#desenvolvido por thalesmoises.com # #log de informacoes inseridas #numero do seu as = [VAR1] #nome do peer = [VAR2] #ip do peer = [VAR3] #asn do peer = [VAR4] #seu ipv4 da sessao = [VAR5] #ipv6 do peer=[VAR6] #seu ipv6 da sessao=[VAR7] #nome do ip-prefix v4 inserido=[VAR8] #nome do ip-prefix v6 inserido=[VAR9] ##################################### #versao da config para vrp8 # !CRIA ROUTE POLICY V4 #deny generico de segurança route-policy TRANSITO-[VAR2]-V4-IN deny node 10 #deny de descarte generico (bogons) route-policy TRANSITO-[VAR2]-V4-IN deny node 200 if-match ip-prefix DESCARTE-GENERICO-V4 # # #deny generico de segurança route-policy TRANSITO-[VAR2]-V4-OUT deny node 10 #permit do ip-prefix selecionado route-policy TRANSITO-[VAR2]-V4-OUT permit node 200 if-match ip-prefix [VAR8] #deny explicito no final route-policy TRANSITO-[VAR2]-V4-OUT deny node 65000 # # !CONFIG PEER V4 bgp [VAR1] peer [VAR3] as-number [VAR4] peer [VAR3] description TRANSITO-[VAR2]-V4 peer [VAR3] timer keepalive 3 hold 30 Y peer [VAR3] connect-interface [VAR5] peer [VAR3] connect-only ipv4-family unicast peer [VAR3] enable peer [VAR3] public-as-only peer [VAR3] route-policy TRANSITO-[VAR2]-V4-IN import peer [VAR3] route-policy TRANSITO-[VAR2]-V4-OUT export peer [VAR3] advertise-community peer [VAR3] advertise-ext-community #################### ################# !CRIA ROUTE POLICY V6 #deny geral de segurança route-policy TRANSITO-[VAR2]-V6-IN deny node 10 #deny bogons v6 route-policy TRANSITO-[VAR2]-V6-IN deny node 200 if-match ipv6 address prefix-list DESCARTE-GENERICO-V6 # #deny geral de segurança route-policy TRANSITO-[VAR2]-V6-OUT deny node 10 # route-policy TRANSITO-[VAR2]-V6-OUT permit node 200 if-match ipv6 address prefix-list [VAR9] #deny explicito ipv6 route-policy TRANSITO-[VAR2]-V6-OUT deny node 65000 # # !CONFIG PEER V6 bgp [VAR1] peer [VAR6] as-number [VAR4] peer [VAR6] description TRANSITO-[VAR2]-V6 peer [VAR6] timer keepalive 3 hold 30 Y peer [VAR6] connect-interface [VAR7] peer [VAR6] connect-only # ipv6-family unicast peer [VAR6] enable Y peer [VAR6] public-as-only peer [VAR6] route-policy TRANSITO-[VAR2]-V6-IN import peer [VAR6] route-policy TRANSITO-[VAR2]-V6-OUT export peer [VAR6] advertise-community peer [VAR6] advertise-ext-community ##################################### #fim da config