ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
IP & ASN

How to Create IRR Route Objects: route/route6 in the RIPE Database and RADB, as-set and whois Checks

6 steps 14 min read 1 views 0
On this page

To get the prefixes your ASN announces accepted by upstreams and IXs, the first step is usually to create IRR route objects. The IRR (Internet Routing Registry) records which ASN originates which prefix, and upstream providers build their BGP prefix filters from it automatically; a prefix without a route object is usually filtered. This guide covers route / route6 syntax in the RIPE database, using RADB for non-RIPE space, as-set basics, how upstreams generate filters from IRR, and verification with whois. Commands work on Debian/Ubuntu and CentOS/Rocky/AlmaLinux.

Examples use the documentation ranges 203.0.113.0/24, 198.51.100.0/24, 2001:db8:1000::/48 and private ASN AS64500; replace them with your resources. If you lease IPs from IMIDC and announce them from your own ASN, also read the guides "Announce leased IP space from your own ASN (LOA)" and "ROA/RPKI".

Step 1: Identify the RIR and Maintainer (mnt-by) of the Block

Route objects belong in the database of the RIR that manages the block: RIPE DB for RIPE space, the APNIC database for APNIC space, ARIN's own IRR for ARIN space, and RADB otherwise or as a supplement. Look up the inetnum maintainers and your aut-num:

# install whois: Debian/Ubuntu
apt install -y whois
# CentOS/Rocky/AlmaLinux
dnf install -y whois

# which RIR and maintainer hold the block?
whois -h whois.ripe.net 203.0.113.0/24 | grep -E 'inetnum|netname|mnt-by|mnt-routes|mnt-lower|source'
whois -h whois.ripe.net AS64500 | grep -E 'aut-num|as-name|mnt-by'

In the RIPE database a route object needs two authorizations: the block's mnt-routes (or mnt-lower / mnt-by) maintainer and the maintainer of the origin ASN. For space leased from IMIDC, the prefix side is authorized by IMIDC's maintainer, so open a ticket with the prefix and ASN and we will create or authorize it.

Step 2: Write route / route6 Objects in the RIPE Database

The RIPE database accepts web edits (log in with RIPE NCC Access, then Database → Create an object) and plain-text submissions in whois/email format. Only a few attributes matter: route (prefix), origin (originating ASN), mnt-by (your maintainer) and source. IPv6 uses route6:

route:          203.0.113.0/24
descr:          Example Networks - leased from IMIDC
origin:         AS64500
mnt-by:         EXAMPLE-MNT
source:         RIPE

route6:         2001:db8:1000::/48
descr:          Example Networks IPv6
origin:         AS64500
mnt-by:         EXAMPLE-MNT
source:         RIPE
  • route / route6: must match the exact length you announce; announcing a /23 and two /24s means three objects.
  • origin: the originating ASN; if several ASNs announce the same prefix, create one object per ASN.
  • mnt-by: the maintainer needed to edit or delete the object later.

Step 3: Use RADB for Non-RIPE Space

RADB, run by Merit, is a public IRR queried by many North American and Asia-Pacific upstreams, and it mirrors many other IRRs. You need a RADB maintainer account first (RADB is a paid service), then submit objects via the web or email. Note source: RADB:

route:          198.51.100.0/24
descr:          Example Networks
origin:         AS64500
mnt-by:         MAINT-AS64500
source:         RADB
Only create route objects for prefixes you are entitled to announce. Do not register other people's space in RADB; many upstreams cross-check RIR data and LOAs and will reject mismatches.

Step 4: Manage Multiple ASNs with an as-set (Optional)

If you have downstream customer ASNs, upstreams need to know whose prefixes you may pass on; that is what an as-set is for. Use a hierarchical name (ASN:AS-NAME), list your own and downstream ASNs in members (nested as-sets are allowed), give the name to your upstreams and reference it in your aut-num export policy.

as-set:         AS64500:AS-CUSTOMERS
descr:          AS64500 and its downstream customers
members:        AS64500
members:        AS64501, AS64502
mnt-by:         EXAMPLE-MNT
source:         RIPE

Step 5: How Upstreams Build BGP Prefix Filters from IRR

Most upstreams use tools such as bgpq4: they query the IRR for your ASN or as-set, expand all route objects into a router prefix list and refresh it periodically. Run the same commands to preview what an upstream will allow:

# Debian/Ubuntu
apt install -y bgpq4
# CentOS/Rocky/AlmaLinux (EPEL)
dnf install -y epel-release && dnf install -y bgpq4

# IPv4 prefix list for everything AS64500 originates
bgpq4 -4 -l AS64500-IN AS64500
# IPv6, expanding an as-set, BIRD syntax
bgpq4 -6 -b -l AS64500_V6 AS64500:AS-CUSTOMERS
# aggregate output (-A) for a large as-set
bgpq4 -4 -A -l CUST-IN AS64500:AS-CUSTOMERS

If your prefix is missing here, the upstream will most likely filter it. Refresh intervals vary from hours to once a day; after updating objects you can ask the upstream to refresh manually.

Step 6: Verify Route Objects with whois -h whois.radb.net

After creating objects, confirm them with whois. RADB mirrors RIPE, APNIC, ARIN and other IRRs, so whois.radb.net is a good proxy for what upstreams see (mirrors may lag slightly):

# route object for a prefix (RADB mirrors most IRRs)
whois -h whois.radb.net 203.0.113.0/24
# all route objects with origin AS64500
whois -h whois.radb.net -- '-i origin AS64500'
# RIPE DB only, route and route6
whois -h whois.ripe.net -- '-T route,route6 -i origin AS64500'
# members of an as-set
whois -h whois.radb.net AS64500:AS-CUSTOMERS

FAQ

RIPE says authorization failed when creating a route object

Usually the block maintainer's authorization is missing. Leased space is maintained by IMIDC, so open a ticket with the prefix, ASN and your mnt-by name and we will authorize or create it.

What is the difference between a route object and a ROA?

A route object lives in the IRR, is used to build filters and can be created by anyone with maintainer rights. A ROA belongs to RPKI, is cryptographically signed by the address holder through the RIR and is used for route origin validation. Ideally have both, with the same ASN.

Should I delete route objects for prefixes I no longer use?

Yes. Stale objects suggest the ASN may still announce the prefix, which is a security risk. Remove them when you stop announcing or the lease ends, or ask us to do it.

Still stuck? Open a ticket with IMIDC 24/7 technical support: https://www.imidc.com/submitticket.php

Was this answer helpful?

Related Tutorials