IP Prefix Lists
IP prefix lists provide mechanisms to match two components of an IP route:
- The route prefix (the subnet number)
- The prefix length (the subnet mask)

The redistribute command cannot directly reference a prefix list, but a route map can refer to a prefix list by using the match command.
A prefix list itself has similar characteristics to a route map. The list consists of one or more statements with the same text name. Each statement has a sequence number to allow deletion of individual commands, and insertion of commands into a particular sequence position. Each command has a permit or deny action—but because it is used only for matching packets, the permit or deny keyword just implies whether a route is matched (permit) or not (deny). The generic command syntax is as follows:
ip prefix-list list-name [seq seq-value] {deny network/length | permit network/ length}[ge ge-value] [le le-value]
The sometimes tricky and interesting part of working with prefix lists is that the meaning of the network/length, ge-value, and le-value parameters changes depending on the syntax. The network! length parameters define the values to use to match the route prefix. For example, a network!length of 10.0.0.0/8 means "any route that begins with a 10 in the first octet." The ge and le options are used for comparison to the prefix length—in other words, to the number of binary 1s in the subnet mask. For instance, ge 20 le 22 matches only routes whose masks are /20, /21, or /22. So, prefix list logic can be summarized into a two-step comparison process for each route:
- The route's prefix must be within the range of addresses implied by the prefix-list command's network!length parameters.
- The route's prefix length must match the range ofprefixes implied by the prefix-list command.
The potentially tricky part of the logic relates to knowing the range of prefix lengths checked by this logic. The range is defined by the ge-value and le-value parameters, which stand for greater-than-or-equal-to and less-than-or-equal-to. Table 11-4 formalizes the logic, including the default values for ge-value and le-value. In the table, note that conf-length refers to the prefix length configured in the network/prefix (required) parameter, and route-length refers to the prefix length of a route being examined by the prefix list.
Table 11-4 LE and GE Parameters on IP Prefix List, and the Implied Range of Prefix Lengths
|
Prefix List Parameters |
Range of Prefix Lengths |
|
Neither |
conf-length = route-length |
|
Only le |
conf-length <= route-length <= le-value |
|
Only ge |
ge-value <= route-length <= 32 |
|
Both ge and le |
ge-value <= route-length <= le-value |
Several examples can really help nail down prefix list logic. The following routes will be examined by a variety of prefix lists, with the routes numbered for easier reference:
|
1. |
10.0.0.0/8 |
|
2. |
10.128.0.0/9 |
|
3. |
10.1.1.0/24 |
|
4. |
10.1.2.0/24 |
|
5. |
10.128.10.4/30 |
|
6. |
10.128.10.8/30 |
Next, Table 11-5 shows the results of seven different one-line prefix lists applied to these six example routes. The table lists the matching parameters in the prefix-list commands, omitting the first part of the commands. The table explains which of the six routes would match the listed prefix list, and why.
Table 11-5 Example Prefix Lists Applied to the List of Routes
|
prefix-list Command Parameters |
Routes Matched |
Results |
|
10.0.0.0/8 |
1 |
Without ge or le configured, both the prefix (10.0.0.0) and length (8) must be an exact match. |
|
10.128.0.0/9 |
None |
Without ge or le configured, the prefix (10.128.0.0) and length (9) must be an exact match, so none of the routes match. |
|
10.0.0.0/8 ge 9 |
2-6 |
The 10.0.0.0/8 means "all routes whose first octet is 10," effectively representing an address range. The prefix length must be between 9 and 32, inclusive. |
|
10.0.0.0/8 ge 24 le 24 |
3, 4 |
The 10.0.0.0/8 means "all routes whose first octet is 10," and the prefix range is 24 to 24—meaning only routes with prefix length 24. |
Table 11-5 Example Prefix Lists Applied to the List of Routes (Continued)
|
prefix-list Command Parameters |
Routes Matched |
Results |
|
10.0.0.0/8 le 28 |
1-4 |
The prefix length needs to be between 8 and 28, inclusive. |
|
0.0.0.0/0 |
None |
0.0.0.0/0 means "match all prefixes, with prefix length of exactly 0." So, it would match all routes' prefixes, but none of their prefix lengths. Only a default route would match this prefix list. |
|
0.0.0.0/0 le 32 |
All |
The range implied by 0.0.0.0/0 is all IPv4 addresses. The le 32 then implies any prefix length between 0 and 32, inclusive. This is the syntax for "match all" prefix list logic. |
Continue reading here: The Mechanics of the redistribute Command
Was this article helpful?
Readers' Questions
-
bisirat yemane9 months ago
- Reply
-
benjamin bayer9 months ago
- Reply
-
amaranth10 months ago
- Reply
-
ELLA10 months ago
- Reply
-
WANDA ROLES11 months ago
- Reply
-
aziza11 months ago
- Reply
-
taylor11 months ago
- Reply
-
martina12 months ago
- Reply
-
satu12 months ago
- Reply
-
WILLIAM12 months ago
- Reply
-
valerie1 year ago
- Reply
-
Marie1 year ago
- Reply
-
kacy1 year ago
- Reply
-
Austin Fraser1 year ago
- Reply
-
Stephan1 year ago
- Reply
-
logan ritchie1 year ago
- Reply
-
omar1 year ago
- Reply
-
Kifle1 year ago
- Reply
-
Angelika1 year ago
- Reply
-
Kirsti1 year ago
- Reply
-
Kimberley1 year ago
- Reply
-
Martina1 year ago
- Reply
-
sayid zula1 year ago
- Reply