Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Select route with shorther prefix length

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Select route with shorther prefix length

L1 Bithead

I have a static route for 172.16.0.0/12 but my PA is also learning through OSPF a route for 172.16.0.0/24.

 

As these routes have different prefix length both are installed in the routing table and the dynamic route for 172.16.0.0/24 learnt through OSFP takes precedence over static route for 172.16.0.0/12 without having in consideration the administrative distance.

 

I would like to avoid this situation and force my PA to select the static route with a shorter prefix length. Any suggestion?.

 

Thanks in advance!!!

3 REPLIES 3

L7 Applicator

More specific routes will always win over larger prefixes.  This is the nature of the route selection process and is considered before the protocol of the route in question.

 

You will need to install the /24 as a static to override the OSPF learned route.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Steve, thank you for your answer. The problem is that my PA is learning a lot of routes with larger prefixes. So I would have to install a lot of static routes to solve the problem with the workarround that you suggest. Moreover, I would have to keep an eye on for new routes learnt by OSPF and install new static routes.

 

The ideal solution would be to filter the routes learnt by OSPF but, as far as I know, PA doesn't support this feature. I opened another thread about this:

https://live.paloaltonetworks.com/t5/General-Topics/How-to-ignore-routes-learned-by-OSPF/m-p/139314

Right, if you need that level of route filtering you will need to switch to BGP from OSPF.

 

Bear in mind that Palo Alto is a security company that provides networking features on their devices.  The introduction pace of new networking features can be slow.  We just got BFD for example last year.  So don't count on networking feature requests showing up soon.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
  • 3351 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!