<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Filtering or Suppressing OSPF Type-5 LSA's? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/filtering-or-suppressing-ospf-type-5-lsa-s/m-p/28313#M20690</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working on a network design and have a palo alto firewall that has two areas, 0 inside and 1 outside on the same virtual router.&amp;nbsp; Area 1 has the outside interface of firewall, two routers and then the edge router.&amp;nbsp; OSPF runs on the inside of the internet edge router and BGP with the internet provider.&amp;nbsp; We receive a default route from the carrier and distribute it into OSPF.&amp;nbsp; Area 0 has the inside interface of the firewall, some core switches and an MPLS router running OSPF in area 0 and BGP with MPLS provider.&amp;nbsp; They are redistributing BGP from MPLS back into OSPF area 0. I have everything working properly in the lab except for the OSPF Type-5 LSA's being passed into area 1. Meaning routes from the internal network are being passed into the outside of my firewall.&amp;nbsp; I am able to suppress the inter-area routes or type-3 LSA's from one area to the next but don't know how to suppress or filter out the type-5 LSA's. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can't use a stub or nssa area either because I have to allow external routes into each area, just not pass them through to the opposite area.&amp;nbsp; Has anyone else run in to this problem or know of a solution?&amp;nbsp; I thought about using two virtual routers but don't know how to share OSPF routes between the two virtual routers or how the virtual routers would work together either.&amp;nbsp; Any ideas or help would be appreciated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Mar 2015 20:15:15 GMT</pubDate>
    <dc:creator>prestonhartley</dc:creator>
    <dc:date>2015-03-05T20:15:15Z</dc:date>
    <item>
      <title>Filtering or Suppressing OSPF Type-5 LSA's?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/filtering-or-suppressing-ospf-type-5-lsa-s/m-p/28313#M20690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working on a network design and have a palo alto firewall that has two areas, 0 inside and 1 outside on the same virtual router.&amp;nbsp; Area 1 has the outside interface of firewall, two routers and then the edge router.&amp;nbsp; OSPF runs on the inside of the internet edge router and BGP with the internet provider.&amp;nbsp; We receive a default route from the carrier and distribute it into OSPF.&amp;nbsp; Area 0 has the inside interface of the firewall, some core switches and an MPLS router running OSPF in area 0 and BGP with MPLS provider.&amp;nbsp; They are redistributing BGP from MPLS back into OSPF area 0. I have everything working properly in the lab except for the OSPF Type-5 LSA's being passed into area 1. Meaning routes from the internal network are being passed into the outside of my firewall.&amp;nbsp; I am able to suppress the inter-area routes or type-3 LSA's from one area to the next but don't know how to suppress or filter out the type-5 LSA's. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can't use a stub or nssa area either because I have to allow external routes into each area, just not pass them through to the opposite area.&amp;nbsp; Has anyone else run in to this problem or know of a solution?&amp;nbsp; I thought about using two virtual routers but don't know how to share OSPF routes between the two virtual routers or how the virtual routers would work together either.&amp;nbsp; Any ideas or help would be appreciated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Mar 2015 20:15:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/filtering-or-suppressing-ospf-type-5-lsa-s/m-p/28313#M20690</guid>
      <dc:creator>prestonhartley</dc:creator>
      <dc:date>2015-03-05T20:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering or Suppressing OSPF Type-5 LSA's?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/filtering-or-suppressing-ospf-type-5-lsa-s/m-p/28314#M20691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/32704"&gt;prestonhartley&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think you can suppress type 5 LSA on the firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Mar 2015 21:15:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/filtering-or-suppressing-ospf-type-5-lsa-s/m-p/28314#M20691</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2015-03-05T21:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering or Suppressing OSPF Type-5 LSA's?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/filtering-or-suppressing-ospf-type-5-lsa-s/m-p/28315#M20692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried changing the area 0 to something else so those two areas won't talk because there is no backbone area?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hari Yadavalli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Mar 2015 23:18:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/filtering-or-suppressing-ospf-type-5-lsa-s/m-p/28315#M20692</guid>
      <dc:creator>hyadavalli</dc:creator>
      <dc:date>2015-03-05T23:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering or Suppressing OSPF Type-5 LSA's?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/filtering-or-suppressing-ospf-type-5-lsa-s/m-p/28316#M20693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Preston,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In all vendors Type-5 can not be filtered, basically LSAs can not be filtered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now there are two options.&lt;/P&gt;&lt;P&gt;1. Do filtering based on Network address, follow OSPF filtering document mentioned bellow.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5284"&gt;Understanding Route Redistribution and Filtering&lt;/A&gt;&lt;/P&gt;&lt;P&gt;2. As Hyadavalli suggested, create non-backbone area instead of backbone area.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know for additional queries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Mar 2015 00:40:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/filtering-or-suppressing-ospf-type-5-lsa-s/m-p/28316#M20693</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2015-03-06T00:40:10Z</dc:date>
    </item>
  </channel>
</rss>

