- 前缀列表用途
前缀列表用于对路由的匹配和过滤,既能限制前缀的范围,又能限制掩码的范围。
- 命令详解
ip ip-prefix name index sn permit/deny prefix/len greater-equal X less-equal Y
name:前缀列表名称(任意字符串或数字)
Sequence number:序列号,匹配的时候将根据序列号从小到大,取值范围<1-65535>
prefix:指定的路由前缀(网段)
len:是指定的前缀长度
子网掩码:greater-equal X <子网掩码<less-equal Y
- 前缀列表的应用
R1配置:
基础配置
system-view
sysname r1
interface GigabitEthernet0/0/0
ip address 192.168.1.1 255.255.255.0
interface GigabitEthernet0/0/1
ip address 10.1.1.1 255.255.255.252
interface LoopBack0
ip address 1.1.1.1 255.255.255.255
ospf 1 router-id 1.1.1.1
area 0.0.0.0
network 10.1.1.0 0.0.0.3
network 192.168.1.0 0.0.0.255
关键配置:
acl number 2001
rule 5 deny source 192.168.3.0 0.0.0.255
rule 10 permit
ospf 1 router-id 1.1.1.1
filter-policy 2001 import
area 0.0.0.0
network 10.1.1.0 0.0.0.3
network 192.168.1.0 0.0.0.255
R2配置:
system-view
sysname r2
interface GigabitEthernet0/0/0
ip address 192.168.2.1 255.255.255.0
interface GigabitEthernet0/0/1
ip address 10.1.1.5 255.255.255.252
interface LoopBack0
ip address 2.2.2.2 255.255.255.255
ospf 1 router-id 2.2.2.2
area 0.0.0.0
network 10.1.1.4 0.0.0.3
network 192.168.2.0 0.0.0.255
R3配置:
system-view
sysname r3
interface GigabitEthernet0/0/0
ip address 10.1.1.2 255.255.255.0
interface GigabitEthernet0/0/1
ip address 10.1.1.6 255.255.255.252
interface GigabitEthernet0/0/2
ip address 10.1.1.9 255.255.255.252
interface LoopBack0
ip address 3.3.3.3 255.255.255.255
ospf 1 router-id 3.3.3.3
area 0.0.0.0
network 10.1.1.0 0.0.0.3
network 10.1.1.4 0.0.0.3
network 10.1.1.8 0.0.0.3
R4配置:
基础配置
system-view
sysname r4
interface GigabitEthernet0/0/0
ip address 10.1.1.10 255.255.255.252
interface GigabitEthernet0/0/1
ip address 192.168.3.1 255.255.255.0
interface GigabitEthernet0/0/2
ip address 192.168.4.1 255.255.255.0
interface GigabitEthernet0/0/2
ip address 192.168.5.1 255.255.255.0
interface LoopBack0
ip address 4.4.4.4 255.255.255.255
ospf 1 router-id 4.4.4.4
area 0.0.0.0
network 10.1.1.8 0.0.0.3
关键配置:
ospf 1 router-id 4.4.4.4
filter-policy ip-prefix abc export direct
import-route direct
area 0.0.0.0
network 10.1.1.8 0.0.0.3
ip ip-prefix abc index 10 permit 192.168.3.0 24
ip ip-prefix abc index 20 permit 192.168.5.0 24
- 总结
1)前缀列表不能用于ip报文的过滤,只能用于路由信息的过滤
2)子网掩码可以实现精确匹配
instance:ip ip-prefix abc index 10 permit 192.168.3.0 24 greater-equal 24 less-equal 24
解析:子网掩码须为255.255.255.0