# How to IP summarize an ASN using our free ASN database and IPinfo CLI

**URL:** <https://community.ipinfo.io/t/how-to-ip-summarize-an-asn-using-our-free-asn-database-and-ipinfo-cli/6514>\
**Category:** Database Downloads\
**Tags:** asn, cli\
**Created:** [September 30, 2024, 6:16pm UTC](https://community.ipinfo.io/t/how-to-ip-summarize-an-asn-using-our-free-asn-database-and-ipinfo-cli/6514 "2024-09-30T18:16:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abdullah](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.ipinfo.io/abdullah/32/4973_2.png) [@Abdullah](https://community.ipinfo.io/u/Abdullah)\
**Post date:** [September 30, 2024, 6:16pm UTC](https://community.ipinfo.io/t/how-to-ip-summarize-an-asn-using-our-free-asn-database-and-ipinfo-cli/6514/1 "2024-09-30T18:16:17Z")

</div>

![summarize asn db](https://canada1.discourse-cdn.com/flex035/uploads/ipinfo/original/2X/2/2e1f588d3b86b4aebb33532c87b0ded20b53370a.png)

[In my previous post](https://community.ipinfo.io/t/summarizing-all-the-ip-ranges-of-an-asn/5550/), I described how I use our [ASN API service](https://ipinfo.io/products/asn-api) to get the IP ranges of an ASN and then subsequently summarize those ranges to get an overview of the ASN. It is a super easy and powerful operation that is useful for us in discovering interesting servers for our [ProbeNet](https://ipinfo.io/blog/probe-network-how-we-make-sure-our-data-is-accurate/), and it can be used for threat intelligence, OSINT, and network administration tasks.

However, one thing to point out is that the [ASN API](https://ipinfo.io/products/asn-api) comes with a lot of features and is a [paid service](https://ipinfo.io/pricing). Fortunately for us, we have the [IP to ASN free database](https://ipinfo.io/developers/ip-to-asn-database) that is updated daily and comes with full accuracy. We only need the ranges of the ASN and not the full suite of data available on the ASN API (like [ASN type](https://community.ipinfo.io/t/how-do-we-classify-asn-types/2236), ASN country of origin, breakdown of WHOIS record prefixes by ASN, etc.).

> **[Documentation for IP to ASN Database](https://ipinfo.io/developers/ip-to-asn-database)**
>
> We're the trusted source for IP address information, handling 50 billion IP geolocation API requests per month for over 1,000 businesses and 100,000+ developers

## **Let’s try to replicate the solution for free.**

For example, we would like to summarize the ASN [AS59895](https://ipinfo.io/AS59895).

> AS59895

### Prerequisites

For this we need two things:

- [IPinfo CLI](https://github.com/ipinfo/cli)
- [IP to ASN (Free) Database](https://ipinfo.io/developers/ip-to-asn-database)

## Here is the full script

![1001-ezgif.com-video-to-gif-converter](https://canada1.discourse-cdn.com/flex035/uploads/ipinfo/original/2X/4/4b025abd9a7423c721b1eba617faab0755b4e39c.gif)

```auto
curl -sL https://ipinfo.io/data/free/asn.csv.gz?token=$token -o asn.csv.gz;
gunzip *.gz;
grep ",AS59895," asn.csv | ipinfo range2cidr | ipinfo grepip --cidrs-only --ipv4 -o | ipinfo summarize

```

## Script breakdown

### Step 1: Downloading the IP to ASN database

```auto
curl -sL https://ipinfo.io/data/free/asn.csv.gz?token=$token -o asn.csv.gz

```

This command downloads the IP to ASN (free) database to the current path. Make sure to pass your [IPinfo access token](https://ipinfo.io/account/token) here by replacing `$token`. The downloaded file will be called `asn.csv.gz`. This is a gzipped CSV file that we will need to unzip.

### Step 2: Unzipping the gzipped CSV file

```auto
gunzip *.gz

```

We use the `gunzip` CLI utility to unzip the `.gz` compressed file, but you can use any decompression software you like that supports `.gz` files. The unzipped file will be called `asn.csv`.

### Step 3: Extracting IP data rows for the ASN using `grep`

![WindowsTerminal_OJOibZ5SdG](https://canada1.discourse-cdn.com/flex035/uploads/ipinfo/original/2X/1/1602c9059c7e461437b49dadb70c5c4b70ead094.gif)

```auto
grep ",AS59895," asn.csv

```

Then we grep for the ASN (`AS59895`). Definitely make sure to add the prefix and the trailing comma (`,AS59895,`) as we are running a `grep` operation on a CSV file. This is a trick we often use and you can find featured in different posts ([1](https://community.ipinfo.io/t/getting-all-the-asns-of-a-country-using-our-free-ip-to-country-asn-database/5623), [2](https://community.ipinfo.io/t/filter-asn-database-based-on-a-single-asn/393)) where we use it. This will grep the rows for the ASN (`AS59895`).

### Step 4: Converting the IP range to it’s CIDR format using `range2cidr`

```auto
ipinfo range2cidr

```

The IP data rows from the grep output contain values in the IP range format (`start_ip,end_ip`), which is a bit tricky to handle. To make our lives easier, we are going to use the IPinfo CLI’s `range2cidr` command, which converts IP ranges to their CIDR format (`41.77.142.0,41.77.143.255` → `41.77.142.0/23`). We are going to summarize these ranges.

![0930](https://canada1.discourse-cdn.com/flex035/uploads/ipinfo/original/2X/0/091d9cc7b77b47241f18b752de1e41a266cac1ca.gif)

### Step 5: Extracting the IPv4 networks of the ASN using `grepip`

```auto
ipinfo grepip --cidrs-only --ipv4 --only-matching

```

So far, we have the IP data rows in their CIDR for the target ASN (`AS59895`). However, the data is not clean enough to be passed to our summarize command. Instead of figuring out Regex or the `cut` command, we are going to cheat by `grep`ping these IP address CIDRs with our other IPinfo CLI command, `grepip`. The `grepip` is one of the most powerful commands in the IPinfo CLI and comes with a ton of features. Here we are using the following features:

- `--cidrs-only`: Extracts the CIDRs only from plaintext.
- `--ipv4` (`-4`): Extract the IPv4 IP addresses.
- `--only-matching` (`-o`): Outputs only the matching text.

![WindowsTerminal_dcF7QhH661](https://canada1.discourse-cdn.com/flex035/uploads/ipinfo/original/2X/f/ff6a9f91808edaa557ec620e735672e86006d4dd.gif)

Then, the `grepip` command gives us the IPv4 CIDRs of the ASN.

### Step 6: Summarize the networks of the ASN using `summarize`

```auto
ipinfo summarize

```

```auto
Summary
- Total 5120
- Unique 5120
- Anycast 0
- Bogon 0
- Mobile 0
- VPN 517
- Proxy 0
- Hosting 5120
- Tor 0
- Relay 0

Top ASNs
- AS59895 Binary Racks Limited 5120 (100.0%)

Top Usage Types
- Hosting 5120 (100.0%)

Top Routes
- 41.216.187.0/24 (AS59895) 256 (5.0%)
- 41.216.179.0/24 (AS59895) 256 (5.0%)
- 41.215.243.0/24 (AS59895) 256 (5.0%)
- 41.77.143.0/24 (AS59895) 256 (5.0%)
- 41.77.142.0/24 (AS59895) 256 (5.0%)

Top Countries
- United Kingdom 5120 (100.0%)

Top Cities
- London, England, GB 4600 (89.8%)
- Slough, England, GB 512 (10.0%)
- Bournemouth, England, GB 8 (0.2%)

Top Regions
- England, GB 5120 (100.0%)

Top Privacy Services
- AstrillVPN 256 (5.0%)
- VanishedVPN 255 (5.0%)
- Invisible Browsing VPN 1 (0.0%)

Top Domains
- yamanhosting.com 256 (5.0%)
- binaryracks.net 210 (4.1%)
- mubasherhost.com 71 (1.4%)
- binaryracks.com 60 (1.2%)

```

Now we will summarize the IPv4 CIDRs of the ASN. The summarize command supports up to 500,000 IPs in a single request, so please be aware of CIDR size and IPv6 IPs.

* * *

It is that simple. You can create a basic shell script that accepts ASN and the path to the IP to ASN database and always generate summary reports like this. If you want, I can also write the code for that. 🙂

Feel free to ask any questions you have. Thanks for reading.

---

<div class="post-metadata">

**Author:** ![cybersteve99](https://avatars.discourse-cdn.com/v4/letter/c/71c47a/32.png) [@cybersteve99](https://community.ipinfo.io/u/cybersteve99)\
**Post date:** [October 15, 2024, 3:42pm UTC](https://community.ipinfo.io/t/how-to-ip-summarize-an-asn-using-our-free-asn-database-and-ipinfo-cli/6514/2 "2024-10-15T15:42:07Z")

</div>

Thanks very much for swiftly responding to my request for this tutorial and apologies for not responding sooner. I have played with this with some success when comparing with other sources of ASN data to determine the IP ranges for an AS until working with AS13238 which only returned 2 ipv4 ranges when I was expecting around 15. I expect I am probably comparing apples with pears with my somewhat limited knowledge.

For comparison I was using:-

`grep ",AS13238," asn.csv | ipinfo range2cidr | ipinfo grepip --cidrs-only --ipv4 -o`

and

`curl -s --request GET --url 'https://stat.ripe.net/data/announced-prefixes/data.json?resource='AS13238'&time='$yesterday'' | jq -r '.data.prefixes[].prefix' | cidr-merger`

The first returns 2 ipv4 ranges and the second returns 14 ipv4 (& 2 ipv6) ranges.

I also set up a cron job to run a script to download the databases daily which fails on the call to “/usr/local/bin/ipinfo download asn -f mmdb” with the error “err: gzip: invalid header”. It works fine when the script is called from the terminal but I couldn’t resolve when running via cron!

Cheers  
Steve

---

<div class="post-metadata">

**Author:** ![Abdullah](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.ipinfo.io/abdullah/32/4973_2.png) [@Abdullah](https://community.ipinfo.io/u/Abdullah)\
**Post date:** [October 19, 2024, 5:19pm UTC](https://community.ipinfo.io/t/how-to-ip-summarize-an-asn-using-our-free-asn-database-and-ipinfo-cli/6514/3 "2024-10-19T17:19:13Z")

</div>

> Thanks very much for swiftly responding to my request for this tutorial and apologies for not responding sooner

My pleasure, Steve. The community is all about developers like you. I am happy to help 🙂

> ASN data to determine the IP ranges for an AS until working with AS13238 which only returned 2 ipv4 ranges when I was expecting around 15

There is a reason for that. The IP database we have “aggregates” IP ranges to reduce the size the database file.

Here is another post, I just wrote for you: [Understanding Range Aggregation in IPinfo's IP Databases](https://community.ipinfo.io/t/understanding-range-aggregation-when-it-comes-to-asn-ranges/6528)

> [@Understanding Range Aggregation in IPinfo's IP Databases](https://community.ipinfo.io/t/understanding-range-aggregation-when-it-comes-to-asn-ranges/6528):
>
> You will often see that the number of ranges of an ASN you obtain through IPinfo WHOIS records, [IP to Company Database](https://ipinfo.io/products/ip-company-database) or our [ASN API](https://ipinfo.io/products/asn-api) does not match with the number of ranges in the [ASN database](https://ipinfo.io/developers/ip-to-asn-database) or the [free IP to ASN database](https://ipinfo.io/developers/ip-to-asn-database). The database often returns fewer ranges than expected. So why is that? Understanding range aggregation Range aggregation is a technique that reduces the number of neighboring ranges with respect to the corresponding IP metadata. Range aggregations aggregate neighboring ra…

_P.S.: The article is a bit rushed, so please let me know if you see any typos or if I am not explaining the issue well._

> I also set up a cron job to run a script to download the databases daily which fails on the call to “/usr/local/bin/ipinfo download asn -f mmdb” with the error “err: gzip: invalid header”. It works fine when the script is called from the terminal but I couldn’t resolve when running via cron!

It could be a CLI-related issue. I have opened an internal ticket. For now, please use the storage URI directly, it should work well with cron.

```auto
curl -L https://ipinfo.io/data/free/asn.mmdb?token=$TOKEN -o asn.mmdb

```

* * *

Let me know if you have any more questions! I am always happy to help.

---

<div class="post-metadata">

**Author:** ![cybersteve99](https://avatars.discourse-cdn.com/v4/letter/c/71c47a/32.png) [@cybersteve99](https://community.ipinfo.io/u/cybersteve99)\
**Post date:** [October 22, 2024, 7:09pm UTC](https://community.ipinfo.io/t/how-to-ip-summarize-an-asn-using-our-free-asn-database-and-ipinfo-cli/6514/4 "2024-10-22T19:09:38Z")

</div>

Abdullah

Thanks for the detailed explanation of aggregation which makes perfect sense although see comments below regarding the video clip…

I’ve successfully used your suggestion of using curl for the download via cron.

With reference to the examples in the aggregation examples I do have a question around what looks to me to be a disparity between IPINFO ASN address ranges shown on the web page and those returned from Country + ASN database download.

Example  
[AS13238 YANDEX LLC details - IPinfo.io](https://ipinfo.io/AS13238) shows 30 IPv4 ranges and 17 IPv6 ranges.

Whereas the following call only returns 2 as does my original query using asn.csv file.

```auto
# grep ",AS13238," /tmp/country_asn.csv
90.156.181.0,90.156.181.255,RU,Russia,EU,Europe,AS13238,YANDEX LLC,yandex.ru
5.45.213.0,5.45.213.255,RU,Russia,EU,Europe,AS13238,YANDEX LLC,yandex.ru

```

I don’t know what the ASN API returns as my account doesn’t have that API available but I would expect it returns the same list as on the web page. Your example on the aggregation post uses AS13238 for the API call which certainly looks like it returns more than 2 IPv4 ranges in the video output but you then use AS44534 in the code example and for the rest of the example.

Does the country\_asn.csv (and asn.csv) not replicate the list returned on the web page even if aggregated as per the example? It seems to be OK for AS44534 but not for AS13238.

Taking the range 37.9.64.0/24 - (37.9.64.0-37.9.64.255) as shown on the web page for AS13238.  
[37.9.64.0/24 IP range details - IPinfo.io](https://ipinfo.io/AS13238/37.9.64.0/24) shows it under “AS13238 · YANDEX LLC”

and then trying to get the info from country\_asn.csv gives a different ASN of AS208398.

```auto
# grep "37.9.64.0" /tmp/country_asn.csv
37.9.64.0,37.9.66.69,RU,Russia,EU,Europe,AS208398,Edge Technology Plus d.o.o. Beograd,edge.net.au
─
# grep "37.9.64." /tmp/country_asn.csv |ipinfo grepip|ipinfo range2cidr
37.9.64.0/23,RU,Russia,EU,Europe,AS208398,Edge Technology Plus d.o.o. Beograd,edge.net.au (37.9.64.0-37.9.65.255)
37.9.66.0/26,RU,Russia,EU,Europe,AS208398,Edge Technology Plus d.o.o. Beograd,edge.net.au
37.9.66.64/30,RU,Russia,EU,Europe,AS208398,Edge Technology Plus d.o.o. Beograd,edge.net.au
37.9.66.68/31,RU,Russia,EU,Europe,AS208398,Edge Technology Plus d.o.o. Beograd,edge.net.au

```

37.9.64.0/nn can also be found as a range under [AS208398 Edge Technology Plus d.o.o. Beograd details - IPinfo.io](https://ipinfo.io/AS208398)  
[37.9.64.0/18 IP range details - IPinfo.io](https://ipinfo.io/AS208398/37.9.64.0/18) (37.9.64.0-37.9.127.255) shows it under “AS208398 · Edge Technology Plus d.o.o. Beograd”

Is it valid for an IP subnet range to be listed under 2 different ASNs albeit with different subnetting of /24 or /18?

Thanks  
Steve

---

<div class="post-metadata">

**Author:** ![Abdullah](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.ipinfo.io/abdullah/32/4973_2.png) [@Abdullah](https://community.ipinfo.io/u/Abdullah)\
**Post date:** [October 25, 2024, 7:09pm UTC](https://community.ipinfo.io/t/how-to-ip-summarize-an-asn-using-our-free-asn-database-and-ipinfo-cli/6514/5 "2024-10-25T19:09:53Z")

</div>

Steve, sorry for the late reply. This is an interesting situation. I have opened internal tickets to investigate. I will report back as soon as possible.
