Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

PAN-OS 10.2 : filter incoming OSPF routes

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PAN-OS 10.2 : filter incoming OSPF routes

L1 Bithead

Hi,

 

We are trying to setup OSPFv2 between a PA-5220 in 10.2 and a Cisco ACI Fabric with "Advanced Routing" enabled.

For now, we are able to advertise routes to our ACI Fabric, we can filter outgoing advertisement but we are unable to filter incoming routes. We tried with RIB Filter - OSPFv2 without success (https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/network/network-routing-logi...) :

 

EmilienRichard_1-1652344524666.png

 

EmilienRichard_3-1652344694867.png

 

EmilienRichard_4-1652344728564.png

 

Have-you an idea of what we are missing ?

 

Thanks,


Emilien

4 REPLIES 4

L0 Member

Hi,

If it is not the way to do that, how can we filter incoming prefix with OSPF ?

Regards,

Vincent

L1 Bithead

Hi,

Please remember with OSPF in general there is no way to filter prefixes within the area, as all routers in the area should agree on the LSA database. Removing routes from the RIB, yet still having corresponding LSAs is a very bad practice. If you are looking for prefix filtering, follow OSPF design requirements for that (such as stub areas).

Cyber Elite
Cyber Elite

Hello @EmilienRichard

 

with OSPF, the filtering of prefixes is typically done on device that is either ABR or ASBR. I have to admit that I have no hands on experience with Advanced Routing Engine, however by looking into documentation: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/advanced-routing/create-filter... under section: Prefix Lists, there is below point:

PavelK_0-1652537419039.png

From the screen shots you provided, it is not clear whether ACI is in a different OSPF area or the same area. If both devices are in the same area, then this would be my first guess that this is a reason why inbound filter does not work as Palo Alto firewall is not ABR.

 

If I would be in your place and OSPF area re-design would be an option on the table, I would place ACI into non backbone area and used the same filter you already created.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

L1 Bithead

Hello,


We tried to filter incoming OSPF routes without success so we switched to a BGP peering with our ACI Fabric and we configured inbound prefix filtering :

 

EmilienRichard_0-1654072806639.png

with a prefix list :

EmilienRichard_1-1654072884491.png

 

Thanks for your help.

 

  • 3909 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!