6 - 10
ForeRunner ATM Switch Network Configuration Manual
ATM Forum PNNI
6.3.2.3 Propagation of Reachability Information
The leaking of reachability information between two areas is constrained by two things: policy
and scope.
6.3.2.3.1
Policies
ForeThought software lets you configure a policy as a flexible means of enforcing security
across the network topology. When a node discovers an address that is leaked by another
node, it checks the policy to determine if the address is to be advertised within its own area.
There are three types of policies:
•
summary - Addresses matching a
summary
policy cause just the summarized
prefix of the address to be announced to the node’s peer group.
•
suppress - Addresses matching a
suppress
policy are not announced to the
node’s peer group at all.
•
advertise - Addresses matching an
advertise
policy cause the entire address to
be announced to the node’s peer group.
In each node’s policy table, the switch chooses the best address match, meaning the longest
prefix match, to determine which policy applies to an address. Therefore, the
suppress
and
advertise
policies provide limited filtering since addresses matching a broad prefix can be
filtered at the split switch or gateway switch through the
suppress
policy, then a particular
service, device, or switch can be exempted by advertising an address within the suppressed
range. The
summary
policy is best for scalability since one address prefix is shared, rather than
dozens or hundreds of more specific addresses.
For example, suppose you have an area A which contains peer groups A.1 and A.2. Suppose
you create two policies: one says suppress all address that are area A and the other policy says
advertise all address that are peer group A.1. If an address comes in to the area that has the
prefix for A.1, the policy for advertise takes precedence over the policy for suppress (the
advertise policy is a longer prefix match). Therefore, the address will be advertised. However,
if an address comes in to the area that has a prefix for A.2, it will be suppressed (since there is
no advertise or summary match for A.2).
6.3.2.3.2
Scope
Each piece of reachability information has a source area ID and a scope associated with it. The
source area ID of reachability information originated in a given area is 0 within that area,
meaning that is local. The source area ID of reachability information advertised from, for
example, area A1 into area A2 has source area ID A1.
Summary of Contents for forerunner series
Page 6: ......
Page 16: ...TOC 10 ForeRunner ATM Switch Network Configuration Manual Table of Contents ...
Page 20: ...LOF 4 ForeRunner ATM Switch Network Configuration Manual List of Figures ...
Page 22: ...LOT 2 ForeRunner ATM Switch Network Configuration Manual List of Tables ...
Page 30: ...viii ForeRunner ATM Switch Network Configuration Manual Preface ...
Page 144: ...3 58 ForeRunner ATM Switch Network Configuration Manual Configuring an Emulated LAN ...
Page 180: ...6 12 ForeRunner ATM Switch Network Configuration Manual ATM Forum PNNI ...
Page 220: ...9 6 ForeRunner ATM Switch Network Configuration Manual Configuring Timing ...
Page 300: ...D 24 ForeRunner ATM Switch Network Configuration Manual Configuring FramePlus Modules ...
Page 308: ...Acronyms 8 ForeRunner ATM Switch Network Configuration Manual Acronyms ...
Page 346: ...Glossary 38 ForeRunner ATM Switch Network Configuration Manual Glossary ...
Page 352: ...Index 6 ForeRunner ATM Switch Network Configuration Manual Index ...