Make route leaks hard
Filtering shouldn't be a checklist you hope you remembered. ispforge resolves prefix sets from IRR, validates origins against RPKI, enforces max-prefix limits and drops bogons — on by default, refreshed on a schedule, and it warns you before a change ships something leaky.
Every peer, properly filtered
Per-peer prefix filters resolved from AS-SETs with bgpq4, RPKI drop-invalid, max-prefix limits sourced from PeeringDB or set by hand, and bogon/martian filtering as standard. A scheduled refresh keeps prefix sets current so your filters never quietly go stale.
Every session filtered — and continuously checked
RPKI drop-invalid and per-peer IRR filters on every adjacency, with live prefix counts — and continuous drift detection the moment the device diverges from intent.


The mistakes that cause outages, caught pre-deploy
ispforge checks your rendered intent for the classic leak patterns and flags them before anything reaches a router.
Export without a prefix filter
An eBGP export with no prefix-list is how full tables leak. Flagged.
Import without RPKI reject
Accepting RPKI-invalid routes on import — caught before it ships.
Session without max-prefix
No ceiling on received prefixes is an unbounded blast radius.
Unguarded blackhole export
Blackhole communities re-advertised beyond where they belong.
Import accept-all
A permit-any import policy — the classic misconfiguration.
Your validator, your trust domain
Run Routinator, Fort, StayRTR or rpki-client yourself; ispforge renders the match clauses and marks invalids for rejection on every platform.
ASPA hygiene, checked for you
We read your published ASPA and flag when it's missing an upstream we see — or lists one you've dropped. Publish at your RIR; we watch the drift.
Ship BGP you can defend
Bring a single router into the beta and see your filters, RPKI state and leak checks in the first preview.