ip prefix-list provides the most powerful prefix based filtering mechanism
Here is a quick little tutorial on Prefix-lists for you.
A normal access-list CANNOT check the subnet mask of a network. It can only check bits to make
sure they match, nothing more. A prefix-list has an advantage over an access-list in that it CAN
check BOTH bits and subnet mask – both would have to match for the network to be either
permitted or denied.
For checking bits a prefix list ALWAYS goes from left to right and CANNOT skip any bits.
A basic example would be this:
172.16.8.0/24
ip prefix-list OSPF_Redist seq 5 permit 172.16.8.0/24
ip prefix-list OSPF_Redist seq 10 permit 0.0.0.0/0 le 32
If there is only a / after the network (no le or ge) then the number after the / is BOTH bits checked and
subnet mask. So in this case it will check the 24 bits from left to right (won’t care about the last 8 bits)
AND it will make sure that it has a 24 bit mask. BOTH the 24 bits checked and the 24 bit
subnet mask must match for the network to be permitted or denied.
!
Now we can do a range of subnet masks also that could be permitted or denyed:
172.16.8.0/24 ge 25
If we use either the le or ge (or both le and ge) after the /, then the number directly after the /
becomes ONLY bits checked and the number after the ge or le (or both) is the subnet mask.
So in this case we are still going to check the first 24 bits of the network from left to right.
If those match we are then going to check the subnet mask, which in this case can be
GREATER THAN OR EQUAL TO 25 bits – meaning that as long as the first 24 bits of the
network match the subnet mask could be 25,26,27,28,29,30,31,or 32 bits. They would all match.
!
We can also do:
172.16.8.0/24 le 28
Again this will check the first 24 bits of the network to make sure that they match.
Then it will check to make sure that the subnet mask is LESS THAN OR EQUAL TO 28 bits.
Now this isn’t going to be 28 bits down to 0 bits, the subnet mask can’t be any lower than the
bits we are checking. So the valid range of subnet masks for this one would be 28 bits down to
24 bits (24,25,26,27,and 28). All of those would match.
!
Again this will check the first 24 bits of the network to make sure that they match. Then it
will check to make sure that the subnet mask is LESS THAN OR EQUAL TO 28 bits.
Now this isn’t going to be 28 bits down to 0 bits, the subnet mask can’t be any lower than the
bits we are checking. So the valid range of subnet masks for this one would be
28 bits down to 24 bits (24,25,26,27,and 28). All of those would match.
We can also do both ge and le:
172.16.8.0/24 ge 25 le 27
!
Here again we are checking the first 24 bits to make sure they match. Then our subnet mask must be
GREATER THAN OR EQUAL TO 25 bits LESS THAN OR EQUAL TO 27 bits.
Meaning that 25,26,and 27 bit subnet masks would match.
Now for a couple of examples:
If we have the following networks:
172.16.8.0/28
172.16.8.16/28
172.16.8.32/28
172.16.8.48/28
172.16.8.64/28
We could permit all of these networks with on prefix-list statement:
172.16.8.0/24 ge 28 le 28
Comments
(There are currently no comments for this post.)