Networking-Blog

My WordPress Blog

ROUTE_REFLECT_OUT

router bgp 34790
bgp router-id 80.74.16.119
bgp log-neighbor-changes
network 85.234.89.128/26
redistribute static route-map WW-LON-RS0-OUT
neighbor 80.74.16.174 remote-as 34790
neighbor 80.74.16.174 description ww-lon-rs0
neighbor 80.74.16.174 update-source eth0
neighbor 80.74.16.174 next-hop-self
neighbor 80.74.16.174 soft-reconfiguration inbound
neighbor 80.74.16.174 maximum-prefix 20
neighbor 80.74.16.174 route-map WW-LON-RS0-OUT out
!
ip route 10.171.5.0/24 10.200.0.1
ip route 10.171.8.0/24 10.200.0.1
ip route 10.171.17.0/24 10.200.0.1
ip route 10.171.31.0/24 10.200.0.1
ip route 10.171.40.0/24 10.200.0.1
ip route 85.234.89.129/32 10.200.0.1
ip route 85.234.89.133/32 10.200.0.1
ip route 85.234.89.136/32 10.200.0.1
ip route 85.234.89.144/32 10.200.0.1
ip route 85.234.89.162/32 10.200.0.1
!
ip prefix-list ROUTE_REFLECT_OUT seq 5 permit 85.234.89.162/32
ip prefix-list ROUTE_REFLECT_OUT seq 10 permit 85.234.89.133/32
ip prefix-list ROUTE_REFLECT_OUT seq 15 permit 85.234.89.136/32
ip prefix-list ROUTE_REFLECT_OUT seq 20 permit 85.234.89.144/32
ip prefix-list ROUTE_REFLECT_OUT seq 25 permit 85.234.89.129/32
!
route-map WW-LON-RS0-OUT permit 10
match ip address prefix-list ROUTE_REFLECT_OUT
!
ip forwarding
!

BGP – Route-map filtering configuration

Using route-map, you can control in/outbound BGP announcement and apply various attributes :

router bgp 65535
network z.z.z.z
neighbor y.y.y.y remote-as 65500
neighbor y.y.y.y route-map ISP-out out
!
route-map ISP-out permit 10
match ip address 100
!
access-list 100 permit z.z.z.0 0.0.0.255

Recommended to use ip prefix-list since it is lower on cpu/memory resources :

ip prefix-list IPV4-OUT seq 5 permit z.z.z.0/21
ip prefix-list IPV4-OUT seq 10 deny 0.0.0.0/0 le 32
!
route-map ISP-out permit 10
match ip address IPV4-OUT
!
neighbor y.y.y.y route-map ISP-out out

Prevent a Route from being Redistributed from OSPF to BGP

Assume you wanted to prevent a route for 10.0.0.0/24 from being redistributed from OSPF to BGP.
One way to accomplish this would be to define an extended ACL matching this prefix and reference
it from the BGP redistribution route map:

router ospf 1
router-id 2.2.2.2
log-adjacency-changes

!
router bgp 65100
no synchronization
bgp router-id 2.2.2.2
bgp log-neighbor-changes
redistribute ospf 1 route-map OSPF->BGP
neighbor 172.16.23.3 remote-as 65100
no auto-summar
y
!
ip access-list extended OSPF_Redist
deny   ip host 10.0.0.0 host 255.255.255.0
permit ip any any

!
route-map OSPF->BGP permit 10
match ip address OSPF_Redist

The above configuration prevents the exact prefix 10.0.0.0/24 from being advertised by denying the
10.0.0.0 network (“source” address) with a mask of 255.255.255.0 (“destination” address).
All other prefixes are allowed by the permit ip any any statement.

This can be accomplished more intuitively by employing a prefix list:

router ospf 1
router-id 2.2.2.2
log-adjacency-changes

!
router bgp 65100
no synchronization
bgp router-id 2.2.2.2
bgp log-neighbor-changes

redistribute ospf 1 route-map OSPF->BGP
neighbor 172.16.23.3 remote-as 65100
no auto-summary

!
ip prefix-list OSPF_Redist seq 5 deny 10.0.0.0/24
ip prefix-list OSPF_Redist seq 10 permit 0.0.0.0/0 le 32

!
route-map OSPF->BGP permit 10
match ip address prefix-list OSPF_Redis