{"id":3714,"date":"2012-02-23T20:04:15","date_gmt":"2012-02-23T20:04:15","guid":{"rendered":"http:\/\/www.wikisee.info\/?p=3714"},"modified":"2016-08-09T12:07:29","modified_gmt":"2016-08-09T12:07:29","slug":"ospf-route-filtering-within-area","status":"publish","type":"post","link":"https:\/\/wiki-see.info\/wp\/2012\/02\/23\/ospf-route-filtering-within-area\/","title":{"rendered":"OSPF ROUTE FILTERING WITHIN AREA"},"content":{"rendered":"<p><span style=\"color: #000000;\">There are two points at which <span style=\"color: #800000;\">OSPF<\/span> routes can be filtered: within an area, or between areas on an<\/span><br \/>\n<span style=\"color: #000000;\">area border router (<\/span><span style=\"color: #800000;\">ABR<\/span><span style=\"color: #000000;\">).<\/span><\/p>\n<p><span style=\"color: #000000;\">This article discusses the differences between the two and the considerations which<\/span><br \/>\n<span style=\"color: #000000;\"> should be made when\u00a0implementing <span style=\"color: #800000;\">OSPF<\/span> filtering.<\/span><\/p>\n<p><span style=\"color: #000000;\">The following topology is provided for illustration of both cases:<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" src=\"http:\/\/www.wikisee.info\/pic\/ospf_filtering1.png\" alt=\"\" width=\"375\" height=\"199\" \/><\/p>\n<p><span style=\"color: #000000;\">####<\/span><span style=\"color: #000000;\"> AREA<\/span><span style=\"color: #000000;\">0<\/span>\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0<span style=\"color: #000000;\">####\u00a0<\/span><span style=\"color: #000000;\">AREA1<\/span><\/p>\n<p><span style=\"color: #000000;\">The<span style=\"color: #800000;\"> 172.16.7.0\/24<\/span> network has been implemented on R3 for testing. The route is intended only to be<\/span><br \/>\n<span style=\"color: #000000;\">propagated throughout the local <span style=\"color: #800000;\">area 1<\/span>, but is currently being advertised to the entire<\/span> <span style=\"color: #000000;\"><span style=\"color: #800000;\">OSPF<\/span> domain.<\/span><\/p>\n<p><span style=\"color: #000080;\">(as indicated by the green arrows in the topology):<\/span><\/p>\n<p><strong><span style=\"color: #000000;\">R3# show ip route<\/span><\/strong><\/p>\n<p><em><span style=\"color: #000000;\">C 172.16.4.0\/24 is directly connected, FastEthernet0\/1<\/span><\/em><br \/>\n<em><span style=\"color: #000000;\"> C 172.16.5.0\/24 is directly connected, Loopback0<\/span><\/em><br \/>\n<em><span style=\"color: #000000;\"> C 172.16.7.0\/24 is directly connected, Loopback1<\/span><\/em><br \/>\n<em><span style=\"color: #000000;\"> O IA 172.16.1.1\/32 [110\/20] via 172.16.4.1, 00:11:06, FastEthernet0\/1<\/span><\/em><br \/>\n<em><span style=\"color: #000000;\"> O IA 172.16.3.1\/32 [110\/21] via 172.16.4.1, 00:06:33, FastEthernet0\/1<\/span><\/em><br \/>\n<em><span style=\"color: #000000;\"> O IA 172.16.2.0\/24 [110\/21] via 172.16.4.1, 00:06:33, FastEthernet0\/1<\/span><\/em><\/p>\n<p><span style=\"color: #000000;\">We can implement inter-area filtering (filtering between areas) on <span style=\"color: #800000;\">R2<\/span> to prevent the route from being<\/span><br \/>\n<span style=\"color: #000000;\">advertised outside of <span style=\"color: #800000;\">area 1<\/span>. First, we define a prefix list on <span style=\"color: #800000;\">R2<\/span> to deny the<\/span> <span style=\"color: #800000;\">172.16.7.1\/24<\/span> <span style=\"color: #000000;\">prefix and allow all others:<\/span><\/p>\n<p><em><span style=\"color: #000080;\">ip prefix-list <span style=\"color: #800000;\">FILTER<\/span> seq 5 deny 172.16.7.1\/32<\/span><\/em><br \/>\n<em><span style=\"color: #000080;\"> ip prefix-list <span style=\"color: #800000;\">FILTER<\/span> seq 10 permit 0.0.0.0\/0 le 32<\/span><\/em><br \/>\n<span style=\"color: #000000;\">!<br \/>\n<\/span><br \/>\n<strong><span style=\"color: #800000;\">R2 :<\/span><\/strong><\/p>\n<p><span style=\"color: #000000;\">router ospf 1<\/span><br \/>\n<span style=\"color: #000000;\"> log-adjacency-changes<\/span><br \/>\n<span style=\"color: #000000;\"><span style=\"color: #000080;\"> area 1 filter-list prefix<\/span> <span style=\"color: #800000;\">FILTER<\/span> <span style=\"color: #000080;\">out<\/span><\/span><br \/>\n<span style=\"color: #000000;\"> network 172.16.2.2 0.0.0.0 area 0<\/span><br \/>\n<span style=\"color: #000000;\"> network 172.16.3.1 0.0.0.0 area 0<\/span><br \/>\n<span style=\"color: #000000;\"> network 172.16.4.1 0.0.0.0 area 1<\/span><br \/>\n<span style=\"color: #000000;\">!<\/span><br \/>\n<span style=\"color: #000000;\">Appending<span style=\"color: #800000;\"> le 32<\/span> to the first prefix list entry ensures that any more-specific routes within <span style=\"color: #800000;\">172.16.7.0\/24<\/span> are denied as well (as opposed to only the exact <span style=\"color: #800000;\">\/24<\/span> route).<\/span><\/p>\n<p><span style=\"color: #000080;\">Complete Configuration :<\/span><\/p>\n<p><strong><span style=\"color: #000000;\">R1 :<\/span><\/strong><\/p>\n<p><span style=\"color: #000000;\">interface Loopback0<\/span><br \/>\n<span style=\"color: #000000;\"> ip address 172.16.1.1 255.255.255.0<\/span><br \/>\n<span style=\"color: #000000;\">!<\/span><br \/>\n<span style=\"color: #000000;\">interface FastEthernet0\/0<\/span><br \/>\n<span style=\"color: #000000;\"> ip address 172.16.2.1 255.255.255.0<\/span><br \/>\n!<br \/>\n<span style=\"color: #000000;\">router ospf 1<\/span><br \/>\n<span style=\"color: #000000;\"> log-adjacency-changes<\/span><br \/>\n<span style=\"color: #000000;\"> network 172.16.1.1 0.0.0.0 area 0<\/span><br \/>\n<span style=\"color: #000000;\"> network 172.16.2.1 0.0.0.0 area 0<\/span><br \/>\n<span style=\"color: #000000;\">!<\/span><br \/>\n<span style=\"color: #000000;\">!<\/span><\/p>\n<p><strong><span style=\"color: #800000;\">R2 :<\/span><\/strong><\/p>\n<p><span style=\"color: #000000;\">interface Loopback0<\/span><br \/>\n<span style=\"color: #000000;\"> ip address 172.16.3.1 255.255.255.0<\/span><br \/>\n<span style=\"color: #000000;\">!<\/span><br \/>\n<span style=\"color: #000000;\">interface FastEthernet0\/0<\/span><br \/>\n<span style=\"color: #000000;\"> ip address 172.16.2.2 255.255.255.0<\/span><br \/>\n<span style=\"color: #000000;\">!<\/span><br \/>\n<span style=\"color: #000000;\">interface FastEthernet0\/1<\/span><br \/>\n<span style=\"color: #000000;\"> ip address 172.16.4.1 255.255.255.0<\/span><br \/>\n<span style=\"color: #000000;\">!<\/span><br \/>\n<span style=\"color: #000000;\">!<\/span><br \/>\n<span style=\"color: #000000;\">router ospf 1<\/span><br \/>\n<span style=\"color: #000000;\"> log-adjacency-changes<\/span><br \/>\n<span style=\"color: #000080;\">area 1 filter-list prefix<\/span><span style=\"color: #800000;\"> FILTER<\/span><span style=\"color: #000080;\"> out<\/span><br \/>\n<span style=\"color: #000000;\">network 172.16.2.2 0.0.0.0 area 0<\/span><br \/>\n<span style=\"color: #000000;\"> network 172.16.3.1 0.0.0.0 area 0<\/span><br \/>\n<span style=\"color: #000000;\"> network 172.16.4.1 0.0.0.0 area 1<\/span><br \/>\n<span style=\"color: #000000;\">!<\/span><br \/>\n<span style=\"color: #000000;\">!<\/span><\/p>\n<p><strong><span style=\"color: #800000;\">R3 :<\/span><\/strong><\/p>\n<p><span style=\"color: #000000;\">interface Loopback0<\/span><br \/>\n<span style=\"color: #000000;\"> ip address 172.16.5.1 255.255.255.0<\/span><br \/>\n<span style=\"color: #000000;\">!<\/span><br \/>\n<span style=\"color: #000000;\">interface Loopback1<\/span><br \/>\n<span style=\"color: #000000;\"> ip address 172.16.7.1 255.255.255.0<\/span><br \/>\n<span style=\"color: #000000;\">!<\/span><br \/>\n<span style=\"color: #000000;\">interface FastEthernet0\/1<\/span><br \/>\n<span style=\"color: #000000;\"> ip address 172.16.4.2 255.255.255.0<\/span><br \/>\n<span style=\"color: #000000;\">!<\/span><br \/>\n<span style=\"color: #000000;\">router ospf 1<\/span><br \/>\n<span style=\"color: #000000;\"> log-adjacency-changes<\/span><br \/>\n<span style=\"color: #000000;\"> network 172.16.4.2 0.0.0.0 area 1<\/span><br \/>\n<span style=\"color: #000000;\"> network 172.16.5.1 0.0.0.0 area 1<\/span><br \/>\n<span style=\"color: #000000;\"> network 172.16.7.1 0.0.0.0 area 1<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><em><span style=\"color: #000000;\"><span style=\"color: #800000;\">Distribute-lists<\/span> do not work for outbound <span style=\"color: #800000;\">OSPF<\/span> filtering (even though the CLI may accept the command) <\/span><\/em><br \/>\n<em><span style=\"color: #000000;\">as <span style=\"color: #800000;\">OSPF<\/span> is a link-state protocol and thus all routers within an area must flood all LSAs.<\/span><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>There are two points at which OSPF routes can be filtered: within an area, or between areas on an area border router (ABR). This article discusses the differences between the two and the considerations which should be made when\u00a0implementing OSPF filtering. The following topology is provided for illustration of both cases: #### AREA0\u00a0 \u00a0 \u00a0 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[526],"class_list":["post-3714","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-ospf-filtering"],"_links":{"self":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/3714","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/comments?post=3714"}],"version-history":[{"count":1,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/3714\/revisions"}],"predecessor-version":[{"id":4970,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/3714\/revisions\/4970"}],"wp:attachment":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/media?parent=3714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/categories?post=3714"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/tags?post=3714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}