Using prefix-list to deny all traffic from Network blocks

Unanswered Question


I'm a little confused about prefix lists. Everything I have read over the past few weeks regarding using prefix lists to deny traffic at the edge, suggests that I can use them rather than and ACL for simplicities sake.

For instance, if I were trying to deny the block any traffic to our network, I would use:

ip prefix-list TEST deny abc.0.0.0/8 le 32

ip prefix-list TEST premit le 32.

This didn't work however. I'm sure I'm missing something stupid. Prefix lists such as this don't have to be applied to a specific interface as an access list would does it?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Collin Clark Thu, 11/01/2007 - 13:39
User Badges:
  • Purple, 4500 points or more

Its applied to a routing process, typically BGP. Some people route the networks to null0 which can be easier for some to understand and troubleshoot.

HTH and please rate.


This Discussion