02-25-2004 07:44 PM - edited 03-02-2019 01:51 PM
the following is the configration from tcp/ip volume II
router bgp 100
aggregate-address 192.168.192.0 255.255.248.0
redistribute eigrp 100
neighbor 192.168.1.253 remote-as 200
neighbor 192.168.1.253 send-community
neighbor 192.168.1.253 route-map yu out
access-list 101 permit ip host 192.168.192.0 host 255.255.248.0
route-map yu permit 10
match ip address 101
set community none
route-map yu permit 20
set community no-export
Can anyone explain this statment "access-list 101 permit ip host 192.168.192.0 host 255.255.248.0"
thank you!
Solved! Go to Solution.
02-26-2004 04:01 AM
The host keyword in this context indicates that all bit have to match. Bear in mind that this ACL has for purpose to filter routes not traffic. In this context, the first pair of
access-list 101 permit ip host 192.168.192.0 host 255.255.248.0
is equivalent to
access-list 101 permit ip 192.168.192.0 0.0.0.0.0 255.255.248.0 0.0.0.0.0
so the only prefix that will match the ACL is 192.168.192.0/21
192.168.192.0/24 would not match even though the prefix matches since the prefix lenght doesn't.
Hope this helps,
02-25-2004 08:04 PM
The behavior of an ACL entry is a bit different in a route-map context. This ACL entry that you use in your configuration will match if the prefix is exactly 192.168.192.0 and the mask is exactly 255.255.248.0.
Any other combinaison would not match.
Hope this helps,
02-26-2004 03:36 AM
Hi hritter,
meaning to say hosts in the segment 192.168.193.0 will not be matched?
02-26-2004 04:01 AM
The host keyword in this context indicates that all bit have to match. Bear in mind that this ACL has for purpose to filter routes not traffic. In this context, the first pair of
access-list 101 permit ip host 192.168.192.0 host 255.255.248.0
is equivalent to
access-list 101 permit ip 192.168.192.0 0.0.0.0.0 255.255.248.0 0.0.0.0.0
so the only prefix that will match the ACL is 192.168.192.0/21
192.168.192.0/24 would not match even though the prefix matches since the prefix lenght doesn't.
Hope this helps,
02-26-2004 10:00 PM
it is the same as the prefix-list command
ip prefix-list a permit 192.168.192.0/21
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide