If I understand what you are trying to do that looks correct to me.
This will permit region-3 without any modifications and then block
everything that hasn't been matched.

On Wed, Jun 8, 2011 at 3:08 PM, Eric Morin <[email protected]> wrote:
> Hi
>
> Are there any caveats to leveraging an outbound route-map for prefix
> filtering (on top of adding policy) to external peers, vs using a prefix
> filter as well as the route-map? The main objective here is to keep an
> additional (large) prefix list out of the config.
>
>
>
> I have to specify prefix lists for each group of prefixes in a
> multi-sequence route map to differentiate policies for different groups
> of prefixes for a particular upstream:
>
>
>
> route-map Upstream1-OUTPOLICY permit 30
>
> match ip address prefix-list region1-prefixes
>
> set community xxxxx:xxx
>
> !
>
> route-map Upstream1-OUTPOLICY permit 40
>
> match ip address prefix-list region-2-prefixes
>
> set as-path prepend xxxxx xxxxx
>
> !
>
> route-map Upstream1-OUTPOLICY permit 50
>
> match ip address prefix-list region-3-prefixes
>
>
>
> Instead of having another large prefix list that includes
> 'region1-prefixes', 'region-2-prefixes', and 'region-3-prefixes', and
> apply it to the neighbor as an out prefix list, I want to use the seq 50
> to simply match the last prefix list to allow through. This seems to
> work well in the lab, but wanted to know if there was something that I
> may have missed? I typically have aggregates and specifics in BGP and
> typically filter out specifics (and RFC1918) outbound to external peers.
> The main objective is to keep the large prefix list out of the
> config(s).
>
>
>
>
>
> Thanks in advance!
>
>
>
> Eric
>
>
>
> _______________________________________________
> cisco-nsp mailing list  [email protected]
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/
>

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to