1. 前缀列表用途

前缀列表用于对路由的匹配和过滤,既能限制前缀的范围,又能限制掩码的范围。

  1. 命令详解

ip ip-prefix name index sn permit/deny prefix/len greater-equal X less-equal Y

name:前缀列表名称(任意字符串或数字)

Sequence number:序列号,匹配的时候将根据序列号从小到大,取值范围<1-65535>

 prefix:指定的路由前缀(网段)

len:是指定的前缀长度

子网掩码:greater-equal X <子网掩码<less-equal Y

  1. 前缀列表的应用

路由策略条件工具—地址前缀列表(ip prefix list)_取值范围

R1配置:

基础配置

system-view

sysname r1


interface GigabitEthernet0/0/0

ip address 192.168.1.1 255.255.255.0

interface GigabitEthernet0/0/1

ip address 10.1.1.1 255.255.255.252

interface LoopBack0

ip address 1.1.1.1 255.255.255.255


ospf 1 router-id 1.1.1.1

area 0.0.0.0

 network 10.1.1.0 0.0.0.3

 network 192.168.1.0 0.0.0.255

关键配置:

acl number 2001

rule 5 deny source 192.168.3.0 0.0.0.255

rule 10 permit


ospf 1 router-id 1.1.1.1

filter-policy 2001 import

area 0.0.0.0

 network 10.1.1.0 0.0.0.3

 network 192.168.1.0 0.0.0.255

R2配置:

system-view

sysname r2


interface GigabitEthernet0/0/0

ip address 192.168.2.1 255.255.255.0

interface GigabitEthernet0/0/1

ip address 10.1.1.5 255.255.255.252

interface LoopBack0

ip address 2.2.2.2 255.255.255.255

ospf 1 router-id 2.2.2.2

area 0.0.0.0

 network 10.1.1.4 0.0.0.3

 network 192.168.2.0 0.0.0.255

R3配置:

system-view

sysname r3


interface GigabitEthernet0/0/0

ip address 10.1.1.2 255.255.255.0

interface GigabitEthernet0/0/1

ip address 10.1.1.6 255.255.255.252

interface GigabitEthernet0/0/2

ip address 10.1.1.9 255.255.255.252

interface LoopBack0

ip address 3.3.3.3 255.255.255.255


ospf 1 router-id 3.3.3.3

area 0.0.0.0

 network 10.1.1.0 0.0.0.3

network 10.1.1.4 0.0.0.3

network 10.1.1.8 0.0.0.3

R4配置:

基础配置

system-view

sysname r4


interface GigabitEthernet0/0/0

ip address 10.1.1.10 255.255.255.252

interface GigabitEthernet0/0/1

ip address 192.168.3.1 255.255.255.0

interface GigabitEthernet0/0/2

ip address 192.168.4.1 255.255.255.0

interface GigabitEthernet0/0/2

ip address 192.168.5.1 255.255.255.0

interface LoopBack0

ip address 4.4.4.4 255.255.255.255


ospf 1 router-id 4.4.4.4

area 0.0.0.0

network 10.1.1.8 0.0.0.3

关键配置:

ospf 1 router-id 4.4.4.4

filter-policy ip-prefix abc export direct

import-route direct

area 0.0.0.0

 network 10.1.1.8 0.0.0.3


ip ip-prefix abc index 10 permit 192.168.3.0 24

ip ip-prefix abc index 20 permit 192.168.5.0 24

  1. 总结

1)前缀列表不能用于ip报文的过滤,只能用于路由信息的过滤

2)子网掩码可以实现精确匹配

instance:ip ip-prefix abc index 10 permit 192.168.3.0 24 greater-equal 24 less-equal 24

解析:子网掩码须为255.255.255.0