Skip to content
Features

Everything you need to run BGP, in one control plane

From policy authoring to deployment to drift detection — ispforge covers the full lifecycle of ISP routing policy, across every vendor in your network.

Policy engine

Author once, render to seven platforms

Policy is a vendor-neutral intermediate representation, compiled to native syntax per platform. The same profile renders correct configuration for Junos, RouterOS, FRR, Arista EOS, Cisco IOS-XE / IOS-XR and VyOS — with community schemes, large-community support for 32-bit ASNs, and idempotent renders that clean up before they apply.

render targets
Juniper Junos · netconf 830 MikroTik RouterOS 7 · rest api FRRouting · vtysh Arista EOS Cisco IOS-XE · native + classic Cisco IOS-XR · netconf VyOS
prefix set · AS-CLOUDFLARE
source IRR · AS-CLOUDFLARE v4 prefixes 1,284 v6 prefixes 312 rpki drop-invalid max-prefix 2000 / 500 # refreshed every 24h
Routing hygiene

IRR and RPKI filtering, on by default

Every peer type gets proper prefix filtering. ispforge resolves prefix sets from IRR using bgpq4, validates origins against RPKI, enforces max-prefix limits, and drops bogons — automatically, and refreshed on a schedule so your filters never go stale. Built-in route-leak checks catch mistakes before a change ever ships.

AI-native operations

Run your network with AI — inside the guardrails

ispforge speaks MCP, so Claude and other AI agents can investigate your network and propose changes in plain language. Every write routes through the same intent pipeline as a human: risk-scored, previewed as a diff, and gated on approval — with an optional two-person rule so nothing self-approves. Prefer to drive it yourself? The same actions run from the portal, a real CLI, and a REST API.

ispforge mcp — intent
» "add AS13335 at SFMIX, customer-default policy" plan 1 session · 2 prefix sets risk medium · approval required preview +18 lines awaiting approval pending
AS35008 · peering
Kerfuffle Networks
Open
SFMIX206.80.238.0/23
DE-CIX New York206.82.104.0/23
LINX LON1195.66.224.0/22
Sign in with PeeringDB
Peering portal

A branded portal your peers actually trust

Every organization gets a public peering page — your ASN, policy, IXP presence and contacts — where operators sign in with PeeringDB and request peering at one or all your shared exchanges in a click. Point it at your own domain and ispforge provisions TLS automatically; outbound requests go out as magic-link emails, and inbound email is parsed straight into your dashboard.

Included on paid plans More on the peering portal
Slack & Discord

Run peering from the chat you already live in

Native Slack and Discord bots — OAuth, not legacy webhooks — post rich alerts when sessions drop, deploys succeed or fail, drift appears, or a peering request arrives. Accept or decline peering requests right from Discord's buttons, and every alert links straight to the right page in ispforge. Telegram and email endpoints too.

#noc-alerts
i
ISPForge APP 10:24
New peering request · AS13335 · Cloudflare
Verified via PeeringDB · SFMIX, DE-CIX New York
Accept Decline View details
And the rest

Built for the full lifecycle

// 01

Peering automation

IXP discovery and per-LAN member sync from PeeringDB, one-click suggestions from co-members you don't yet peer with, magic-link requests inbound and outbound, and sign-in-with-PeeringDB verification — with Slack, Discord and email alerts.

// 02

Safe deploys & drift

A reviewable config diff on every change, a lightweight mTLS agent that speaks each platform's native protocol, commit-confirmed rollback, and continuous drift detection with an acknowledge / resolve workflow.

// 03

Live operations

Looking-glass queries for live received and advertised prefixes, on-demand RPKI validation of what a peer is really sending, and traffic-engineering overlays — drain, de-pref, disable — for maintenance and reroute.

// 04

Advanced services & scale

iBGP and route reflectors with cluster-id, next-hop-self and add-path; L3VPN, EVPN and labeled-unicast address families; BGP FlowSpec origination for DDoS mitigation; VRFs and per-router feature flags. Support varies by vendor.

// 05

Brownfield import

Pull running configuration off your routers and reconstruct sessions, peer-groups, multihop, default-origination and policy intent — bring an existing production network under management incrementally.

// 06

Operator tooling

A change-centric portal with a command palette and diff viewer, a real CLI with scoped ispf_ tokens, a REST API for CI, and role-based access control with a full audit trail on every action.

See it on your own network

Spin up a free account, render your first policy

Enroll an agent against a single router and render your first policy. No card, no commitment.