Escolar Documentos
Profissional Documentos
Cultura Documentos
nstru!tor "ersion
Topolog#
Ob$e!tives
Filter routes using a distribute list and ACL.
Filter routes using a distribute list and prefix list.
Filter redistributed routes using a route map.
Filter redistributed routes and set attributes using a route map.
© 2014 Cisco and/or its affiliates. All rights resered. !his document is Cisco "ublic. "age 1 of 14
CCNPv7 ROUTE Lab 4#$% Controlling &outing 'pdates
%a!&ground
(n this scenario% &1 and &2 are running )(*&" +hile &2 and &$ are running multi#area ,-"F. &2 is the
,-"F autonomous sstem border router A-& consisting of areas 0% 10% and 20.
our tas3 is to control routing updates b u sing distribute lists% prefix lists and route maps.
Note' !his lab uses Cisco 141 routers +ith Cisco (,- &elease 15.2 +ith (" ase. 6epending on the router
or s+itch
from +hatmodel andin
is sho+n Cisco (,- -oft+are ersion% the commands aailable and output produced might ar
this lab.
Re(uired Resour!es
$ routers Cisco (,- &elease 15.2 or comparable
-erial and )thernet cables
Note7 !he follo+ing t+o steps are not re8uired if ou are continuing from Lab 4#1.
a. Configure all loopbac3 interfaces on the three routers in the diagram. Configure the serial interfaces +ith
the (" addresses% bring them up% and set a 6C) cloc3 rate +here appropriate.
R1(config)# interface Loopback0
R1(config-if)# ip address 172.16.1.1 255.255.255.0
R1(config-if)# exit
R1(config)#
R1(config)# interface Loopback48
R1(config-if)# ip address 192.168.48.1 255.255.255.0
R1(config-if)# exit
R1(config)#
R1(config)# interface Loopback49
R1(config-if)# ip address 192.168.49.1 255.255.255.0
R1(config-if)# exit
R1(config)#
R1(config)# interface Loopback50
R1(config-if)# ip address 192.168.50.1 255.255.255.0
R1(config-if)# exit
R1(config)#
R1(config)# interface Loopback51
R1(config-if)# ip address 192.168.51.1 255.255.255.0
R1(config-if)# exit
R1(config)#
R1(config)# interface
R1(config-if)# Loopback70
ip address 192.168.70.1 255.255.255.0
R1(config-if)# exit
R1(config)#
R1(config)# interface Serial0/0/0
R1(config-if)# ip address 172.16.12.1 255.255.255.0
R1(config-if)# clock rate 64000
R1(config-if)# bandwidt 64
R1(config-if)# no s!tdown
© 2014 Cisco and/or its affiliates. All rights resered. !his document is Cisco "ublic. "age 2 of 14
CCNPv7 ROUTE Lab 4#$% Controlling &outing 'pdates
R2(config-if)# exit
R2(config)#
R2(config)# interface Loopback100
R2(config-if)# ip address 172.16.100.1 255.255.255.0
R2(config-if)# ip ospf network point"to"point
R2(config-if)# exit
R2(config)#
R2(config-if)# interface Serial0/0/0
R2(config-if)# bandwidt 64
R2(config-if)# ip address 172.16.12.2 255.255.255.0
R2(config-if)# no s!tdown
R2(config-if)# exit
R2(config)#
R2(config)# interface Serial0/0/1
R2(config-if)# bandwidt 64
R2(config-if)# ip address 172.16.2#.2 255.255.255.0
R2(config-if)# clock rate 64000
R2(config-if)# no s!tdown
© 2014 Cisco and/or its affiliates. All rights resered. !his document is Cisco "ublic. "age $ of 14
CCNPv7 ROUTE Lab 4#$% Controlling &outing 'pdates
R3(config)#
R3(config)# interface Loopback#5
R3(config-if)# ip address 192.168.#5.1 255.255.255.0
R3(config-if)# ip ospf network point"to"point
R3(config-if)# exit
R3(config)#
R3(config)# interface Loopback40
R3(config-if)# ip address 192.168.40.1 255.255.255.0
R3(config-if)# ip ospf network point"to"point
R3(config-if)# exit
R3(config)#
R3(config)# interface Serial0/0/1
R3(config-if)# ip address 172.16.2#.# 255.255.255.0
R3(config-if)# bandwidt 64
R3(config-if)# no s!tdown
b. ,n &$% summari9e area 20 routes and configure ,-"F for area 0 and area 20.
R3(config)# ro!ter ospf 1
R3(config-router)# area 20 ran&e 192.168.8.0 255.255.252.0
R3(config-router)# network 172.16.0.0 0.0.255.255 area 0
R3(config-router)# network 192.168.0.0 0.0.255.255 area 0
R3(config-router)# network 192.168.8.0 0.0.#.255 area 20
R3(config-router)#
c. ,n &2% configure )(*&" and redistribute the ,-"F net+or3s into )(*&" A- 1. !hen configure ,-"F
and redistribute and summari9e the )(*&" net+or3s into ,-"F.
R2(config)# ro!ter ei&rp 1
R2(config-router)# no a!to"s!$$ar%
R2(config-router)# network 172.16.0.0
R2(config-router)# redistrib!te ospf 1 $etric 10000 100 255 1 1500
R2(config-router)# exit
R2(config)#
R2(config)# ro!ter ospf 1
R2(config-router)# network 172.16.2#.0 0.0.0.255 area 0
R2(config-router)# network 172.16.100.0 0.0.0.255 area 10
R2(config-router)# redistrib!te ei&rp 1 s!bnets
R2(config-router)# s!$$ar%"address 192.168.48.0 255.255.252.0
R2(config-router)# exit
R2(config)#
© 2014 Cisco and/or its affiliates. All rights resered. !his document is Cisco "ublic. "age 4 of 14
CCNPv7 ROUTE Lab 4#$% Controlling &outing 'pdates
As expected% &2 3no+s about the &1 routes including the summari9ed 12.1<:.4:.0/22 )(*&" route. &2
also 3no+s about the &$ ,-"F area 0 routes and the summari9ed area 20 routes.
D &?
D 12.16.3.02* =10*03600>
12.16.23.02* ia 12.16.12.2
=70*102*000> ia 12.16.12.2 00:11:*0
00:11:*0 eria/000
eria/000
D 12.16.100.02* =70*06*0000> ia 12.16.12.2 00:11:*0 eria/000
D &? 172.168.8.022 =10*03600> ia 12.16.12.2 00:11:*0 eria/000
D &? 172.168.20.02* =10*03600> ia 12.16.12.2 00:11:*0 eria/000
D &? 172.168.2.02* =10*03600> ia 12.16.12.2 00:11:*0 eria/000
D &? 172.168.30.02* =10*03600> ia 12.16.12.2 00:11:*0 eria/000
D &? 172.168.3.02* =10*03600> ia 12.16.12.2 00:11:*0 eria/000
D &? 172.168.*0.02* =10*03600> ia 12.16.12.2 00:11:*0 eria/000
D &? 172.168.*8.022 =10*03600> ia 12.16.12.2 00:11:38 eria/000
D 172.168.*8.023 i a u;;ar 00:11:*0 !u//0
R1#
© 2014 Cisco and/or its affiliates. All rights resered. !his document is Cisco "ublic. "age 5 of 14
CCNPv7 ROUTE Lab 4#$% Controlling &outing 'pdates
&1 3no+s about the internal )(*&" routes and the external routes redistributed from the ,-"F routing
domain b &2. !he highlighted entr identifies the ,-"F 20 routes +hich +ill be filtered using a distribute
list and ACL in the next step.
&$ 3no+s about the internal ,-"F routes and the external routes redistributed b &2 from the )(*&"
routing domain. !he highlighted entries identif the )(*&" routes +hich +ill be filtered using a d istribute
list and prefix list in another step.
g. ;erif that ou can ping across the serial lin3s +hen ou are finished. 'se the follo+ing !cl script to chec3
connectiit.
R3# tcls
foreac+ a44re @
12.16.1.1
172.168.*8.1
172.168.*7.1
172.168.0.1
172.168.1.1
172.168.0.1
12.16.12.1
12.16.12.2
12.16.2.1
12.16.100.1
12.16.23.2
12.16.23.3
12.16.3.1
172.168.8.1
172.168.7.1
172.168.10.1
172.168.11.1
172.168.20.1
172.168.2.1
172.168.30.1
172.168.3.1
172.168.*0.1
@ ing Ba44re
© 2014 Cisco and/or its affiliates. All rights resered. !his document is Cisco "ublic. "age < of 14
CCNPv7 ROUTE Lab 4#$% Controlling &outing 'pdates
)tep /' 0ilter redistributed routes using a distribute list and 1CL
&outes can be filtered using a ariet of techni8ues including7
istribute list and 1CL= A distribute list allo+s an access control lists ACLs to be applied to routing
updates.
istribute list and pre+i3 list = A distribute list +ith a prefix list is an alternatie to ACLs designed to
filter routes. "refix lists are not exclusiel used +ith distribute lists but can also be u sed +ith route
maps and other commands.
Route aps= &oute maps are complex access lists that allo+ conditions to be tested against a
pac3et or route% and then actions ta3en to modif attributes of the pac3et or route.
(n this step% +e +ill use a distribute list and ACL to filter routes being adertised from &2 to &1. -pecificall%
+e +ill filter the ,-"F 20 routes i.e.% 12.1<:.:.0/22 from being adertised b &2 to &1.
a. ,n &1% erif the routing table entr for the 12.1<:.:.0/22 route.
R1# sow ip ro!te 192.168.8.0
Routing entr for 172.168.8.022 uernet
Cnon ia eigr 1 4itance 10 ;etric *03600 te eEterna/
Re4itri,uting ia eigr 1
Lat u4ate fro; 12.16.12.2 on eria/000 00:00:*3 ago
Routing Decritor "/oc<:
F 12.16.12.2 fro; 12.16.12.2 00:00:*3 ago ia eria/000
Route ;etric i *03600 traffic +are count i 1
Gota/ 4e/a i 21000 ;icroecon4 ;ini;u; ,an4i4t+ i 6* C,it
Re/ia,i/it 22 ;ini;u; HGU 100 ,te
Loa4ing 12 $o 1
R1#
b. Although a distribute list could be implemented on the receiing router% it is usuall best to filter routes
from the distributing router. !herefore on &2% create an ACL called O)P02-0LTER that denies the
12.1<:.:.0/22 route. !he ACL must also permit all other routes other+ise% no ,-"F routes +ould be
redistributed into )(*&".
R2(config)# ip access"list standard )S*+20"+,L-
R2(config-t4-nac/)# re$ark sed wit List to filter )S*+ 20 ro!tes
R2(config-t4-nac/)# den% 192.168.8.0 0.0.#.255
R2(config-t4-nac/)# per$it an%
R2(config-t4-nac/)# exit
R2(config)#
c. Configure a distribute list under the )(*&" process to filter routes propagated to &1 using the pr e#
configured ACL.
R2(config)# ro!ter ei&rp 1
R2(config-router)# distrib!te"list )S*+20"+,L- o!t ospf 1
R2(config-router)#
d. ,n &1% erif if the route is no+ missing from the &1 routing table.
R1# sow ip ro!te 192.168.8.0
% !etor< not in ta,/e
R1#
R1# sow ip ro!te ei&rp ' be&in (atewa%
atea of /at reort i not et
© 2014 Cisco and/or its affiliates. All rights resered. !his document is Cisco "ublic. "age > of 14
CCNPv7 ROUTE Lab 4#$% Controlling &outing 'pdates
!he output confirms that the 12.1<:.:.0/22 route is no longer in the routing table of &1.
?ote that if additional router filtering +as re8uired% onl the ACL on &2 +ould need to be altered.
)tep 4' 0ilter redistributed routes using a distribute list and pre+i3 list
(n this step% a prefix list +ill be configured +ith a distribute list to filter &1 routes being adertised from &2 to
&$.
a. ,n &$% erif the routing table entr for the routes learned externall identified +ith the 0 )2 source entr.
R3# sow ip ro!te ospf ' incl!de ) 2
&2 12.16.1.02* =11020> ia 12.16.23.2 00:10:12 eria/001
&2 12.16.2.02* =11020> ia 12.16.23.2 00:10:12 eria/001
&2 12.16.12.02* =11020> ia 12.16.23.2 00:10:12 eria/001
&2 172.168.*8.022 =11020> ia 12.16.23.2 00:02:0 eria/001
&2 172.168.0.02* =11020> ia 12.16.23.2 00:02:0 eria/001
R3#
-pecificall% the highlighted routes +ill be omitted from being adertised using a prefix list.
b. &2 +ill be conf igured +ith a prefix li st identifing +hich net+or3s to adertise to adertise to &$.
-pecificall% onl the 1>2.1<.0.0 net+or3s are permitted.
R2(config)# ip prefix"list ,(*"+,L- description sed wit List to filter
,(* ro!tes
R2(config)# ip prefix"list ,(*"+,L- per$it 172.16.0.0/16 le 24
R2(config)#
c. Configure a distribute list under the ,-"F process to filter routes propagated to &$ using the pre#
configured prefix list.
R2(config)# ro!ter ospf 1
R2(config-router)#
R2(config-router)# distrib!te"list prefix ,(*"+,L- o!t ei&rp 1
d. ,n &$% erif if the route is no+ missing from the &1 routing table.
R3# sow ip ro!te ospf ' incl!de ) 2
&2 12.16.1.02* =11020> ia 12.16.23.2 00:13: eria/001
&2 12.16.2.02* =11020> ia 12.16.23.2 00:13: eria/001
&2 12.16.12.02* =11020> ia 12.16.23.2 00:13: eria/001
R3#
!he output confirms that onl the 1>2.1<.0.0/1< net+or3s are being adertised to &$.
© 2014 Cisco and/or its affiliates. All rights resered. !his document is Cisco "ublic. "age : of 14
CCNPv7 ROUTE Lab 4#$% Controlling &outing 'pdates
&oute maps can also be used to filter redistributed routes. A route map +or3s li3e an access list b ecause it
has multiple den and permit statements that are read in a se8uential order. @o+eer% route maps can match
and set specific attributes and therefore proide additional options and more flexibilit +hen redistributing
routes.
&oute maps are not ust for redistribution. !he are also commonl used for7
Poli!#-based routing 6P%R= "& allo+s an administrator to define routing polic other than basic
destination#based routing using the routing table. !he route map is applied to an interface using the ip
poli!# route-ap interface configuration command.
%8P=&oute maps are the primar tools for implementing *" polic and allo+s an administrator to
do path control and proide sophisticated manipulation of *" path attributes. !he route map is
applied using the *" neighbor router configuration command.
(n this step% +e +ill filter the &$ loopbac3 25 and $0 net+or3s from being redistributed into )(*&" on &2.
a. 6ispla the &1 routing table and erif that those t+o routes currentl appear there.
R1# sow ip ro!te ei&rp ' be&in (atewa%
atea of /at reort i not et
b. !here are multiple +as to configure this filtering. (n this step% +e +ill configure an ACL that matches
these t+o net+or3. Configure the follo+ing named access list to identif the t+o routes to be filtered.
R2(config)# ip access"list standard #"3L
R2(config-t4-nac/)# re$ark 3L !sed wit te #"+,L- ro!te $ap
R2(config-t4-nac/)# per$it 192.168.25.0 0.0.0.255
R2(config-t4-nac/)# per$it 192.168.#0.0 0.0.0.255
R2(config-t4-nac/)# exit
R2(config)#
c. Configure a route map +ith a statement that denies based on a match +ith the named ACL. !hen add a
perit statement +ithout a at!h statement. !his acts as an explicit Bpermit all.
R2(config)# ro!te"$ap #"+,L- den% 10
R2(config-route-;a)# description filters # )S*+ ro!tes
© 2014 Cisco and/or its affiliates. All rights resered. !his document is Cisco "ublic. "age of 14
CCNPv7 ROUTE Lab 4#$% Controlling &outing 'pdates
d. Appl this route map to )(*&" b reentering the redistribute command using the route-ap 3e+ord.
R2(config)# ro!ter ei&rp 1
R2(config-router)# redistrib!te ospf 1 ro!te"$ap #"+,L- $etric 64 100 255 1
1500
R2(config-router)#
e. ;erif that the t+o &$ net+or3s are filtered out in the &1 routing table.
R1# sow ip ro!te ei&rp ' be&in (atewa%
atea of /at reort i not et
?otice that the12.1<:.25.0/24 and 12.1<:.$0.0/24 net+or3s are no longer in the routing table.
)tep 9' 0ilter redistributed routes and set attributes using a route ap
!he preceding step +as a simple example of using a route map to filter redistributed routes.
(n this step% +e +ill filter a route from &1 to change its metric and metric tpe.
a. ,n &$% erif the routing table entr for the routes learned externall identified +ith the 0 )2 source entr.
R3# sow ip ro!te ospf ' incl!de ) 2
&2 12.16.1.02* =11020> ia 12.16.23.2 00:13: eria/001
&2 12.16.2.02* =11020> ia 12.16.23.2 00:13: eria/001
&2 12.16.12.02* =11020> ia 12.16.23.2 00:13: eria/001
R3#
c. Configure a route map matching the identified route in the prefix list and assign the metric cost of 25 and
change the metric tpe to )xternal !pe 1. !hen add a perit statement +ithout a at!h statement
acting as an explicit Bpermit all.
R2(config)# ro!te"$ap 1"+,L- per$it 10
R2(config-route-;a)# description filters 172.16.12.0/24
R2(config-route-;a)# $atc ip address prefix"list 1"*L
R2(config-route-;a)# set $etric 25
R2(config-route-;a)# set $etric"t%pe t%pe"1
© 2014 Cisco and/or its affiliates. All rights resered. !his document is Cisco "ublic. "age 10 of 14
CCNPv7 ROUTE Lab 4#$% Controlling &outing 'pdates
R2(config-route-;a)# exit
R2(config)# ro!te"$ap 1"+,L- per$it 20
R2(config-route-;a)# description per$its all oter 1 )S*+ ro!tes
R2(config-route-;a)# exit
R2(config)#
d. Appl this route map to ,-"F b reentering the redistribute command using the route-ap 3e+ord.
R2(config)# ro!ter ospf 1
R2(config-router)# redistrib!te ei&rp 1 s!bnets ro!te"$ap 1"+,L-
R2(config-router)# exit
R2(config)#
e. ;erif that the t+o &$ net+or3s are filtered out in the &1 routing table.
R3# sow ip ro!te ospf ' be&in (atewa%
atea of /at reort i not et
?otice that the1>2.1<.12.0/24 route is no+ a tpe 1 route a nd calculates the actual metric.
© 2014 Cisco and/or its affiliates. All rights resered. !his document is Cisco "ublic. "age 11 of 14
CCNPv7 ROUTE Lab 4#$% Controlling &outing 'pdates
Router R*
+otna;e R1
I
interface Loo,ac<0
i a44re 12.16.1.1 2.2.2.0
I
interface Loo,ac<*8
i a44re 172.168.*8.1 2.2.2.0
I
interface Loo,ac<*7
i a44re 172.168.*7.1 2.2.2.0
I
interface Loo,ac<0
i a44re 172.168.0.1 2.2.2.0
I
interface Loo,ac<1
i a44re 172.168.1.1 2.2.2.0
I
interface Loo,ac<0
i a44re 172.168.0.1 2.2.2.0
I
interface eria/000
,an4i4t+ 6*
no i a44re
i u;;ar-a44re eigr 1 172.168.*8.0 2.2.2*.0
c/oc< rate 6*000
I
router eigr 1
netor< 12.16.0.0
netor< 172.168.0.0 0.0.2.2
I
en4
Router R2
+otna;e R2
I
interface Loo,ac<0
i a44re 12.16.2.1 2.2.2.0
I
interface Loo,ac<100
i a44re 12.16.100.1 2.2.2.0
i of netor< oint-to-oint
I
interface eria/001
,an4i4t+ 6*
i a44re 12.16.23.2 2.2.2.0
c/oc< rate 6*000
I
router eigr 1
4itri,ute-/it 920-9'LG&R out of 1
netor< 12.16.0.0
re4itri,ute of 1 ;etric 6* 100 2 1 100 route-;a R3-9'LG&R
© 2014 Cisco and/or its affiliates. All rights resered. !his document is Cisco "ublic. "age 12 of 14
CCNPv7 ROUTE Lab 4#$% Controlling &outing 'pdates
I
router of 1
u;;ar-a44re 172.168.*8.0 2.2.22.0
re4itri,ute eigr 1 u,net route-;a R1-9'LG&R
netor< 12.16.23.0 0.0.0.2 area 0
netor< 12.16.100.0 0.0.0.2 area 10
4itri,ute-/it refiE &'R-9'LG&R out eigr 1
I
i acce-/it tan4ar4 920-9'LG&R
re;ar< Ue4 it+ 4itri,ute /it to fi/ter 9 20 route
4en 172.168.8.0 0.0.3.2
er;it an
I
i acce-/it tan4ar4 R3-AL
re;ar< AL ue4 it+ t+e R3-9'LG&R route ;a
er;it 172.168.2.0 0.0.0.2
er;it 172.168.30.0 0.0.0.2
I
I
i refiE-/it &'R-9'LG&R 4ecrition Ue4 it+ DLit to fi/ter &'R route
i refiE-/it &'R-9'LG&R e er;it 12.16.0.016 /e 2*
I
i refiE-/it R1-L 4ecrition L ue4 it+ t+e R1-9'LG&R route ;a
i refiE-/it R1-L e er;it 12.16.12.02*
I
route-;a R3-9'LG&R 4en 10
;atc+ i a44re R3-AL
I
route-;a R3-9'LG&R er;it 20
I
route-;a R1-9'LG&R er;it 10
4ecrition RH fi/ter 12.16.12.02*
;atc+ i a44re refiE-/it R1-L
et ;etric 2
et ;etric-te te-1
I
route-;a R1-9'LG&R er;it 20
4ecrition RH er;it a// ot+er R1 9 route
I
en4
Router R/
+otna;e R3
I
interface Loo,ac<0
i a44re 12.16.3.1 2.2.2.0
i of netor< oint-to-oint
I
interface Loo,ac<8
i a44re 172.168.8.1 2.2.2.0
i of netor< oint-to-oint
I
interface Loo,ac<7
i a44re 172.168.7.1 2.2.2.0
© 2014 Cisco and/or its affiliates. All rights resered. !his document is Cisco "ublic. "age 1$ of 14
CCNPv7 ROUTE Lab 4#$% Controlling &outing 'pdates
© 2014 Cisco and/or its affiliates. All rights resered. !his document is Cisco "ublic. "age 14 of 14