Technical Guide: Generating BGP Prefix Filters with WhizIRR for Mikrotik RouterOS v7
EXECUTIVE TAKEAWAYS & ARCHITECTURAL SUMMARY
WhizIRR is a specialized utility tool designed to automatically generate BGP prefix filters for Mikrotik RouterOS v7 by leveraging IRR AS-SETs.
The architecture of the script centers on querying authoritative IRR databases, recursively expanding specified AS-SETs to locate all member autonomous system numbers, performing prefix aggregation to minimize filter entries, and subsequently generating native RouterOS commands.
This automated pipeline ensures that network engineers maintain up-to-date routing policies without manual intervention.
INDEX Table of Contents (5 sections) ▼
Practical Overview & Architecture
WhizIRR is a specialized utility tool designed to automatically generate BGP prefix filters for Mikrotik RouterOS v7 by leveraging IRR AS-SETs. The architecture of the script centers on querying authoritative IRR databases, recursively expanding specified AS-SETs to locate all member autonomous system numbers, performing prefix aggregation to minimize filter entries, and subsequently generating native RouterOS commands. This automated pipeline ensures that network engineers maintain up-to-date routing policies without manual intervention.
By abstracting the complexities of manual filter construction, the tool provides robust support for both IPv4 and IPv6 prefixes. Additionally, WhizIRR features optional SSH deployment capabilities using the Paramiko library, allowing generated rules to be pushed directly to target routers or saved to structured configuration files when direct network access is unavailable. The system relies on a foundational configuration file to map peer autonomous system numbers and their respective AS-SETs, establishing a predictable, reliable workflow for modern networking environments.
Prerequisites & Installation Setup
Running WhizIRR successfully requires specific foundational prerequisites within your operational environment. The underlying system must be a Linux operating system running Python 3.7 or higher. Furthermore, the tool depends on the external Python library paramiko to handle optional secure shell functionality for automated router deployment. Without this specific library, the utility gracefully degrades to file-based output generation rather than failing completely. Users must ensure their network management setup accounts for these software dependencies prior to initiating deployment procedures.
Installation procedures for the utility are exceptionally straightforward. Operators must first clone or download the official repository from GitHub at WhizIRR GitHub Repository. Following acquisition of the source files, dependencies are installed using Python's package manager with the command
pip3 install -r requirements.txt
Documented Implementation Workflow
Configuring WhizIRR involves editing the config.json file to establish peer definitions and execution settings. A standard configuration includes peer arrays containing the ASN, target AS-SET, and a human-readable description, alongside router credentials and global settings such as the preferred IRR server. The documented configuration layout is structured as follows:
{ "peers": [ { "asn": "AS65001", "as_set": "AS-EXAMPLE", "description": "Example Peer" } ], "router": { "enabled": false, "hostname": "192.168.1.1", "username": "admin", "password": "", "port": 22 }, "settings": { "irr_server": "whois.apnic.net", "ipv4_enabled": true, "ipv6_enabled": true, "output_directory": "./output", "max_prefix_length_ipv4": 24, "max_prefix_length_ipv6": 48 } }
Once configuration is complete, operators execute the utility using various command-line arguments. The default operational mode utilizes differential tracking to generate commands only for new peers or those exhibiting detected prefix modifications. Operators can execute the script with default settings or apply advanced flags as documented:
python3 bgp_filter_generator.py python3 bgp_filter_generator.py -c custom_config.json python3 bgp_filter_generator.py --full python3 bgp_filter_generator.py --debug -v
Known Limitations Tradeoffs & Error Scenarios
While WhizIRR streamlines prefix filter creation, operators must account for specific documented limitations and common failure modes during deployment. A frequent issue involves IRR connection timeouts, which typically stem from internet connectivity disruptions, unresponsive default IRR servers, or restrictive firewall configurations. When timeouts occur, operators are advised to verify their network connection, adjust internal timeout thresholds, or switch to an alternative registry server defined in the settings block of the JSON configuration file.
Additional operational challenges include SSH connection failures and missing prefix scenarios. If router authentication fails, or if target AS-SETs are empty, misspelled, or outdated within the IRR database, the utility will encounter errors or automatically filter out invalid prefixes. When SSH is disabled or connection failures arise, the script defaults to writing output files locally. These files follow a strict naming convention, such as prefix-filter-65001.rsc, and must be imported manually into RouterOS via the command
/import file-name=prefix-filter-65001.rsc
Who Should Use It & Production Fit
WhizIRR is purpose-built for network engineers, infrastructure administrators, and systems operators managing Mikrotik RouterOS v7 environments who need an automated, reliable method for synchronizing BGP routing policies with authoritative IRR databases. It is exceptionally well-suited for professionals managing multi-homed autonomous systems that require continuous tracking of peer prefix updates without manual script maintenance or constant human oversight. Organizations utilizing standard Mikrotik hardware looking to optimize routing security will find the tool fits neatly into existing automation pipelines.
Conversely, environments utilizing non-Mikrotik routing platforms or teams lacking basic Python execution capabilities will not benefit from this specific codebase. Security considerations also dictate that operators must store router passwords securely, prefer SSH keys over plain-text passwords where possible, restrict management network access, and thoroughly review all generated filters before applying them to production systems to prevent unintended routing loops or traffic blackholing.
This technical guide was independently researched and verified against official repositories, container environments, and CLI manifests. GitNeural does not accept paid placements, sponsored reviews, or affiliate kickbacks.