AF替换h3c防火墙,关于BGP的配置,主要是控制路由的发布和接收部分。看下AF的配置对不对。 AF关于BGP的文档太少了,有些名词不是很了解,比如路由映射是啥意思?
AF的配置:
h3c防火墙BGP部分的配置:
bgp 20801 peer 10.211.128.133 as-number 64945 peer 10.211.130.133 as-number 64820 # address-family ipv4 unicast import-route direct import-route static peer 10.211.128.133 enable peer 10.211.128.133 route-policy TO_yewu import peer 10.211.128.133 route-policy deny_yidong_TO_dianxing export peer 10.211.130.133 enable peer 10.211.130.133 route-policy TO_shiping import peer 10.211.130.133 route-policy deny_dianxing_TO_yidong export # route-policy TO_yewu permit node 10 apply preferred-value 100 # route-policy deny_dianxing_TO_yidong deny node 10 if-match as-path 255 # route-policy deny_dianxing_TO_yidong permit node 20 # route-policy deny_yidong_TO_dianxing deny node 10 if-match as-path 256 # route-policy deny_yidong_TO_dianxing permit node 20 # ip as-path 255 permit ^64945 ip as-path 256 permit ^64820 |