Configuring Route Maps with the routemap Command
Route maps provide programming logic similar to the If/Then/Else logic seen in other programming languages. A single route map has one or more route-map commands in it, and routers process route-map commands in sequential order based on sequence numbers. Each route-map command has underlying matching parameters, configured with the aptly named match command. (To match all packets, the route-map clause simply omits the match command.) Each route-map command also has one or more optional set commands that you can use to manipulate information— for instance, to set the metric for some redistributed routes. The general rules for route maps are as follows:
■ Each route-map command must have an explicitly configured name, with all commands that use the same name being part of the same route map.
■ Each route-map command has an action (permit or deny).
■ Each route-map command in the same route map has a unique sequence number, allowing deletion and insertion of single route-map commands.
■ When a route map is used for redistribution, the route map processes routes taken from the then-current routing table.
■ The route map is processed sequentially based on the sequence numbers.
■ Once a particular route is matched by the route map, it is not processed beyond that matching route-map command (specific to route redistribution).
■ When a route is matched in a route-map statement, if the route-map command has a permit parameter, the route is redistributed (specific to route redistribution).
■ When a route is matched in a route-map statement, if the route-map statement has a deny parameter, the route is not redistributed (specific to route redistribution).
Route maps can be confusing at times, especially when using the deny option on the route-map command. To help make sure the logic is clear before getting into redistribution, Figure 10-1 shows a logic diagram for an example route map. (This example is contrived to demonstrate some nuances of route map logic; a better, more efficient route map could be created to achieve the same results.) In the figure, R1 has eight loopback interfaces configured to be in class A networks 32 through 39. Figure 10-1 shows how the contrived route-map picky would process the routes.
Figure 10-1 Route Map Logic Example
@ The set of routes to redistribute
S) Routes for which no decision has been made yet
;) The set of routes that are not redistributed
Matched 32
Matched 37
ACL 32:
Permits Network 32 Default Deny Any at End
Denies Network 36 Permits Network 37 Default Deny Any at End
Denies Network 38 /A 32 37
Permits Network 39 ^ 32' 37
Default Deny Any at End
ACL 33:
Permits Network 33 (A 32, 37 Default Deny Any at End
|
32, 33, 34, 35, 36, 37, 38, 39 |
|||||||||||||||||||||||||||||
|
route-map picky permit 10 match ip address 32 |
|||||||||||||||||||||||||||||
|
Not Matched ^ |
|||||||||||||||||||||||||||||
|
33, 34, 35, 36, 37, 38, 39 |
|||||||||||||||||||||||||||||
|
route-map picky permit 25 match ip address d-36-p-37 |
|||||||||||||||||||||||||||||
|
Not Matched |
|||||||||||||||||||||||||||||
|
33, 34, 35, 36, 38, 39 |
|||||||||||||||||||||||||||||
|
route-map picky deny 33 match ip address d-38-p39 |
|||||||||||||||||||||||||||||
|
Not Matched |
|||||||||||||||||||||||||||||
|
33, 34, 35, 36, 38 |
|||||||||||||||||||||||||||||
|
route-map picky deny 40 match ip address 33 |
|||||||||||||||||||||||||||||
|
Not Matched |
|||||||||||||||||||||||||||||
|
34, 35, 36, 38 |
|||||||||||||||||||||||||||||
|
End of List: implied deny all |
|||||||||||||||||||||||||||||
|
Deny C 39 Deny Deny Matched 39 Matched 33 (B Null Permit PermitFirst, a few clarifications about the meaning of Figure 10-1 are in order. The top of the figure begins with the set of connected networks (32 through 39), labeled with a "B," which is the set of routes still being considered for redistribution. Moving down the figure, four separate route-map commands sit inside this single route map. Each route-map clause (the clause includes the underlying match and set commands) in turn moves routes from the list of possible routes ("B") to either the list of routes to redistribute ("A") or the list to not redistribute ("C"). By the bottom of the figure, all routes will be noted as either to be redistributed or not to be redistributed. The route map chooses to redistribute a route only if the route-map command has a permit option; the only time a route-map clause chooses to not redistribute a route is when the clause has a deny option. Ignoring the matching logic for a moment, the first two route-map commands (sequence numbers 10 and 25) use the permit option. As a result of those clauses, routes are either added to the list of routes to redistribute ("A") or left in the list of candidate routes ("B"). The third and fourth clauses (sequence numbers 33 and 40) use the deny option, so those clauses cause routes to be either added to the list of routes to not redistribute ("C"), or left in the list of candidate routes ("B"). In effect, once a route-map clause has matched a route, that route is flagged either as to be redistributed or as not to be redistributed, and the route is no longer processed by the route map. One point that can sometimes be confused is that if a route is denied by an ACL used by a match command, it does not mean that the route is prevented from being redistributed. For instance, the match ip address 32 command in clause 10 refers to ACL 32, which has one explicit access control entry (ACE) that matches network 32, with a permit action. Of course, ACL 32 has an implied deny all at the end, so ACL 32 permits network 32, and denies 33 through 39. However, denying networks 33 through 39 in the ACL does not mean that those routes are not redistributed—it simply means that those routes do not match route-map clause 10, so those routes are eligible for consideration by a later route-map clause. The following list summarizes the key points about route map logic when used for redistribution: _________ ■ route-map commands with the permit option either cause a route to be redistributed or leave Key the route in the list of routes to be examined by the next route-map clause. Topic ■ route-map commands with the deny option either filter the route or leave the route in the list of routes to be examined by the next route-map clause. ■ If a clause's match commands use an ACL, an ACL match with the deny action does not cause the route to be filtered. Instead, it just means that route does not match that particular route-map clause. ■ The route-map command includes an implied deny all clause at the end; to configure a permit all, use the route-map command, with a permit action, but without a match command. Route Map match Commands for Route RedistributionRoute maps use the match command to define the fields and values used for matching the routes being processed. If more than one match command is configured in a single route-map clause, a route is matched only if all the match commands' parameters match the route. The logic in each match command itself is relatively straightforward. Table 10-2 lists the match command options when used for IGP route redistribution.
*Can reference multiple numbered and named ACLs on a single command. *Can reference multiple numbered and named ACLs on a single command. Route Map set Commands for Route RedistributionWhen used for redistribution, route maps have an implied action—either to allow the route to be redistributed or to filter the route so that it is not redistributed. As described earlier in this chapter, that choice is implied by the permit or deny option on the route-map command. Route maps can also change information about the redistributed routes by using the set command. Table 10-3 lists the set command options when used for IGP route redistribution. Responses
Continue reading here: IP Prefix Lists Was this article helpful? |
|||||||||||||||||||||||||||||