BGP: Configuring Distribute Filters

BGP: Configuring Distribute Filters

Distribute filters use ACLs (Access Control Lists) to filter particular routes on the basis of their prefixes. Distribute filters and prefix filters both filter individual routes out of BGP update packets. They are mutually exclusive.

About ACLs

From the point of view of route filtering, an ACL is one or more simple unnumbered filter entries, each with a prefix and an action of deny or permit.

You can use any of the following syntax options to create the ACL entries. The main difference is in how you label the ACL—whether you use a name or a number.

access-list standard <name> {denypermit} <ipadd/prefixlength> exact-match

access-list <1-99>{denypermit} <ipadd> <reverse-mask> access-list <1300-1999>{denypermit} <ipadd> <reverse-mask>

Entries are unnumbered, so each new entry gets added to the end of the ACL.

Named ACLs Using a standard named ACL lets you specify whether the prefix needs to be an exact match or not. If you specify exact-match, then routes only match the ACL if they have the specified prefix length. Otherwise, routes match the ACL if they have a prefix length equal to or longer than the specified prefix length. For example, if you specify 10.0.0.0/8, then:

without exact-match, the ACL matches all of 10.0.0.0/8–10.0.0.0/32

with exact-match, the ACL only matches 10.0.0.0/8

Numbered For numbered ACLs, the mask is a reverse (or wildcard) mask. This is the opposite of a ACLs standard mask in dotted decimal notation. However—in line with industry standards—the

mask value has no effect. The ACL always applies to all prefix lengths.

Extended ACLs You can also use an extended ACL (number range 100-199, or 2000-2699, or by using the extended <name> parameter) but there is no advantage to doing so. Extended ACLs include two prefixes (source and destination), and using two prefixes is meaningless when filtering routes.

Use Route Maps and Other Filters to Filter and Alter BGP and OSPF Routes Page 11

Page 11
Image 11
Allied Telesis X8100, x908 manual BGP Configuring Distribute Filters, About ACLs

X8100, x908 specifications

The Allied Telesis x908 and the SwitchBlade x900 series of network switches are cutting-edge solutions designed to address the demands of modern networking environments. These switches are known for their high performance, reliability, and robust feature sets, making them ideal for enterprise and service provider networks.

The Allied Telesis x908 series consists of modular and chassis-based systems that can accommodate a variety of network configurations. One of the main features of the x908 series is its ability to offer high scalability with support for a large number of ports. This makes it suitable for data centers and large enterprise networks where space and bandwidth optimization are critical.

In addition to scalability, the x908 series supports advanced Layer 2 and Layer 3 switching capabilities. This allows for efficient traffic management and routing, ensuring that data is delivered swiftly and reliably. The x908 also incorporates intelligent features such as Quality of Service (QoS), which prioritizes critical network traffic, ensuring that time-sensitive data—like voice and video—maintains its quality during transmission.

The SwitchBlade x900 series takes this functionality further with its innovative modular architecture. This allows organizations to configure their networks to meet specific needs by choosing from a variety of interface cards and service modules. The SwitchBlade x900 also supports advanced security features such as Access Control Lists (ACLs) and VLAN segmentation, which provide enhanced protection against unauthorized access and network threats.

Another hallmark of the x908 and SwitchBlade series is their support for high-speed Ethernet technologies, including 10G and 40G Ethernet. This enables organizations to keep pace with the increasing bandwidth demands of applications and services, particularly in cloud computing and data-intensive workloads.

Both the x908 and the SwitchBlade x900 series are designed with energy efficiency in mind, featuring power-saving technologies that reduce overall operational costs. Coupled with Allied Telesis' management tools, which provide detailed analytics and monitoring, network administrators can optimize performance and energy consumption simultaneously.

In summary, the Allied Telesis x908 and SwitchBlade x900 series offer a comprehensive suite of features, high performance, scalability, and advanced networking technologies. They represent a strategic investment for organizations looking to build resilient, efficient, and future-proof network infrastructures.