From: Justin Menga (Justin.Menga@xxxxxxxxxxxxxxxxxx)
Date: Fri Feb 02 2001 - 09:14:20 GMT-3
Hi Mike,
Setting the no-export community string is my first reaction, but thinking
about it, this means that the policy is effectively applied at the ingress
of the AS, and not at the egress of the AS.
This has several implications
1. If a new EBGP router is added without the community manipulation, your
AS becomes a transit AS.
2. If a new IBGP router is added without send-community support, any routes
it learns from an EBGP peer will lose the community tag, regardless.
Typically, an AS can be summarised by one or several prefixes:
e.g. your AS may own the 200.10.0.0/16 address space
Thus to apply the policy at the egress all you do is set a
route-map/distribute-list that only permits 200.10.0.0/16 le 32 (all
networks within 200.10.0.0) to be advertised to EBGP neighbors. This means
the policy is applied at the egress of the AS.
So in summary, either solution works, but I think the network prefix
filtering is a better solution.
Regards,
Justin Menga CCIE #6640 MCSE+I CCSE
WAN Specialist
Computerland New Zealand
PO Box 3631, Auckland
DDI: (+64) 9 360 4864 Mobile: (+64) 25 349 599
mailto: justin.menga@computerland.co.nz
-----Original Message-----
From: Mike S. Lee [mailto:mikele@cisco.com]
Sent: Friday, 2 February 2001 11:54 a.m.
To: Earl Aboytes
Cc: 'Mike S. Lee'; ccielab@groupstudy.com
Subject: RE: Non-transient AS's in BGP
Thanks to all that replied. it looks like the no-export option is the way
to go. Thanks for the help.
Mike
At 02:46 PM 2/1/2001 -0800, Earl Aboytes wrote:
>I think that you are looking for the no-export community here. Don't
>forget your neighbor command keyword 'send-community'
>
>Earl Aboytes, CCIE 6097
> -----Original Message-----
>From: Mike S. Lee [<mailto:mikele@cisco.com>mailto:mikele@cisco.com]
>Sent: Thursday, February 01, 2001 1:01 PM
>To: ccielab@groupstudy.com
>Subject: Non-transient AS's in BGP
>
>Can any one please explain how to make an AS non-transient. I can do this
>with an AS-Path ( ^$) but how would this be accomplished without using an
>AS-Path filter. I have exhausted Halabi and just need to be pushed in the
>right direction. Thanks for any help you can provide.
>
>Mike Lee
>CCNP+LATM+Security+Voice Access/CCDP
>NNCSE/NNCDE
>Cisco Systems, Inc.
>12515 Research Blvd., Bldg. 04
>Austin, TX 78759-2200
>
>DSL Customer Support Engineering
>mikele@cisco.com
>(512)378-1331 ofc
>Text Page: mikele@epage.cisco.com
>Mike Lee
>CCNP+LATM+Security+Voice Access/CCDP
>NNCSE/NNCDE
>Cisco Systems, Inc.
>12515 Research Blvd., Bldg. 04
>Austin, TX 78759-2200
>
>DSL Customer Support Engineering
>mikele@cisco.com
>(512)378-1331 ofc
>Text Page: mikele@epage.cisco.com
>
This archive was generated by hypermail 2.1.4 : Thu Jun 13 2002 - 10:28:34 GMT-3