[j-nsp] L3VPN advertises the directly connected subnet - why?
Luis Ximenez Gomez
lxg at luis.geezas.net
Tue Jan 26 11:41:45 EST 2010
Well, if you use the command "vrf-target import target:xxxx:yy" then
everything which is in your local VRF will be advertised via MBGP to other
peers with a matching RT. <--- your connected subnet will go
In the other hand, if you use "vrf-export <policy>" then more granularity
is available and you will be advertising exactly what your policy matches
and nothing else. <--- your connected subnet will not go unless specified
in the policy.
Does this help?
Best regards, luis
> -----Original Message-----
> From: juniper-nsp-bounces at puck.nether.net
> [mailto:juniper-nsp-bounces at puck.nether.net] On Behalf Of
> Jeroen Valcke
> Sent: martes, 26 de enero de 2010 16:52
> To: juniper-nsp at puck.nether.net
> Subject: [j-nsp] L3VPN advertises the directly connected subnet - why?
>
> Hi,
>
> I'm doing some testing with simple plain L3VPNs and ran into
> some weird behaviour. At least I think it's weird. Perhaps
> somebody can enlighten me.
>
> A CE router is exchanging routes with the PE through BGP.
> These routes are correctly advertised 'over' the L3VPN
> towards other CE routers.
> However the directly connected subnet between the CE and PE
> is also advertised to the other CE routers.
>
> Why is this? It was my understanding that only the routes
> learned from the BGP advertisement from the CE router would
> be advertised to the other CE routers.
>
> What's the reasoning behind this behaviour?
> Can I alter this behaviour? And if yes, is it safe to do so?
>
> Weirdly enough I've found a Juniper KB [1] which seems to
> document the exact opposite behaviour of what I'm
> experiencing. This KB describes a case where the directly
> connected subnet is not advertised over the L3VPN and how to
> 'fix' this.
>
> Thanks for any clues.
> Kind regards,
> -Jeroen-
>
> PS: JunOS version on the PE routers is 9.3R2.8
>
> [1]
> http://kb.juniper.net/index?page=content&id=KB12430&cat=BGP&actp=LIST
>
> --
> Jeroen Valcke
> _______________________________________________
> juniper-nsp mailing list juniper-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/juniper-nsp
>
More information about the juniper-nsp
mailing list