Everything you need to run BGP, in one control plane
From policy authoring to deployment to drift detection — ispforge covers the full lifecycle of ISP routing policy, across every vendor in your network.
Author once, render to seven platforms
Policy is a vendor-neutral intermediate representation, compiled to native syntax per platform. The same profile renders correct configuration for Junos, RouterOS, FRR, Arista EOS, Cisco IOS-XE / IOS-XR and VyOS — with community schemes, large-community support for 32-bit ASNs, and idempotent renders that clean up before they apply.
IRR and RPKI filtering, on by default
Every peer type gets proper prefix filtering. ispforge resolves prefix sets from IRR using bgpq4, validates origins against RPKI, enforces max-prefix limits, and drops bogons — automatically, and refreshed on a schedule so your filters never go stale. Built-in route-leak checks catch mistakes before a change ever ships.
Run your network with AI — inside the guardrails
ispforge speaks MCP, so Claude and other AI agents can investigate your network and propose changes in plain language. Every write routes through the same intent pipeline as a human: risk-scored, previewed as a diff, and gated on approval — with an optional two-person rule so nothing self-approves. Prefer to drive it yourself? The same actions run from the portal, a real CLI, and a REST API.
A branded portal your peers actually trust
Every organization gets a public peering page — your ASN, policy, IXP presence and contacts — where operators sign in with PeeringDB and request peering at one or all your shared exchanges in a click. Point it at your own domain and ispforge provisions TLS automatically; outbound requests go out as magic-link emails, and inbound email is parsed straight into your dashboard.
Run peering from the chat you already live in
Native Slack and Discord bots — OAuth, not legacy webhooks — post rich alerts when sessions drop, deploys succeed or fail, drift appears, or a peering request arrives. Accept or decline peering requests right from Discord's buttons, and every alert links straight to the right page in ispforge. Telegram and email endpoints too.
Built for the full lifecycle
Peering automation
IXP discovery and per-LAN member sync from PeeringDB, one-click suggestions from co-members you don't yet peer with, magic-link requests inbound and outbound, and sign-in-with-PeeringDB verification — with Slack, Discord and email alerts.
Safe deploys & drift
A reviewable config diff on every change, a lightweight mTLS agent that speaks each platform's native protocol, commit-confirmed rollback, and continuous drift detection with an acknowledge / resolve workflow.
Live operations
Looking-glass queries for live received and advertised prefixes, on-demand RPKI validation of what a peer is really sending, and traffic-engineering overlays — drain, de-pref, disable — for maintenance and reroute.
Advanced services & scale
iBGP and route reflectors with cluster-id, next-hop-self and add-path; L3VPN, EVPN and labeled-unicast address families; BGP FlowSpec origination for DDoS mitigation; VRFs and per-router feature flags. Support varies by vendor.
Brownfield import
Pull running configuration off your routers and reconstruct sessions, peer-groups, multihop, default-origination and policy intent — bring an existing production network under management incrementally.
Operator tooling
A change-centric portal with a command palette and diff viewer, a real CLI with scoped ispf_ tokens, a REST API for CI, and role-based access control with a full audit trail on every action.
Spin up a free account, render your first policy
Enroll an agent against a single router and render your first policy. No card, no commitment.