CGNAT (Carrier-Grade NAT) is a technique that lets an Internet service provider share a single public IPv4 address among many customers at once, instead of giving each customer their own. It adds a second layer of network address translation inside the provider’s network, so hundreds or thousands of subscribers sit behind one public address that the outside Internet sees. For ordinary browsing, streaming, and app use, CGNAT usually worksRead more
RPKI (Resource Public Key Infrastructure) is a security framework that lets IP address holders publish cryptographically signed statements about who is allowed to announce their address space in BGP. A ROA (Route Origin Authorization) is that signed statement — it names the prefix, the ASN authorized to originate it, and how specific the announcement may be. Together they give the world’s routers a way to reject false announcements aboutRead more
IP spoofing is the practice of sending Internet traffic with a forged source IP address, making packets appear to come from a different machine than the one that actually sent them. It exploits a foundational design fact of the Internet Protocol: routers forward packets based on the destination address and generally do not verify that the source address is genuine. Spoofing matters to businesses for two distinct reasons. First,Read more
BGP hijacking is the illegitimate takeover of traffic destined for IP address space, carried out by announcing routes for prefixes the announcer is not authorized to originate. Also called prefix hijacking, route hijacking, or IP hijacking, it corrupts the Internet’s routing tables themselves: networks around the world are told that the wrong party can deliver traffic for an address block, and they believe it. This makes hijacking fundamentally differentRead more
IPv4 addresses may be globally routable, but transferring their registration from one organization to another is governed by Regional Internet Registry (RIR) policy. For organizations buying or selling IPv4 address space internationally, this creates an important question: Which RIRs support inter-RIR IPv4 transfers in 2026? As of August 2026, ARIN, RIPE NCC, APNIC, and LACNIC have established frameworks for inter-RIR IPv4 transfers, subject to compatibility between the RIRs andRead more