[quagga-users 14860] Re: ospf route-map

William Herrin <[email protected]> Wed, 1 Nov 2017 11:41:05 -0400
Newsgroups gmane.network.quagga.user
Message-ID <CAP-guGX0bSSmqFebZ5_8-5Aybb3=NsiYcBLVQzdcdRgQfpdHNw@mail.gmail.com>
On Wed, Nov 1, 2017 at 11:17 AM, Mark Coetser <mark-ajVlV48O6s/[email protected]> wrote:

> Its complicated to explain, it was site that was shared by 2 clients who
> shared a physical network but have since split networks (still on the same
> premises) they share certain services but now have separate routers and
> breakout links which they dont want each others traffic to flow across but
> still want to provide access to other services/networks NOT connected to
> router A.
>
> I know I could achieve this with firewall rules etc it just seemed a
> better solution just to not advertise the routes not needed on each
> respective router...
>
> there are more devices than just routers A B C, wish I was good at asci
> art I could create a small diagram.


Hi Mark,

I figured something like this was the case. Here's the key thing to
understand about OSPF: it's strictly an interior gateway protocol. It does
not have the functionality you need to cross administrative or security
domain boundaries. To cross domain boundaries you should use an exterior
gateway protocol, such as BGP.

So, don't extend OSPF to the routers which have the customer-only routes.
Use BGP there with the 65000-series private AS numbers. Control your
filtering at the OSPF/BGP border and pick borders such that the filtering
you need can happen.

Regards,
Bill Herrin


-- 
William Herrin ................ herrin-n7Wb/xkVUn1Wk0Htik3J/[email protected]  [email protected]
Dirtside Systems ......... Web: <http://www.dirtside.com/>

_______________________________________________
Quagga-users mailing list
Quagga-users-UOy77sIEA+cAd7ICUelF/[email protected]
https://lists.quagga.net/mailman/listinfo/quagga-users