No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

Use ACL to make routing policy, but import an extra aggregation routing

Publication Date:  2012-10-22 Views:  27 Downloads:  0
Issue Description
There are two routers BSR 1 and BSR 2 in the network, in the BSR 1 configuration routing policy import a certain routing.
Network topology is as follows:
There are two aggregation routing 192.168.0.0/11 and 192.168.0.0/16 in BSR 2, BSR need import 192.168.0.0/16
After the configuration has been completed, and found that import an extra aggregation routing, 192.168.0.0/11 and 192.168.0.0/16 are all imported
Alarm Information
none
Handling Process
In the BSR 1 execute the following command:
Step 1 execute system - view command, into the system view.
Step 2 execute command ip ip-prefix test 192.168.0.0 0.0.255.255 greater-equal 16 less-equal 16, configure IPv4 address prefix list.
Set the IP prefix greater - equal and less - equal to 16, i.e. introducing 16 bit mask routing.
Step 3 execute command route - policy test permit node 10, create route - policy node, and enter the route - policy view.
Step 4 execute command if-match ip-prefix test, matching address prefix list.
- end
Complete the above configuration, can success to import 192.168.0.0/16 a route, and filter 192.168.0.0/11 routing.
Root Cause
In the BSR 1 check routing policy configuration situation, found that the policy matching condition referenced routing policy is ACL, ACL configuration is as follows:
#
acl 2001
rule 10 permit source 192.168.0.0 0.0.255.255
The introduced two routing IP prefix is 192.168.0.0/11 and 192.168.0.0/16.
Routing policy ACL only support a standard ACL, namely only contains source IP address and mask.
For standard ACL, do not consider IP prefix length, as long as the prefix number matching (IP prefix composed by prefix number and prefix length), that means matching. So two routing were matched to and is introduced.
Suggestions
When filter route, need to pay attention to ACL and IP prefix application effect, when need to accurately determine mask length, use IP prefix to define.

END