Wanguard 6.2 User Guide
Appendix 4 – Network Integration Guideline for Wanguard Filter
r7200(config)#ip extcommunity-list standard VRF-Inside permit rt 65000:200
r7200(config)#route-map VRF-Inside-Import deny 10
r7200(config-route-map)#match community Wanguard-Filter
→
The
Wanguard-Filter
community
has
been already configured above; this will deny redirect-routes
r7200(config-route-map)#exit
r7200(config)#route-map VRF-Inside-Import permit 20
→
This will allow any other routes
r7200(config-route-map)#exit
r7200(config)#
r7200(config)#ip vrf
Outside
r7200(config-vrf)#rd 65000:100
r7200(config-vrf)#route-target import 65000:100
r7200(config-vrf)#route-target import 65000:200
r7200(config-vrf)#route-target export 65000:100
r7200(config-vrf)#exit
r7200(config)#
r7200(config)#ip vrf
Inside
r7200(config-vrf)#rd 65000:200
r7200(config-vrf)#route-target import 65000:100
r7200(config-vrf)#route-target import 65000:200
r7200(config-vrf)#import map VRF-Inside-Import
r7200(config-vrf)#route-target export 65000:200
r7200(config-vrf)#exit
r7200(config)#
r7200(config)# interface Loopback0
→ This is needed to have a BGP router-id (any existing
Loopback from global can be reused)
r7200(config-if)# ip address
<Z.Z.Z.Z/32>
r7200(config-if)#no shut
r7200(config-if)#exit
r7200(config)#
r7200(config)# interface
<to Upstream Provider>
r7200(config-if)#ip vrf forwarding
Outside
→ Warning!
This will remove IP address from
interface/IP-address has to be reconfigured again
r7200(config-if)#exit
r7200(config)#
r7200(config)# interface
<to Filter off-ramp interface>
r7200(config-if)#ip vrf forwarding
Outside
→ Warning!
This will remove IP address from
interface/IP-address has to be reconfigured again
r7200(config-if)#exit
r7200(config)#
r7200(config)# interface
<to Filter on-ramp interface>
r7200(config-if)#ip vrf forwarding
Inside
→ Warning!
This will remove IP address from
interface/IP-address has to be reconfigured again
r7200(config-if)#exit
r7200(config)#
r7200(config)# interface
<to Inject-to/Next-hop>
r7200(config-if)#ip vrf forwarding
Inside
→ Warning!
This will remove IP address from
interface/IP-address has to be reconfigured again
r7200(config-if)#exit
r7200(config)#
r7200(config)#router bgp 65000
→ Y
ou may use your ASN instead of 65000
r7200(config-router)# no synchronization
r7200(config-router)#bgp log-neighbor-changes
r7200(config-router)#no auto-summary
r7200(config-router)#address-family vpnv4
r7200(config-router-af)# no synchronization
r7200(config-router-af)#exit-address-family
r7200(config-router)# address-family ipv4 vrf
Inside
r7200(config-router-af)# no synchronization
r7200(config-router-af)# redistribute connected
r7200(config-router-af)# redistribute
<other IGP/static if needed>
r7200(config-router-af)#exit-address-family
- 125 -
Summary of Contents for wanguard 6.2
Page 1: ......