/* prefix-lists */
This commit is contained in:
parent
3406bbfdf2
commit
fe6a343dd0
16
C3D2VPN.mw
16
C3D2VPN.mw
|
@ -367,17 +367,11 @@ Wir filtern eingehende Routen, damit uns nicht jeder Peer den eigenen Traffic um
|
|||
neighbor fe80::f00 prefix-list vpn-in in
|
||||
|
||||
Diese Listen müssen auch noch angelegt werden, das geschieht in direkt im ''configure terminal''. Beispielkonfiguration:
|
||||
<pre><nowiki>ip prefix-list diac-in seq 10 permit 172.16.0.0/12 ge 18
|
||||
ip prefix-list diac-in seq 40 permit 195.16.84.0/22 le 32
|
||||
ip prefix-list diac-in seq 100 deny 0.0.0.0/0 le 32
|
||||
ip prefix-list diac-out seq 10 permit 172.16.0.0/12 ge 20
|
||||
ip prefix-list diac-out seq 40 permit 195.16.84.0/22 le 32
|
||||
ip prefix-list diac-out seq 100 deny 0.0.0.0/0
|
||||
!
|
||||
ipv6 prefix-list diac-in seq 10 permit 2000::/3 ge 16
|
||||
ipv6 prefix-list diac-in seq 100 deny ::/0 le 128
|
||||
ipv6 prefix-list diac-out seq 10 permit 2000::/3 le 128
|
||||
ipv6 prefix-list diac-out seq 100 deny ::/0
|
||||
<pre><nowiki>ip prefix-list vpn-in seq 10 permit 172.16.0.0/12 ge 16
|
||||
ip prefix-list vpn-in seq 100 deny 0.0.0.0/0 le 32
|
||||
|
||||
ipv6 prefix-list vpn-in seq 10 permit 2000::/3 ge 16
|
||||
ipv6 prefix-list vpn-in seq 100 deny ::/0 le 128
|
||||
</nowiki></pre>
|
||||
|
||||
=TODO=
|
||||
|
|
Loading…
Reference in New Issue