cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1508
Views
0
Helpful
1
Replies

Using prefix-list to deny all traffic from Network blocks

Hello,

I'm a little confused about prefix lists. Everything I have read over the past few weeks regarding using prefix lists to deny traffic at the edge, suggests that I can use them rather than and ACL for simplicities sake.

For instance, if I were trying to deny the block 221.0.0.0/8 any traffic to our network, I would use:

ip prefix-list TEST deny abc.0.0.0/8 le 32

ip prefix-list TEST premit 0.0.0.0/0 le 32.

This didn't work however. I'm sure I'm missing something stupid. Prefix lists such as this don't have to be applied to a specific interface as an access list would does it?

If this posts answers your question or is helpful, please consider rating it and/or marking as answered.
1 Reply 1

Collin Clark
VIP Alumni
VIP Alumni

Its applied to a routing process, typically BGP. Some people route the networks to null0 which can be easier for some to understand and troubleshoot.

HTH and please rate.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: