![Huawei S6700 Series Configuration Manual Download Page 415](http://html.mh-extra.com/html/huawei/s6700-series/s6700-series_configuration-manual_169517415.webp)
For details on ACL configurations, see the
S6700 Series Ethernet Switches Configuration
Guide - IP Services
.
An ACL can be used as a matching condition of a route-policy or used in the
filter-
policy
{
acl-number
|
acl-name
acl-name
}
import
command or the
peer
{
group-name
|
ipv4-address
}
filter-policy
{
acl-number
|
acl-name
acl-name
}
import
command.
l
Configure an IP prefix list.
An IP prefix list is a type of filter used to filter routes based on destination addresses. An
IP prefix list is identified by its name. An IP prefix list can be used flexibly to implement
accurate filtering. For example, it can be used to filter a route or routes to a network segment.
If a large number of routes that do not have the same prefix need to be filtered, configuring
an IP prefix list to filter the routes is very complex.
An IP prefix list can be used as a matching condition of a route-policy or used in the
filter-
policy
ip-prefix ip-prefix-name
import
command or the
peer
{
group-name
|
ipv4-
address
}
ip-prefix
ip-prefix-name
import
command.
Perform the following steps on a BGP switch:
1.
Run:
system-view
The system view is displayed.
2.
Run:
ip ip-prefix
ip-prefix-name
[
index
index-number
] {
permit
|
deny
}
ip-
address
mask-length
[
greater-equal
greater-equal-value
] [
less-equal
less-equal-value
]
An IPv4 prefix list is configured.
The mask length range can be specified as
mask-length
<=
greater-equal-value
<=
less-equal-value
<= 32. If only
greater-equal
is specified, the prefix range is [
greater-
equal-value
, 32]. If only
less-equal
is specified, the prefix range is [
mask-length
,
less-
equal-value
].
An IPv4 prefix list is identified by its name, and each IP prefix list can contain multiple
entries. Each entry is identified by an index number, and can specify a matching range
in the form of a network prefix uniquely. An IPv4 prefix list named
abcd
is used as
an example.
#
ip ip-prefix abcd index 10 permit 1.0.0.0 8
ip ip-prefix abcd index 20 permit 2.0.0.0 8
During route matching, the system checks the entries by index number in ascending
order. If a route matches an entry, the route will not be matched with the next entry.
The S6700 denies all unmatched routes by default. If all entries in an IPv4 prefix list
are in deny mode, all routes will be denied by the IPv4 prefix list. In this case, you
must define an entry
permit 0.0.0.0 0 less-equal 32
after the entries in deny mode to
allow all the other IPv4 routes to by permitted by the IPv4 prefix list.
NOTE
If more than one IP prefix entry is defined, at least one entry should be set in permit mode.
l
Configure an AS_Path filter.
An AS_Path filter is used to filter BGP routes based on the AS_Path attributes contained
in the BGP routes. If you do not want traffic to pass through an AS, configure an AS_Path
S6700 Series Ethernet Switches
Configuration Guide - IP Routing
7 BGP Configuration
Issue 01 (2012-03-15)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
396