Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Filter some routes

    Scheduled Pinned Locked Moved FRR
    28 Posts 4 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      fmroeira86
      last edited by

      Hi!

      So I was using Quagga and now updated to PFSense 2.5 and I migrated to FRR (OSPF).

      I'm ok with the overall configs but I need to exclude some routes to be advertised.

      I tried everything from filters to route maps and nothing seems to work.

      Can some one clarify me on how to exclude a specific route from FRR OSPF. Let's call it 192.168.1.0/24 and allow everything else?

      :) thank you!!

      P 1 Reply Last reply Reply Quote 0
      • P
        pete35 @fmroeira86
        last edited by

        @fmroeira86
        You may try to include all routes (connected and from other sources so called kernel routes) into created access lists. You can permit or deny networks there. Be carefull with the sequence numbering, you should only use "zebra" list for the first approach and check the corresponding frr.conf under Status, Configuration. Clear all other entries of your try and error sessions, best is to start over with an fresh config. I takes some time to distinguish between the terms.

        09133a33-ea7b-4bde-a2d3-d37f239d416c-image.png

        <a href="https://carsonlam.ca">bintang88</a>
        <a href="https://carsonlam.ca">slot88</a>

        F 1 Reply Last reply Reply Quote 0
        • F
          fmroeira86 @pete35
          last edited by

          @pete35 Thank you.

          Where should I apply those ACL?

          P 1 Reply Last reply Reply Quote 0
          • P
            pete35 @fmroeira86
            last edited by pete35

            @fmroeira86
            Just enable it:
            2541d670-f643-4f49-a88a-5f64c805b02f-image.png

            <a href="https://carsonlam.ca">bintang88</a>
            <a href="https://carsonlam.ca">slot88</a>

            F 1 Reply Last reply Reply Quote 0
            • F
              fmroeira86 @pete35
              last edited by

              @pete35 said in Filter some routes:

              @fmroeira86
              Just enable it:
              2541d670-f643-4f49-a88a-5f64c805b02f-image.png

              I've that enabled.

              My ACL as a route with deny (position 1) and an allow all for all the other networks at position 2.

              But All the routes still get advertised...

              P 1 Reply Last reply Reply Quote 0
              • P
                pete35 @fmroeira86
                last edited by

                @fmroeira86
                does it look like this:

                d0fae28e-8aad-480b-85d5-523ec55097ac-image.png

                <a href="https://carsonlam.ca">bintang88</a>
                <a href="https://carsonlam.ca">slot88</a>

                F 1 Reply Last reply Reply Quote 0
                • F
                  fmroeira86 @pete35
                  last edited by

                  @pete35 said in Filter some routes:

                  @fmroeira86
                  does it look like this:

                  d0fae28e-8aad-480b-85d5-523ec55097ac-image.png

                  OH!!!! I thought of that but mine doesn't show any "Distribute List" it says "None". I tried with Zebra ACL, Extended ACL and Standard ACL. Always show "none"

                  P 1 Reply Last reply Reply Quote 0
                  • P
                    pete35 @fmroeira86
                    last edited by

                    @fmroeira86

                    Yes i see it here too. This looks like a bug in the GUI. You may include it into the raw setting of the config.

                    <a href="https://carsonlam.ca">bintang88</a>
                    <a href="https://carsonlam.ca">slot88</a>

                    F 1 Reply Last reply Reply Quote 0
                    • F
                      fmroeira86 @pete35
                      last edited by

                      @pete35

                      Can you please show me where you include in the RAW config?

                      P 1 Reply Last reply Reply Quote 0
                      • P
                        pete35 @fmroeira86
                        last edited by

                        @fmroeira86

                        5b842349-e421-4a85-b800-5e30ccf6f406-image.png

                        <a href="https://carsonlam.ca">bintang88</a>
                        <a href="https://carsonlam.ca">slot88</a>

                        F 1 Reply Last reply Reply Quote 0
                        • F
                          fmroeira86 @pete35
                          last edited by

                          @pete35 I'll try that.

                          In the meantime I'll try to report this bug.

                          I don't really know where I should do that...

                          Thank you!

                          P 1 Reply Last reply Reply Quote 0
                          • P
                            pete35 @fmroeira86
                            last edited by pete35

                            @jimp

                            The GUI does not find the configured ACL Lists any more within Pfsense 2.5 and the Route Distribution section of the configuration.. There is only "None", no lists to choose.
                            Is this a bug?

                            <a href="https://carsonlam.ca">bintang88</a>
                            <a href="https://carsonlam.ca">slot88</a>

                            F 1 Reply Last reply Reply Quote 1
                            • F
                              fmroeira86 @pete35
                              last edited by

                              @jdillard , @Steve_B , @loos , @rbgarga Can anyone advise on this?

                              Is this a bug?

                              Thank you so much!

                              1 Reply Last reply Reply Quote 0
                              • viktor_gV
                                viktor_g Netgate
                                last edited by

                                Please try to re-save your access/prefix lists

                                see https://forum.netgate.com/topic/160694/frr-7-3-7-5-bgp-not-announcing-routes
                                and https://redmine.pfsense.org/issues/11404

                                P 1 Reply Last reply Reply Quote 0
                                • P
                                  pete35 @viktor_g
                                  last edited by

                                  @viktor_g

                                  i did this several times, even created a new one, but the lists dont apear on the selection.

                                  <a href="https://carsonlam.ca">bintang88</a>
                                  <a href="https://carsonlam.ca">slot88</a>

                                  1 Reply Last reply Reply Quote 0
                                  • F
                                    fmroeira86
                                    last edited by

                                    I confirm that the lists don't apear...

                                    1 Reply Last reply Reply Quote 0
                                    • viktor_gV
                                      viktor_g Netgate
                                      last edited by

                                      Please try this patch: 56.diff

                                      Redmine issue: https://redmine.pfsense.org/issues/11511

                                      F P 2 Replies Last reply Reply Quote 0
                                      • F
                                        fmroeira86 @viktor_g
                                        last edited by

                                        @viktor_g said in Filter some routes:

                                        Please try this patch: 56.diff

                                        Redmine issue: https://redmine.pfsense.org/issues/11511

                                        Can you please instruct on how to apply that?

                                        viktor_gV 1 Reply Last reply Reply Quote 0
                                        • viktor_gV
                                          viktor_g Netgate @fmroeira86
                                          last edited by

                                          @fmroeira86 you need to install System Patches pkg: https://docs.netgate.com/pfsense/en/latest/development/system-patches.html
                                          and paste/apply diff

                                          F 1 Reply Last reply Reply Quote 0
                                          • F
                                            fmroeira86 @viktor_g
                                            last edited by

                                            @viktor_g Thank you!

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.