Tuesday, April 5, 2011

LAB: EIGRP Filtering with Prefix-Lists


Requirements:

- Configure a prefix-list on R4 so that it does not advertise the 30.0.0.0 and 31.0.0.0 subnets learned from BB3 out the point-to-point link to R5; use the most efficient list to accomplish this that will not deny any other networks than those subnets R4 is learning.
- Configure a prefix-list on R1 so that it does not install any updates received from R4 on the VLAN 146 segment.


R1:
router eigrp 100
distribute-list prefix PERMIT_ALL gateway NOT_FROM_R4 in
!
ip prefix-list NOT_FROM_R4 seq 5 deny 155.1.146.4/32
ip prefix-list NOT_FROM_R4 seq 10 permit 0.0.0.0/0 le 32
!
ip prefix-list PERMIT_ALL seq 5 permit 0.0.0.0/0 le 32
R4:
router eigrp 100
distribute-list prefix STOP_RIP_SUBNETS out Serial0/1
!
ip prefix-list STOP_RIP_SUBNETS seq 5 deny 30.0.0.0/14 ge 16 le 16
ip prefix-list STOP_RIP_SUBNETS seq 10 deny 31.0.0.0/14 ge 16 le 16
ip prefix-list STOP_RIP_SUBNETS seq 15 permit 0.0.0.0/0 le 32



before:

Rack1R1#show ip route | include 3(0|1).[0-3].0.0
31.0.0.0/16 is subnetted, 4 subnets
D EX 31.3.0.0 [170/28160] via 155.1.146.4, 00:17:02, FastEthernet0/0
D EX 31.2.0.0 [170/28160] via 155.1.146.4, 00:17:02, FastEthernet0/0
D EX 31.1.0.0 [170/28160] via 155.1.146.4, 00:17:02, FastEthernet0/0
D EX 31.0.0.0 [170/28160] via 155.1.146.4, 00:17:02, FastEthernet0/0
30.0.0.0/16 is subnetted, 4 subnets
D EX 30.2.0.0 [170/28160] via 155.1.146.4, 00:17:02, FastEthernet0/0
D EX 30.3.0.0 [170/28160] via 155.1.146.4, 00:17:02, FastEthernet0/0
D EX 30.0.0.0 [170/28160] via 155.1.146.4, 00:17:02, FastEthernet0/0
D EX 30.1.0.0 [170/28160] via 155.1.146.4, 00:17:02, FastEthernet0/0

Rack1R5#show ip route | include via 155.1.(0|45).4
D EX 204.12.1.0/24 [170/537600] via 155.1.45.4, 00:21:37, Serial0/1
[170/537600] via 155.1.0.4, 00:21:37, Serial0/0
D 155.1.146.0 [90/514560] via 155.1.45.4, 00:21:37, Serial0/1
[90/514560] via 155.1.0.4, 00:21:37, Serial0/0
D 155.1.67.0 [90/517120] via 155.1.45.4, 00:21:36, Serial0/1
[90/517120] via 155.1.0.4, 00:21:36, Serial0/0
D EX 200.0.0.0/24 [170/1154560] via 155.1.45.4, 00:21:36, Serial0/1
[170/1154560] via 155.1.0.4, 00:21:36, Serial0/0
D EX 54.1.1.0 [170/1026560] via 155.1.45.4, 00:21:37, Serial0/1
[170/1026560] via 155.1.0.4, 00:21:37, Serial0/0
D EX 200.0.1.0/24 [170/1154560] via 155.1.45.4, 00:21:37, Serial0/1
[170/1154560] via 155.1.0.4, 00:21:37, Serial0/0
D EX 200.0.2.0/24 [170/1154560] via 155.1.45.4, 00:21:37, Serial0/1
[170/1154560] via 155.1.0.4, 00:21:37, Serial0/0
D EX 200.0.3.0/24 [170/1154560] via 155.1.45.4, 00:21:37, Serial0/1
[170/1154560] via 155.1.0.4, 00:21:37, Serial0/0
D EX 31.3.0.0 [170/537600] via 155.1.45.4, 00:03:52, Serial0/1
[170/537600] via 155.1.0.4, 00:03:52, Serial0/0
D EX 31.2.0.0 [170/537600] via 155.1.45.4, 00:03:52, Serial0/1
[170/537600] via 155.1.0.4, 00:03:52, Serial0/0
D EX 31.1.0.0 [170/537600] via 155.1.45.4, 00:03:52, Serial0/1
[170/537600] via 155.1.0.4, 00:03:52, Serial0/0
D EX 31.0.0.0 [170/537600] via 155.1.45.4, 00:03:52, Serial0/1
[170/537600] via 155.1.0.4, 00:03:52, Serial0/0
D 150.1.6.0 [90/642560] via 155.1.45.4, 00:21:40, Serial0/1
[90/642560] via 155.1.0.4, 00:21:40, Serial0/0
D 150.1.4.0 [90/640000] via 155.1.45.4, 00:21:41, Serial0/1
[90/640000] via 155.1.0.4, 00:21:41, Serial0/0
D EX 30.2.0.0 [170/537600] via 155.1.45.4, 00:03:55, Serial0/1
[170/537600] via 155.1.0.4, 00:03:55, Serial0/0
D EX 30.3.0.0 [170/537600] via 155.1.45.4, 00:03:55, Serial0/1
[170/537600] via 155.1.0.4, 00:03:55, Serial0/0
D EX 30.0.0.0 [170/537600] via 155.1.45.4, 00:03:55, Serial0/1
[170/537600] via 155.1.0.4, 00:03:55, Serial0/0
D EX 30.1.0.0 [170/537600] via 155.1.45.4, 00:03:55, Serial0/1
[170/537600] via 155.1.0.4, 00:03:55, Serial0/0


after:

Rack1R1#show ip route | include 3(0|1).[0-3].0.0
31.0.0.0/16 is subnetted, 4 subnets
D EX 31.3.0.0 [170/1049600] via 155.1.0.5, 00:00:04, Serial0/0.1
D EX 31.2.0.0 [170/1049600] via 155.1.0.5, 00:00:04, Serial0/0.1
D EX 31.1.0.0 [170/1049600] via 155.1.0.5, 00:00:04, Serial0/0.1
D EX 31.0.0.0 [170/1049600] via 155.1.0.5, 00:00:04, Serial0/0.1
30.0.0.0/16 is subnetted, 4 subnets
D EX 30.2.0.0 [170/1049600] via 155.1.0.5, 00:00:04, Serial0/0.1
D EX 30.3.0.0 [170/1049600] via 155.1.0.5, 00:00:04, Serial0/0.1
D EX 30.0.0.0 [170/1049600] via 155.1.0.5, 00:00:04, Serial0/0.1
D EX 30.1.0.0 [170/1049600] via 155.1.0.5, 00:00:04, Serial0/0.1


Rack1R5#show ip route | include via 155.1.(0|45).4
D EX 204.12.1.0/24 [170/537600] via 155.1.45.4, 00:04:25, Serial0/1
[170/537600] via 155.1.0.4, 00:04:25, Serial0/0
D 155.1.146.0 [90/514560] via 155.1.45.4, 00:04:25, Serial0/1
[90/514560] via 155.1.0.4, 00:04:25, Serial0/0
D 155.1.67.0 [90/517120] via 155.1.45.4, 00:04:24, Serial0/1
[90/517120] via 155.1.0.4, 00:04:24, Serial0/0
D EX 200.0.0.0/24 [170/1154560] via 155.1.45.4, 00:04:24, Serial0/1
[170/1154560] via 155.1.0.4, 00:04:25, Serial0/0
D EX 54.1.1.0 [170/1026560] via 155.1.45.4, 00:04:25, Serial0/1
[170/1026560] via 155.1.0.4, 00:04:25, Serial0/0
D EX 200.0.1.0/24 [170/1154560] via 155.1.45.4, 00:04:25, Serial0/1
[170/1154560] via 155.1.0.4, 00:04:25, Serial0/0
D EX 200.0.2.0/24 [170/1154560] via 155.1.45.4, 00:04:25, Serial0/1
[170/1154560] via 155.1.0.4, 00:04:25, Serial0/0
D EX 200.0.3.0/24 [170/1154560] via 155.1.45.4, 00:04:25, Serial0/1
[170/1154560] via 155.1.0.4, 00:04:25, Serial0/0
D EX 31.3.0.0 [170/537600] via 155.1.0.4, 00:04:26, Serial0/0
D EX 31.2.0.0 [170/537600] via 155.1.0.4, 00:04:26, Serial0/0
D EX 31.1.0.0 [170/537600] via 155.1.0.4, 00:04:26, Serial0/0
D EX 31.0.0.0 [170/537600] via 155.1.0.4, 00:04:26, Serial0/0
D 150.1.6.0 [90/642560] via 155.1.45.4, 00:04:26, Serial0/1
[90/642560] via 155.1.0.4, 00:04:26, Serial0/0
D 150.1.4.0 [90/640000] via 155.1.45.4, 00:04:26, Serial0/1
[90/640000] via 155.1.0.4, 00:04:26, Serial0/0
D EX 30.2.0.0 [170/537600] via 155.1.0.4, 00:04:28, Serial0/0
D EX 30.3.0.0 [170/537600] via 155.1.0.4, 00:04:28, Serial0/0
D EX 30.0.0.0 [170/537600] via 155.1.0.4, 00:04:28, Serial0/0
D EX 30.1.0.0 [170/537600] via 155.1.0.4, 00:04:28, Serial0/0

No comments:

Post a Comment