2026
Keeps a MikroTik firewall address-list of Iranian IPv4 prefixes current from RIPE data, and publishes the merged list weekly as a plain text file.
iran-ipset fetches the IPv4 prefixes registered to Iran and keeps a MikroTik RouterOS address-list in sync with them, so the router can treat domestic destinations differently — route them directly instead of through a VPN, restrict SSH by country, and so on.
RIPE (+ optional lists) → iran-ipset → REST or SSH → /ip firewall address-list
The main source is the RIPEstat country-resource-list for IR. Two
community aggregates (ipverse and ipdeny) are unioned in by default to fill
gaps. The source set can be replaced with URLs or ripe://CC entries, and RIPE
range strings that aren't CIDRs are skipped.
iran-ipset by
default), so --prune removes only stale rows it added and leaves manual
entries alone..rsc script and imported.--serve runs once, then every INTERVAL (default 7 days).--dry-run shows what would change.The tool refuses to apply or export when fewer than MIN_PREFIXES (default 50)
prefixes parse, so a broken upstream response can't empty the list. The design
prefers under-inclusion: a missing Iranian prefix only sends some domestic
traffic through the VPN, while an extra one would force a foreign destination
out of the WAN directly.
A scheduled CI job publishes the merged list every week (and when sources or code change) as a rolling GitHub release:
curl -fsSL -o iran.txt \
https://github.com/reloadlife/iran-ipset/releases/download/lists/iran.txt
Or generate it locally with go run . -export dist/iran.txt — no router needed.
As a binary on any LAN host, as a multi-arch Docker image (linux/amd64,
linux/arm64), or as a RouterOS 7 container on the router itself.
Go standard library, RouterOS REST API / SSH, GitHub Actions. Licensed under AGPL-3.0-or-later.