BGP Route filtering

Source: Internet
Author: User

650) this.width=650; "title=" 1.jpg "src=" Http://s2.51cto.com/wyfs02/M02/7D/68/wKiom1bnqi6AS7ZEAACL5nzpsow254.jpg " alt= "Wkiom1bnqi6as7zeaacl5nzpsow254.jpg"/>

This experiment is derived from the HCNP routing experiment Guide

Experimental requirements: 1. AS200 cannot receive routes from other branch offices

2. Branch Office 2 (AS300) cannot advertise its own routing information to other branch offices

3. Branch Office 4 (AS500) cannot receive routing for branch Office 3 (AS400)

Experimental addressing table

R1

Ge0/0/0:10.0.12.1/24

Ge0/0/1:10.0.13.1/24

Ge0/0/2:10.0.14.1/24

lo0:10.0.1.1 32

R2

Ge0/0/0:10.0.12.2/24

Ge0/0/1:10.0.25.2/24

Ge0/0/2:10.0.26.2/24

lo0:10.0.2.2 32

R3

Ge0/0/0:10.0.13.3/24

Lo0:10.0.3.3/32

LO1:192.168.1.1/24 Simulation under the Hanging network segment

R4

Ge0/0/0:10.0.14.4/24

Lo0:10.0.4.4/32

LO1:192.168.2.1/24 Simulation under the Hanging network segment

R5

Ge0/0/0:10.0.25.5/24

Lo0:10.0.5.5/32

LO1:192.168.3.1/24 Simulation under the Hanging network segment

R6

Ge0/0/0:10.0.26.6/24

Lo0:10.0.6.6/32

LO1:192.168.4./24 Simulation under the Hanging network segment

Establish BGP neighbor relationships through straight connections

1. AS200 (R3) cannot receive routes from other branch offices

Only to receive the headquarters of the AS100, thinking: Regular expression !

View the routing table

650) this.width=650; "title=" 2.jpg "src=" Http://s4.51cto.com/wyfs02/M00/7D/65/wKioL1bnrXfQndMLAAB5Q2MZtYc928.jpg " alt= "Wkiol1bnrxfqndmlaab5q2mztyc928.jpg"/>

650) this.width=650; "title=" 3.jpg "src=" Http://s1.51cto.com/wyfs02/M00/7D/68/wKiom1bnrY7xWgGQAAALn1_lWUw116.jpg " alt= "Wkiom1bnry7xwggqaaaln1_lwuw116.jpg"/>

Define a As-path filter 1 allows only 100 routes to originate, 100$ should know.

650) this.width=650; "title=" 4.jpg "src=" Http://s3.51cto.com/wyfs02/M01/7D/66/wKioL1bnrqij0rQuAAAOSzS7_CQ742.jpg " alt= "Wkiol1bnrqij0rquaaaoszs7_cq742.jpg"/>

Apply in BGP view, apply in import direction of 10.0.13.1

650) this.width=650; "title=" 5.jpg "src=" Http://s3.51cto.com/wyfs02/M01/7D/68/wKiom1bnrlzi8Y3UAAAdxXwUfPs804.jpg " alt= "Wkiom1bnrlzi8y3uaaadxxwufps804.jpg"/>

The first one requires success.

2. Branch Office 2 (AS300 (AR4)) cannot advertise its own routing information to other branch offices

Using the group attribute No-export

First look at the routing table R1 Headquarters,

650) this.width=650; "title=" 6.jpg "src=" Http://s3.51cto.com/wyfs02/M00/7D/68/wKiom1bnr8rSkF50AABdHLRSGiE998.jpg " alt= "Wkiom1bnr8rskf50aabdhlrsgie998.jpg"/>

R5 Branch

650) this.width=650; "title=" 7.jpg "src=" Http://s4.51cto.com/wyfs02/M00/7D/68/wKiom1bnr_-S-1N8AABdBY6Heh4945.jpg " alt= "Wkiom1bnr_-s-1n8aabdby6heh4945.jpg"/>

Next, configure the R4 on the

650) this.width=650; "title=" 8.jpg "src=" Http://s5.51cto.com/wyfs02/M01/7D/66/wKioL1bnsbiAXeaJAAAcJbKp_YQ529.jpg " alt= "Wkiol1bnsbiaxeajaaacjbkp_yq529.jpg"/>

Define a Route-policy 1

R4 the out-of-the-out route to the Community attribute No-export

Next apply

650) this.width=650; "title=" 9.jpg "src=" Http://s2.51cto.com/wyfs02/M02/7D/66/wKioL1bnsvPjKUrMAAAVY5RZh7s953.jpg " alt= "Wkiol1bnsvpjkurmaaavy5rzh7s953.jpg"/>

Peer 10.0.14.1 Advertise-community means to notify neighbors of community attributes

AS100 's AR1 is also to be announced to AS100 in the AR2

Next, look at the routing table on R1 and R6

650) this.width=650; "style=" Float:none; "title=" 10.jpg "src=" http://s4.51cto.com/wyfs02/M01/7D/66/ Wkiol1bns8xbozm9aaaesqqs9h4582.jpg "alt=" Wkiol1bns8xbozm9aaaesqqs9h4582.jpg "/>

R1 See Community properties above

650) this.width=650; "style=" Float:none; "title=" 11.jpg "src=" http://s4.51cto.com/wyfs02/M00/7D/66/ Wkiol1bns8wyovpeaab61xdkbg0590.jpg "alt=" Wkiol1bns8wyovpeaab61xdkbg0590.jpg "/>

650) this.width=650; "title=" 12.jpg "src=" http://s1.51cto.com/wyfs02/M02/7D/68/wKiom1bns4ORtWBuAABEQvYxmz4862.jpg "alt=" Wkiom1bns4ortwbuaabeqvyxmz4862.jpg "/>

You can see that R6 did not receive a route of 4.4 and 192.168.2.0.

3. Branch Office 4 (AS500) cannot receive routing for branch Office 3 (AS400)

Idea: AS500 is to receive AS400 from AS100 's routing information, as long as the AS400 route is not released to AS500 on AS100.

650) this.width=650; "title=" 13.jpg "src=" http://s3.51cto.com/wyfs02/M02/7D/66/wKioL1bntpfQGGuTAAANZAN7MTM365.jpg "alt=" Wkiol1bntpfqggutaaanzan7mtm365.jpg "/>

I didn't use the 10.0.25.5 24 before I read it, but it was released to AS500.

650) this.width=650; "title=" 14.jpg "src=" http://s4.51cto.com/wyfs02/M02/7D/66/wKioL1bnt9mxS5b7AAAeeviItas808.jpg "alt=" Wkiol1bnt9mxs5b7aaaeeviitas808.jpg "/>

Here, if the next hop of the route is 10.0.25.5, deny it.

Then the app is published to AR6

650) this.width=650; "title=" 15.jpg "src=" http://s5.51cto.com/wyfs02/M00/7D/66/wKioL1bnuDCDtBISAAAJ3E9gQIo871.jpg "alt=" Wkiol1bnudcdtbisaaaj3e9gqio871.jpg "/>

Viewing the routing table on AR6

650) this.width=650; "title=" 16.jpg "src=" http://s4.51cto.com/wyfs02/M02/7D/68/wKiom1bnt-CQKu9iAAA0csKc_fg323.jpg "alt=" Wkiom1bnt-cqku9iaaa0cskc_fg323.jpg "/>

No routing information such as 10.0.4.4 192.168.3.1

BGP Route filtering

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.