Compare commits
	
		
			2 commits
		
	
	
		
			9a56e48141
			...
			7b5980f871
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| 7b5980f871 | |||
| fe8f9161d9 | 
					 2 changed files with 5 additions and 3 deletions
				
			
		| 
						 | 
					@ -188,7 +188,6 @@ router bgp {{ asn.asn }} vrf inside
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					
 | 
				
			||||||
{% for vrf in vrfs.values() | selectattr('name', 'in', inside_vrfs) %}
 | 
					{% for vrf in vrfs.values() | selectattr('name', 'in', inside_vrfs) %}
 | 
				
			||||||
# VRF for L2 network {{ vrf.name }}. Imports gateway from inside VRF.
 | 
					 | 
				
			||||||
router bgp {{ asn.asn }} vrf {{ vrf.name }}
 | 
					router bgp {{ asn.asn }} vrf {{ vrf.name }}
 | 
				
			||||||
  bgp bestpath as-path multipath-relax
 | 
					  bgp bestpath as-path multipath-relax
 | 
				
			||||||
 | 
					
 | 
				
			||||||
| 
						 | 
					@ -359,6 +358,8 @@ route-map firewall->outside permit 1
 | 
				
			||||||
  match ip address prefix-list fabric
 | 
					  match ip address prefix-list fabric
 | 
				
			||||||
route-map firewall->outside permit 2
 | 
					route-map firewall->outside permit 2
 | 
				
			||||||
  match ipv6 address prefix-list fabric
 | 
					  match ipv6 address prefix-list fabric
 | 
				
			||||||
 | 
					route-map firewall->outside permit 20
 | 
				
			||||||
 | 
					  match ip address prefix-list office
 | 
				
			||||||
route-map firewall->outside permit 21
 | 
					route-map firewall->outside permit 21
 | 
				
			||||||
  match ipv6 address prefix-list office
 | 
					  match ipv6 address prefix-list office
 | 
				
			||||||
route-map firewall->outside permit 30
 | 
					route-map firewall->outside permit 30
 | 
				
			||||||
| 
						 | 
					
 | 
				
			||||||
| 
						 | 
					@ -136,10 +136,11 @@ route-map outside->default permit 10
 | 
				
			||||||
route-map outside->default permit 11
 | 
					route-map outside->default permit 11
 | 
				
			||||||
  match ipv6 address prefix-list default
 | 
					  match ipv6 address prefix-list default
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# Send IPv6 office addresses and IPv4 NAT addresses to outside peers
 | 
					# Send inside and NAT addresses to outside peers so inbound packets go through the firewall.
 | 
				
			||||||
# so inbound packets go through the firewall.
 | 
					 | 
				
			||||||
route-map default->outside permit 1
 | 
					route-map default->outside permit 1
 | 
				
			||||||
  match interface lo
 | 
					  match interface lo
 | 
				
			||||||
 | 
					route-map default->outside permit 10
 | 
				
			||||||
 | 
					  match ip address prefix-list office
 | 
				
			||||||
route-map default->outside permit 11
 | 
					route-map default->outside permit 11
 | 
				
			||||||
  match ipv6 address prefix-list office
 | 
					  match ipv6 address prefix-list office
 | 
				
			||||||
route-map default->outside permit 20
 | 
					route-map default->outside permit 20
 | 
				
			||||||
| 
						 | 
					
 | 
				
			||||||
		Loading…
	
	Add table
		Add a link
		
	
		Reference in a new issue