IRR Compliance Audit — Five-Registry Route Object Validation
Maintaining accurate Internet Routing Registry records stopped being optional the day major IXPs started building prefix-filter generators directly from IRR data. A missing or stale route object today means rejected announcements tomorrow, a customer ticket escalation the day after, and an audit-cycle finding the quarter after that. RoutePulse continuously audits your live BGP routing table against the five global IRR databases — RIPE, RADB, APNIC, ARIN, and AFRINIC — surfacing unregistered prefixes, origin-AS mismatches, and stale objects before they break peering automation or trigger compliance penalties.
The audit engine consumes the RIPE REST DB API and per-registry mirrors to cover over 1.28 million prefixes in real time. Every prefix is cross-correlated with its RPKI ROA status, ASPA provider authorizations, and live RIB announcement, producing a unified multi-layer compliance view that no single-registry tool can match. Per-AS compliance scoring drills down to specific prefix-level discrepancies; orphaned and stale route objects are surfaced for cleanup; and MANRS-ready evidence is generated on demand for every operator-controlled prefix. Combined with RoutePulse’s RPKI and ASPA validation modules, IRR audit closes the third side of the routing-security triangle: registry hygiene, origin validation, and provider authorization — the trio every modern IXP filter generator and every Tier-1 transit provider now checks.
Five-registry coverage — one unified view
RIPE, RADB, APNIC, ARIN, and AFRINIC route objects are pulled, normalised, and indexed against the live BGP table. Per-prefix the audit surfaces route / route6 objects from every registry that holds one, lets the operator see at a glance which registry’s data drove a given peering decision, and flags every prefix where the registries disagree on origin AS — a strong indicator of stale data needing cleanup or a registry that never received the update.
Real-time BGP vs IRR comparison
Every prefix observed in the RIB is checked against IRR objects within seconds of announcement. Mismatches are categorized: unregistered (no route object anywhere), origin mismatch (IRR says one AS, BGP announces another), stale (route object refers to a prefix no longer in the global table or an obsolete origin AS). Per-AS compliance score aggregates these signals into a single percentage suitable for executive reporting or MANRS attestation.
Multi-layer security correlation
IRR audit doesn’t run in isolation. Each prefix-level result is joined with RPKI ROA status (Valid / Invalid / NotFound) and ASPA RFC 9234 provider authorization at query time. The unified compliance view shows operators the prefixes where IRR, RPKI, and ASPA all agree (clean), where they disagree (cleanup needed), and where the gaps create exploitable hijack windows (urgent). This is the evidence stream that turns “we are MANRS compliant” from a claim into a cryptographically-backed audit trail.
Key Capabilities
- Real-time comparison of live BGP routing table against IRR route objects across RIPE, RADB, APNIC, ARIN, AFRINIC
- RIPE REST DB API integration plus per-registry mirror ingest for full five-registry coverage
- Over 1.28 million prefixes audited continuously in real time across the global DFZ
- Multi-class discrepancy detection: unregistered prefixes, origin-AS mismatches, stale records, orphaned objects
- Joined-at-query-time correlation with RPKI ROA validation (~830K VRPs) and ASPA RFC 9234 provider authorization (~1,200 pairs)
- Per-AS compliance scoring with drill-down into prefix-level discrepancy categories
- Stale-record detection — objects pointing to prefixes no longer announced or to obsolete origin ASNs
- Orphan-object surface — route objects with no matching live announcement, candidates for registry cleanup
- MANRS-ready attestation evidence with every claim cited to a specific registry record and observation timestamp
- Cross-registry conflict view — per-prefix display where RIPE, RADB, APNIC, ARIN, AFRINIC disagree on origin
- Essential for peering agreements with IXPs and Tier-1 transits that auto-filter based on IRR data (every modern automated filter generator: bgpq3/bgpq4, IRRtoolset, RPSL-NG)
- Multi-layer routing security audit trail compatible with NIS2 Article 21 and DORA Article 17 evidence requirements
Engineered and operated by the GOLINE SOC & Network Engineering team.
Explore all RoutePulse features →