/* prefix-lists */
This commit is contained in:
parent
3406bbfdf2
commit
fe6a343dd0
16
C3D2VPN.mw
16
C3D2VPN.mw
|
@ -367,17 +367,11 @@ Wir filtern eingehende Routen, damit uns nicht jeder Peer den eigenen Traffic um
|
||||||
neighbor fe80::f00 prefix-list vpn-in in
|
neighbor fe80::f00 prefix-list vpn-in in
|
||||||
|
|
||||||
Diese Listen müssen auch noch angelegt werden, das geschieht in direkt im ''configure terminal''. Beispielkonfiguration:
|
Diese Listen müssen auch noch angelegt werden, das geschieht in direkt im ''configure terminal''. Beispielkonfiguration:
|
||||||
<pre><nowiki>ip prefix-list diac-in seq 10 permit 172.16.0.0/12 ge 18
|
<pre><nowiki>ip prefix-list vpn-in seq 10 permit 172.16.0.0/12 ge 16
|
||||||
ip prefix-list diac-in seq 40 permit 195.16.84.0/22 le 32
|
ip prefix-list vpn-in seq 100 deny 0.0.0.0/0 le 32
|
||||||
ip prefix-list diac-in seq 100 deny 0.0.0.0/0 le 32
|
|
||||||
ip prefix-list diac-out seq 10 permit 172.16.0.0/12 ge 20
|
ipv6 prefix-list vpn-in seq 10 permit 2000::/3 ge 16
|
||||||
ip prefix-list diac-out seq 40 permit 195.16.84.0/22 le 32
|
ipv6 prefix-list vpn-in seq 100 deny ::/0 le 128
|
||||||
ip prefix-list diac-out seq 100 deny 0.0.0.0/0
|
|
||||||
!
|
|
||||||
ipv6 prefix-list diac-in seq 10 permit 2000::/3 ge 16
|
|
||||||
ipv6 prefix-list diac-in seq 100 deny ::/0 le 128
|
|
||||||
ipv6 prefix-list diac-out seq 10 permit 2000::/3 le 128
|
|
||||||
ipv6 prefix-list diac-out seq 100 deny ::/0
|
|
||||||
</nowiki></pre>
|
</nowiki></pre>
|
||||||
|
|
||||||
=TODO=
|
=TODO=
|
||||||
|
|
Loading…
Reference in New Issue
Block a user