Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Filter some routes

    Scheduled Pinned Locked Moved FRR
    28 Posts 4 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pete35 @fmroeira86
      last edited by

      @fmroeira86
      You may try to include all routes (connected and from other sources so called kernel routes) into created access lists. You can permit or deny networks there. Be carefull with the sequence numbering, you should only use "zebra" list for the first approach and check the corresponding frr.conf under Status, Configuration. Clear all other entries of your try and error sessions, best is to start over with an fresh config. I takes some time to distinguish between the terms.

      09133a33-ea7b-4bde-a2d3-d37f239d416c-image.png

      <a href="https://carsonlam.ca">bintang88</a>
      <a href="https://carsonlam.ca">slot88</a>

      F 1 Reply Last reply Reply Quote 0
      • F
        fmroeira86 @pete35
        last edited by

        @pete35 Thank you.

        Where should I apply those ACL?

        P 1 Reply Last reply Reply Quote 0
        • P
          pete35 @fmroeira86
          last edited by pete35

          @fmroeira86
          Just enable it:
          2541d670-f643-4f49-a88a-5f64c805b02f-image.png

          <a href="https://carsonlam.ca">bintang88</a>
          <a href="https://carsonlam.ca">slot88</a>

          F 1 Reply Last reply Reply Quote 0
          • F
            fmroeira86 @pete35
            last edited by

            @pete35 said in Filter some routes:

            @fmroeira86
            Just enable it:
            2541d670-f643-4f49-a88a-5f64c805b02f-image.png

            I've that enabled.

            My ACL as a route with deny (position 1) and an allow all for all the other networks at position 2.

            But All the routes still get advertised...

            P 1 Reply Last reply Reply Quote 0
            • P
              pete35 @fmroeira86
              last edited by

              @fmroeira86
              does it look like this:

              d0fae28e-8aad-480b-85d5-523ec55097ac-image.png

              <a href="https://carsonlam.ca">bintang88</a>
              <a href="https://carsonlam.ca">slot88</a>

              F 1 Reply Last reply Reply Quote 0
              • F
                fmroeira86 @pete35
                last edited by

                @pete35 said in Filter some routes:

                @fmroeira86
                does it look like this:

                d0fae28e-8aad-480b-85d5-523ec55097ac-image.png

                OH!!!! I thought of that but mine doesn't show any "Distribute List" it says "None". I tried with Zebra ACL, Extended ACL and Standard ACL. Always show "none"

                P 1 Reply Last reply Reply Quote 0
                • P
                  pete35 @fmroeira86
                  last edited by

                  @fmroeira86

                  Yes i see it here too. This looks like a bug in the GUI. You may include it into the raw setting of the config.

                  <a href="https://carsonlam.ca">bintang88</a>
                  <a href="https://carsonlam.ca">slot88</a>

                  F 1 Reply Last reply Reply Quote 0
                  • F
                    fmroeira86 @pete35
                    last edited by

                    @pete35

                    Can you please show me where you include in the RAW config?

                    P 1 Reply Last reply Reply Quote 0
                    • P
                      pete35 @fmroeira86
                      last edited by

                      @fmroeira86

                      5b842349-e421-4a85-b800-5e30ccf6f406-image.png

                      <a href="https://carsonlam.ca">bintang88</a>
                      <a href="https://carsonlam.ca">slot88</a>

                      F 1 Reply Last reply Reply Quote 0
                      • F
                        fmroeira86 @pete35
                        last edited by

                        @pete35 I'll try that.

                        In the meantime I'll try to report this bug.

                        I don't really know where I should do that...

                        Thank you!

                        P 1 Reply Last reply Reply Quote 0
                        • P
                          pete35 @fmroeira86
                          last edited by pete35

                          @jimp

                          The GUI does not find the configured ACL Lists any more within Pfsense 2.5 and the Route Distribution section of the configuration.. There is only "None", no lists to choose.
                          Is this a bug?

                          <a href="https://carsonlam.ca">bintang88</a>
                          <a href="https://carsonlam.ca">slot88</a>

                          F 1 Reply Last reply Reply Quote 1
                          • F
                            fmroeira86 @pete35
                            last edited by

                            @jdillard , @Steve_B , @loos , @rbgarga Can anyone advise on this?

                            Is this a bug?

                            Thank you so much!

                            1 Reply Last reply Reply Quote 0
                            • viktor_gV
                              viktor_g Netgate
                              last edited by

                              Please try to re-save your access/prefix lists

                              see https://forum.netgate.com/topic/160694/frr-7-3-7-5-bgp-not-announcing-routes
                              and https://redmine.pfsense.org/issues/11404

                              P 1 Reply Last reply Reply Quote 0
                              • P
                                pete35 @viktor_g
                                last edited by

                                @viktor_g

                                i did this several times, even created a new one, but the lists dont apear on the selection.

                                <a href="https://carsonlam.ca">bintang88</a>
                                <a href="https://carsonlam.ca">slot88</a>

                                1 Reply Last reply Reply Quote 0
                                • F
                                  fmroeira86
                                  last edited by

                                  I confirm that the lists don't apear...

                                  1 Reply Last reply Reply Quote 0
                                  • viktor_gV
                                    viktor_g Netgate
                                    last edited by

                                    Please try this patch: 56.diff

                                    Redmine issue: https://redmine.pfsense.org/issues/11511

                                    F P 2 Replies Last reply Reply Quote 0
                                    • F
                                      fmroeira86 @viktor_g
                                      last edited by

                                      @viktor_g said in Filter some routes:

                                      Please try this patch: 56.diff

                                      Redmine issue: https://redmine.pfsense.org/issues/11511

                                      Can you please instruct on how to apply that?

                                      viktor_gV 1 Reply Last reply Reply Quote 0
                                      • viktor_gV
                                        viktor_g Netgate @fmroeira86
                                        last edited by

                                        @fmroeira86 you need to install System Patches pkg: https://docs.netgate.com/pfsense/en/latest/development/system-patches.html
                                        and paste/apply diff

                                        F 1 Reply Last reply Reply Quote 0
                                        • F
                                          fmroeira86 @viktor_g
                                          last edited by

                                          @viktor_g Thank you!

                                          1 Reply Last reply Reply Quote 0
                                          • P
                                            pete35 @viktor_g
                                            last edited by

                                            @viktor_g

                                            I tried to apply the patch, but on my pfsense there is no
                                            /net/pfSense-pkg-frr/files/usr/local/pkg/frr/frr_ospf.xml

                                            the whole /net path is empty. so the patch failed to test and cant apply.

                                            frr_ospf.xml is on /usr/local/pkg/frr/frr_ospf.xml

                                            is there anything which i do wrong?

                                            <a href="https://carsonlam.ca">bintang88</a>
                                            <a href="https://carsonlam.ca">slot88</a>

                                            viktor_gV 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.