[quagga-users 14860] Re: ospf route-map
William Herrin <[email protected]> Wed, 1 Nov 2017 11:41:05 -0400
| Newsgroups | gmane.network.quagga.user |
|---|---|
| Message-ID | <CAP-guGX0bSSmqFebZ5_8-5Aybb3=NsiYcBLVQzdcdRgQfpdHNw@mail.gmail.com> |
On Wed, Nov 1, 2017 at 11:17 AM, Mark Coetser <mark-ajVlV48O6s/[email protected]> wrote: > Its complicated to explain, it was site that was shared by 2 clients who > shared a physical network but have since split networks (still on the same > premises) they share certain services but now have separate routers and > breakout links which they dont want each others traffic to flow across but > still want to provide access to other services/networks NOT connected to > router A. > > I know I could achieve this with firewall rules etc it just seemed a > better solution just to not advertise the routes not needed on each > respective router... > > there are more devices than just routers A B C, wish I was good at asci > art I could create a small diagram. Hi Mark, I figured something like this was the case. Here's the key thing to understand about OSPF: it's strictly an interior gateway protocol. It does not have the functionality you need to cross administrative or security domain boundaries. To cross domain boundaries you should use an exterior gateway protocol, such as BGP. So, don't extend OSPF to the routers which have the customer-only routes. Use BGP there with the 65000-series private AS numbers. Control your filtering at the OSPF/BGP border and pick borders such that the filtering you need can happen. Regards, Bill Herrin -- William Herrin ................ herrin-n7Wb/xkVUn1Wk0Htik3J/[email protected] [email protected] Dirtside Systems ......... Web: <http://www.dirtside.com/> _______________________________________________ Quagga-users mailing list Quagga-users-UOy77sIEA+cAd7ICUelF/[email protected] https://lists.quagga.net/mailman/listinfo/quagga-users