iBGP to OSPF redistribution - weird behavior?

From: Hotmail (jthao1@xxxxxxxxxxx)
Date: Mon Dec 10 2001 - 11:46:25 GMT-3


   
Hello Group,

I have a very simple problem that I'm having a mental block on. I am
performing redistribution of BGP to OSPF but for some reason, iBGP
discovered routes are not getting redistributed into the OSPF domain. I
have turned off synchronization and auto summary on all BGP routers.

Can iBGP discovered routes be redistributed into OSPF? I don't see why not
but I can't do it.

Here's the scenario:

r1 ----- r2 ----- r3 ----- r4

The connections between routers does not matter.

r1 to r2 - running ospf area 0 only on the interface connecting them
r3 to r4 - running ospf area 0 only on the interface connecting them
r2 to r3 - no IGP, no OSPF, just iBGP AS 10
r2 has a loopback that is introduced into BGP on r2 with the network
command.
r3 has a loopback that is introduced into BGP on r3 with the network
command.

Mutual redistribution from BGP to OSPF (and vice-versa) is performed on r3.
r3 loopback appears on r4 but not r2 loopback.

Also, if you perform mutual redistribution on r2, the same converse thing
happens. That is: you can see r2 loopback on r1 but not r3 loopback.

My question is: Is this the proper behavior. I don't see why iBGP
discovered routes can not be redistributed into OSPF. This does not seem
right to me. Am I missing something obvious here?

Thanks
Joseph

----- Original Message -----
From: "Frank Kim" <frank@comegetus.com>
To: "Dean, Justin" <Justin.Dean@nrtinc.com>
Cc: <>
Sent: Monday, December 10, 2001 12:12 AM
Subject: Re: OT: Quick way to check if Pix is being attacked

> Try "show conn count"
>
> That will show how many concurrent connections you have running both
> tcp/udp. If you have a small network and the number of the connections is
> outrageously high, then you're being screwed around by kiddie hacker on
> the internet.
>
>
> -Frank
>
> On Fri, 7 Dec 2001, Dean, Justin wrote:
>
> > Does anyone know how to see if your network is being attacked (or
attemped
> > to be attacked) from the internet, by looking at the PIX? Basically, I
want
> > to find some hard data that would justify looking into an IDS product.
> > Thanks for any input. JD



This archive was generated by hypermail 2.1.4 : Thu Jun 13 2002 - 10:32:40 GMT-3