If I understand what you are trying to do that looks correct to me. This will permit region-3 without any modifications and then block everything that hasn't been matched.
On Wed, Jun 8, 2011 at 3:08 PM, Eric Morin <[email protected]> wrote: > Hi > > Are there any caveats to leveraging an outbound route-map for prefix > filtering (on top of adding policy) to external peers, vs using a prefix > filter as well as the route-map? The main objective here is to keep an > additional (large) prefix list out of the config. > > > > I have to specify prefix lists for each group of prefixes in a > multi-sequence route map to differentiate policies for different groups > of prefixes for a particular upstream: > > > > route-map Upstream1-OUTPOLICY permit 30 > > match ip address prefix-list region1-prefixes > > set community xxxxx:xxx > > ! > > route-map Upstream1-OUTPOLICY permit 40 > > match ip address prefix-list region-2-prefixes > > set as-path prepend xxxxx xxxxx > > ! > > route-map Upstream1-OUTPOLICY permit 50 > > match ip address prefix-list region-3-prefixes > > > > Instead of having another large prefix list that includes > 'region1-prefixes', 'region-2-prefixes', and 'region-3-prefixes', and > apply it to the neighbor as an out prefix list, I want to use the seq 50 > to simply match the last prefix list to allow through. This seems to > work well in the lab, but wanted to know if there was something that I > may have missed? I typically have aggregates and specifics in BGP and > typically filter out specifics (and RFC1918) outbound to external peers. > The main objective is to keep the large prefix list out of the > config(s). > > > > > > Thanks in advance! > > > > Eric > > > > _______________________________________________ > cisco-nsp mailing list [email protected] > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
