Within a closed network, we have a single hub BGP route reflector server and several remote RR client routers. Each remote RR client router propagates both its physically connected subnet and a static null route that represents a NAT pool configured on the inbound interface to the RR server. All hosts connected to the RR server must communicate with hosts behind the RR clients using the NATd subnet. All hosts behind all RR clients must communicate with one another using their native IPs.
I need to be able to filter the remote physical IP space out of the RR server's routing table, while at the same time filter the NATd subnets out of routing updates propagated to the RR clients and to ensure they receive remote RR client?s native IP space. Is there a way I can do this? When I implement a distribute list in on the RR server, it successfully filters out the remote native IP space, but also filters the native subnets out of the updates sent down to RR clients. In effect, the RR client is only receiving the NATd subnet which I only want the server to have. I understand that I could BGP peer them in a full mesh to accomplish this, but I would like to use RRs to keep things scalable. Thanks in advance for any help provided.
I don't think you can accomplish what you are trying to do with the existing RR configuration. When the route doesn't exist the routing table the RR server wouldn't reflect the route to the RR clients that it learned from another client. Hence, distribute list on the RR server isn't an option. You can use confederations instead of RR to work around this problem or make IBGP fully meshed.
Question We run asr9001 with XR 6.1.3, and we have a very long delay to
login w/ SSH 1 or 2 to the device compare to IOS device. After
investigation, the there is 1s delay between the client KEXDH_INIT and
the server (XR) KEXDH_REPLY. After debug ssh serv...
Introduction The purpose of this document is to demonstrate the Open
Shortest Path First (OSPF) behavior when the V-bit (Virtual-link bit) is
present in a non-backbone area. The V-bit is signaled in Type-1 LSA only
if the router is the endpoint of one or ...
Hi, I am seeing quite a few issues with patch install and wanted to
share my experience and workaround to this. Login to admin via CLI, then
access root with the “shell” command Issue “df –h” and you’ll probably
see the following directory full or nearly ...