[c-nsp] Deny default route (From customer - BGP)

CiscoNSP List cisconsp_list at hotmail.com
Tue Mar 10 02:30:05 EDT 2015


Thanks also Sascha...did not know this was the case with the 2 outputs (received-routes shows all routes pre filtering, routes shows post filtering).

> From: sp at iphh.net
> To: cisconsp_list at hotmail.com; cisco-nsp at puck.nether.net
> Date: Tue, 10 Mar 2015 07:13:36 +0100
> Subject: Re: [c-nsp] Deny default route (From customer - BGP)
> 
> received-routes show all routes even though they might have been filteres 
> out. Take a look at "show ip bgp neigh ... routes"
> 
> Cheers
> Sascha
> 
> 
> 
> Am 10. März 2015 03:53:58 schrieb CiscoNSP List <cisconsp_list at hotmail.com>:
> 
> > Hi Everyone,
> >
> > Only had a few hours sleep, so I may be overlooking something extremely 
> > obvious...but we are receiving a default from a customer, even though 
> > route-map/prefix list *should* block it...
> > router bgp xxx
> > ...
> > address-family ipv4
> > ...
> > neighbor CUST_A route-map CUST_A-BGP-IN in
> >
> > ip prefix-list PL_DENY_DEFAULT seq 5 permit 0.0.0.0/0
> > ip prefix-list PL_CUST_A_BGP_PREFIXES seq 5 permit xxx.xxx.xxx.0/24
> >
> > route-map CUST_A-BGP-IN deny 5
> > match ip address prefix-list PL_DENY_DEFAULT
> > route-map CUST_A-BGP-IN permit 10
> >  match ip address prefix-list PL_CUST_A_BGP_PREFIXES
> >  set community xxxxx:1400
> >
> > Weird thing is, that "sh ip bgp summary" shows that neighbour as only 
> > having 1 in "State/PfxRcd"
> >
> > but "sh ip bgp nei xxx.xxx.xx.xx received-routes" shows the neighbour with 
> > 0.0.0.0 and there single /24
> >
> > Cheers for any help.
> >
> >
> >  		 	   		
> > _______________________________________________
> > cisco-nsp mailing list  cisco-nsp at puck.nether.net
> > https://puck.nether.net/mailman/listinfo/cisco-nsp
> > archive at http://puck.nether.net/pipermail/cisco-nsp/
> 
> 
 		 	   		  


More information about the cisco-nsp mailing list