Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dphonovation
Collaborator

BGP Route Map to restrict certain ranges from private ranges

I have the following route map:

 

set routemap t0privedge-out id 10 on
set routemap t0privedge-out id 10 restrict
set routemap t0privedge-out id 10 match network 10.0.0.1/32 exact
set routemap t0privedge-out id 10 match network 10.0.0.2/32 exact
set routemap t0privedge-out id 10 match network 10.0.0.3/32 exact
set routemap t0privedge-out id 10 match network 10.0.0.4/32 exact
set routemap t0privedge-out id 10 match network 10.0.0.5/32 exact
set routemap t0privedge-out id 10 match network 10.0.0.101/32 exact
set routemap t0privedge-out id 10 match network 10.0.0.102/32 exact
set routemap t0privedge-out id 10 match network 10.0.0.103/32 exact
set routemap t0privedge-out id 10 match network 10.0.0.104/32 exact
set routemap t0privedge-out id 10 match network 10.0.0.105/32 exact
set routemap t0privedge-out id 10 match network 10.50.171.64/26 all
set routemap t0privedge-out id 10 match network 10.50.171.128/26 all
set routemap t0privedge-out id 10 match network 10.51.1.0/28 all
set routemap t0privedge-out id 10 match network 172.19.0.0/29 all
set routemap t0privedge-out id 10 match network 172.19.0.8/29 all
set routemap t0privedge-out id 10 match network 172.19.0.40/29 all
set routemap t0privedge-out id 10 match network 172.19.18.0/29 all
set routemap t0privedge-out id 10 match network 172.21.0.0/28 all
set routemap t0privedge-out id 20 on
set routemap t0privedge-out id 20 allow
set routemap t0privedge-out id 20 match network 10.0.0.0/8 all
set routemap t0privedge-out id 20 match protocol direct
set routemap t0privedge-out id 30 on
set routemap t0privedge-out id 30 allow
set routemap t0privedge-out id 30 match network 172.16.0.0/12 all
set routemap t0privedge-out id 30 match protocol direct
set routemap t0privedge-out id 40 on
set routemap t0privedge-out id 40 allow
set routemap t0privedge-out id 40 match network 192.168.0.0/16 all
set routemap t0privedge-out id 40 match protocol direct
set routemap t0privedge-out id 100 on
set routemap t0privedge-out id 100 restrict

 

 

+ this:

 

 set routemap dflt-out id 10 on
 set routemap dflt-out id 10 allow
 set routemap dflt-out id 10 match network 0.0.0.0/0 exact
 set routemap dflt-out id 100 on
 set routemap dflt-out id 100 restrict
 

 

 

And then applied against my bgp:

 

set bgp external remote-as 65007 export-routemap "dflt-out" preference 10 on
set bgp external remote-as 65007 export-routemap "t0privedge-out" preference 20 on

 


I'm still seeing the restricted subnets in id 10 as advertised however, along with the directly connected routes I also expect. Why is this?

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

Version/JHF of gateway?
Also tagging @Sundeep_Mudgal 

0 Kudos
PhoneBoy
Admin
Admin

In order to understand why this isn't working, this will likely need a ticket with TAC.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events