Skip to content

Instantly share code, notes, and snippets.

@mschep
Created October 25, 2019 12:50
Show Gist options
  • Save mschep/d9cf5885dcb5ba8c1e475294d1a994b0 to your computer and use it in GitHub Desktop.
Save mschep/d9cf5885dcb5ba8c1e475294d1a994b0 to your computer and use it in GitHub Desktop.
FRR configuration including RPKI - sh run output
Building configuration...
Current configuration:
!
frr version 6.0.2
frr defaults traditional
hostname vrtr-2.ripeadm.ripe.net
log file /var/log/frr/zebra.log informational
log file /var/log/frr/bgpd.log informational
rpki
rpki polling_period 3600
rpki timeout 600
rpki initial-synchronisation-timeout 30
rpki cache 193.0.31.2 8323 preference 1
exit
log file /var/log/frr/staticd.log informational
hostname vrtr-2.mtg.ripe.net
!
ip route 0.0.0.0/0 reject
ip route 192.168.2.0/24 193.0.31.216
ip route 193.0.24.0/21 reject
ip route 193.0.24.0/22 193.0.31.216
ip route 193.0.28.0/23 193.0.31.216
ip route 193.0.31.0/26 193.0.31.216
ip route 193.0.31.64/26 193.0.31.216
ip route 193.0.31.192/28 193.0.31.216
ip route 193.0.31.236/30 193.0.31.216
ip route 193.0.31.240/28 vmx1
ipv6 route ::/0 reject
ipv6 route 2001:67c:64::/48 reject
ipv6 route 2001:67c:64:42::/64 2001:67c:64:50::8
ipv6 route 2001:67c:64:43::/64 2001:67c:64:50::8
ipv6 route 2001:67c:64:44::/64 2001:67c:64:50::8
ipv6 route 2001:67c:64:47::/64 2001:67c:64:50::8
ipv6 route 2001:67c:64:53::/64 2001:67c:64:50::8
!
router bgp 2121
bgp router-id 193.0.31.215
neighbor eurofiber-v4 peer-group
neighbor eurofiber-v4 remote-as 39686
neighbor eurofiber-v4 capability dynamic
neighbor eurofiber-v6 peer-group
neighbor eurofiber-v6 remote-as 39686
neighbor eurofiber-v6 capability dynamic
neighbor 144.178.80.173 peer-group eurofiber-v4
neighbor 2a02:fe9:a::4f41 peer-group eurofiber-v6
!
address-family ipv4 unicast
network 193.0.24.0/21
neighbor eurofiber-v4 soft-reconfiguration inbound
neighbor eurofiber-v4 prefix-list transit-out-v4 out
neighbor eurofiber-v4 route-map transit-in-v4 in
exit-address-family
!
address-family ipv6 unicast
network 2001:67c:64::/48
neighbor eurofiber-v6 activate
neighbor eurofiber-v6 soft-reconfiguration inbound
neighbor eurofiber-v6 prefix-list transit-out-v6 out
neighbor eurofiber-v6 route-map transit-in-v6 in
exit-address-family
!
ip prefix-list as2121-v4 seq 5 permit 193.0.24.0/21 le 32
ip prefix-list martians-v4 seq 5 permit 10.0.0.0/8 le 32
ip prefix-list martians-v4 seq 10 permit 172.16.0.0/12 le 32
ip prefix-list martians-v4 seq 15 permit 192.168.0.0/16 le 32
ip prefix-list martians-v4 seq 20 permit 0.0.0.0/0
ip prefix-list martians-v4 seq 25 permit 0.0.0.0/8 le 32
ip prefix-list martians-v4 seq 30 permit 100.64.0.0/10 le 32
ip prefix-list martians-v4 seq 35 permit 127.0.0.0/8 le 32
ip prefix-list martians-v4 seq 40 permit 169.254.0.0/16 le 32
ip prefix-list martians-v4 seq 45 permit 192.0.0.0/24 le 32
ip prefix-list martians-v4 seq 50 permit 192.0.2.0/24 le 32
ip prefix-list martians-v4 seq 55 permit 198.18.0.0/15 le 32
ip prefix-list martians-v4 seq 60 permit 198.51.100.0/24 le 32
ip prefix-list martians-v4 seq 65 permit 203.0.113.0/24 le 32
ip prefix-list martians-v4 seq 70 permit 224.0.0.0/3 le 32
ip prefix-list martians-v4 seq 75 permit 0.0.0.0/0 ge 25
ip prefix-list transit-out-v4 seq 5 permit 193.0.24.0/21
ip prefix-list transit-out-v4 seq 10 deny any
!
ipv6 prefix-list as2121-v6 seq 5 permit 2001:67c:64::/48 le 128
ipv6 prefix-list martians-v6 seq 5 permit ::/0
ipv6 prefix-list martians-v6 seq 10 permit 2001::/32 ge 33
ipv6 prefix-list martians-v6 seq 15 permit 2001:10::/28 le 128
ipv6 prefix-list martians-v6 seq 20 permit 2001:db8::/32 le 128
ipv6 prefix-list martians-v6 seq 25 permit 2002::/16 ge 17
ipv6 prefix-list martians-v6 seq 30 permit 2000::/3 ge 49
ipv6 prefix-list transit-out-v6 seq 5 permit 2001:67c:64::/48
ipv6 prefix-list transit-out-v6 seq 10 deny any
!
route-map test-unknown permit 10
match rpki notfound
!
route-map transit-in-v4 deny 10
match ip address prefix-list martians-v4
!
route-map transit-in-v4 deny 20
match ip address prefix-list as2121-v4
!
route-map transit-in-v4 deny 30
match rpki invalid
!
route-map transit-in-v4 permit 40
!
route-map transit-in-v6 deny 10
match ip address prefix-list martians-v6
!
route-map transit-in-v6 deny 20
match ip address prefix-list as2121-v6
!
route-map transit-in-v6 deny 30
match rpki invalid
!
route-map transit-in-v6 permit 40
!
route-map test-rpki-invalid permit 10
match rpki invalid
!
line vty
!
end
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment