Compare commits
2 commits
9a56e48141
...
7b5980f871
Author | SHA1 | Date | |
---|---|---|---|
Timotej Lazar | 7b5980f871 | ||
Timotej Lazar | fe8f9161d9 |
|
@ -188,7 +188,6 @@ router bgp {{ asn.asn }} vrf inside
|
||||||
|
|
||||||
|
|
||||||
{% for vrf in vrfs.values() | selectattr('name', 'in', inside_vrfs) %}
|
{% for vrf in vrfs.values() | selectattr('name', 'in', inside_vrfs) %}
|
||||||
# VRF for L2 network {{ vrf.name }}. Imports gateway from inside VRF.
|
|
||||||
router bgp {{ asn.asn }} vrf {{ vrf.name }}
|
router bgp {{ asn.asn }} vrf {{ vrf.name }}
|
||||||
bgp bestpath as-path multipath-relax
|
bgp bestpath as-path multipath-relax
|
||||||
|
|
||||||
|
@ -359,6 +358,8 @@ route-map firewall->outside permit 1
|
||||||
match ip address prefix-list fabric
|
match ip address prefix-list fabric
|
||||||
route-map firewall->outside permit 2
|
route-map firewall->outside permit 2
|
||||||
match ipv6 address prefix-list fabric
|
match ipv6 address prefix-list fabric
|
||||||
|
route-map firewall->outside permit 20
|
||||||
|
match ip address prefix-list office
|
||||||
route-map firewall->outside permit 21
|
route-map firewall->outside permit 21
|
||||||
match ipv6 address prefix-list office
|
match ipv6 address prefix-list office
|
||||||
route-map firewall->outside permit 30
|
route-map firewall->outside permit 30
|
||||||
|
|
|
@ -136,10 +136,11 @@ route-map outside->default permit 10
|
||||||
route-map outside->default permit 11
|
route-map outside->default permit 11
|
||||||
match ipv6 address prefix-list default
|
match ipv6 address prefix-list default
|
||||||
|
|
||||||
# Send IPv6 office addresses and IPv4 NAT addresses to outside peers
|
# Send inside and NAT addresses to outside peers so inbound packets go through the firewall.
|
||||||
# so inbound packets go through the firewall.
|
|
||||||
route-map default->outside permit 1
|
route-map default->outside permit 1
|
||||||
match interface lo
|
match interface lo
|
||||||
|
route-map default->outside permit 10
|
||||||
|
match ip address prefix-list office
|
||||||
route-map default->outside permit 11
|
route-map default->outside permit 11
|
||||||
match ipv6 address prefix-list office
|
match ipv6 address prefix-list office
|
||||||
route-map default->outside permit 20
|
route-map default->outside permit 20
|
||||||
|
|
Loading…
Reference in a new issue