Route Control
Route Control
Route Control unauthorized access of certain traffic and sub-optimal traffic path
selection. To ensure data access security and improve link
bandwidth usage, traffic behavior on the network must be
controlled, for example, reachability control and traffic path
adjustment.
[Link]
Objectives Contents
Upon completion of this section, you will be able to: 1. Traffic Behavior Control Requirement
Master the method to control network traffic reachability 2. Control Reachability
Master the method to adjust network traffic paths 3. Adjust Network Traffic Path
Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page22 Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page33
1
Traffic Behavior Control Requirement Contents
1. Control traffic reachability. 1. Traffic Behavior Control Requirement
To enhance network security, some departments
Financial
Marketing
are not allowed to access each other.
department 2. Control Reachability
department OSPF
R&D
Routing Policy
department
Headquarters
Policy-based Routing
Documentation
department
3. Adjust Network Traffic Path
2. Adjust network traffic path.
In network optimization stage, network
traffic paths may need to be adjusted.
Marketing
department
10M 10M
OSPF Headquarters
Financial 5M 10M
department
Idle link
Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page44 Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page55
Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page66 Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page77
2
ACL Application Example (1/3) ACL Application Example (2/3)
[Link]/32 [Link]/32
[Link]/32 [Link]/32
[Link]/24 [Link]/16
[Link]/24 [Link]/24
[Link]/16
[Link]/16 [Link]/16
[Link]/8
[Link]/8
Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page88 Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page99
acl 2001 IP-Prefix List can match both IP address prefix and
rule 0 permit source [Link] 0
mask length.
[Link]/32 [Link]/24 IP-Prefix List cannot filter IP packets, but can filter only routing
information.
[Link]/24 [Link]/25
ip ip-prefix test index 10 permit [Link] 16
[Link]/25 ACL can flexibly match packets against greater-equal 24 less-equal 28
IP address prefixes, but cannot match IP address range: [Link] – 10.0.x.x
[Link]/16 mask length. 24<= Mask length<=28
Example: [Link]/24, [Link]/25, [Link]/26
[Link]/8 Question: How to filter out the
route [Link]/25?
Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page10
10 Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page11
11
3
IP-Prefix List Application Example (2/2) Filter-Policy Tool
Filter-Policy can filter the received or advertised RIP, OSPF, and BGP routes.
ip ip-prefix Pref1 index 10 permit [Link] 24
greater-equal 24 less-equal 24
Filter the routes received by protocols:
[Link]/32 [Link]/24 filter-policy { acl-number | ip-prefix ip-prefix-name } import
[Link]/24
"greater-equal 24 less-equal 24" Filter the routes advertised by protocols:
[Link]/25 indicates that the mask length is 24.
filter-policy { acl-number | ip-prefix ip-prefix-name } export
[Link]/16
Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page12
12 Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page13
13
Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page14
14 Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page15
15
4
Route-Policy Configuration (1/3) Route-Policy Configuration (2/3)
ospf 1 ospf 1 acl 2000
area 0 area 0 rule 5 deny source [Link] [Link]
network [Link] [Link] network [Link] [Link] rule 10 permit source any
network [Link] [Link] network [Link] [Link] ospf 1
network [Link] [Link]
filter-policy 2000 import
[Link] [Link]
R&D R&D
[Link] department
department
Headquarters RTB RTA Headquarters RTB RTA
Documentation
Documentation
RTD department RTD department
Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page16
16 Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page17
17
Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page18
18 Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page19
19
5
Solution 2: Policy-based Routing (1/2) Solution 2: Policy-based Routing (2/2)
[RTC]dis ip routing-table
Based on customized policy: uses the traffic filter. Route Flags: R - relay, D - download to fib
------------------------------------------------------------------------------
acl number 3000 Routing Tables: Public
rule 0 deny ip source [Link] [Link] dest [Link] [Link] Destinations : 16 Routes : 16
rule 5 deny ip source [Link] [Link] dest [Link] [Link]
rule 10 permit ip source any
int g0/0/1
Destination/Mask Proto Pre Cost Flags NextHop Interface
traffic-filter inbound acl 3000
[Link]/24 O_ASE 150 1 D [Link] GigabitEthernet 0/0/0
[Link]/24 O_ASE 150 1 D [Link] GigabitEthernet 0/0/0
Financial [Link]/24 O_ASE 150 1 D [Link] GigabitEthernet 0/0/0
Marketing RTC OSPF department [Link]/24 Direct 0 0 D [Link] GigabitEthernet 0/0/1
department
[Link]/24 OSPF 10 3 D [Link] GigabitEthernet 0/0/0
Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page20
20 Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page21
21
Idle link
RTC
Solution 1: uses route policy to change the protocol attribute to control routing
table entries and adjust traffic path.
Solution 2: uses policy-based routing to control traffic behavior before searching
the routing table.
Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page22
22 Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page23
23
6
Solution 1: Routing Policy Limitation of Solution 1
dis ip routing-table The traffic path from the marketing department to headquarters is RTA-RTB-
Destination/Mask Proto Pre Cost Flags NextHop Interface
[Link]/24 OSPF 10 3 D [Link] GigabitEthernet 0/0/0 RTD, and the traffic path from the financial department to headquarters is RTA-
RTB RTC-RTD.
Marketing
department RTB
10M(cost 1)
20 persons 10M(cost 1) Headquarters Marketing
G0/0/0 department
10M 10M
OSPF 20 persons Headquarters
G0/0/1
Financial 5M(cost 2) 10M(cost 1)
RTD
[Link]
department RTA OSPF
10 persons Financial 5M 10M
department RTA RTD
RTC 10 persons
int g0/0/0
Route RTC
ospf cost 2
Policy-Adjust OSPF Attributes
dis ip routing-table As shown in the figure, solution 1 cannot meet the requirement because packets are
Destination/Mask Proto Pre Cost Flags NextHop Interface
[Link]/24 OSPF 10 4 D [Link] GigabitEthernet 0/0/0 forwarded based on destination address. It cannot meet the requirements of source
OSPF 10 4 D [Link] GigabitEthernet 0/0/1
address-based, destination address-based, or application layer-based forwarding.
Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page24
24 Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page25
25
RTB
3. Adjust Network Traffic Path Marketing
department
20 persons 10M 10M Headquarters
Routing Policy
OSPF
Policy-based Routing Financial 5M 10M
[Link]
department RTA RTD
10 persons
RTC
Policy-based routing is implemented using traffic policy:
Use ACL to match traffic;
Define behavior for traffic, for example, change the next hop.
Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page26
26 Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page27
27
7
Solution 2: Policy-based Routing (2/3) Solution 2: Policy-based Routing (3/3)
[RTA]acl 3001
rule 5 permit ip source [Link] [Link] dest [Link] [Link] PC-Marketing department>tracert PC-Financial department>tracert
[Link] [Link]
traffic classifier huawei-control2
if-match acl 3001
traceroute to [Link], 8 hops max traceroute to [Link], 8 hops max
traffic behavior huawei-control2 (ICMP), press Ctrl+C to stop (ICMP), press Ctrl+C to stop
redirect ip-nexthop [Link] 1 [Link] 47 ms 31 ms 15 ms 1 [Link] 16 ms 31 ms 16 ms
traffic policy huawei-control2 2 [Link] 47 ms 31 ms 32 ms 2 [Link] 62 ms 47 ms 31 ms
classifier huawei-control2 behavior huawei-control2 3 [Link] 93 ms 63 ms 46 ms 3 [Link] 47 ms 47 ms 31 ms
PBR-Traffic-Polic
int g4/0/0 y Tool
4 *[Link] 62 ms 31 ms 4 [Link] 32 ms 46 ms 32 ms
traffic-policy huawei-control2 inbound
Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page28
28 Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page29
29
Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page30
30 Copyright
Copyright©©2017
2017Huawei
HuaweiTechnologies Co.,Co.,
Technologies Ltd. All
[Link] reserved.
All rights reserved. Page
Page31
31
8
Thank You
[Link]