Include Page | ||||
---|---|---|---|---|
|
Hide_comments |
---|
Scroll Ignore | |
---|---|
|
...
- Filters are viewed in order from less to more general.
- First are considered filters related to specific interface addresses; then, to specific interfaces; then the general ones.
- Individual rules in the tables are ordered according to the same principle: from the smallest networks to the biggest ones, from the more detailed information to the more general.
- By default (when no filters are specified), all routes with their natural metrics are imported and exported.
- If at least one prohibiting filter is enabled, all the rest is assumed as permitted.
- If at least one permitting filter is enabled, all the rest is assumed as prohibited. Therefore, if you have started with a permitting filter, you must continue with permitting filters up to the end. If you have prohibited something, only that particular thing will be prohibited.
- If for a given network a permitting and a prohibiting filter are simultaneously enabled, then the prohibiting filter will take priority.
- To each network / subnet will be applied filters of only one group having the highest priority.
Examples
Enable RIP-1 version and disable RIP-2 for interface import.
| |||||||||||||||||||||
Limit nodes number through which routing information is exchanged. Information will be sent only though interfaces "10.1.2.3", "10.4.5.6" and all from "192.168.1.0/16" range.
| |||||||||||||||||||||
Set the filter for a whole protocol and all interfaces.
Set the filter for the "eth0" network interface.
Set the filter for "10.2.3.4" IP-address.
| |||||||||||||||||||||
Permit export of all routing information, except a private networks "192.168.9.0/24", "192.168.10.0/24" and "192.168.20.0/24", and the default route.
Delete part of the filter created before.
| |||||||||||||||||||||
A route metric values are explicitly specified in exporting/importing filters.
| |||||||||||||||||||||
Original metrics values of all routes will be increased by 2.
| |||||||||||||||||||||
Forbid the import of the "10.0.0.0" network, but the import of the subnetworks is permitted.
|