subnetting is another fundamental technique. Operators divide larger address blocks into smaller units for different regions, departments, customer groups, or service types. Clear divisions narrow the scope of configuration work and troubleshooting, and make it easier to connect resource requirements to specific services.
Finer subdivision is not always better, however. Reserving too much space can leave resources idle for long periods, while excessive fragmentation can increase management complexity and constrain future expansion. Effective planning must account for both current use and reasonable room for growth, with ongoing adjustments informed by usage records. ISPs that lack this understanding may face shortages in particular address pools even while scattered resources remain unused, or exhaust their allocatable capacity sooner than expected.
5. The Transition to IPv6 and Network Infrastructure Upgrades
IPv6 expands address space at the protocol level. According to the IPv6 specification, RFC 8200, address length increases from IPv4's 32 bits to 128 bits. Its full address space contains 2128, or approximately 3.4 × 1038, addresses. This is the protocol's total address space; it does not mean that every bit pattern can be assigned to a globally routable interface. Special-purpose uses, reserved ranges, and the actual allocation structure also come into play.
This vast address space provides more room to plan for network growth, but deploying IPv6 involves far more than obtaining a new address block. Operators need to check whether backbone and access equipment, customer routers, address configuration systems, monitoring platforms, and operational procedures can handle IPv6 correctly. Equipment or software that lacks support may need to be upgraded or replaced, and customers may also need to adjust their network configurations.
During a gradual rollout, ISPs can provide IPv6 for new connections while continuing to maintain existing IPv4 services. Dual stack and other transition arrangements support the coexistence of both protocols. Deploying IPv6 does not automatically take all IPv4 resources out of use: users may still need to access IPv4-only services, and customer equipment and applications are not all upgraded on the same schedule.
The transition therefore involves both address planning and an overhaul of infrastructure and operational capabilities. It requires sustained investment, testing, and staff preparation, with progress shaped by equipment lifecycles, customer needs, and the interconnection environment. The history of gradual deployment shows that addressing growth in demand requires attention both to the new protocol's capabilities and to continuity of existing services.
6. The Role of the IPv4 Address Transfer Market and Questions of Fairness
When the supply of new IPv4 addresses is constrained, previously allocated resources that are no longer needed or are underused may return to use through transfers. The resulting secondary market gives ISPs and other organizations another way to acquire addresses, reducing their reliance on ordinary new allocations as their sole source.
What is commonly described as “buying and selling IP addresses” generally involves arrangements to transfer the use and registration of address resources. Both parties still need to address applicable registry policies, contractual terms, and legal requirements. Payment alone cannot replace the required registration or transfer procedures. These requirements vary by region and arrangement; they cannot be reduced to a single, globally uniform set of trading regulations.
Brokers or transfer service providers can help find counterparties and coordinate procedures, but this does not mean that every transfer must go through a broker. In its August 7, 2023 announcement, ARIN explicitly stated that using a transfer facilitator for IPv4 or Autonomous System Number transfers is optional, not required. This historical statement is sufficient to correct the claim that brokers are always mandatory, but it should not be read more broadly as suggesting that other regions have no policies or legal requirements of their own.
Address transfers can put idle resources to work meeting new network demand, while also raising questions about concentration and equitable access. If resource holders choose to keep addresses off the market for long periods, or better-funded participants can continually acquire scarce resources, smaller operators and new entrants may face higher costs or fewer options. These are potential mechanisms that deserve attention; without evidence, they must not be presented as proof that a few groups already control the market.
Discussion of these issues cannot stop at whether trading should be allowed. Maintaining accurate registration, making rules more transparent, and balancing resource transfers, justified demand, and competitive opportunity are all part of number resource governance. The market can ease an individual ISP's resource shortage, but it cannot by itself remove the structural pressure created by IPv4's finite supply.
7. The Security Boundaries of Address Management
Once IP addresses are in use, their management also needs to work in concert with network security. Operators must address IP address spoofing, anomalous routing, abuse, and distributed denial-of-service (DDoS) attacks, while maintaining the links between customer, address, time, and configuration records. Accurate resource records can assist incident investigation and response, but legitimately acquiring an address block does not make the associated traffic or systems inherently secure.
BGP monitoring tracks changes in Internet routing announcements, helping operators identify unexpected origins, changes in reachability, or other conditions that warrant investigation. Monitoring provides observations and alerts; it does not itself prove that address registration is valid or automatically prevent route hijacking. Determining whether an anomaly constitutes an attack still requires an assessment of network conditions and other evidence.
RPKI and Route Origin Authorizations (ROAs) provide verifiable information about the authorization relationship between a particular prefix and its origin Autonomous System. The BGP origin validation described in RFC 6811 uses this information to check whether the prefix and origin AS in a route announcement are consistent with the authorization. Its scope is origin validation: it does not validate the entire AS path, adjudicate contractual ownership, or defend against every type of network attack.
DNSSEC addresses a different layer of the problem. As RFC 4033's explanation of DNS Security Extensions describes, it provides DNS data origin authentication, integrity verification, and authenticated denial of existence for certain data. It does not verify whether IP addresses have been legitimately allocated, monitor BGP routes, or provide traffic confidentiality or DDoS protection. Even a successfully validated DNS response does not establish that the service at the corresponding address is free of security risks.
These mechanisms each have their own role. Address and configuration records, route monitoring, origin validation, anti-spoofing measures, and attack response collectively form operational practice; they cannot substitute for one another. Disorganized management may increase the risk of misconfiguration, resource abuse, and difficulties in incident response. Where access controls are misconfigured, it may also increase the possibility of data exposure. But address pool management cannot simply be treated as the cause of every attack or data breach.
8. How ISPs Participate in Internet Governance
ISPs influence the Internet in ways that extend beyond providing access. Their experience in address allocation, customer connectivity, interconnection, and fault resolution can provide practical evidence for number resource policies and technical standards. As address scarcity, the transition to IPv6, and security requirements interact, operators' participation helps bring the real constraints facing networks of different sizes into public discussion.
Number resource policies need to be distinguished from protocol standards. RIR communities discuss rules for resource allocation and management through their respective policy development processes. For example, the RIPE Policy Development Process allows participants to join discussions through working group mailing lists and meetings. ISPs can raise issues, submit proposals, and comment on suggested approaches. These processes do not give operators unilateral control over the rules, nor are they open only to large resource holders.
The IETF's main work, by contrast, is developing Internet technical standards, rather than allocating address blocks to ISPs. The IETF's participation guidance sets out open routes for contributing, through which network operators can discuss protocol design, implementation, and operational experience alongside other participants. Number resource policies and protocol standards are interconnected, but their responsibilities and development processes differ.
The global coordination system involving ICANN and IANA is also part of this context, but global coordination, regional number resource policy, and protocol engineering must not be conflated into a single decision-making body. Operators need to understand these boundaries to bring specific issues to the appropriate forums.
Seen in this light, ISPs are both users of address resources and participants in the Internet's continuing development. They can bring expansion pressures, security incidents, and customer needs into public discussion, working with other stakeholders to maintain the Internet's openness, accessibility, and security. Address governance is ultimately an ongoing effort to find workable, explainable, and fair arrangements between finite resources and changing connectivity needs.
Frequently Asked Questions
What is IP address allocation?
Broadly, it is the process of providing address resources for organizations or networks to use, followed by configuring addresses for subnets and interfaces. Global resource coordination generally begins with IANA allocating resource pools to RIRs, after which distribution may involve NIRs, LIRs, or ISPs. Public unicast addresses must be unique within the relevant global routing scope; private addresses can be reused in separate networks. Address allocation therefore does not mean that every device must receive its own exclusive public address.
Why is IPv4 exhaustion a problem?
Network and customer demand continues to grow, while IPv4 resources available for new allocations are limited. The exhaustion of the central pool in 2011 was an important milestone in this historical process. It did not mean that all regions stopped all allocations simultaneously, nor did it invalidate addresses already in use. For operators, the main problem is that resources become harder to acquire when expanding, requiring a combination of more effective management, address sharing, resource transfers, and IPv6 deployment.
Why do ISPs use subnetting?
Subnetting organizes large address blocks into smaller units suited to different regions, departments, services, or customer groups, making configuration, fault isolation, and capacity planning clearer. It can help reduce unjustified resource use, but it does not increase the total number of addresses or guarantee zero waste. Subnet planning needs to balance current demand with future growth, avoiding both excessive reservations and excessive fragmentation.
What is NAT, and how does it ease IPv4 exhaustion?
NAT stands for Network Address Translation. In the common scenario where multiple internal devices share a single public IPv4 address, port translation is usually involved as well; this is NAPT. It reduces the need for separate public addresses, allowing existing resources to support business growth for longer. However, it requires translation state to be maintained, is subject to limits such as port and session capacity, and can complicate inbound connections, application compatibility, and troubleshooting. It cannot replace the long-term address scalability that IPv6 provides.
What is IP address trading?
In the context of IPv4 scarcity, it generally refers to organizations transferring existing address resources through commercial arrangements and completing the corresponding registration and procedures under applicable policies. It can move resources that are no longer needed to networks with actual demand, but it does not create new IPv4 addresses. Brokers or other service providers can assist with transactions, but their involvement cannot be assumed to be mandatory in every case. Compliance must still be assessed against the relevant registry rules, contracts, and laws.