3-12
# Reference IP prefix list
abc
to filter outbound routes on VLAN-interface 1.
[Sysname-rip-1] filter-policy ip-prefix abc export Vlan-interface 1
# Configure ACL 3000 to permit only route 113.0.0.0/16 to pass, and reference ACL 3000 to
filter outbound routes.
<Sysname> system-view
[Sysname] acl number 3000
[Sysname-acl-adv-3000] rule 10 permit ip source 113.0.0.0 0 destination 255.255.0.0
0
[Sysname-acl-adv-3000] rule 100 deny ip
[Sysname-acl-adv-3000] quit
[Sysname] rip 1
[Sysname-rip 1] filter-policy 3000 export
filter-policy import (RIP view)
Syntax
filter-policy
{
acl-number
|
gateway
ip-prefix-name
|
ip-prefix
ip-prefix-name
[
gateway
ip-prefix-name
] }
import
[
interface-type
interface-number
]
undo filter-policy
import
[
interface-type interface-number
]
View
RIP view
Default Level
2: System level
Parameters
acl-number
: Number of the ACL used for filtering incoming routes, in the range of 2000 to 3999.
ip-prefix ip-prefix-name
: References an IP prefix list to filter incoming routes. The
ip-prefix-name
is a string of 1 to 19 characters.
gateway ip-prefix-name
: References an IP prefix list to filter routes from gateways.
ip-prefix-name
is a string of 1 to 19 characters.
interface-type interface-number
: Specifies an interface by its interface type and interface
number.
Description
Use the
filter-policy
import
command to configure RIP to filter the incoming routes.
Use the
undo filter-policy import
command to restore the default.
By default, RIP does not filter incoming routes.
Note that if you want to reference an advanced ACL (with a number from 3000 to 3999) in the
command, the ACL should be configured with the
rule
[
rule-id
] {
deny
|
permit
}
ip source
sour-addr sour-wildcard
command to deny/permit a route with the specified destination, or with
the
rule
[
rule-id
] {
deny
|
permit
}
ip source
sour-addr sour-wildcard
destination
dest-addr
dest-wildcard
command to deny/permit a route with the specified destination and mask. The
source
keyword specifies the destination address of a route while the
destination
keyword
specifies the subnet mask of the route (the subnet mask must be valid; otherwise, the
configuration is ineffective).