Filtering BGP Routes Based on AS Paths
Problem
You want to filter the BGP routes that you either send or receive based on AS Path information.
Solution
You can use AS Path filters, either inbound or outbound, to filter either the routes you send or the routes you receive, respectively. You must apply these filters to each peer separately:
Router1#configure terminalEnter configuration commands, one per line. End with CNTL/Z. Router1(config)#ip as-path access-list15permitRouter1(config)#^65501$ip as-path access-list25permitRouter1(config)#_65530_ip as-path access-list25denyRouter1(config)#_65531$ip as-path access-list25permitRouter1(config)#.*router bgpRouter1(config-router)#65500neighbor192.168.1.5remote-asRouter1(config-router)#65510neighbor192.168.1.5filter-list15inRouter1(config-router)#neighbor192.168.2.5remote-asRouter1(config-router)#65520neighbor192.168.2.5filter-list25outRouter1(config-router)#exitRouter1(config)#endRouter1#
Discussion
One of the most common reasons for filtering routes based on the AS Path is to prevent AS transit, as we showed in Recipes 9.4 and 9.5. However, there are some other useful applications for AS Path filters. The example shown above contains two distinct filters, one of which applies to routes received inbound from one neighbor, and the other works on outbound routes sent to a second neighbor.
AS Path filters are constructed by using a subset of UNIX regular expressions. Regular expressions provide an extremely ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access