Cisco IOSvでprefix-listとroute-mapを設定する
CML 2.10 の IOSv 15.9 で、prefix-list と route-map を使い、再配送対象の絞り込み、tag付け、PBRを設定する。
prefix-listを作る
Section titled “prefix-listを作る”静的ルート 172.16.10.0/24 だけを対象にする。
conf tip prefix-list STATIC-TO-OSPF seq 10 permit 172.16.10.0/24ip prefix-list STATIC-TO-OSPF seq 100 deny 0.0.0.0/0 le 32end0.0.0.0/0 le 32 はすべてのIPv4 prefixを表す。最後に暗黙の deny があるため、明示denyは必須ではないが、意図を読みやすくできる。
route-mapで再配送属性を付ける
Section titled “route-mapで再配送属性を付ける”prefix-listに一致した経路へ、OSPF external metric と tag を付ける。
conf troute-map STATIC-TO-OSPF permit 10 match ip address prefix-list STATIC-TO-OSPF set metric 20 set metric-type type-1 set tag 100exitendOSPFへ再配送する。
conf trouter ospf 10 redistribute static subnets route-map STATIC-TO-OSPFexitend再配送では、prefix-listで対象を絞り、route-mapでmetricやtagを付ける。
tagで戻り再配送を止める
Section titled “tagで戻り再配送を止める”OSPFへ入れた経路を別プロトコルへ戻さないため、tagを見てdenyする。
conf troute-map OSPF-TO-EIGRP deny 5 match tag 100exitroute-map OSPF-TO-EIGRP permit 10 match ip address prefix-list OSPF-TO-EIGRP set metric 100000 100 255 1 1500exitenddeny 5 に一致した経路は、この route-map を使う再配送では処理されない。
BGP属性を付ける
Section titled “BGP属性を付ける”BGPへ入れる経路に LOCAL_PREF と community を付ける例。
conf tip prefix-list OSPF-TO-BGP seq 10 permit 10.10.0.0/16 le 24
route-map OSPF-TO-BGP permit 10 match ip address prefix-list OSPF-TO-BGP set local-preference 200 set community 65001:100 additiveexit
router bgp 65001 address-family ipv4 unicast redistribute ospf 10 route-map OSPF-TO-BGP exit-address-familyexitendBGPの経路制御では、route-mapで属性を付けて後段の選択や広告ポリシーにつなげる。
PBRでnext-hopを変える
Section titled “PBRでnext-hopを変える”特定の宛先へのHTTPSだけを別next-hopへ向ける。
conf tip access-list extended PBR-HTTPS permit tcp 192.168.10.0 0.0.0.255 host 203.0.113.10 eq 443exit
route-map PBR-HTTPS permit 10 match ip address PBR-HTTPS set ip next-hop 192.0.2.254exit
interface GigabitEthernet0/0 ip policy route-map PBR-HTTPSexitendPBRは、宛先ベースの通常ルーティングより先に、インターフェースへ入ってきたパケットをroute-mapで評価する。
show ip prefix-listshow route-mapshow running-config | section route-mapshow running-config | include redistributeshow ip protocolsPBRは次も確認する。
show ip policyshow route-map PBR-HTTPSshow running-config interface GigabitEthernet0/0