1
|
This is how it should look...
|
2
|
ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30
|
3
|
ip prefix-list ACCEPTFILTER seq 10 deny 10.255.1.1/32
|
4
|
ip prefix-list ACCEPTFILTER seq 15 permit any
|
5
|
|
6
|
...although my personal prference is to start at 10 with +5 increments for textual alignment....so....
|
7
|
ip prefix-list ACCEPTFILTER seq 10 deny 10.255.1.0/30
|
8
|
ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.1/32
|
9
|
ip prefix-list ACCEPTFILTER seq 20 permit any
|
10
|
|
11
|
|
12
|
|
13
|
But what actually happens when running the command in about half-second increments....
|
14
|
|
15
|
############## actual CLI output begins next line ##############
|
16
|
firewall1.home.arpa# show running-config no-header | include prefix-list
|
17
|
ip prefix-list CONNECT seq 10 permit 10.1.194.0/24
|
18
|
ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32
|
19
|
ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30
|
20
|
ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32
|
21
|
ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30
|
22
|
ip prefix-list ACCEPTFILTER seq 10 permit any
|
23
|
ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30
|
24
|
match ip address prefix-list CONNECT
|
25
|
match ip address prefix-list ACCEPTFILTER
|
26
|
firewall1.home.arpa# show running-config no-header | include prefix-list
|
27
|
ip prefix-list CONNECT seq 10 permit 10.1.194.0/24
|
28
|
ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30
|
29
|
ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32
|
30
|
ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30
|
31
|
ip prefix-list ACCEPTFILTER seq 10 permit any
|
32
|
ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30
|
33
|
ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32
|
34
|
match ip address prefix-list CONNECT
|
35
|
match ip address prefix-list ACCEPTFILTER
|
36
|
firewall1.home.arpa# show running-config no-header | include prefix-list
|
37
|
ip prefix-list CONNECT seq 10 permit 10.1.194.0/24
|
38
|
ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32
|
39
|
ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30
|
40
|
ip prefix-list ACCEPTFILTER seq 10 permit any
|
41
|
ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30
|
42
|
ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32
|
43
|
ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30
|
44
|
match ip address prefix-list CONNECT
|
45
|
match ip address prefix-list ACCEPTFILTER
|
46
|
firewall1.home.arpa# show running-config no-header | include prefix-list
|
47
|
ip prefix-list CONNECT seq 10 permit 10.1.194.0/24
|
48
|
ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30
|
49
|
ip prefix-list ACCEPTFILTER seq 10 permit any
|
50
|
ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30
|
51
|
ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32
|
52
|
ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30
|
53
|
ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32
|
54
|
match ip address prefix-list CONNECT
|
55
|
match ip address prefix-list ACCEPTFILTER
|
56
|
firewall1.home.arpa# show running-config no-header | include prefix-list
|
57
|
ip prefix-list CONNECT seq 10 permit 10.1.194.0/24
|
58
|
ip prefix-list ACCEPTFILTER seq 10 permit any
|
59
|
ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30
|
60
|
ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32
|
61
|
ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30
|
62
|
ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32
|
63
|
ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30
|
64
|
match ip address prefix-list CONNECT
|
65
|
match ip address prefix-list ACCEPTFILTER
|
66
|
firewall1.home.arpa# show running-config no-header | include prefix-list
|
67
|
ip prefix-list CONNECT seq 10 permit 10.1.194.0/24
|
68
|
ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30
|
69
|
ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32
|
70
|
ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30
|
71
|
ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32
|
72
|
ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30
|
73
|
ip prefix-list ACCEPTFILTER seq 10 permit any
|
74
|
match ip address prefix-list CONNECT
|
75
|
match ip address prefix-list ACCEPTFILTER
|
76
|
firewall1.home.arpa# show running-config no-header | include prefix-list
|
77
|
ip prefix-list CONNECT seq 10 permit 10.1.194.0/24
|
78
|
ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32
|
79
|
ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30
|
80
|
ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32
|
81
|
ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30
|
82
|
ip prefix-list ACCEPTFILTER seq 10 permit any
|
83
|
ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30
|
84
|
match ip address prefix-list CONNECT
|
85
|
match ip address prefix-list ACCEPTFILTER
|
86
|
firewall1.home.arpa# show running-config no-header | include prefix-list
|
87
|
ip prefix-list CONNECT seq 10 permit 10.1.194.0/24
|
88
|
ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30
|
89
|
ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32
|
90
|
ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30
|
91
|
ip prefix-list ACCEPTFILTER seq 10 permit any
|
92
|
ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30
|
93
|
ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32
|
94
|
match ip address prefix-list CONNECT
|
95
|
match ip address prefix-list ACCEPTFILTER
|
96
|
firewall1.home.arpa# show running-config no-header | include prefix-list
|
97
|
ip prefix-list CONNECT seq 10 permit 10.1.194.0/24
|
98
|
ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32
|
99
|
ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30
|
100
|
ip prefix-list ACCEPTFILTER seq 10 permit any
|
101
|
ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30
|
102
|
ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32
|
103
|
ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30
|
104
|
match ip address prefix-list CONNECT
|
105
|
match ip address prefix-list ACCEPTFILTER
|
106
|
firewall1.home.arpa# show running-config no-header | include prefix-list
|
107
|
ip prefix-list CONNECT seq 10 permit 10.1.194.0/24
|
108
|
ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30
|
109
|
ip prefix-list ACCEPTFILTER seq 10 permit any
|
110
|
ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30
|
111
|
ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32
|
112
|
ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30
|
113
|
ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32
|
114
|
match ip address prefix-list CONNECT
|
115
|
match ip address prefix-list ACCEPTFILTER
|
116
|
firewall1.home.arpa# show running-config no-header | include prefix-list
|
117
|
ip prefix-list CONNECT seq 10 permit 10.1.194.0/24
|
118
|
ip prefix-list ACCEPTFILTER seq 10 permit any
|
119
|
ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30
|
120
|
ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32
|
121
|
ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30
|
122
|
ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32
|
123
|
ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30
|
124
|
match ip address prefix-list CONNECT
|
125
|
match ip address prefix-list ACCEPTFILTER
|
126
|
firewall1.home.arpa# show running-config no-header | include prefix-list
|
127
|
ip prefix-list CONNECT seq 10 permit 10.1.194.0/24
|
128
|
ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30
|
129
|
ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32
|
130
|
ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30
|
131
|
ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32
|
132
|
ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30
|
133
|
ip prefix-list ACCEPTFILTER seq 10 permit any
|
134
|
match ip address prefix-list CONNECT
|
135
|
match ip address prefix-list ACCEPTFILTER
|
136
|
|
137
|
|
138
|
|
139
|
############## full config ##############
|
140
|
firewall1.home.arpa# show running-config
|
141
|
Building configuration...
|
142
|
|
143
|
Current configuration:
|
144
|
!
|
145
|
frr version 7.5
|
146
|
frr defaults traditional
|
147
|
hostname firewall1.home.arpa
|
148
|
service integrated-vtysh-config
|
149
|
!
|
150
|
password LAB
|
151
|
!
|
152
|
ip router-id 192.168.1.1
|
153
|
!
|
154
|
interface em1
|
155
|
description "ospfd: LAN_passive"
|
156
|
ip ospf area 0.0.0.0
|
157
|
ip ospf cost 4
|
158
|
ip ospf priority 0
|
159
|
!
|
160
|
interface ovpns2
|
161
|
description "ospfd: LAN_passive - ospfd: TUNNEL1_active"
|
162
|
ip ospf area 0.0.0.0
|
163
|
ip ospf authentication message-digest
|
164
|
ip ospf cost 8000
|
165
|
ip ospf message-digest-key 1 md5 BAAAAAAAAAAAAAAD
|
166
|
!
|
167
|
interface ovpns3
|
168
|
description "ospfd: LAN_passive - ospfd: TUNNEL1_active - ospfd: TUNNEL2_active"
|
169
|
ip ospf area 0.0.0.0
|
170
|
ip ospf authentication message-digest
|
171
|
ip ospf cost 9000
|
172
|
ip ospf message-digest-key 1 md5 BAAAAAAAAAAAAAAD
|
173
|
!
|
174
|
router ospf
|
175
|
ospf router-id 192.168.1.1
|
176
|
auto-cost reference-bandwidth 400000
|
177
|
redistribute connected metric 20 route-map CONNECT
|
178
|
passive-interface em1
|
179
|
area 0.0.0.0 authentication message-digest
|
180
|
!
|
181
|
ip prefix-list CONNECT seq 10 permit 10.1.194.0/24
|
182
|
ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32
|
183
|
ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30
|
184
|
ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32
|
185
|
ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30
|
186
|
ip prefix-list ACCEPTFILTER seq 10 permit any
|
187
|
ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30
|
188
|
!
|
189
|
route-map CONNECT permit 10
|
190
|
match ip address prefix-list CONNECT
|
191
|
!
|
192
|
route-map ACCEPTFILTER permit 10
|
193
|
match ip address prefix-list ACCEPTFILTER
|
194
|
!
|
195
|
ip protocol ospf route-map ACCEPTFILTER
|
196
|
!
|
197
|
ipv6 protocol ospf6 route-map ACCEPTFILTER
|
198
|
!
|
199
|
ip protocol bgp route-map ACCEPTFILTER
|
200
|
!
|
201
|
ipv6 protocol bgp route-map ACCEPTFILTER
|
202
|
!
|
203
|
line vty
|
204
|
!
|
205
|
end
|