R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
907
3. Configure Firewall D to reject the routes from AS 200.
# Configure AS-PATH list 1.
[FirewallD] ip as-path 1 permit .*200.*
# Create routing policy rt1 with node 1, and specify the match mode as deny to deny routes from
AS 200.
[FirewallD] route-policy rt1 deny node 1
[FirewallD-route-policy] if-match as-path 1
[FirewallD-route-policy] quit
# Create routing policy rt1 with node 10, and specify the match mode as permit to permit routes
from other ASs.
[FirewallD] route-policy rt1 permit node 10
[FirewallD-route-policy] quit
# On Firewall D, specify routing policy rt1 to filter routes received from peer 1.1.3.1.
[FirewallD] bgp 400
[FirewallD-bgp] peer 1.1.3.1 route-policy rt1 import
# Display the BGP routing table information of Firewall D.
[FirewallD-bgp] display bgp routing-table
Total Number of Routes: 3
BGP Local router ID is 4.4.4.4
Status codes: * - valid, > - best, d - damped,
h - history, i - internal, s - suppressed, S - Stale
Origin : i - IGP, e - EGP, ? - incomplete
Network NextHop MED LocPrf PrefVal Path/Ogn
*> 4.4.4.0/24 1.1.3.1 0 300 100i
*> 5.5.5.0/24 1.1.3.1 0 300 100i
*> 6.6.6.0/24 1.1.3.1 0 300 100i
The output shows that Firewall D has learned only routes 4.4.4.0/24, 5.5.5.0/24, and
6.6.6.0/24 from AS 100.
Troubleshooting routing policy configuration
IPv4 routing information filtering failure
Symptom
The routing protocol is running properly, but filtering routing information failed.
Analysis
At least one item of the IP prefix list should be configured as permit mode, and at least one node in the
routing policy should be configured as permit mode.
Solution
1. Use the display ip ip-prefix command to display IP prefix list information.
2. Use the display route-policy command to display routing policy information.