Hello, I am working on a network design and have a palo alto firewall that has two areas, 0 inside and 1 outside on the same virtual router. Area 1 has the outside interface of firewall, two routers and then the edge router. OSPF runs on the inside of the internet edge router and BGP with the internet provider. We receive a default route from the carrier and distribute it into OSPF. Area 0 has the inside interface of the firewall, some core switches and an MPLS router running OSPF in area 0 and BGP with MPLS provider. They are redistributing BGP from MPLS back into OSPF area 0. I have everything working properly in the lab except for the OSPF Type-5 LSA's being passed into area 1. Meaning routes from the internal network are being passed into the outside of my firewall. I am able to suppress the inter-area routes or type-3 LSA's from one area to the next but don't know how to suppress or filter out the type-5 LSA's. Can't use a stub or nssa area either because I have to allow external routes into each area, just not pass them through to the opposite area. Has anyone else run in to this problem or know of a solution? I thought about using two virtual routers but don't know how to share OSPF routes between the two virtual routers or how the virtual routers would work together either. Any ideas or help would be appreciated. Thank you!
... View more