06-23-2017 06:07 PM - edited 03-05-2019 08:45 AM
Hi all,
I work in the service provider industry and recently took on the responsibilities of the transit and peering.
I am working through extending the use of communities to control traffic within our business over some current as path filtering and prefix lists.
my thoughts are that I will setup customer route maps, and set communities on the ingress from the customer that tag the routes as a CUSTOMER learnt route.
I expect to have potentially around 100 prefixes that customers send us.
I will setup similar communities for learnt routes via IX, and TRANSIT by also setting each with specific communities for this. These communities will then be used to decide which routes need to be sent, eg IX or TRANSIT or both.
Regarding the use of communities in the above and filtering on egress, is there any reason to go ahead and maintain a prefix list on the borders that we use to send out to our transit providers as well? I know its a double check, but problem is that this is more overhead, and I am trying to find the right balance of workload and keeping the configuration in tip top shape such we don't have to carry out time consuming auditing.
Would love some feedback here, of people who work in SP environments and how they maintain their border devices.
06-25-2017 04:02 PM
If they are a major transit provider - I wouldn't bother - you don't really have a choice but to use them.
If they are a smaller provider (or similar in size to yourself) then I probably would. You wouldn't want to have a major chunk of your traffic accidentally transit through a "peer" (or for them to transit through you).
06-29-2017 02:59 AM
Hi Philip,
thank you. I would tag the routes from IX and tag our transit routes as well both with different communities and ensure the IX learned routes do not get sent out the transit and vice versa. This to me is best practises.
im just considering whether we need filter lists on our transit link of only originated and customer prefixes to allow to be sent upstream or just rely on the communities we set for each at their injection point and gave these communities as the route map for sending upstream?
Does this make sense?
06-29-2017 01:09 PM
Oh, I see.
Do you IX(s) or upstream reqyuire you to supply them with a prefix list? If so, then I would also use a prefix list. If not, then I would just use your community lists.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide