AWS Security ChangesHomeSearch

AWS AWSEC2: Add ASN validation for AWS GovCloud and European Sovereign Cloud

Service: AWSEC2 · 2026-08-02 · Documentation medium

File: AWSEC2/latest/UserGuide/byoip-onboard.md · Type: network

Summary

Updated ROA validation instructions to include specific ASNs for AWS GovCloud (US) and AWS European Sovereign Cloud regions.

Security assessment

Ensures proper ASN authorization for IP ranges in specialized regions, preventing unauthorized BGP advertisements that could lead to traffic hijacking.

Evidence

+Validate the successful creation of the ROA objects using the RIPEstat Data API. Be sure to test your address range against the Amazon ASNs 16509 and 14618, plus the ASNs that are currently authorized to advertise the address range. For the AWS GovCloud (US) Regions, test against ASN 8987. For the AWS European Sovereign Cloud, test against ASNs 16509 and 214101.

Diff

diff --git a/AWSEC2/latest/UserGuide/byoip-onboard.md b/AWSEC2/latest/UserGuide/byoip-onboard.md
index 37d0305f3..612be905e 100644
--- a//AWSEC2/latest/UserGuide/byoip-onboard.md
+++ b//AWSEC2/latest/UserGuide/byoip-onboard.md
@@ -267 +267 @@ This returns output with the contents of the key, which should be similar to the
-Validate the successful creation of the ROA objects using the RIPEstat Data API. Be sure to test your address range against the Amazon ASNs 16509 and 14618, plus the ASNs that are currently authorized to advertise the address range.
+Validate the successful creation of the ROA objects using the RIPEstat Data API. Be sure to test your address range against the Amazon ASNs 16509 and 14618, plus the ASNs that are currently authorized to advertise the address range. For the AWS GovCloud (US) Regions, test against ASN 8987. For the AWS European Sovereign Cloud, test against ASNs 16509 and 214101.