Created on 10-06-2020 09:59 AM Edited on 06-13-2022 10:11 PM By Anonymous
Description
This article provides a prefix-list policy configuration example to control a FortiGate from advertising routes to the BGP peers.
Control the BGP routes using access-list, prefix-list, route-maps (or) combination of (access-list/prefix-list with route-maps).
Solution
For this example, we will use the following topology:
# show router prefix-listNow, refer the prefix-list directly in the BGP configuration.
config router prefix-list
edit "blockrule"
config rule
edit 1
set action deny
set prefix 10.10.1.0 255.255.255.0
unset ge
unset le
next
edit 2
set prefix any
unset ge
unset le
next
end
next
end
# show router bgpNote.
# config router bgp
set as 100
set network-import-check disable
config neighbor
edit "10.5.20.160"
set prefix-list-out "blockrule" >>>>>
set remote-as 101
next
end
# get router info bgp neighbors 10.5.20.160 advAfter configuring prefix-list.
VRF 0 BGP table version is 3, local router ID is 172.31.135.228
Status codes: s suppressed, d damped, h history, * valid, > best, i - internal
Origin codes: i - IGP, e - EGP, ? - incomplete
Network Next Hop Metric LocPrf Weight RouteTag Path
*> 10.10.1.0/24 10.5.23.228 100 32768 0 i <-/->
*> 192.168.1.0 10.5.23.228 100 32768 0 i <-/->
*> 192.168.2.0 10.5.23.228 100 32768 0 i <-/->
Total number of prefixes 3
# get router info bgp neighbors 10.5.20.160 adv
VRF 0 BGP table version is 2, local router ID is 172.31.135.228
Status codes: s suppressed, d damped, h history, * valid, > best, i - internal
Origin codes: i - IGP, e - EGP, ? - incomplete
Network Next Hop Metric LocPrf Weight RouteTag Path
*> 192.168.1.0 10.5.23.228 100 32768 0 i <-/->
*> 192.168.2.0 10.5.23.228 100 32768 0 i <-/->
Total number of prefixes 2
Related Articles
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.