cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1028
Views
0
Helpful
6
Replies

Cisco ASA OSPF Administrative Distance 255

fara.rhea
Level 1
Level 1

Hi ..

My ASA run OSPF dynamic routing, I want to "clean up" route table by set AD for OSPF by 255. But in route table there is still route for it although it have AD 255.

Anyone have try this ?

BR

6 Replies 6

cadet alain
VIP Alumni
VIP Alumni

Hi,

maybe shutting/no shutting the interface receiving these OSPF LSAs should  make it work.

Regards.

Alain

Don't forget to rate helpful posts.

Don't forget to rate helpful posts.

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Fara,

Actually turning off the interface will not change anything as this is the expected behavior with the ASA.

Different from a dedicated routing device that will not install nor use a route with a AD of 255.

So you will need to use a different method to filter this routes to get installed or used by the ASA

Remember to rate all of the helpful posts

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Hi Julio,

what's the use of this command then?

Would a distribute-list have the same effect as on a router?

Regards.

Alain

Don't forget to rate helpful posts.

Don't forget to rate helpful posts.

Hello Cadet,

It's going to alter the metric being shown an all of the updates to the other devices but from the ASA itself (locally) the route will still be implemented. So you can send LSU containing different LSAs but each of them will have the distant set to 255 and this as explained before on a router will be handled different,

The distribute-list does have the same behavior,

Regards,

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Hello guys ..

There are no "distribute-list" for OSPF in ASA 8.4 it just have "filter-list" to filter between area which can use to filter when ASA become ABR or ASBR. Because of that i try to use distance 255 .

BR

Hello,

Yeahp... Remember that the ASA has been built in as a security box not as a routing dedicated box...

That being said the OSPF route filtering will need to be done on another box

Regards,

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card