There are two points at which OSPF routes can be filtered: within an area, or between areas on an
area border router (ABR).

This article discusses the differences between the two and the considerations which
should be made when implementing OSPF filtering.

The following topology is provided for illustration of both cases:

#### AREA0                                               #### AREA1

The 172.16.7.0/24 network has been implemented on R3 for testing. The route is intended only to be
propagated throughout the local area 1, but is currently being advertised to the entire OSPF domain.

(as indicated by the green arrows in the topology):

R3# show ip route

C 172.16.4.0/24 is directly connected, FastEthernet0/1
C 172.16.5.0/24 is directly connected, Loopback0
C 172.16.7.0/24 is directly connected, Loopback1
O IA 172.16.1.1/32 [110/20] via 172.16.4.1, 00:11:06, FastEthernet0/1
O IA 172.16.3.1/32 [110/21] via 172.16.4.1, 00:06:33, FastEthernet0/1
O IA 172.16.2.0/24 [110/21] via 172.16.4.1, 00:06:33, FastEthernet0/1

We can implement inter-area filtering (filtering between areas) on R2 to prevent the route from being
advertised outside of area 1. First, we define a prefix list on R2 to deny the 172.16.7.1/24 prefix and allow all others:

ip prefix-list FILTER seq 5 deny 172.16.7.1/32
ip prefix-list FILTER seq 10 permit 0.0.0.0/0 le 32
!

R2 :

router ospf 1
log-adjacency-changes
area 1 filter-list prefix FILTER out
network 172.16.2.2 0.0.0.0 area 0
network 172.16.3.1 0.0.0.0 area 0
network 172.16.4.1 0.0.0.0 area 1
!
Appending le 32 to the first prefix list entry ensures that any more-specific routes within 172.16.7.0/24 are denied as well (as opposed to only the exact /24 route).

Complete Configuration :

R1 :

interface Loopback0
ip address 172.16.1.1 255.255.255.0
!
interface FastEthernet0/0
ip address 172.16.2.1 255.255.255.0
!
router ospf 1
log-adjacency-changes
network 172.16.1.1 0.0.0.0 area 0
network 172.16.2.1 0.0.0.0 area 0
!
!

R2 :

interface Loopback0
ip address 172.16.3.1 255.255.255.0
!
interface FastEthernet0/0
ip address 172.16.2.2 255.255.255.0
!
interface FastEthernet0/1
ip address 172.16.4.1 255.255.255.0
!
!
router ospf 1
log-adjacency-changes
area 1 filter-list prefix FILTER out
network 172.16.2.2 0.0.0.0 area 0
network 172.16.3.1 0.0.0.0 area 0
network 172.16.4.1 0.0.0.0 area 1
!
!

R3 :

interface Loopback0
ip address 172.16.5.1 255.255.255.0
!
interface Loopback1
ip address 172.16.7.1 255.255.255.0
!
interface FastEthernet0/1
ip address 172.16.4.2 255.255.255.0
!
router ospf 1
log-adjacency-changes
network 172.16.4.2 0.0.0.0 area 1
network 172.16.5.1 0.0.0.0 area 1
network 172.16.7.1 0.0.0.0 area 1

 

Distribute-lists do not work for outbound OSPF filtering (even though the CLI may accept the command)
as OSPF is a link-state protocol and thus all routers within an area must flood all LSAs.