This is how it should look... ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 10 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 15 permit any ...although my personal prference is to start at 10 with +5 increments for textual alignment....so.... ip prefix-list ACCEPTFILTER seq 10 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 20 permit any But what actually happens when running the command in about half-second increments.... ############## actual CLI output begins next line ############## firewall1.home.arpa# show running-config no-header | include prefix-list ip prefix-list CONNECT seq 10 permit 10.1.194.0/24 ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 10 permit any ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30 match ip address prefix-list CONNECT match ip address prefix-list ACCEPTFILTER firewall1.home.arpa# show running-config no-header | include prefix-list ip prefix-list CONNECT seq 10 permit 10.1.194.0/24 ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 10 permit any ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32 match ip address prefix-list CONNECT match ip address prefix-list ACCEPTFILTER firewall1.home.arpa# show running-config no-header | include prefix-list ip prefix-list CONNECT seq 10 permit 10.1.194.0/24 ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 10 permit any ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30 match ip address prefix-list CONNECT match ip address prefix-list ACCEPTFILTER firewall1.home.arpa# show running-config no-header | include prefix-list ip prefix-list CONNECT seq 10 permit 10.1.194.0/24 ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 10 permit any ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32 match ip address prefix-list CONNECT match ip address prefix-list ACCEPTFILTER firewall1.home.arpa# show running-config no-header | include prefix-list ip prefix-list CONNECT seq 10 permit 10.1.194.0/24 ip prefix-list ACCEPTFILTER seq 10 permit any ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30 match ip address prefix-list CONNECT match ip address prefix-list ACCEPTFILTER firewall1.home.arpa# show running-config no-header | include prefix-list ip prefix-list CONNECT seq 10 permit 10.1.194.0/24 ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 10 permit any match ip address prefix-list CONNECT match ip address prefix-list ACCEPTFILTER firewall1.home.arpa# show running-config no-header | include prefix-list ip prefix-list CONNECT seq 10 permit 10.1.194.0/24 ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 10 permit any ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30 match ip address prefix-list CONNECT match ip address prefix-list ACCEPTFILTER firewall1.home.arpa# show running-config no-header | include prefix-list ip prefix-list CONNECT seq 10 permit 10.1.194.0/24 ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 10 permit any ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32 match ip address prefix-list CONNECT match ip address prefix-list ACCEPTFILTER firewall1.home.arpa# show running-config no-header | include prefix-list ip prefix-list CONNECT seq 10 permit 10.1.194.0/24 ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 10 permit any ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30 match ip address prefix-list CONNECT match ip address prefix-list ACCEPTFILTER firewall1.home.arpa# show running-config no-header | include prefix-list ip prefix-list CONNECT seq 10 permit 10.1.194.0/24 ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 10 permit any ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32 match ip address prefix-list CONNECT match ip address prefix-list ACCEPTFILTER firewall1.home.arpa# show running-config no-header | include prefix-list ip prefix-list CONNECT seq 10 permit 10.1.194.0/24 ip prefix-list ACCEPTFILTER seq 10 permit any ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30 match ip address prefix-list CONNECT match ip address prefix-list ACCEPTFILTER firewall1.home.arpa# show running-config no-header | include prefix-list ip prefix-list CONNECT seq 10 permit 10.1.194.0/24 ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 10 permit any match ip address prefix-list CONNECT match ip address prefix-list ACCEPTFILTER ############## full config ############## firewall1.home.arpa# show running-config Building configuration... Current configuration: ! frr version 7.5 frr defaults traditional hostname firewall1.home.arpa service integrated-vtysh-config ! password LAB ! ip router-id 192.168.1.1 ! interface em1 description "ospfd: LAN_passive" ip ospf area 0.0.0.0 ip ospf cost 4 ip ospf priority 0 ! interface ovpns2 description "ospfd: LAN_passive - ospfd: TUNNEL1_active" ip ospf area 0.0.0.0 ip ospf authentication message-digest ip ospf cost 8000 ip ospf message-digest-key 1 md5 BAAAAAAAAAAAAAAD ! interface ovpns3 description "ospfd: LAN_passive - ospfd: TUNNEL1_active - ospfd: TUNNEL2_active" ip ospf area 0.0.0.0 ip ospf authentication message-digest ip ospf cost 9000 ip ospf message-digest-key 1 md5 BAAAAAAAAAAAAAAD ! router ospf ospf router-id 192.168.1.1 auto-cost reference-bandwidth 400000 redistribute connected metric 20 route-map CONNECT passive-interface em1 area 0.0.0.0 authentication message-digest ! ip prefix-list CONNECT seq 10 permit 10.1.194.0/24 ip prefix-list ACCEPTFILTER seq 20 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 25 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 30 deny 10.255.1.1/32 ip prefix-list ACCEPTFILTER seq 5 deny 10.255.1.0/30 ip prefix-list ACCEPTFILTER seq 10 permit any ip prefix-list ACCEPTFILTER seq 15 deny 10.255.1.0/30 ! route-map CONNECT permit 10 match ip address prefix-list CONNECT ! route-map ACCEPTFILTER permit 10 match ip address prefix-list ACCEPTFILTER ! ip protocol ospf route-map ACCEPTFILTER ! ipv6 protocol ospf6 route-map ACCEPTFILTER ! ip protocol bgp route-map ACCEPTFILTER ! ipv6 protocol bgp route-map ACCEPTFILTER ! line vty ! end