Using Prefix Lists and Route Maps to Filter RIP Routes

You can configure prefix lists to permit or deny specific routes and then apply them globally or to individual interfaces. When you apply a prefix-list, you must specify whether the list applies to learned routes (in) or advertised routes (out).

Note: A route is defined by the destination’s IP address and network mask.
Note: By default, routes that do not match a prefix list are learned or advertised. To prevent a route from being learned or advertised, you must configure a prefix list to deny the route.

To configure prefix lists you can apply later, enter commands such as the following.

device(config)# ip prefix-list list1  permit 10.53.4.1 255.255.255.0
device(config)# ip prefix-list list4  deny 10.53.7.1 255.255.255.0

In this example, list1 is configured to permit an IP address and mask, and list4 is configured to deny another IP address and mask.

Using Route Maps in RIP

Use route maps to define how you want to permit or deny redistribution through an individual interface. A route map is a named set of match conditions that the device can use to modify route attributes or to control redistribution of certain routes into other protocols.

A route map consists of a sequence of up to 50 instances. The device evaluates a route according to a route map’s instances in ascending numerical order. The route is first compared against instance 1, then against instance 2, and so on. If a match is found, the device stops evaluating the route against the remaining route map instances.

Route maps contain match statements. In RIP, match statements are based on prefix lists and access control lists. A route map can be applied to learned routes (in) our advertised routes (out). Each route is checked against match statements. When a match is found, the route may be permitted, denied, or modified, depending on the contents of the route map.

The following rules apply to route maps:

  • If there is no match statement at all in the route map, the route is considered to be a match.
  • If a match statement contains a permit action, a matching route is permitted, and no additional route map instances are checked for that route.
  • If a match statement contains a deny action, a matching route is denied, and no additional route map instances are checked for that route.
  • If a route does not match any match statements in the route map, the route is denied. This is the default action. To change the default action, configure the last match statement in the last instance of the route map to "permit any any".
  • For route maps that contain address filters, AS-path filters, or community filters, if the action specified by a filter conflicts with the action specified by the route map, the route map’s action takes precedence over the individual filter’s action.
  • For a virtual routing interface, the default redistribution action is permit, even after you configure and apply redistribution filters. If you want to tightly control redistribution, apply a filter to deny all routes as the last filter (the filter with the highest ID), and then apply filters to allow specific routes.

The following example shows the configuration of a route map that permits routes to two networks and denies routes to one network.

In the following example, an access list (ACL) named 21 is created. The first ACL entry denies IP source addresses that match a particular network mask. The second ACL entry permits any other IP addresses. A route map is configured with the name routemap1 to permit routes that are defined in routemap configuration sub-mode, and a sequence number of 21 is assigned. In the routemap, a match statement is defined to match addresses filtered using ACL 21. Any routes that match the IP address and mask of 10.16.0.0 0.0.255.255 will be denied. All other routers are permitted.

device(config-)# ip access-list standard 21
device(config-std-ipacl-21)# deny 160.1.0.0 0.0.255.255
device(config-std-ipacl-21)# permit any
device(config-std-ipacl-21)# exit
device(config)# route-map routemap1 permit 21
device(config-routemap routemap1)# match ip address 21
Note: You can configure a route map to match on all RIP routes as shown in the following match statement. This example allows any RIP route.
device(config-routemap test)# match protocol rip permit any