Palo Alto Networks Knowledgebase: Filter specific route from being advertised to OSPF
Filter specific route from being advertised to OSPF
Created On 02/08/19 00:03 AM - Last Updated 02/08/19 00:03 AM
This article explains how to filter specific static routes from being advertised into OSPF while still advertising all other static routes.
The method highlighted in this article is useful when firewall has a large number of static routes configured and only some of the routes needs to be filtered.
PA-1 (22.214.171.124) ------ (126.96.36.199) PA-2
1- Static routes configured on PA-1:
2- Redistribution profile configured on PA-1:
3- This redistribution profile causes all static routes configured on PA-1 firewall to be redistributed into OSPF:
4- Now, suppose we want that all static routes should be advertised to PA-2 except the static route 188.8.131.52/24. This could be achieved by using Priority value in Redistribution Profile:
Profile "Redist-Static" has a priority of 5 and action set to "Redist". New profile, "Filter-Static" has a priority of 1 and action set to "No Redist".
When both profiles are referred in OSPF Export rules, profiles would be evaluated according to the priority assigned.
Lower value means higher priority. This would cause Filter-Static profile to be evaluated first and preferred over "Redist-Static" profile hence route 184.108.40.206/24 would not be redistributed while other static routes would still be redistributed.
Note: Same configuration can be done for routes learned from other source type also e.g. for filtering specific connected routes to be exported into OSPF etc.