- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-05-2015 12:15 PM
Hello,
I am working on a network design and have a palo alto firewall that has two areas, 0 inside and 1 outside on the same virtual router. Area 1 has the outside interface of firewall, two routers and then the edge router. OSPF runs on the inside of the internet edge router and BGP with the internet provider. We receive a default route from the carrier and distribute it into OSPF. Area 0 has the inside interface of the firewall, some core switches and an MPLS router running OSPF in area 0 and BGP with MPLS provider. They are redistributing BGP from MPLS back into OSPF area 0. I have everything working properly in the lab except for the OSPF Type-5 LSA's being passed into area 1. Meaning routes from the internal network are being passed into the outside of my firewall. I am able to suppress the inter-area routes or type-3 LSA's from one area to the next but don't know how to suppress or filter out the type-5 LSA's.
Can't use a stub or nssa area either because I have to allow external routes into each area, just not pass them through to the opposite area. Has anyone else run in to this problem or know of a solution? I thought about using two virtual routers but don't know how to share OSPF routes between the two virtual routers or how the virtual routers would work together either. Any ideas or help would be appreciated.
Thank you!
03-05-2015 01:15 PM
I don't think you can suppress type 5 LSA on the firewall.
03-05-2015 03:18 PM
Hello,
Have you tried changing the area 0 to something else so those two areas won't talk because there is no backbone area?
Regards,
Hari Yadavalli
03-05-2015 04:40 PM
Hi Preston,
In all vendors Type-5 can not be filtered, basically LSAs can not be filtered.
Now there are two options.
1. Do filtering based on Network address, follow OSPF filtering document mentioned bellow.
Understanding Route Redistribution and Filtering
2. As Hyadavalli suggested, create non-backbone area instead of backbone area.
Let me know for additional queries.
Regards,
Hardik Shah
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!