From 5d6fa52b8985f8068314aba26878a1d7d5cb84e5 Mon Sep 17 00:00:00 2001 From: Yuriy Andamasov Date: Wed, 6 May 2026 20:42:32 +0300 Subject: feat: flip swap mechanism — MD as primary, RST as override (Phase 1) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This is the first of three phases inverting the per-page swap mechanism so MD becomes the canonical primary and RST becomes the rare override. Phase 1 — file renames + conf.py exclude_patterns flip only: - Rename docs/**/md-.md to docs/**/.md (drop md- prefix) for all 254 stems previously listed in docs/_swap.txt - Rename docs/**/.rst to docs/**/rst-.rst (add rst- prefix) for the same 254 stems - Repurpose docs/_swap.txt as docs/_rst_overrides.txt; initially empty comment-only since no pages need the RST fallback right now - conf.py exclude_patterns flipped: rst-*.rst is now excluded by default instead of md-*.md - conf.py runtime-artifact references updated to _rst_override_state.json and _md_exclude.txt (Phase 2 will rewrite swap_sources.py to produce these names; for now no swap script runs because overrides list is empty) Phase 2 (next commit on this branch) will rewrite scripts/swap_sources.py with inverted rename direction, delete scripts/import_myst.py + tests, and update tests/test_swap_sources.py for the new semantics. Phase 3 will be the cleanup pass and ready-for-review flip. Generated by robots https://vyos.io --- docs/configuration/policy/access-list.md | 70 ++++ docs/configuration/policy/access-list.rst | 70 ---- docs/configuration/policy/as-path-list.md | 29 ++ docs/configuration/policy/as-path-list.rst | 33 -- docs/configuration/policy/community-list.md | 29 ++ docs/configuration/policy/community-list.rst | 35 -- docs/configuration/policy/examples.md | 205 ++++++++++ docs/configuration/policy/examples.rst | 213 ---------- docs/configuration/policy/extcommunity-list.md | 33 ++ docs/configuration/policy/extcommunity-list.rst | 40 -- docs/configuration/policy/index.md | 53 +++ docs/configuration/policy/index.rst | 54 --- docs/configuration/policy/large-community-list.md | 29 ++ docs/configuration/policy/large-community-list.rst | 36 -- docs/configuration/policy/local-route.md | 100 +++++ docs/configuration/policy/local-route.rst | 87 ---- docs/configuration/policy/md-access-list.md | 70 ---- docs/configuration/policy/md-as-path-list.md | 29 -- docs/configuration/policy/md-community-list.md | 29 -- docs/configuration/policy/md-examples.md | 205 ---------- docs/configuration/policy/md-extcommunity-list.md | 33 -- docs/configuration/policy/md-index.md | 53 --- .../policy/md-large-community-list.md | 29 -- docs/configuration/policy/md-local-route.md | 100 ----- docs/configuration/policy/md-prefix-list.md | 152 ------- docs/configuration/policy/md-route-map.md | 439 --------------------- docs/configuration/policy/md-route.md | 424 -------------------- docs/configuration/policy/prefix-list.md | 152 +++++++ docs/configuration/policy/prefix-list.rst | 112 ------ docs/configuration/policy/route-map.md | 439 +++++++++++++++++++++ docs/configuration/policy/route-map.rst | 383 ------------------ docs/configuration/policy/route.md | 424 ++++++++++++++++++++ docs/configuration/policy/route.rst | 306 -------------- docs/configuration/policy/rst-access-list.rst | 70 ++++ docs/configuration/policy/rst-as-path-list.rst | 33 ++ docs/configuration/policy/rst-community-list.rst | 35 ++ docs/configuration/policy/rst-examples.rst | 213 ++++++++++ .../configuration/policy/rst-extcommunity-list.rst | 40 ++ docs/configuration/policy/rst-index.rst | 54 +++ .../policy/rst-large-community-list.rst | 36 ++ docs/configuration/policy/rst-local-route.rst | 87 ++++ docs/configuration/policy/rst-prefix-list.rst | 112 ++++++ docs/configuration/policy/rst-route-map.rst | 383 ++++++++++++++++++ docs/configuration/policy/rst-route.rst | 306 ++++++++++++++ 44 files changed, 2932 insertions(+), 2932 deletions(-) create mode 100644 docs/configuration/policy/access-list.md delete mode 100644 docs/configuration/policy/access-list.rst create mode 100644 docs/configuration/policy/as-path-list.md delete mode 100644 docs/configuration/policy/as-path-list.rst create mode 100644 docs/configuration/policy/community-list.md delete mode 100644 docs/configuration/policy/community-list.rst create mode 100644 docs/configuration/policy/examples.md delete mode 100644 docs/configuration/policy/examples.rst create mode 100644 docs/configuration/policy/extcommunity-list.md delete mode 100644 docs/configuration/policy/extcommunity-list.rst create mode 100644 docs/configuration/policy/index.md delete mode 100644 docs/configuration/policy/index.rst create mode 100644 docs/configuration/policy/large-community-list.md delete mode 100644 docs/configuration/policy/large-community-list.rst create mode 100644 docs/configuration/policy/local-route.md delete mode 100644 docs/configuration/policy/local-route.rst delete mode 100644 docs/configuration/policy/md-access-list.md delete mode 100644 docs/configuration/policy/md-as-path-list.md delete mode 100644 docs/configuration/policy/md-community-list.md delete mode 100644 docs/configuration/policy/md-examples.md delete mode 100644 docs/configuration/policy/md-extcommunity-list.md delete mode 100644 docs/configuration/policy/md-index.md delete mode 100644 docs/configuration/policy/md-large-community-list.md delete mode 100644 docs/configuration/policy/md-local-route.md delete mode 100644 docs/configuration/policy/md-prefix-list.md delete mode 100644 docs/configuration/policy/md-route-map.md delete mode 100644 docs/configuration/policy/md-route.md create mode 100644 docs/configuration/policy/prefix-list.md delete mode 100644 docs/configuration/policy/prefix-list.rst create mode 100644 docs/configuration/policy/route-map.md delete mode 100644 docs/configuration/policy/route-map.rst create mode 100644 docs/configuration/policy/route.md delete mode 100644 docs/configuration/policy/route.rst create mode 100644 docs/configuration/policy/rst-access-list.rst create mode 100644 docs/configuration/policy/rst-as-path-list.rst create mode 100644 docs/configuration/policy/rst-community-list.rst create mode 100644 docs/configuration/policy/rst-examples.rst create mode 100644 docs/configuration/policy/rst-extcommunity-list.rst create mode 100644 docs/configuration/policy/rst-index.rst create mode 100644 docs/configuration/policy/rst-large-community-list.rst create mode 100644 docs/configuration/policy/rst-local-route.rst create mode 100644 docs/configuration/policy/rst-prefix-list.rst create mode 100644 docs/configuration/policy/rst-route-map.rst create mode 100644 docs/configuration/policy/rst-route.rst (limited to 'docs/configuration/policy') diff --git a/docs/configuration/policy/access-list.md b/docs/configuration/policy/access-list.md new file mode 100644 index 00000000..c3a92e56 --- /dev/null +++ b/docs/configuration/policy/access-list.md @@ -0,0 +1,70 @@ +# Access List Policy + +Filtering is used for both input and output of the routing information. Once +filtering is defined, it can be applied in any direction. VyOS makes filtering +possible using acls and prefix lists. + +Basic filtering can be done using access-list and access-list6. + +## Configuration + +### Access Lists + +```{cfgcmd} set policy access-list \ + +This command creates the new access list policy, where `` must be +a number from 1 to 2699. +``` + +```{cfgcmd} set policy access-list \ description \ + +Set description for the access list. +``` + +```{cfgcmd} set policy access-list \ rule \<1-65535\> action \ + +This command creates a new rule in the access list and defines an action. +``` + +```{cfgcmd} set policy access-list \ rule \<1-65535\> \ \ + +This command defines matching parameters for access list rule. Matching +criteria could be applied to destination or source parameters: + +* any: any IP address to match. +* host: single host IP address to match. +* inverse-match: network/netmask to match (requires network be defined). +* network: network/netmask to match (requires inverse-match be defined). +``` + + +### IPv6 Access List + +Basic filtering could also be applied to IPv6 traffic. + +```{cfgcmd} set policy access-list6 \ + +This command creates the new IPv6 access list, identified by `` +``` + +```{cfgcmd} set policy access-list6 \ description \ + +Set description for the IPv6 access list. +``` + +```{cfgcmd} set policy access-list6 \ rule \<1-65535\> action \ + +This command creates a new rule in the IPv6 access list and defines an +action. +``` + +```{cfgcmd} set policy access-list6 \ rule \<1-65535\> source \ + +This command defines matching parameters for IPv6 access list rule. Matching +criteria could be applied to source parameters: + +* any: any IPv6 address to match. +* exact-match: exact match of the network prefixes. +* network: network/netmask to match (requires inverse-match be defined) BUG, +NO invert-match option in access-list6 +``` \ No newline at end of file diff --git a/docs/configuration/policy/access-list.rst b/docs/configuration/policy/access-list.rst deleted file mode 100644 index 0af9b911..00000000 --- a/docs/configuration/policy/access-list.rst +++ /dev/null @@ -1,70 +0,0 @@ -################## -Access List Policy -################## - -Filtering is used for both input and output of the routing information. Once -filtering is defined, it can be applied in any direction. VyOS makes filtering -possible using acls and prefix lists. - -Basic filtering can be done using access-list and access-list6. - -************* -Configuration -************* - -Access Lists -============ - -.. cfgcmd:: set policy access-list - - This command creates the new access list policy, where must be - a number from 1 to 2699. - -.. cfgcmd:: set policy access-list description - - Set description for the access list. - -.. cfgcmd:: set policy access-list rule <1-65535> action - - - This command creates a new rule in the access list and defines an action. - -.. cfgcmd:: set policy access-list rule <1-65535> - - - This command defines matching parameters for access list rule. Matching - criteria could be applied to destination or source parameters: - - * any: any IP address to match. - * host: single host IP address to match. - * inverse-match: network/netmask to match (requires network be defined). - * network: network/netmask to match (requires inverse-match be defined). - -IPv6 Access List -================ - -Basic filtering could also be applied to IPv6 traffic. - -.. cfgcmd:: set policy access-list6 - - This command creates the new IPv6 access list, identified by - -.. cfgcmd:: set policy access-list6 description - - Set description for the IPv6 access list. - -.. cfgcmd:: set policy access-list6 rule <1-65535> action - - This command creates a new rule in the IPv6 access list and defines an - action. - -.. cfgcmd:: set policy access-list6 rule <1-65535> source - - - This command defines matching parameters for IPv6 access list rule. Matching - criteria could be applied to source parameters: - - * any: any IPv6 address to match. - * exact-match: exact match of the network prefixes. - * network: network/netmask to match (requires inverse-match be defined) BUG, - NO invert-match option in access-list6 \ No newline at end of file diff --git a/docs/configuration/policy/as-path-list.md b/docs/configuration/policy/as-path-list.md new file mode 100644 index 00000000..1fcece91 --- /dev/null +++ b/docs/configuration/policy/as-path-list.md @@ -0,0 +1,29 @@ +# BGP - AS Path Policy + +VyOS provides policies commands exclusively for BGP traffic filtering and +manipulation: **as-path-list** is one of them. + +## Configuration + +### policy as-path-list + +```{cfgcmd} set policy as-path-list \ + +Create as-path-policy identified by name ``. +``` +```{cfgcmd} set policy as-path-list \ description \ + +Set description for as-path-list policy. +``` +```{cfgcmd} set policy as-path-list \ rule \<1-65535\> action \ + +Set action to take on entries matching this rule. +``` +```{cfgcmd} set policy as-path-list \ rule \<1-65535\> description \ + +Set description for rule. +``` +```{cfgcmd} set policy as-path-list \ rule \<1-65535\> regex \ + +Regular expression to match against an AS path. For example "64501 64502". +``` \ No newline at end of file diff --git a/docs/configuration/policy/as-path-list.rst b/docs/configuration/policy/as-path-list.rst deleted file mode 100644 index ceeb8e01..00000000 --- a/docs/configuration/policy/as-path-list.rst +++ /dev/null @@ -1,33 +0,0 @@ -#################### -BGP - AS Path Policy -#################### - -VyOS provides policies commands exclusively for BGP traffic filtering and -manipulation: **as-path-list** is one of them. - -************* -Configuration -************* - -policy as-path-list -=================== - -.. cfgcmd:: set policy as-path-list - - Create as-path-policy identified by name . - -.. cfgcmd:: set policy as-path-list description - - Set description for as-path-list policy. - -.. cfgcmd:: set policy as-path-list rule <1-65535> action - - Set action to take on entries matching this rule. - -.. cfgcmd:: set policy as-path-list rule <1-65535> description - - Set description for rule. - -.. cfgcmd:: set policy as-path-list rule <1-65535> regex - - Regular expression to match against an AS path. For example "64501 64502". diff --git a/docs/configuration/policy/community-list.md b/docs/configuration/policy/community-list.md new file mode 100644 index 00000000..bdcf4140 --- /dev/null +++ b/docs/configuration/policy/community-list.md @@ -0,0 +1,29 @@ +# BGP - Community List + +VyOS provides policies commands exclusively for BGP traffic filtering and +manipulation: **community-list** is one of them. + +## Configuration + +### policy community-list + +```{cfgcmd} set policy community-list \ + +Creat community-list policy identified by name ``. +``` +```{cfgcmd} set policy community-list \ description \ + +Set description for community-list policy. +``` +```{cfgcmd} set policy community-list \ rule \<1-65535\> action \ + +Set action to take on entries matching this rule. +``` +```{cfgcmd} set policy community-list \ rule \<1-65535\> description \ + +Set description for rule. +``` +```{cfgcmd} set policy community-list \ rule \<1-65535\> regex \ + +Regular expression to match against a community-list. +``` \ No newline at end of file diff --git a/docs/configuration/policy/community-list.rst b/docs/configuration/policy/community-list.rst deleted file mode 100644 index ee2da03c..00000000 --- a/docs/configuration/policy/community-list.rst +++ /dev/null @@ -1,35 +0,0 @@ -#################### -BGP - Community List -#################### - -VyOS provides policies commands exclusively for BGP traffic filtering and -manipulation: **community-list** is one of them. - -************* -Configuration -************* - -policy community-list -===================== - -.. cfgcmd:: set policy community-list - - Creat community-list policy identified by name . - -.. cfgcmd:: set policy community-list description - - Set description for community-list policy. - -.. cfgcmd:: set policy community-list rule <1-65535> action - - - Set action to take on entries matching this rule. - -.. cfgcmd:: set policy community-list rule <1-65535> description - - Set description for rule. - -.. cfgcmd:: set policy community-list rule <1-65535> regex - - - Regular expression to match against a community-list. \ No newline at end of file diff --git a/docs/configuration/policy/examples.md b/docs/configuration/policy/examples.md new file mode 100644 index 00000000..4dc3f3b0 --- /dev/null +++ b/docs/configuration/policy/examples.md @@ -0,0 +1,205 @@ +# BGP Example + +**Policy definition:** + +```none +# Create policy +set policy route-map setmet rule 2 action 'permit' +set policy route-map setmet rule 2 set as-path prepend '2 2 2' + +# Apply policy to BGP +set protocols bgp system-as 1 +set protocols bgp neighbor 203.0.113.2 address-family ipv4-unicast route-map import 'setmet' +set protocols bgp neighbor 203.0.113.2 address-family ipv4-unicast soft-reconfiguration 'inbound' +``` + +Using 'soft-reconfiguration' we get the policy update without bouncing the +neighbor. + +**Routes learned before routing policy applied:** + +```none +vyos@vos1:~$ show ip bgp +BGP table version is 0, local router ID is 192.168.56.101 +Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, + r RIB-failure, S Stale, R Removed +Origin codes: i - IGP, e - EGP, ? - incomplete + + Network Next Hop Metric LocPrf Weight Path +*> 198.51.100.3/32 203.0.113.2 1 0 2 i < Path + +Total number of prefixes 1 +``` + +**Routes learned after routing policy applied:** + +```none +vyos@vos1:~$ show ip bgp +BGP table version is 0, local router ID is 192.168.56.101 +Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, + r RIB-failure, S Stale, R Removed +Origin codes: i - IGP, e - EGP, ? - incomplete + + Network Next Hop Metric LocPrf Weight Path +*> 198.51.100.3/32 203.0.113.2 1 0 2 2 2 2 i + +Total number of prefixes 1 +vyos@vos1:~$ +``` + +You now see the longer AS path. + +# Transparent Proxy + +The following example will show how VyOS can be used to redirect web +traffic to an external transparent proxy: + +```none +set policy route FILTER-WEB rule 1000 destination port 80 +set policy route FILTER-WEB rule 1000 protocol tcp +set policy route FILTER-WEB rule 1000 set table 100 +``` + +This creates a route policy called FILTER-WEB with one rule to set the +routing table for matching traffic (TCP port 80) to table ID 100 +instead of the default routing table. + +To create routing table 100 and add a new default gateway to be used by +traffic matching our route policy: + +```none +set protocols static table 100 route 0.0.0.0/0 next-hop 10.255.0.2 +``` + +This can be confirmed using the `show ip route table 100` operational +command. + +Finally, to apply the policy route to ingress traffic on our LAN +interface, we use: + +```none +set policy route FILTER-WEB interface eth1 +``` + + +# Multiple Uplinks + +VyOS Policy-Based Routing (PBR) works by matching source IP address +ranges and forwarding the traffic using different routing tables. + +Routing tables that will be used in this example are: + +- `table 10` Routing table used for VLAN 10 (192.168.188.0/24) +- `table 11` Routing table used for VLAN 11 (192.168.189.0/24) +- `main` Routing table used by VyOS and other interfaces not + participating in PBR + +:::{figure} /_static/images/pbr_example_1.webp +:alt: PBR multiple uplinks +:scale: 80 % + +Policy-Based Routing with multiple ISP uplinks +(source ./draw.io/pbr_example_1.drawio) +::: + +Add default routes for routing `table 10` and `table 11` + +```none +set protocols static table 10 route 0.0.0.0/0 next-hop 192.0.2.1 +set protocols static table 11 route 0.0.0.0/0 next-hop 192.0.2.2 +``` + +Add policy route matching VLAN source addresses + +```none +set policy route PBR rule 20 set table '10' +set policy route PBR rule 20 description 'Route VLAN10 traffic to table 10' +set policy route PBR rule 20 source address '192.168.188.0/24' + +set policy route PBR rule 30 set table '11' +set policy route PBR rule 30 description 'Route VLAN11 traffic to table 11' +set policy route PBR rule 30 source address '192.168.189.0/24' +``` + +Apply routing policy to **inbound** direction of out VLAN interfaces + +```none +set policy route 'PBR' interface eth0.10 +set policy route 'PBR' interface eth0.11 +``` + +**OPTIONAL:** Exclude Inter-VLAN traffic (between VLAN10 and VLAN11) +from PBR + +```none +set firewall group network-group VLANS-GR description 'VLANs networks' +set firewall group network-group VLANS-GR network '192.168.188.0/24' +set firewall group network-group VLANS-GR network '192.168.189.0/24' + +set policy route PBR rule 10 description 'VLAN10 <-> VLAN11 shortcut' +set policy route PBR rule 10 destination group network-group 'VLANS-GR' +set policy route PBR rule 10 set table 'main' +``` + +These commands allow the VLAN10 and VLAN11 hosts to communicate with +each other using the main routing table. + +## Local route + +The following example allows VyOS to use {abbr}`PBR (Policy-Based Routing)` +for traffic, which originated from the router itself. That solution for multiple +ISP's and VyOS router will respond from the same interface that the packet was +received. Also, it used, if we want that one VPN tunnel to be through one +provider, and the second through another. + +- `203.0.113.254` IP address on VyOS eth1 from ISP1 +- `192.168.2.254` IP address on VyOS eth2 from ISP2 +- `table 10` Routing table used for ISP1 +- `table 11` Routing table used for ISP2 + +```none +set policy local-route rule 101 set table '10' +set policy local-route rule 101 source address '203.0.113.254' +set policy local-route rule 102 set table '11' +set policy local-route rule 102 source address '192.0.2.254' +set protocols static table 10 route 0.0.0.0/0 next-hop '203.0.113.1' +set protocols static table 11 route 0.0.0.0/0 next-hop '192.0.2.2' +``` + +Add multiple source IP in one rule with same priority + +```none +set policy local-route rule 101 set table '10' +set policy local-route rule 101 source address '203.0.113.254' +set policy local-route rule 101 source address '203.0.113.253' +set policy local-route rule 101 source address '198.51.100.0/24' +``` + + +# Clamp MSS for a specific IP + +This example shows how to target an MSS clamp (in our example to 1360 bytes) +to a specific destination IP. + +```none +set policy route IP-MSS-CLAMP rule 10 description 'Clamp TCP session MSS to 1360 for 198.51.100.30' +set policy route IP-MSS-CLAMP rule 10 destination address '198.51.100.30/32' +set policy route IP-MSS-CLAMP rule 10 protocol 'tcp' +set policy route IP-MSS-CLAMP rule 10 set tcp-mss '1360' +set policy route IP-MSS-CLAMP rule 10 tcp flags 'SYN' +``` + +To apply this policy to the correct interface, configure it on the +interface the inbound local host will send through to reach our +destined target host (in our example eth1). + +```none +set policy route IP-MSS-CLAMP interface eth1 +``` + +You can view that the policy is being correctly (or incorrectly) utilised +with the following command: + +```none +show policy route statistics +``` diff --git a/docs/configuration/policy/examples.rst b/docs/configuration/policy/examples.rst deleted file mode 100644 index 6c5c592a..00000000 --- a/docs/configuration/policy/examples.rst +++ /dev/null @@ -1,213 +0,0 @@ -########### -BGP Example -########### - -**Policy definition:** - -.. code-block:: none - - # Create policy - set policy route-map setmet rule 2 action 'permit' - set policy route-map setmet rule 2 set as-path prepend '2 2 2' - - # Apply policy to BGP - set protocols bgp system-as 1 - set protocols bgp neighbor 203.0.113.2 address-family ipv4-unicast route-map import 'setmet' - set protocols bgp neighbor 203.0.113.2 address-family ipv4-unicast soft-reconfiguration 'inbound' - -Using 'soft-reconfiguration' we get the policy update without bouncing the -neighbor. - -**Routes learned before routing policy applied:** - -.. code-block:: none - - vyos@vos1:~$ show ip bgp - BGP table version is 0, local router ID is 192.168.56.101 - Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, - r RIB-failure, S Stale, R Removed - Origin codes: i - IGP, e - EGP, ? - incomplete - - Network Next Hop Metric LocPrf Weight Path - *> 198.51.100.3/32 203.0.113.2 1 0 2 i < Path - - Total number of prefixes 1 - -**Routes learned after routing policy applied:** - -.. code-block:: none - - vyos@vos1:~$ show ip bgp - BGP table version is 0, local router ID is 192.168.56.101 - Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, - r RIB-failure, S Stale, R Removed - Origin codes: i - IGP, e - EGP, ? - incomplete - - Network Next Hop Metric LocPrf Weight Path - *> 198.51.100.3/32 203.0.113.2 1 0 2 2 2 2 i - - Total number of prefixes 1 - vyos@vos1:~$ - -You now see the longer AS path. - -################# -Transparent Proxy -################# - -The following example will show how VyOS can be used to redirect web -traffic to an external transparent proxy: - -.. code-block:: none - - set policy route FILTER-WEB rule 1000 destination port 80 - set policy route FILTER-WEB rule 1000 protocol tcp - set policy route FILTER-WEB rule 1000 set table 100 - -This creates a route policy called FILTER-WEB with one rule to set the -routing table for matching traffic (TCP port 80) to table ID 100 -instead of the default routing table. - -To create routing table 100 and add a new default gateway to be used by -traffic matching our route policy: - -.. code-block:: none - - set protocols static table 100 route 0.0.0.0/0 next-hop 10.255.0.2 - -This can be confirmed using the ``show ip route table 100`` operational -command. - -Finally, to apply the policy route to ingress traffic on our LAN -interface, we use: - -.. code-block:: none - - set policy route FILTER-WEB interface eth1 - -################ -Multiple Uplinks -################ - -VyOS Policy-Based Routing (PBR) works by matching source IP address -ranges and forwarding the traffic using different routing tables. - -Routing tables that will be used in this example are: - -* ``table 10`` Routing table used for VLAN 10 (192.168.188.0/24) -* ``table 11`` Routing table used for VLAN 11 (192.168.189.0/24) -* ``main`` Routing table used by VyOS and other interfaces not - participating in PBR - -.. figure:: /_static/images/pbr_example_1.* - :scale: 80 % - :alt: PBR multiple uplinks - - Policy-Based Routing with multiple ISP uplinks - (source ./draw.io/pbr_example_1.drawio) - -Add default routes for routing ``table 10`` and ``table 11`` - -.. code-block:: none - - set protocols static table 10 route 0.0.0.0/0 next-hop 192.0.1.1 - set protocols static table 11 route 0.0.0.0/0 next-hop 192.0.2.2 - -Add policy route matching VLAN source addresses - -.. code-block:: none - - set policy route PBR rule 20 set table '10' - set policy route PBR rule 20 description 'Route VLAN10 traffic to table 10' - set policy route PBR rule 20 source address '192.168.188.0/24' - - set policy route PBR rule 30 set table '11' - set policy route PBR rule 30 description 'Route VLAN11 traffic to table 11' - set policy route PBR rule 30 source address '192.168.189.0/24' - -Apply routing policy to **inbound** direction of out VLAN interfaces - -.. code-block:: none - - set policy route 'PBR' interface eth0.10 - set policy route 'PBR' interface eth0.11 - - -**OPTIONAL:** Exclude Inter-VLAN traffic (between VLAN10 and VLAN11) -from PBR - -.. code-block:: none - - set firewall group network-group VLANS-GR description 'VLANs networks' - set firewall group network-group VLANS-GR network '192.168.188.0/24' - set firewall group network-group VLANS-GR network '192.168.189.0/24' - - set policy route PBR rule 10 description 'VLAN10 <-> VLAN11 shortcut' - set policy route PBR rule 10 destination group network-group 'VLANS-GR' - set policy route PBR rule 10 set table 'main' - -These commands allow the VLAN10 and VLAN11 hosts to communicate with -each other using the main routing table. - -Local route -=========== - -The following example allows VyOS to use :abbr:`PBR (Policy-Based Routing)` -for traffic, which originated from the router itself. That solution for multiple -ISP's and VyOS router will respond from the same interface that the packet was -received. Also, it used, if we want that one VPN tunnel to be through one -provider, and the second through another. - -* ``203.0.113.254`` IP addreess on VyOS eth1 from ISP1 -* ``192.168.2.254`` IP addreess on VyOS eth2 from ISP2 -* ``table 10`` Routing table used for ISP1 -* ``table 11`` Routing table used for ISP2 - - -.. code-block:: none - - set policy local-route rule 101 set table '10' - set policy local-route rule 101 source address '203.0.113.254' - set policy local-route rule 102 set table '11' - set policy local-route rule 102 source address '192.0.2.254' - set protocols static table 10 route 0.0.0.0/0 next-hop '203.0.113.1' - set protocols static table 11 route 0.0.0.0/0 next-hop '192.0.2.2' - -Add multiple source IP in one rule with same priority - -.. code-block:: none - - set policy local-route rule 101 set table '10' - set policy local-route rule 101 source address '203.0.113.254' - set policy local-route rule 101 source address '203.0.113.253' - set policy local-route rule 101 source address '198.51.100.0/24' - -########################### -Clamp MSS for a specific IP -########################### - -This example shows how to target an MSS clamp (in our example to 1360 bytes) -to a specific destination IP. - -.. code-block:: none - - set policy route IP-MSS-CLAMP rule 10 description 'Clamp TCP session MSS to 1360 for 198.51.100.30' - set policy route IP-MSS-CLAMP rule 10 destination address '198.51.100.30/32' - set policy route IP-MSS-CLAMP rule 10 protocol 'tcp' - set policy route IP-MSS-CLAMP rule 10 set tcp-mss '1360' - set policy route IP-MSS-CLAMP rule 10 tcp flags 'SYN' - -To apply this policy to the correct interface, configure it on the -interface the inbound local host will send through to reach our -destined target host (in our example eth1). - -.. code-block:: none - - set policy route IP-MSS-CLAMP interface eth1 - -You can view that the policy is being correctly (or incorrectly) utilised -with the following command: - -.. code-block:: none - - show policy route statistics diff --git a/docs/configuration/policy/extcommunity-list.md b/docs/configuration/policy/extcommunity-list.md new file mode 100644 index 00000000..5247c13c --- /dev/null +++ b/docs/configuration/policy/extcommunity-list.md @@ -0,0 +1,33 @@ +# BGP - Extended Community List + +VyOS provides policies commands exclusively for BGP traffic filtering and +manipulation: **extcommunity-list** is one of them. + +## Configuration + +### policy extcommunity-list + +```{cfgcmd} set policy extcommunity-list \ + +Creat extcommunity-list policy identified by name \. +``` +```{cfgcmd} set policy extcommunity-list \ description \ + +Set description for extcommunity-list policy. +``` +```{cfgcmd} set policy extcommunity-list \ rule \<1-65535\> action \ + +Set action to take on entries matching this rule. +``` +```{cfgcmd} set policy extcommunity-list \ rule \<1-65535\> description \ + +Set description for rule. +``` +```{cfgcmd} set policy extcommunity-list \ rule \<1-65535\> regex \ + +Regular expression to match against an extended community list, where text +could be: +* \: Extended community list regular expression. +* \: Route Target regular expression. +* \: Site of Origin regular expression. +``` \ No newline at end of file diff --git a/docs/configuration/policy/extcommunity-list.rst b/docs/configuration/policy/extcommunity-list.rst deleted file mode 100644 index c413b8b5..00000000 --- a/docs/configuration/policy/extcommunity-list.rst +++ /dev/null @@ -1,40 +0,0 @@ -############################# -BGP - Extended Community List -############################# - -VyOS provides policies commands exclusively for BGP traffic filtering and -manipulation: **extcommunity-list** is one of them. - -************* -Configuration -************* - -policy extcommunity-list -======================== - -.. cfgcmd:: set policy extcommunity-list - - Creat extcommunity-list policy identified by name . - -.. cfgcmd:: set policy extcommunity-list description - - Set description for extcommunity-list policy. - -.. cfgcmd:: set policy extcommunity-list rule <1-65535> action - - - Set action to take on entries matching this rule. - -.. cfgcmd:: set policy extcommunity-list rule <1-65535> description - - - Set description for rule. - -.. cfgcmd:: set policy extcommunity-list rule <1-65535> regex - - Regular expression to match against an extended community list, where text - could be: - - * : Extended community list regular expression. - * : Route Target regular expression. - * : Site of Origin regular expression. diff --git a/docs/configuration/policy/index.md b/docs/configuration/policy/index.md new file mode 100644 index 00000000..f919e70a --- /dev/null +++ b/docs/configuration/policy/index.md @@ -0,0 +1,53 @@ +--- +lastproofread: '2021-07-12' +--- + +```{include} /_include/need_improvement.txt +``` + + +# Policy + +Policies are used for filtering and traffic management. With policies, network +administrators could filter and treat traffic +according to their needs. + +There could be a wide range of routing policies. Some examples are listed +below: +- Filter traffic based on source/destination address. +- Set some metric to routes learned from a particular neighbor. +- Set some attributes (like AS PATH or Community value) to advertised routes + to neighbors. +- Prefer a specific routing protocol routes over another routing protocol + running on the same router. + +Policies, in VyOS, are implemented using FRR filtering and route maps. Detailed +information of FRR could be found in + +## Policy Sections + +```{toctree} +:includehidden: true +:maxdepth: 1 + +access-list +prefix-list +route +route-map +local-route +as-path-list +community-list +extcommunity-list +large-community-list +``` + +## Examples + +Examples of policies usage: + +```{toctree} +:includehidden: true +:maxdepth: 1 + +examples +``` diff --git a/docs/configuration/policy/index.rst b/docs/configuration/policy/index.rst deleted file mode 100644 index 0394eb21..00000000 --- a/docs/configuration/policy/index.rst +++ /dev/null @@ -1,54 +0,0 @@ -:lastproofread: 2021-07-12 - -.. include:: /_include/need_improvement.txt - -###### -Policy -###### - -Policies are used for filtering and traffic management. With policies, network -administrators could filter and treat traffic -according to their needs. - -There could be a wide range of routing policies. Some examples are listed -below: - -* Filter traffic based on source/destination address. -* Set some metric to routes learned from a particular neighbor. -* Set some attributes (like AS PATH or Community value) to advertised routes - to neighbors. -* Prefer a specific routing protocol routes over another routing protocol - running on the same router. - -Policies, in VyOS, are implemented using FRR filtering and route maps. Detailed -information of FRR could be found in http://docs.frrouting.org/ - -*************** -Policy Sections -*************** - -.. toctree:: - :maxdepth: 1 - :includehidden: - - access-list - prefix-list - route - route-map - local-route - as-path-list - community-list - extcommunity-list - large-community-list - -******** -Examples -******** - -Examples of policies usage: - -.. toctree:: - :maxdepth: 1 - :includehidden: - - examples \ No newline at end of file diff --git a/docs/configuration/policy/large-community-list.md b/docs/configuration/policy/large-community-list.md new file mode 100644 index 00000000..23b9a85a --- /dev/null +++ b/docs/configuration/policy/large-community-list.md @@ -0,0 +1,29 @@ +# BGP - Large Community List + +VyOS provides policies commands exclusively for BGP traffic filtering and +manipulation: **large-community-list** is one of them. + +## Configuration + +### policy large-community-list + +```{cfgcmd} set policy large-community-list \ + +Create large-community-list policy identified by name ``. +``` +```{cfgcmd} set policy large-community-list \ description \ + +Set description for large-community-list policy. +``` +```{cfgcmd} set policy large-community-list \ rule \<1-65535\> action \ + +Set action to take on entries matching this rule. +``` +```{cfgcmd} set policy large-community-list \ rule \<1-65535\> description \ + +Set description for rule. +``` +```{cfgcmd} set policy large-community-list \ rule \<1-65535\> regex \ + +Regular expression to match against a large community list. +``` \ No newline at end of file diff --git a/docs/configuration/policy/large-community-list.rst b/docs/configuration/policy/large-community-list.rst deleted file mode 100644 index 0c57fd4a..00000000 --- a/docs/configuration/policy/large-community-list.rst +++ /dev/null @@ -1,36 +0,0 @@ -########################## -BGP - Large Community List -########################## - -VyOS provides policies commands exclusively for BGP traffic filtering and -manipulation: **large-community-list** is one of them. - -************* -Configuration -************* - -policy large-community-list -=========================== - -.. cfgcmd:: set policy large-community-list - - Create large-community-list policy identified by name . - -.. cfgcmd:: set policy large-community-list description - - Set description for large-community-list policy. - -.. cfgcmd:: set policy large-community-list rule <1-65535> action - - - Set action to take on entries matching this rule. - -.. cfgcmd:: set policy large-community-list rule <1-65535> description - - - Set description for rule. - -.. cfgcmd:: set policy large-community-list rule <1-65535> regex - - - Regular expression to match against a large community list. diff --git a/docs/configuration/policy/local-route.md b/docs/configuration/policy/local-route.md new file mode 100644 index 00000000..527a2380 --- /dev/null +++ b/docs/configuration/policy/local-route.md @@ -0,0 +1,100 @@ +# Local Route Policy + +Policies for local traffic are defined in this section. + +## Configuration + +### Local Route IPv4 + +```{cfgcmd} set policy local-route rule \<1-32765\> set table \<1-200|main\> + +Set the routing table to use for forwarding matching packets. +``` + +```{cfgcmd} set policy local-route rule \<1-32765\> set vrf \ + +Set the VRF to use for forwarding matching packets. +``` + +```{cfgcmd} set policy local-route rule \<1-32765\> protocol \ + +Match specified protocol (name or number). +``` + +```{cfgcmd} set policy local-route rule \<1-32765\> fwmark \<1-2147483647\> + +Match specified firewall mark (fwmark). +``` + +```{cfgcmd} set policy local-route rule \<1-32765\> source address \ + +Match specified source address or prefix. +``` + +```{cfgcmd} set policy local-route rule \<1-32765\> source port \<1-65535\> + +Match specified source port. +``` + +```{cfgcmd} set policy local-route rule \<1-32765\> destination address \ + +Match specified destination address or prefix. +``` + +```{cfgcmd} set policy local-route rule \<1-32765\> destination port \<1-65535\> + +Match specified destination port. +``` + +```{cfgcmd} set policy local-route rule \<1-32765\> inbound-interface \ + +Match specified inbound interface. +``` + + +### Local Route IPv6 + +```{cfgcmd} set policy local-route6 rule \<1-32765\> set table \<1-200|main\> + +Set the routing table to use for forwarding matching packets. +``` + +```{cfgcmd} set policy local-route6 rule \<1-32765\> set vrf \ + +Set the VRF to use for forwarding matching packets. +``` + +```{cfgcmd} set policy local-route6 rule \<1-32765\> protocol \ + +Match specified protocol (name or number). +``` + +```{cfgcmd} set policy local-route6 rule \<1-32765\> fwmark \<1-2147483647\> + +Match specified firewall mark (fwmark). +``` + +```{cfgcmd} set policy local-route6 rule \<1-32765\> source address \ + +Match specified source address or prefix. +``` + +```{cfgcmd} set policy local-route6 rule \<1-32765\> source port \<1-65535\> + +Match specified source port. +``` + +```{cfgcmd} set policy local-route6 rule \<1-32765\> destination address \ + +Match specified destination address or prefix. +``` + +```{cfgcmd} set policy local-route6 rule \<1-32765\> destination port \<1-65535\> + +Match specified destination port. +``` + +```{cfgcmd} set policy local-route6 rule \<1-32765\> inbound-interface \ + +Match specified inbound interface. +``` \ No newline at end of file diff --git a/docs/configuration/policy/local-route.rst b/docs/configuration/policy/local-route.rst deleted file mode 100644 index a3e42816..00000000 --- a/docs/configuration/policy/local-route.rst +++ /dev/null @@ -1,87 +0,0 @@ -################## -Local Route Policy -################## - -Policies for local traffic are defined in this section. - -************* -Configuration -************* - -Local Route IPv4 -================ - -.. cfgcmd:: set policy local-route rule <1-32765> set table <1-200|main> - - Set the routing table to use for forwarding matching packets. - -.. cfgcmd:: set policy local-route rule <1-32765> set vrf - - Set the VRF to use for forwarding matching packets. - -.. cfgcmd:: set policy local-route rule <1-32765> protocol - - Match specified protocol (name or number). - -.. cfgcmd:: set policy local-route rule <1-32765> fwmark <1-2147483647> - - Match specified firewall mark (fwmark). - -.. cfgcmd:: set policy local-route rule <1-32765> source address - - Match specified source address or prefix. - -.. cfgcmd:: set policy local-route rule <1-32765> source port <1-65535> - - Match specified source port. - -.. cfgcmd:: set policy local-route rule <1-32765> destination address - - Match specified destination address or prefix. - -.. cfgcmd:: set policy local-route rule <1-32765> destination port <1-65535> - - Match specified destination port. - -.. cfgcmd:: set policy local-route rule <1-32765> inbound-interface - - Match specified inbound interface. - -Local Route IPv6 -================ - -.. cfgcmd:: set policy local-route6 rule <1-32765> set table <1-200|main> - - Set the routing table to use for forwarding matching packets. - -.. cfgcmd:: set policy local-route6 rule <1-32765> set vrf - - Set the VRF to use for forwarding matching packets. - -.. cfgcmd:: set policy local-route6 rule <1-32765> protocol - - Match specified protocol (name or number). - -.. cfgcmd:: set policy local-route6 rule <1-32765> fwmark <1-2147483647> - - Match specified firewall mark (fwmark). - -.. cfgcmd:: set policy local-route6 rule <1-32765> source address - - Match specified source address or prefix. - -.. cfgcmd:: set policy local-route6 rule <1-32765> source port <1-65535> - - Match specified source port. - -.. cfgcmd:: set policy local-route6 rule <1-32765> destination address - - Match specified destination address or prefix. - -.. cfgcmd:: set policy local-route6 rule <1-32765> destination port <1-65535> - - Match specified destination port. - -.. cfgcmd:: set policy local-route6 rule <1-32765> inbound-interface - - Match specified inbound interface. \ No newline at end of file diff --git a/docs/configuration/policy/md-access-list.md b/docs/configuration/policy/md-access-list.md deleted file mode 100644 index c3a92e56..00000000 --- a/docs/configuration/policy/md-access-list.md +++ /dev/null @@ -1,70 +0,0 @@ -# Access List Policy - -Filtering is used for both input and output of the routing information. Once -filtering is defined, it can be applied in any direction. VyOS makes filtering -possible using acls and prefix lists. - -Basic filtering can be done using access-list and access-list6. - -## Configuration - -### Access Lists - -```{cfgcmd} set policy access-list \ - -This command creates the new access list policy, where `` must be -a number from 1 to 2699. -``` - -```{cfgcmd} set policy access-list \ description \ - -Set description for the access list. -``` - -```{cfgcmd} set policy access-list \ rule \<1-65535\> action \ - -This command creates a new rule in the access list and defines an action. -``` - -```{cfgcmd} set policy access-list \ rule \<1-65535\> \ \ - -This command defines matching parameters for access list rule. Matching -criteria could be applied to destination or source parameters: - -* any: any IP address to match. -* host: single host IP address to match. -* inverse-match: network/netmask to match (requires network be defined). -* network: network/netmask to match (requires inverse-match be defined). -``` - - -### IPv6 Access List - -Basic filtering could also be applied to IPv6 traffic. - -```{cfgcmd} set policy access-list6 \ - -This command creates the new IPv6 access list, identified by `` -``` - -```{cfgcmd} set policy access-list6 \ description \ - -Set description for the IPv6 access list. -``` - -```{cfgcmd} set policy access-list6 \ rule \<1-65535\> action \ - -This command creates a new rule in the IPv6 access list and defines an -action. -``` - -```{cfgcmd} set policy access-list6 \ rule \<1-65535\> source \ - -This command defines matching parameters for IPv6 access list rule. Matching -criteria could be applied to source parameters: - -* any: any IPv6 address to match. -* exact-match: exact match of the network prefixes. -* network: network/netmask to match (requires inverse-match be defined) BUG, -NO invert-match option in access-list6 -``` \ No newline at end of file diff --git a/docs/configuration/policy/md-as-path-list.md b/docs/configuration/policy/md-as-path-list.md deleted file mode 100644 index 1fcece91..00000000 --- a/docs/configuration/policy/md-as-path-list.md +++ /dev/null @@ -1,29 +0,0 @@ -# BGP - AS Path Policy - -VyOS provides policies commands exclusively for BGP traffic filtering and -manipulation: **as-path-list** is one of them. - -## Configuration - -### policy as-path-list - -```{cfgcmd} set policy as-path-list \ - -Create as-path-policy identified by name ``. -``` -```{cfgcmd} set policy as-path-list \ description \ - -Set description for as-path-list policy. -``` -```{cfgcmd} set policy as-path-list \ rule \<1-65535\> action \ - -Set action to take on entries matching this rule. -``` -```{cfgcmd} set policy as-path-list \ rule \<1-65535\> description \ - -Set description for rule. -``` -```{cfgcmd} set policy as-path-list \ rule \<1-65535\> regex \ - -Regular expression to match against an AS path. For example "64501 64502". -``` \ No newline at end of file diff --git a/docs/configuration/policy/md-community-list.md b/docs/configuration/policy/md-community-list.md deleted file mode 100644 index bdcf4140..00000000 --- a/docs/configuration/policy/md-community-list.md +++ /dev/null @@ -1,29 +0,0 @@ -# BGP - Community List - -VyOS provides policies commands exclusively for BGP traffic filtering and -manipulation: **community-list** is one of them. - -## Configuration - -### policy community-list - -```{cfgcmd} set policy community-list \ - -Creat community-list policy identified by name ``. -``` -```{cfgcmd} set policy community-list \ description \ - -Set description for community-list policy. -``` -```{cfgcmd} set policy community-list \ rule \<1-65535\> action \ - -Set action to take on entries matching this rule. -``` -```{cfgcmd} set policy community-list \ rule \<1-65535\> description \ - -Set description for rule. -``` -```{cfgcmd} set policy community-list \ rule \<1-65535\> regex \ - -Regular expression to match against a community-list. -``` \ No newline at end of file diff --git a/docs/configuration/policy/md-examples.md b/docs/configuration/policy/md-examples.md deleted file mode 100644 index 4dc3f3b0..00000000 --- a/docs/configuration/policy/md-examples.md +++ /dev/null @@ -1,205 +0,0 @@ -# BGP Example - -**Policy definition:** - -```none -# Create policy -set policy route-map setmet rule 2 action 'permit' -set policy route-map setmet rule 2 set as-path prepend '2 2 2' - -# Apply policy to BGP -set protocols bgp system-as 1 -set protocols bgp neighbor 203.0.113.2 address-family ipv4-unicast route-map import 'setmet' -set protocols bgp neighbor 203.0.113.2 address-family ipv4-unicast soft-reconfiguration 'inbound' -``` - -Using 'soft-reconfiguration' we get the policy update without bouncing the -neighbor. - -**Routes learned before routing policy applied:** - -```none -vyos@vos1:~$ show ip bgp -BGP table version is 0, local router ID is 192.168.56.101 -Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, - r RIB-failure, S Stale, R Removed -Origin codes: i - IGP, e - EGP, ? - incomplete - - Network Next Hop Metric LocPrf Weight Path -*> 198.51.100.3/32 203.0.113.2 1 0 2 i < Path - -Total number of prefixes 1 -``` - -**Routes learned after routing policy applied:** - -```none -vyos@vos1:~$ show ip bgp -BGP table version is 0, local router ID is 192.168.56.101 -Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, - r RIB-failure, S Stale, R Removed -Origin codes: i - IGP, e - EGP, ? - incomplete - - Network Next Hop Metric LocPrf Weight Path -*> 198.51.100.3/32 203.0.113.2 1 0 2 2 2 2 i - -Total number of prefixes 1 -vyos@vos1:~$ -``` - -You now see the longer AS path. - -# Transparent Proxy - -The following example will show how VyOS can be used to redirect web -traffic to an external transparent proxy: - -```none -set policy route FILTER-WEB rule 1000 destination port 80 -set policy route FILTER-WEB rule 1000 protocol tcp -set policy route FILTER-WEB rule 1000 set table 100 -``` - -This creates a route policy called FILTER-WEB with one rule to set the -routing table for matching traffic (TCP port 80) to table ID 100 -instead of the default routing table. - -To create routing table 100 and add a new default gateway to be used by -traffic matching our route policy: - -```none -set protocols static table 100 route 0.0.0.0/0 next-hop 10.255.0.2 -``` - -This can be confirmed using the `show ip route table 100` operational -command. - -Finally, to apply the policy route to ingress traffic on our LAN -interface, we use: - -```none -set policy route FILTER-WEB interface eth1 -``` - - -# Multiple Uplinks - -VyOS Policy-Based Routing (PBR) works by matching source IP address -ranges and forwarding the traffic using different routing tables. - -Routing tables that will be used in this example are: - -- `table 10` Routing table used for VLAN 10 (192.168.188.0/24) -- `table 11` Routing table used for VLAN 11 (192.168.189.0/24) -- `main` Routing table used by VyOS and other interfaces not - participating in PBR - -:::{figure} /_static/images/pbr_example_1.webp -:alt: PBR multiple uplinks -:scale: 80 % - -Policy-Based Routing with multiple ISP uplinks -(source ./draw.io/pbr_example_1.drawio) -::: - -Add default routes for routing `table 10` and `table 11` - -```none -set protocols static table 10 route 0.0.0.0/0 next-hop 192.0.2.1 -set protocols static table 11 route 0.0.0.0/0 next-hop 192.0.2.2 -``` - -Add policy route matching VLAN source addresses - -```none -set policy route PBR rule 20 set table '10' -set policy route PBR rule 20 description 'Route VLAN10 traffic to table 10' -set policy route PBR rule 20 source address '192.168.188.0/24' - -set policy route PBR rule 30 set table '11' -set policy route PBR rule 30 description 'Route VLAN11 traffic to table 11' -set policy route PBR rule 30 source address '192.168.189.0/24' -``` - -Apply routing policy to **inbound** direction of out VLAN interfaces - -```none -set policy route 'PBR' interface eth0.10 -set policy route 'PBR' interface eth0.11 -``` - -**OPTIONAL:** Exclude Inter-VLAN traffic (between VLAN10 and VLAN11) -from PBR - -```none -set firewall group network-group VLANS-GR description 'VLANs networks' -set firewall group network-group VLANS-GR network '192.168.188.0/24' -set firewall group network-group VLANS-GR network '192.168.189.0/24' - -set policy route PBR rule 10 description 'VLAN10 <-> VLAN11 shortcut' -set policy route PBR rule 10 destination group network-group 'VLANS-GR' -set policy route PBR rule 10 set table 'main' -``` - -These commands allow the VLAN10 and VLAN11 hosts to communicate with -each other using the main routing table. - -## Local route - -The following example allows VyOS to use {abbr}`PBR (Policy-Based Routing)` -for traffic, which originated from the router itself. That solution for multiple -ISP's and VyOS router will respond from the same interface that the packet was -received. Also, it used, if we want that one VPN tunnel to be through one -provider, and the second through another. - -- `203.0.113.254` IP address on VyOS eth1 from ISP1 -- `192.168.2.254` IP address on VyOS eth2 from ISP2 -- `table 10` Routing table used for ISP1 -- `table 11` Routing table used for ISP2 - -```none -set policy local-route rule 101 set table '10' -set policy local-route rule 101 source address '203.0.113.254' -set policy local-route rule 102 set table '11' -set policy local-route rule 102 source address '192.0.2.254' -set protocols static table 10 route 0.0.0.0/0 next-hop '203.0.113.1' -set protocols static table 11 route 0.0.0.0/0 next-hop '192.0.2.2' -``` - -Add multiple source IP in one rule with same priority - -```none -set policy local-route rule 101 set table '10' -set policy local-route rule 101 source address '203.0.113.254' -set policy local-route rule 101 source address '203.0.113.253' -set policy local-route rule 101 source address '198.51.100.0/24' -``` - - -# Clamp MSS for a specific IP - -This example shows how to target an MSS clamp (in our example to 1360 bytes) -to a specific destination IP. - -```none -set policy route IP-MSS-CLAMP rule 10 description 'Clamp TCP session MSS to 1360 for 198.51.100.30' -set policy route IP-MSS-CLAMP rule 10 destination address '198.51.100.30/32' -set policy route IP-MSS-CLAMP rule 10 protocol 'tcp' -set policy route IP-MSS-CLAMP rule 10 set tcp-mss '1360' -set policy route IP-MSS-CLAMP rule 10 tcp flags 'SYN' -``` - -To apply this policy to the correct interface, configure it on the -interface the inbound local host will send through to reach our -destined target host (in our example eth1). - -```none -set policy route IP-MSS-CLAMP interface eth1 -``` - -You can view that the policy is being correctly (or incorrectly) utilised -with the following command: - -```none -show policy route statistics -``` diff --git a/docs/configuration/policy/md-extcommunity-list.md b/docs/configuration/policy/md-extcommunity-list.md deleted file mode 100644 index 5247c13c..00000000 --- a/docs/configuration/policy/md-extcommunity-list.md +++ /dev/null @@ -1,33 +0,0 @@ -# BGP - Extended Community List - -VyOS provides policies commands exclusively for BGP traffic filtering and -manipulation: **extcommunity-list** is one of them. - -## Configuration - -### policy extcommunity-list - -```{cfgcmd} set policy extcommunity-list \ - -Creat extcommunity-list policy identified by name \. -``` -```{cfgcmd} set policy extcommunity-list \ description \ - -Set description for extcommunity-list policy. -``` -```{cfgcmd} set policy extcommunity-list \ rule \<1-65535\> action \ - -Set action to take on entries matching this rule. -``` -```{cfgcmd} set policy extcommunity-list \ rule \<1-65535\> description \ - -Set description for rule. -``` -```{cfgcmd} set policy extcommunity-list \ rule \<1-65535\> regex \ - -Regular expression to match against an extended community list, where text -could be: -* \: Extended community list regular expression. -* \: Route Target regular expression. -* \: Site of Origin regular expression. -``` \ No newline at end of file diff --git a/docs/configuration/policy/md-index.md b/docs/configuration/policy/md-index.md deleted file mode 100644 index f919e70a..00000000 --- a/docs/configuration/policy/md-index.md +++ /dev/null @@ -1,53 +0,0 @@ ---- -lastproofread: '2021-07-12' ---- - -```{include} /_include/need_improvement.txt -``` - - -# Policy - -Policies are used for filtering and traffic management. With policies, network -administrators could filter and treat traffic -according to their needs. - -There could be a wide range of routing policies. Some examples are listed -below: -- Filter traffic based on source/destination address. -- Set some metric to routes learned from a particular neighbor. -- Set some attributes (like AS PATH or Community value) to advertised routes - to neighbors. -- Prefer a specific routing protocol routes over another routing protocol - running on the same router. - -Policies, in VyOS, are implemented using FRR filtering and route maps. Detailed -information of FRR could be found in - -## Policy Sections - -```{toctree} -:includehidden: true -:maxdepth: 1 - -access-list -prefix-list -route -route-map -local-route -as-path-list -community-list -extcommunity-list -large-community-list -``` - -## Examples - -Examples of policies usage: - -```{toctree} -:includehidden: true -:maxdepth: 1 - -examples -``` diff --git a/docs/configuration/policy/md-large-community-list.md b/docs/configuration/policy/md-large-community-list.md deleted file mode 100644 index 23b9a85a..00000000 --- a/docs/configuration/policy/md-large-community-list.md +++ /dev/null @@ -1,29 +0,0 @@ -# BGP - Large Community List - -VyOS provides policies commands exclusively for BGP traffic filtering and -manipulation: **large-community-list** is one of them. - -## Configuration - -### policy large-community-list - -```{cfgcmd} set policy large-community-list \ - -Create large-community-list policy identified by name ``. -``` -```{cfgcmd} set policy large-community-list \ description \ - -Set description for large-community-list policy. -``` -```{cfgcmd} set policy large-community-list \ rule \<1-65535\> action \ - -Set action to take on entries matching this rule. -``` -```{cfgcmd} set policy large-community-list \ rule \<1-65535\> description \ - -Set description for rule. -``` -```{cfgcmd} set policy large-community-list \ rule \<1-65535\> regex \ - -Regular expression to match against a large community list. -``` \ No newline at end of file diff --git a/docs/configuration/policy/md-local-route.md b/docs/configuration/policy/md-local-route.md deleted file mode 100644 index 527a2380..00000000 --- a/docs/configuration/policy/md-local-route.md +++ /dev/null @@ -1,100 +0,0 @@ -# Local Route Policy - -Policies for local traffic are defined in this section. - -## Configuration - -### Local Route IPv4 - -```{cfgcmd} set policy local-route rule \<1-32765\> set table \<1-200|main\> - -Set the routing table to use for forwarding matching packets. -``` - -```{cfgcmd} set policy local-route rule \<1-32765\> set vrf \ - -Set the VRF to use for forwarding matching packets. -``` - -```{cfgcmd} set policy local-route rule \<1-32765\> protocol \ - -Match specified protocol (name or number). -``` - -```{cfgcmd} set policy local-route rule \<1-32765\> fwmark \<1-2147483647\> - -Match specified firewall mark (fwmark). -``` - -```{cfgcmd} set policy local-route rule \<1-32765\> source address \ - -Match specified source address or prefix. -``` - -```{cfgcmd} set policy local-route rule \<1-32765\> source port \<1-65535\> - -Match specified source port. -``` - -```{cfgcmd} set policy local-route rule \<1-32765\> destination address \ - -Match specified destination address or prefix. -``` - -```{cfgcmd} set policy local-route rule \<1-32765\> destination port \<1-65535\> - -Match specified destination port. -``` - -```{cfgcmd} set policy local-route rule \<1-32765\> inbound-interface \ - -Match specified inbound interface. -``` - - -### Local Route IPv6 - -```{cfgcmd} set policy local-route6 rule \<1-32765\> set table \<1-200|main\> - -Set the routing table to use for forwarding matching packets. -``` - -```{cfgcmd} set policy local-route6 rule \<1-32765\> set vrf \ - -Set the VRF to use for forwarding matching packets. -``` - -```{cfgcmd} set policy local-route6 rule \<1-32765\> protocol \ - -Match specified protocol (name or number). -``` - -```{cfgcmd} set policy local-route6 rule \<1-32765\> fwmark \<1-2147483647\> - -Match specified firewall mark (fwmark). -``` - -```{cfgcmd} set policy local-route6 rule \<1-32765\> source address \ - -Match specified source address or prefix. -``` - -```{cfgcmd} set policy local-route6 rule \<1-32765\> source port \<1-65535\> - -Match specified source port. -``` - -```{cfgcmd} set policy local-route6 rule \<1-32765\> destination address \ - -Match specified destination address or prefix. -``` - -```{cfgcmd} set policy local-route6 rule \<1-32765\> destination port \<1-65535\> - -Match specified destination port. -``` - -```{cfgcmd} set policy local-route6 rule \<1-32765\> inbound-interface \ - -Match specified inbound interface. -``` \ No newline at end of file diff --git a/docs/configuration/policy/md-prefix-list.md b/docs/configuration/policy/md-prefix-list.md deleted file mode 100644 index eb827c77..00000000 --- a/docs/configuration/policy/md-prefix-list.md +++ /dev/null @@ -1,152 +0,0 @@ -# Prefix List Policy - -Prefix lists provides the most powerful prefix based filtering mechanism. In -addition to access-list functionality, ip prefix-list has prefix length range -specification. - -If no ip prefix list is specified, it acts as permit. If ip prefix list is -defined, and no match is found, default deny is applied. - -Prefix filtering can be done using prefix-list and prefix-list6. - -## Configuration - -### IPv4 Prefix Lists (prefix-list) - -```{cfgcmd} set policy prefix-list \ - -This command creates the new prefix-list policy, identified by ``. -``` - -```{cfgcmd} set policy prefix-list \ description \ - -Set description for the prefix-list policy. -``` - -```{cfgcmd} set policy prefix-list \ rule \<1-65535\> action \ - -This command creates a new rule in the prefix-list and defines an action. -``` - -```{cfgcmd} set policy prefix-list \ rule \<1-65535\> description \ - -Set description for rule in the prefix-list. -``` - -```{cfgcmd} set policy prefix-list \ rule \<1-65535\> prefix \ - -Prefix to match against. -``` - -```{cfgcmd} set policy prefix-list \ rule \<1-65535\> ge \<0-32\> - -Netmask greater than length. -``` - -```{cfgcmd} set policy prefix-list \ rule \<1-65535\> le \<0-32\> - -Netmask less than length -``` - - -### Example: IPv4 Prefix Lists (prefix-list) - -This example creates an IPv4 prefix-list named PL4-EXAMPLE-NAME, defines 3 -rules each with 1 prefix, and matches le (less than/equal to) /32. - -```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 10 action 'permit' - -``` -```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 10 le '32' -``` - -```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 10 prefix '192.0.2.0/24' -``` - -```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 20 action 'permit' -``` - -```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 20 le '32' -``` - -```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 20 prefix '198.51.100.0/24' -``` - -```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 30 action 'permit' -``` - -```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 30 le '32' -``` - -```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 30 prefix '203.0.113.0/24' -``` - -### IPv6 Prefix Lists (prefix-list6) - -```{cfgcmd} set policy prefix-list6 \ - -This command creates the new IPv6 prefix-list policy, identified by ``. -``` - -```{cfgcmd} set policy prefix-list6 \ description \ - -Set description for the IPv6 prefix-list policy. -``` - -```{cfgcmd} set policy prefix-list6 \ rule \<1-65535\> action \ - -This command creates a new rule in the IPv6 prefix-list and defines an -action. -``` - -```{cfgcmd} set policy prefix-list6 \ rule \<1-65535\> description \ - -Set description for rule in IPv6 prefix-list. -``` - -```{cfgcmd} set policy prefix-list6 \ rule \<1-65535\> prefix \ - -IPv6 prefix. -``` - -```{cfgcmd} set policy prefix-list6 \ rule \<1-65535\> ge \<0-128\> - -Netmask greater than length. -``` - -```{cfgcmd} set policy prefix-list6 \ rule \<1-65535\> le \<0-128\> - -Netmask less than length -``` - -### Example: IPv6 Prefix Lists (prefix-list6) - -This example creates an IPv6 prefix-list6 named PL6-EXAMPLE-NAME, defines 3 -rules each with 1 prefix, and matches le (less than/equal to) /128. - -```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 10 action 'permit' -``` - -```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 10 le '128' -``` - -```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 10 prefix '2001:db8:0:0::/64' -``` - -```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 20 action 'permit' -``` - -```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 20 le '128' -``` - -```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 20 prefix '2001:db8:0:1::/64' -``` - -```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 30 action 'permit' -``` - -```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 30 le '128' -``` - -```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 30 prefix '2001:db8:0:2::/64' -``` \ No newline at end of file diff --git a/docs/configuration/policy/md-route-map.md b/docs/configuration/policy/md-route-map.md deleted file mode 100644 index cf419a48..00000000 --- a/docs/configuration/policy/md-route-map.md +++ /dev/null @@ -1,439 +0,0 @@ -# Route Map Policy - -Route map is a powerful command, that gives network administrators a very -useful and flexible tool for traffic manipulation. - -## Configuration - -### Route Map - -```{cfgcmd} set policy route-map \ - - This command creates a new route-map policy, identified by \. -``` - - -```{cfgcmd} set policy route-map \ description \ - -Set description for the route-map policy. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> action \ - -Set action for the route-map policy. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> call \ - -Call another route-map policy on match. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> continue \<1-65535\> - -Jump to a different rule in this route-map on a match. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> description \ - -Set description for the rule in the route-map policy. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match as-path \ - -BGP as-path list to match. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match community community-list \ - -BGP community-list to match. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match community exact-match - -Set BGP community-list to exactly match. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match extcommunity \ - -BGP extended community to match. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match interface \ - -First hop interface of a route to match. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip address access-list \<1-2699\> - -IP address of route to match, based on access-list. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip address prefix-list \ - -IP address of route to match, based on prefix-list. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip address prefix-len \<0-32\> - -IP address of route to match, based on specified prefix-length. -Note that this can be used for kernel routes only. -Do not apply to the routes of dynamic routing protocols (e.g. BGP, -RIP, OSFP), as this can lead to unexpected results.. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip nexthop access-list \<1-2699\> - -IP next-hop of route to match, based on access-list. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip nexthop address \ - -IP next-hop of route to match, based on ip address. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip nexthop prefix-len \<0-32\> - -IP next-hop of route to match, based on prefix length. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip nexthop prefix-list \ - -IP next-hop of route to match, based on prefix-list. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip nexthop type \ - -IP next-hop of route to match, based on type. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip route-source access-list \<1-2699\> - -IP route source of route to match, based on access-list. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip route-source prefix-list \ - -IP route source of route to match, based on prefix-list. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match ipv6 address access-list \ - -IPv6 address of route to match, based on IPv6 access-list. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match ipv6 address prefix-list \ - -IPv6 address of route to match, based on IPv6 prefix-list. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match ipv6 address prefix-len \<0-128\> - -IPv6 address of route to match, based on specified prefix-length. -Note that this can be used for kernel routes only. -Do not apply to the routes of dynamic routing protocols (e.g. BGP, -RIP, OSFP), as this can lead to unexpected results.. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match ipv6 nexthop \ - -Nexthop IPv6 address to match. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match large-community large-community-list \ - -Match BGP large communities. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match local-preference \<0-4294967295\> - -Match local preference. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match metric \<1-65535\> - -Match route metric. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match origin \ - -Boarder Gateway Protocol (BGP) origin code to match. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match peer \ - -Peer IP address to match. -``` - - -````{cfgcmd} set policy route-map \ rule \<1-65535\> match protocol \ - -```{eval-rst} -Source protocol to match. - * ``babel`` - Babel routing protocol (Babel) - * ``bgp`` - Border Gateway Protocol (BGP) - * ``connected`` - Connected routes (directly attached subnet or host) - * ``isis`` - Intermediate System to Intermediate System (IS-IS) - * ``kernel`` - Kernel routes - * ``ospf`` - Open Shortest Path First (OSPFv2) - * ``ospfv3`` - Open Shortest Path First (IPv6) (OSPFv3) - * ``rip`` - Routing Information Protocol (RIP) - * ``ripng`` - Routing Information Protocol next-generation (IPv6) (RIPng) - * ``static`` - Statically configured routes - * ``table`` - Non-main Kernel Routing Table - * ``vnc`` - Virtual Network Control (VNC) -``` -```` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match rpki \ - -Match RPKI validation result. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match source-vrf \ - -Source VRF to match. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> match tag \<1-65535\> - -Route tag to match. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> on-match goto \<1-65535\> - -Exit policy on match: go to rule <1-65535> -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> on-match next - -Exit policy on match: go to next sequence number. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set aggregator \ \<1-4294967295|x.x.x.x\> - -BGP aggregator attribute: AS number or IP address of an aggregation. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set as-path exclude \<1-4294967295 | all\> - -Drop AS-NUMBER from the BGP AS path. - -If ``all`` is specified, remove all AS numbers from the AS_PATH of the BGP -path's NLRI. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set as-path prepend \<1-4294967295\> - -Prepend the given string of AS numbers to the AS_PATH of the BGP path's NLRI. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set as-path prepend-last-as \ - -Prepend the existing last AS number (the leftmost ASN) to the AS_PATH. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set atomic-aggregate - -BGP atomic aggregate attribute. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set community \ \ - -Add or replace BGP community attribute in format ``<0-65535:0-65535>`` -or from well-known community list -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set community none - -Delete all BGP communities -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set community delete \ - -Delete BGP communities matching the community-list. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set large-community \ \ - -Add or replace BGP large-community attribute in format -``<0-4294967295:0-4294967295:0-4294967295>`` -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set large-community none - -Delete all BGP large-communities -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set large-community delete \ - -Delete BGP communities matching the large-community-list. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set extcommunity bandwidth \<1-25600|cumulative|num-multipaths\> - -Set extcommunity bandwidth -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set extcommunity bandwidth-non-transitive - -The link bandwidth extended community is encoded as non-transitive -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set extcommunity rt \ - -Set route target value in format ``<0-65535:0-4294967295>`` or ````. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set extcommunity soo \ - -Set site of origin value in format ``<0-65535:0-4294967295>`` or ````. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set extcommunity none - -Clear all BGP extcommunities. -``` - - -```{cfgcmd} set policy route-map \ rule \<1-65535\> set distance \<0-255\> - -Locally significant administrative distance. -``` -```{cfgcmd} set policy route-map \ rule \<1-65535\> set ip-next-hop \ - -Nexthop IP address. -``` -```{cfgcmd} set policy route-map \ rule \<1-65535\> set ip-next-hop unchanged - -Set the next-hop as unchanged. Pass through the route-map without -changing its value -``` -```{cfgcmd} set policy route-map \ rule \<1-65535\> set ip-next-hop peer-address - -Set the BGP nexthop address to the address of the peer. For an incoming -route-map this means the ip address of our peer is used. For an -outgoing route-map this means the ip address of our self is used to -establish the peering with our neighbor. -``` -```{cfgcmd} set policy route-map \ rule \<1-65535\> set ipv6-next-hop \ \ - -Nexthop IPv6 address. -``` -```{cfgcmd} set policy route-map \ rule \<1-65535\> set ipv6-next-hop peer-address - -Set the BGP nexthop address to the address of the peer. For an incoming -route-map this means the ip address of our peer is used. For an -outgoing route-map this means the ip address of our self is used to -establish the peering with our neighbor. -``` -```{cfgcmd} set policy route-map \ rule \<1-65535\> set ipv6-next-hop prefer-global - -For Incoming and Import Route-maps if we receive a v6 global and v6 LL -address for the route, then prefer to use the global address as the -nexthop. -``` -```{cfgcmd} set policy route-map \ rule \<1-65535\> set local-preference \<0-4294967295\> - -Set BGP local preference attribute. -``` -```{cfgcmd} set policy route-map \ rule \<1-65535\> set metric \<+/-metric|0-4294967295|rtt|+rtt|-rtt\> - -Set the route metric. When used with BGP, set the BGP attribute MED -to a specific value. Use ``+/-`` to add or subtract the specified value -to/from the existing/MED. Use ``rtt`` to set the MED to the round trip -time or ``+rtt/-rtt`` to add/subtract the round trip time to/from the MED. -``` -```{cfgcmd} set policy route-map \ rule \<1-65535\> set metric-type \ - -Set OSPF external metric-type. -``` -```{cfgcmd} set policy route-map \ rule \<1-65535\> set origin \ - -Set BGP origin code. -``` -```{cfgcmd} set policy route-map \ rule \<1-65535\> set originator-id \ - -Set BGP originator ID attribute. -``` -```{cfgcmd} set policy route-map \ rule \<1-65535\> set src \ - -Set source IP/IPv6 address for route. -``` -```{cfgcmd} set policy route-map \ rule \<1-65535\> set table \<1-200\> - -Set prefixes to table. -``` -```{cfgcmd} set policy route-map \ rule \<1-65535\> set tag \<1-65535\> - -Set tag value for routing protocol. -``` -```{cfgcmd} set policy route-map \ rule \<1-65535\> set weight \<0-4294967295\> - -Set BGP weight attribute -``` - -### List of well-known communities - -> - `local-as` - Well-known communities value NO_EXPORT_SUBCONFED 0xFFFFFF03 -> - `no-advertise` - Well-known communities value NO_ADVERTISE 0xFFFFFF02 -> - `no-export` - Well-known communities value NO_EXPORT 0xFFFFFF01 -> - `graceful-shutdown` - Well-known communities value GRACEFUL_SHUTDOWN 0xFFFF0000 -> - `accept-own` - Well-known communities value ACCEPT_OWN 0xFFFF0001 -> - `route-filter-translated-v4` - Well-known communities value ROUTE_FILTER_TRANSLATED_v4 0xFFFF0002 -> - `route-filter-v4` - Well-known communities value ROUTE_FILTER_v4 0xFFFF0003 -> - `route-filter-translated-v6` - Well-known communities value ROUTE_FILTER_TRANSLATED_v6 0xFFFF0004 -> - `route-filter-v6` - Well-known communities value ROUTE_FILTER_v6 0xFFFF0005 -> - `llgr-stale` - Well-known communities value LLGR_STALE 0xFFFF0006 -> - `no-llgr` - Well-known communities value NO_LLGR 0xFFFF0007 -> - `accept-own-nexthop` - Well-known communities value accept-own-nexthop 0xFFFF0008 -> - `blackhole` - Well-known communities value BLACKHOLE 0xFFFF029A -> - `no-peer` - Well-known communities value NOPEER 0xFFFFFF04 diff --git a/docs/configuration/policy/md-route.md b/docs/configuration/policy/md-route.md deleted file mode 100644 index b3ef6540..00000000 --- a/docs/configuration/policy/md-route.md +++ /dev/null @@ -1,424 +0,0 @@ -# Route and Route6 Policy - -IPv4 route and IPv6 route policies are defined in this section. These route -policies can then be associated to interfaces. - -## Rule-Sets - -A rule-set is a named collection of rules that can be applied to an interface. -Each rule is numbered, has an action to apply if the rule is matched, and the -ability to specify the criteria to match. Data packets go through the rules -from 1 - 999999, at the first match the action of the rule will be executed. - -```{cfgcmd} set policy route \ description \ - -``` -```{cfgcmd} set policy route6 \ description \ - -Provide a rule-set description. -``` - -```{cfgcmd} set policy route \ default-log -``` - -```{cfgcmd} set policy route6 \ default-log - -Option to log packets hitting default-action. -``` - -```{cfgcmd} set policy route \ interface \ -``` - -```{cfgcmd} set policy route6 \ interface \ - -Apply routing policy to interface -``` - -```{cfgcmd} set policy route \ rule \ description \ -``` - -```{cfgcmd} set policy route6 \ rule \ description \ - -Provide a description for each rule. -``` - -```{cfgcmd} set policy route \ rule \ log \ -``` - -```{cfgcmd} set policy route6 \ rule \ log \ - -Option to enable or disable log matching rule. -``` - -### Matching criteria - -There are a lot of matching criteria options available, both for -`policy route` and `policy route6`. These options are listed -in this section. - -```{cfgcmd} set policy route \ rule \ connection-mark \<1-2147483647\> -``` - -```{cfgcmd} set policy route6 \ rule \ connection-mark \<1-2147483647\> - -Set match criteria based on connection mark. -``` - -```{cfgcmd} set policy route \ rule \ mark \ -``` - -```{cfgcmd} set policy route6 \ rule \ mark \ - -Match based on the firewall mark (fwmark), where \ can be: - * \<0-2147483647\> a single fwmark - * !\<0-2147483647\> everything except a single fwmark - * <start-end> a range of marks - * !<start-end> everything except the range of marks - -:::{note} -When using the ``set table`` or ``set vrf`` commands the mark -settings are ignored and overwritten with a table-specific mark that -is set to 0x7FFFFFFF - the id of the table/VRF. -::: -``` - -```{cfgcmd} set policy route \ rule \ source address \ -``` - -```{cfgcmd} set policy route \ rule \ destination address \ -``` - -```{cfgcmd} set policy route6 \ rule \ source address \ -``` - -```{cfgcmd} set policy route6 \ rule \ destination address \ - -Set match criteria based on source or destination ipv4|ipv6 address, where -<match_criteria> could be: -``` - -For ipv4: -: - \: IP address to match. - - \: Subnet to match. - - \-\: IP range to match. - - !\: Match everything except the specified address. - - !\: Match everything except the specified subnet. - - !\-\: Match everything except the specified range. - -And for ipv6: -: - \: IPv6 address to match. - - \: IPv6 prefix to match. - - \-\: IPv6 range to match. - - !\: Match everything except the specified address. - - !\: Match everything except the specified prefix. - - !\-\: Match everything except the - specified range. - -```{cfgcmd} set policy route \ rule \ source group \ \ -``` - -```{cfgcmd} set policy route \ rule \ destination group \ \ -``` - -```{cfgcmd} set policy route6 \ rule \ source group \ \ -``` - -```{cfgcmd} set policy route6 \ rule \ destination group \ \ - -Set match criteria based on source or destination groups, where <text> -would be the group name/identifier. Prepend character '!' for inverted -matching criteria. -``` - -```{cfgcmd} set policy route \ rule \ destination port \ -``` - -```{cfgcmd} set policy route6 \ rule \ destination port \ - -Set match criteria based on destination port, where \ could -be: -* <port name>: Named port (any name in /etc/services, e.g., http). -* \<1-65535\>: Numbered port. -* <start>-<end>: Numbered port range (e.g., 1001-1005). - -Multiple destination ports can be specified as a comma-separated list. The -whole list can also be "negated" using '!'. For example: -'!22,telnet,http,123,1001-1005' -``` - -```{cfgcmd} set policy route \ rule \ disable -``` - -```{cfgcmd} set policy route6 \ rule \ disable - -Option to disable rule. -``` - -```{cfgcmd} set policy route \ rule \ dscp \ -``` - -```{cfgcmd} set policy route6 \ rule \ dscp \ -``` - -```{cfgcmd} set policy route \ rule \ dscp-exclude \ -``` - -```{cfgcmd} set policy route6 \ rule \ dscp-exclude \ - -Match based on dscp value criteria. Multiple values from 0 to 63 -and ranges are supported. -``` - -```{cfgcmd} set policy route \ rule \ fragment \ -``` - -```{cfgcmd} set policy route6 \ rule \ fragment \ - -Set IP fragment match, where: -* match-frag: Second and further fragments of fragmented packets. -* match-non-frag: Head fragments or unfragmented packets. -``` - -```{cfgcmd} set policy route \ rule \ icmp \ -``` - -```{cfgcmd} set policy route6 \ rule \ icmpv6 \ - -Match based on icmp|icmpv6 code and type. -``` - -```{cfgcmd} set policy route \ rule \ icmp type-name \ -``` - -```{cfgcmd} set policy route6 \ rule \ icmpv6 type-name \ - -Match based on icmp|icmpv6 type-name criteria. Use tab for information -about what type-name criteria are supported. -``` - -```{cfgcmd} set policy route \ rule \ ipsec \ -``` - -```{cfgcmd} set policy route6 \ rule \ ipsec \ - -Set IPSec inbound match criterias, where: -* match-ipsec: match inbound IPsec packets. -* match-none: match inbound non-IPsec packets. -``` - -```{cfgcmd} set policy route \ rule \ limit burst \<0-4294967295\> -``` - -```{cfgcmd} set policy route6 \ rule \ limit burst \<0-4294967295\> - -Set maximum number of packets to allow in excess of rate. -``` - -```{cfgcmd} set policy route \ rule \ limit rate \ -``` - -```{cfgcmd} set policy route6 \ rule \ limit rate \ - -Set maximum average matching rate. Format for rate: integer/time_unit, where -time_unit could be any one of second, minute, hour or day.For example -1/second implies rule to be matched at an average of once per second. -``` - -```{cfgcmd} set policy route \ rule \ protocol \ -``` - -```{cfgcmd} set policy route6 \ rule \ protocol \ - -Match a protocol criteria. A protocol number or a name which is defined in: -``/etc/protocols``. Special names are ``all`` for all protocols and -``tcp_udp`` for tcp and udp based packets. The ``!`` negates the selected -protocol. -``` - -```{cfgcmd} set policy route \ rule \ packet-length \ -``` - -```{cfgcmd} set policy route6 \ rule \ packet-length \ -``` - -```{cfgcmd} set policy route \ rule \ packet-length-exclude \ -``` - -```{cfgcmd} set policy route6 \ rule \ packet-length-exclude \ - -Match based on packet length criteria. Multiple values from 1 to 65535 -and ranges are supported. -``` - -```{cfgcmd} set policy route \ rule \ packet-type \[broadcast | host | multicast | other\] -``` - -```{cfgcmd} set policy route6 \ rule \ packet-type \[broadcast | host | multicast | other\] - -Match based on packet type criteria. -``` - -```{cfgcmd} set policy route \ rule \ recent count \<1-255\> -``` - -```{cfgcmd} set policy route6 \ rule \ recent count \<1-255\> -``` - -```{cfgcmd} set policy route \ rule \ recent time \<1-4294967295\> -``` - -```{cfgcmd} set policy route6 \ rule \ recent time \<1-4294967295\> - -Set parameters for matching recently seen sources. This match could be used -by seeting count (source address seen more than <1-255> times) and/or time -(source address seen in the last <0-4294967295> seconds). -``` - -```{cfgcmd} set policy route \ rule \ state \ -``` - -```{cfgcmd} set policy route6 \ rule \ state \ - -Set match criteria based on session state. -``` - -```{cfgcmd} set policy route \ rule \ tcp flags \ -``` - -```{cfgcmd} set policy route6 \ rule \ tcp flags \ - -Set match criteria based on tcp flags. Allowed values for TCP flags: SYN ACK -FIN RST URG PSH ALL. When specifying more than one flag, flags should be -comma-separated. For example : value of 'SYN,!ACK,!FIN,!RST' will only match -packets with the SYN flag set, and the ACK, FIN and RST flags unset. -``` - -```{cfgcmd} set policy route \ rule \ time monthdays \ -``` - -```{cfgcmd} set policy route6 \ rule \ time monthdays \ -``` - -```{cfgcmd} set policy route \ rule \ time startdate \ -``` - -```{cfgcmd} set policy route6 \ rule \ time startdate \ -``` - -```{cfgcmd} set policy route \ rule \ time starttime \ -``` - -```{cfgcmd} set policy route6 \ rule \ time starttime \ -``` - -```{cfgcmd} set policy route \ rule \ time stopdate \ -``` - -```{cfgcmd} set policy route6 \ rule \ time stopdate \ -``` - -```{cfgcmd} set policy route \ rule \ time stoptime \ -``` - -```{cfgcmd} set policy route6 \ rule \ time stoptime \ -``` - -```{cfgcmd} set policy route \ rule \ time weekdays \ -``` - -```{cfgcmd} set policy route6 \ rule \ time weekdays \ -``` - -```{cfgcmd} set policy route \ rule \ time utc -``` - -```{cfgcmd} set policy route6 \ rule \ time utc - -Time to match the defined rule. -``` - -```{cfgcmd} set policy route rule \ ttl \ \<0-255\> - -Match time to live parameter, where 'eq' stands for 'equal'; 'gt' stands for -'greater than', and 'lt' stands for 'less than'. -``` - -```{cfgcmd} set policy route6 rule \ hop-limit \ \<0-255\> - -Match hop-limit parameter, where 'eq' stands for 'equal'; 'gt' stands for -'greater than', and 'lt' stands for 'less than'. -``` - -### Actions - -When matching all patterns defined in a rule, then different actions can -be made. This includes dropping the packet, modifying certain data, or -setting a different routing table. - -```{cfgcmd} set policy route \ rule \ action drop -``` - -```{cfgcmd} set policy route6 \ rule \ action drop - -Set rule action to drop. -``` - -```{cfgcmd} set policy route \ rule \ set connection-mark \<1-2147483647\> -``` - -```{cfgcmd} set policy route6 \ rule \ set connection-mark \<1-2147483647\> - -Set a specific connection mark. -``` - -```{cfgcmd} set policy route \ rule \ set dscp \<0-63\> -``` - -```{cfgcmd} set policy route6 \ rule \ set dscp \<0-63\> - -Set packet modifications: Packet Differentiated Services Codepoint (DSCP) -``` - -```{cfgcmd} set policy route \ rule \ set mark \<1-2147483647\> -``` - -```{cfgcmd} set policy route6 \ rule \ set mark \<1-2147483647\> - -Set a specific packet mark. -``` - -```{cfgcmd} set policy route \ rule \ set table \
-``` - -```{cfgcmd} set policy route6 \ rule \ set table \
- -Set the routing table to forward packet with. - -:::{note} -When using the ``set table`` or ``set vrf`` commands matching -against the mark is not possible, because it gets overwritten with a -table-specific mark that is 0x7FFFFFFF - the id of the table/VRF. -::: -``` - -```{cfgcmd} set policy route \ rule \ set tcp-mss \<500-1460\> -``` - -```{cfgcmd} set policy route6 \ rule \ set tcp-mss \<500-1460\> - -Set packet modifications: Explicitly set TCP Maximum segment size value. -``` - -```{cfgcmd} set policy route \ rule \ set vrf \ -``` - -```{cfgcmd} set policy route6 \ rule \ set vrf \ - -Set the VRF to forward packet with. - -:::{note} -When using the ``set table`` or ``set vrf`` commands matching -against the mark is not possible, because it gets overwritten with a -table-specific mark that is 0x7FFFFFFF - the id of the table/VRF. -::: -``` \ No newline at end of file diff --git a/docs/configuration/policy/prefix-list.md b/docs/configuration/policy/prefix-list.md new file mode 100644 index 00000000..eb827c77 --- /dev/null +++ b/docs/configuration/policy/prefix-list.md @@ -0,0 +1,152 @@ +# Prefix List Policy + +Prefix lists provides the most powerful prefix based filtering mechanism. In +addition to access-list functionality, ip prefix-list has prefix length range +specification. + +If no ip prefix list is specified, it acts as permit. If ip prefix list is +defined, and no match is found, default deny is applied. + +Prefix filtering can be done using prefix-list and prefix-list6. + +## Configuration + +### IPv4 Prefix Lists (prefix-list) + +```{cfgcmd} set policy prefix-list \ + +This command creates the new prefix-list policy, identified by ``. +``` + +```{cfgcmd} set policy prefix-list \ description \ + +Set description for the prefix-list policy. +``` + +```{cfgcmd} set policy prefix-list \ rule \<1-65535\> action \ + +This command creates a new rule in the prefix-list and defines an action. +``` + +```{cfgcmd} set policy prefix-list \ rule \<1-65535\> description \ + +Set description for rule in the prefix-list. +``` + +```{cfgcmd} set policy prefix-list \ rule \<1-65535\> prefix \ + +Prefix to match against. +``` + +```{cfgcmd} set policy prefix-list \ rule \<1-65535\> ge \<0-32\> + +Netmask greater than length. +``` + +```{cfgcmd} set policy prefix-list \ rule \<1-65535\> le \<0-32\> + +Netmask less than length +``` + + +### Example: IPv4 Prefix Lists (prefix-list) + +This example creates an IPv4 prefix-list named PL4-EXAMPLE-NAME, defines 3 +rules each with 1 prefix, and matches le (less than/equal to) /32. + +```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 10 action 'permit' + +``` +```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 10 le '32' +``` + +```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 10 prefix '192.0.2.0/24' +``` + +```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 20 action 'permit' +``` + +```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 20 le '32' +``` + +```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 20 prefix '198.51.100.0/24' +``` + +```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 30 action 'permit' +``` + +```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 30 le '32' +``` + +```{cfgcmd} set policy prefix-list PL4-EXAMPLE-NAME rule 30 prefix '203.0.113.0/24' +``` + +### IPv6 Prefix Lists (prefix-list6) + +```{cfgcmd} set policy prefix-list6 \ + +This command creates the new IPv6 prefix-list policy, identified by ``. +``` + +```{cfgcmd} set policy prefix-list6 \ description \ + +Set description for the IPv6 prefix-list policy. +``` + +```{cfgcmd} set policy prefix-list6 \ rule \<1-65535\> action \ + +This command creates a new rule in the IPv6 prefix-list and defines an +action. +``` + +```{cfgcmd} set policy prefix-list6 \ rule \<1-65535\> description \ + +Set description for rule in IPv6 prefix-list. +``` + +```{cfgcmd} set policy prefix-list6 \ rule \<1-65535\> prefix \ + +IPv6 prefix. +``` + +```{cfgcmd} set policy prefix-list6 \ rule \<1-65535\> ge \<0-128\> + +Netmask greater than length. +``` + +```{cfgcmd} set policy prefix-list6 \ rule \<1-65535\> le \<0-128\> + +Netmask less than length +``` + +### Example: IPv6 Prefix Lists (prefix-list6) + +This example creates an IPv6 prefix-list6 named PL6-EXAMPLE-NAME, defines 3 +rules each with 1 prefix, and matches le (less than/equal to) /128. + +```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 10 action 'permit' +``` + +```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 10 le '128' +``` + +```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 10 prefix '2001:db8:0:0::/64' +``` + +```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 20 action 'permit' +``` + +```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 20 le '128' +``` + +```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 20 prefix '2001:db8:0:1::/64' +``` + +```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 30 action 'permit' +``` + +```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 30 le '128' +``` + +```{cfgcmd} set policy prefix-list6 PL6-EXAMPLE-NAME rule 30 prefix '2001:db8:0:2::/64' +``` \ No newline at end of file diff --git a/docs/configuration/policy/prefix-list.rst b/docs/configuration/policy/prefix-list.rst deleted file mode 100644 index 98df1b9b..00000000 --- a/docs/configuration/policy/prefix-list.rst +++ /dev/null @@ -1,112 +0,0 @@ -################## -Prefix List Policy -################## - -Prefix lists provides the most powerful prefix based filtering mechanism. In -addition to access-list functionality, ip prefix-list has prefix length range -specification. - -If no ip prefix list is specified, it acts as permit. If ip prefix list is -defined, and no match is found, default deny is applied. - -Prefix filtering can be done using prefix-list and prefix-list6. - -************* -Configuration -************* - -IPv4 Prefix Lists (prefix-list) -============ - -.. cfgcmd:: set policy prefix-list - - This command creates the new prefix-list policy, identified by . - -.. cfgcmd:: set policy prefix-list description - - Set description for the prefix-list policy. - -.. cfgcmd:: set policy prefix-list rule <1-65535> action - - This command creates a new rule in the prefix-list and defines an action. - -.. cfgcmd:: set policy prefix-list rule <1-65535> description - - Set description for rule in the prefix-list. - -.. cfgcmd:: set policy prefix-list rule <1-65535> prefix - - Prefix to match against. - -.. cfgcmd:: set policy prefix-list rule <1-65535> ge <0-32> - - Netmask greater than length. - -.. cfgcmd:: set policy prefix-list rule <1-65535> le <0-32> - - Netmask less than length - -Example: IPv4 Prefix Lists (prefix-list) -============ - -This example creates an IPv4 prefix-list named PL4-EXAMPLE-NAME, defines 3 -rules each with 1 prefix, and matches le (less than/equal to) /32. - -.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 10 action 'permit' -.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 10 le '32' -.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 10 prefix '192.0.2.0/24' -.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 20 action 'permit' -.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 20 le '32' -.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 20 prefix '198.51.100.0/24' -.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 30 action 'permit' -.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 30 le '32' -.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 30 prefix '203.0.113.0/24' - -IPv6 Prefix Lists (prefix-list6) -================= - -.. cfgcmd:: set policy prefix-list6 - - This command creates the new IPv6 prefix-list policy, identified by . - -.. cfgcmd:: set policy prefix-list6 description - - Set description for the IPv6 prefix-list policy. - -.. cfgcmd:: set policy prefix-list6 rule <1-65535> action - - This command creates a new rule in the IPv6 prefix-list and defines an - action. - -.. cfgcmd:: set policy prefix-list6 rule <1-65535> description - - Set description for rule in IPv6 prefix-list. - -.. cfgcmd:: set policy prefix-list6 rule <1-65535> prefix - - - IPv6 prefix. - -.. cfgcmd:: set policy prefix-list6 rule <1-65535> ge <0-128> - - Netmask greater than length. - -.. cfgcmd:: set policy prefix-list6 rule <1-65535> le <0-128> - - Netmask less than length - -Example: IPv6 Prefix Lists (prefix-list6) -============ - -This example creates an IPv6 prefix-list6 named PL6-EXAMPLE-NAME, defines 3 -rules each with 1 prefix, and matches le (less than/equal to) /128. - -.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 10 action 'permit' -.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 10 le '128' -.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 10 prefix '2001:db8:0:0::/64' -.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 20 action 'permit' -.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 20 le '128' -.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 20 prefix '2001:db8:0:1::/64' -.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 30 action 'permit' -.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 30 le '128' -.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 30 prefix '2001:db8:0:2::/64' \ No newline at end of file diff --git a/docs/configuration/policy/route-map.md b/docs/configuration/policy/route-map.md new file mode 100644 index 00000000..cf419a48 --- /dev/null +++ b/docs/configuration/policy/route-map.md @@ -0,0 +1,439 @@ +# Route Map Policy + +Route map is a powerful command, that gives network administrators a very +useful and flexible tool for traffic manipulation. + +## Configuration + +### Route Map + +```{cfgcmd} set policy route-map \ + + This command creates a new route-map policy, identified by \. +``` + + +```{cfgcmd} set policy route-map \ description \ + +Set description for the route-map policy. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> action \ + +Set action for the route-map policy. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> call \ + +Call another route-map policy on match. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> continue \<1-65535\> + +Jump to a different rule in this route-map on a match. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> description \ + +Set description for the rule in the route-map policy. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match as-path \ + +BGP as-path list to match. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match community community-list \ + +BGP community-list to match. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match community exact-match + +Set BGP community-list to exactly match. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match extcommunity \ + +BGP extended community to match. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match interface \ + +First hop interface of a route to match. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip address access-list \<1-2699\> + +IP address of route to match, based on access-list. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip address prefix-list \ + +IP address of route to match, based on prefix-list. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip address prefix-len \<0-32\> + +IP address of route to match, based on specified prefix-length. +Note that this can be used for kernel routes only. +Do not apply to the routes of dynamic routing protocols (e.g. BGP, +RIP, OSFP), as this can lead to unexpected results.. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip nexthop access-list \<1-2699\> + +IP next-hop of route to match, based on access-list. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip nexthop address \ + +IP next-hop of route to match, based on ip address. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip nexthop prefix-len \<0-32\> + +IP next-hop of route to match, based on prefix length. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip nexthop prefix-list \ + +IP next-hop of route to match, based on prefix-list. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip nexthop type \ + +IP next-hop of route to match, based on type. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip route-source access-list \<1-2699\> + +IP route source of route to match, based on access-list. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match ip route-source prefix-list \ + +IP route source of route to match, based on prefix-list. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match ipv6 address access-list \ + +IPv6 address of route to match, based on IPv6 access-list. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match ipv6 address prefix-list \ + +IPv6 address of route to match, based on IPv6 prefix-list. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match ipv6 address prefix-len \<0-128\> + +IPv6 address of route to match, based on specified prefix-length. +Note that this can be used for kernel routes only. +Do not apply to the routes of dynamic routing protocols (e.g. BGP, +RIP, OSFP), as this can lead to unexpected results.. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match ipv6 nexthop \ + +Nexthop IPv6 address to match. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match large-community large-community-list \ + +Match BGP large communities. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match local-preference \<0-4294967295\> + +Match local preference. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match metric \<1-65535\> + +Match route metric. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match origin \ + +Boarder Gateway Protocol (BGP) origin code to match. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match peer \ + +Peer IP address to match. +``` + + +````{cfgcmd} set policy route-map \ rule \<1-65535\> match protocol \ + +```{eval-rst} +Source protocol to match. + * ``babel`` - Babel routing protocol (Babel) + * ``bgp`` - Border Gateway Protocol (BGP) + * ``connected`` - Connected routes (directly attached subnet or host) + * ``isis`` - Intermediate System to Intermediate System (IS-IS) + * ``kernel`` - Kernel routes + * ``ospf`` - Open Shortest Path First (OSPFv2) + * ``ospfv3`` - Open Shortest Path First (IPv6) (OSPFv3) + * ``rip`` - Routing Information Protocol (RIP) + * ``ripng`` - Routing Information Protocol next-generation (IPv6) (RIPng) + * ``static`` - Statically configured routes + * ``table`` - Non-main Kernel Routing Table + * ``vnc`` - Virtual Network Control (VNC) +``` +```` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match rpki \ + +Match RPKI validation result. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match source-vrf \ + +Source VRF to match. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> match tag \<1-65535\> + +Route tag to match. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> on-match goto \<1-65535\> + +Exit policy on match: go to rule <1-65535> +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> on-match next + +Exit policy on match: go to next sequence number. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set aggregator \ \<1-4294967295|x.x.x.x\> + +BGP aggregator attribute: AS number or IP address of an aggregation. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set as-path exclude \<1-4294967295 | all\> + +Drop AS-NUMBER from the BGP AS path. + +If ``all`` is specified, remove all AS numbers from the AS_PATH of the BGP +path's NLRI. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set as-path prepend \<1-4294967295\> + +Prepend the given string of AS numbers to the AS_PATH of the BGP path's NLRI. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set as-path prepend-last-as \ + +Prepend the existing last AS number (the leftmost ASN) to the AS_PATH. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set atomic-aggregate + +BGP atomic aggregate attribute. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set community \ \ + +Add or replace BGP community attribute in format ``<0-65535:0-65535>`` +or from well-known community list +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set community none + +Delete all BGP communities +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set community delete \ + +Delete BGP communities matching the community-list. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set large-community \ \ + +Add or replace BGP large-community attribute in format +``<0-4294967295:0-4294967295:0-4294967295>`` +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set large-community none + +Delete all BGP large-communities +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set large-community delete \ + +Delete BGP communities matching the large-community-list. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set extcommunity bandwidth \<1-25600|cumulative|num-multipaths\> + +Set extcommunity bandwidth +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set extcommunity bandwidth-non-transitive + +The link bandwidth extended community is encoded as non-transitive +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set extcommunity rt \ + +Set route target value in format ``<0-65535:0-4294967295>`` or ````. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set extcommunity soo \ + +Set site of origin value in format ``<0-65535:0-4294967295>`` or ````. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set extcommunity none + +Clear all BGP extcommunities. +``` + + +```{cfgcmd} set policy route-map \ rule \<1-65535\> set distance \<0-255\> + +Locally significant administrative distance. +``` +```{cfgcmd} set policy route-map \ rule \<1-65535\> set ip-next-hop \ + +Nexthop IP address. +``` +```{cfgcmd} set policy route-map \ rule \<1-65535\> set ip-next-hop unchanged + +Set the next-hop as unchanged. Pass through the route-map without +changing its value +``` +```{cfgcmd} set policy route-map \ rule \<1-65535\> set ip-next-hop peer-address + +Set the BGP nexthop address to the address of the peer. For an incoming +route-map this means the ip address of our peer is used. For an +outgoing route-map this means the ip address of our self is used to +establish the peering with our neighbor. +``` +```{cfgcmd} set policy route-map \ rule \<1-65535\> set ipv6-next-hop \ \ + +Nexthop IPv6 address. +``` +```{cfgcmd} set policy route-map \ rule \<1-65535\> set ipv6-next-hop peer-address + +Set the BGP nexthop address to the address of the peer. For an incoming +route-map this means the ip address of our peer is used. For an +outgoing route-map this means the ip address of our self is used to +establish the peering with our neighbor. +``` +```{cfgcmd} set policy route-map \ rule \<1-65535\> set ipv6-next-hop prefer-global + +For Incoming and Import Route-maps if we receive a v6 global and v6 LL +address for the route, then prefer to use the global address as the +nexthop. +``` +```{cfgcmd} set policy route-map \ rule \<1-65535\> set local-preference \<0-4294967295\> + +Set BGP local preference attribute. +``` +```{cfgcmd} set policy route-map \ rule \<1-65535\> set metric \<+/-metric|0-4294967295|rtt|+rtt|-rtt\> + +Set the route metric. When used with BGP, set the BGP attribute MED +to a specific value. Use ``+/-`` to add or subtract the specified value +to/from the existing/MED. Use ``rtt`` to set the MED to the round trip +time or ``+rtt/-rtt`` to add/subtract the round trip time to/from the MED. +``` +```{cfgcmd} set policy route-map \ rule \<1-65535\> set metric-type \ + +Set OSPF external metric-type. +``` +```{cfgcmd} set policy route-map \ rule \<1-65535\> set origin \ + +Set BGP origin code. +``` +```{cfgcmd} set policy route-map \ rule \<1-65535\> set originator-id \ + +Set BGP originator ID attribute. +``` +```{cfgcmd} set policy route-map \ rule \<1-65535\> set src \ + +Set source IP/IPv6 address for route. +``` +```{cfgcmd} set policy route-map \ rule \<1-65535\> set table \<1-200\> + +Set prefixes to table. +``` +```{cfgcmd} set policy route-map \ rule \<1-65535\> set tag \<1-65535\> + +Set tag value for routing protocol. +``` +```{cfgcmd} set policy route-map \ rule \<1-65535\> set weight \<0-4294967295\> + +Set BGP weight attribute +``` + +### List of well-known communities + +> - `local-as` - Well-known communities value NO_EXPORT_SUBCONFED 0xFFFFFF03 +> - `no-advertise` - Well-known communities value NO_ADVERTISE 0xFFFFFF02 +> - `no-export` - Well-known communities value NO_EXPORT 0xFFFFFF01 +> - `graceful-shutdown` - Well-known communities value GRACEFUL_SHUTDOWN 0xFFFF0000 +> - `accept-own` - Well-known communities value ACCEPT_OWN 0xFFFF0001 +> - `route-filter-translated-v4` - Well-known communities value ROUTE_FILTER_TRANSLATED_v4 0xFFFF0002 +> - `route-filter-v4` - Well-known communities value ROUTE_FILTER_v4 0xFFFF0003 +> - `route-filter-translated-v6` - Well-known communities value ROUTE_FILTER_TRANSLATED_v6 0xFFFF0004 +> - `route-filter-v6` - Well-known communities value ROUTE_FILTER_v6 0xFFFF0005 +> - `llgr-stale` - Well-known communities value LLGR_STALE 0xFFFF0006 +> - `no-llgr` - Well-known communities value NO_LLGR 0xFFFF0007 +> - `accept-own-nexthop` - Well-known communities value accept-own-nexthop 0xFFFF0008 +> - `blackhole` - Well-known communities value BLACKHOLE 0xFFFF029A +> - `no-peer` - Well-known communities value NOPEER 0xFFFFFF04 diff --git a/docs/configuration/policy/route-map.rst b/docs/configuration/policy/route-map.rst deleted file mode 100644 index a2313466..00000000 --- a/docs/configuration/policy/route-map.rst +++ /dev/null @@ -1,383 +0,0 @@ -################ -Route Map Policy -################ - -Route map is a powerfull command, that gives network administrators a very -useful and flexible tool for traffic manipulation. - -************* -Configuration -************* - -Route Map -========= - -.. cfgcmd:: set policy route-map - - This command creates a new route-map policy, identified by . - -.. cfgcmd:: set policy route-map description - - Set description for the route-map policy. - -.. cfgcmd:: set policy route-map rule <1-65535> action - - Set action for the route-map policy. - -.. cfgcmd:: set policy route-map rule <1-65535> call - - Call another route-map policy on match. - -.. cfgcmd:: set policy route-map rule <1-65535> continue <1-65535> - - Jump to a different rule in this route-map on a match. - -.. cfgcmd:: set policy route-map rule <1-65535> description - - Set description for the rule in the route-map policy. - -.. cfgcmd:: set policy route-map rule <1-65535> match as-path - - BGP as-path list to match. - -.. cfgcmd:: set policy route-map rule <1-65535> match community - community-list - - BGP community-list to match. - -.. cfgcmd:: set policy route-map rule <1-65535> match community - exact-match - - Set BGP community-list to exactly match. - -.. cfgcmd:: set policy route-map rule <1-65535> match extcommunity - - - BGP extended community to match. - -.. cfgcmd:: set policy route-map rule <1-65535> match interface - - First hop interface of a route to match. - -.. cfgcmd:: set policy route-map rule <1-65535> match ip address - access-list <1-2699> - - IP address of route to match, based on access-list. - -.. cfgcmd:: set policy route-map rule <1-65535> match ip address - prefix-list - - IP address of route to match, based on prefix-list. - -.. cfgcmd:: set policy route-map rule <1-65535> match ip address - prefix-len <0-32> - - IP address of route to match, based on specified prefix-length. - Note that this can be used for kernel routes only. - Do not apply to the routes of dynamic routing protocols (e.g. BGP, - RIP, OSFP), as this can lead to unexpected results.. - -.. cfgcmd:: set policy route-map rule <1-65535> match ip nexthop - access-list <1-2699> - - IP next-hop of route to match, based on access-list. - -.. cfgcmd:: set policy route-map rule <1-65535> match ip nexthop - address - - IP next-hop of route to match, based on ip address. - -.. cfgcmd:: set policy route-map rule <1-65535> match ip nexthop - prefix-len <0-32> - - IP next-hop of route to match, based on prefix length. - -.. cfgcmd:: set policy route-map rule <1-65535> match ip nexthop - prefix-list - - IP next-hop of route to match, based on prefix-list. - -.. cfgcmd:: set policy route-map rule <1-65535> match ip nexthop - type - - IP next-hop of route to match, based on type. - -.. cfgcmd:: set policy route-map rule <1-65535> match ip route-source - access-list <1-2699> - - IP route source of route to match, based on access-list. - -.. cfgcmd:: set policy route-map rule <1-65535> match ip route-source - prefix-list - - IP route source of route to match, based on prefix-list. - -.. cfgcmd:: set policy route-map rule <1-65535> match ipv6 address - access-list - - IPv6 address of route to match, based on IPv6 access-list. - -.. cfgcmd:: set policy route-map rule <1-65535> match ipv6 address - prefix-list - - IPv6 address of route to match, based on IPv6 prefix-list. - -.. cfgcmd:: set policy route-map rule <1-65535> match ipv6 address - prefix-len <0-128> - - IPv6 address of route to match, based on specified prefix-length. - Note that this can be used for kernel routes only. - Do not apply to the routes of dynamic routing protocols (e.g. BGP, - RIP, OSFP), as this can lead to unexpected results.. - -.. cfgcmd:: set policy route-map rule <1-65535> match ipv6 nexthop - - - Nexthop IPv6 address to match. - -.. cfgcmd:: set policy route-map rule <1-65535> match large-community - large-community-list - - Match BGP large communities. - -.. cfgcmd:: set policy route-map rule <1-65535> match local-preference - <0-4294967295> - - Match local preference. - -.. cfgcmd:: set policy route-map rule <1-65535> match metric <1-65535> - - Match route metric. - -.. cfgcmd:: set policy route-map rule <1-65535> match origin - - - Boarder Gateway Protocol (BGP) origin code to match. - -.. cfgcmd:: set policy route-map rule <1-65535> match peer - - Peer IP address to match. - -.. cfgcmd:: set policy route-map rule <1-65535> match protocol - - Source protocol to match. - * ``babel`` - Babel routing protocol (Babel) - * ``bgp`` - Border Gateway Protocol (BGP) - * ``connected`` - Connected routes (directly attached subnet or host) - * ``isis`` - Intermediate System to Intermediate System (IS-IS) - * ``kernel`` - Kernel routes - * ``ospf`` - Open Shortest Path First (OSPFv2) - * ``ospfv3`` - Open Shortest Path First (IPv6) (OSPFv3) - * ``rip`` - Routing Information Protocol (RIP) - * ``ripng`` - Routing Information Protocol next-generation (IPv6) (RIPng) - * ``static`` - Statically configured routes - * ``table`` - Non-main Kernel Routing Table - * ``vnc`` - Virtual Network Control (VNC) - -.. cfgcmd:: set policy route-map rule <1-65535> match rpki - - - Match RPKI validation result. - -.. cfgcmd:: set policy route-map rule <1-65535> match source-vrf - - Source VRF to match. - -.. cfgcmd:: set policy route-map rule <1-65535> match tag <1-65535> - - Route tag to match. - -.. cfgcmd:: set policy route-map rule <1-65535> on-match goto <1-65535> - - Exit policy on match: go to rule <1-65535> - -.. cfgcmd:: set policy route-map rule <1-65535> on-match next - - Exit policy on match: go to next sequence number. - -.. cfgcmd:: set policy route-map rule <1-65535> set aggregator - <1-4294967295|x.x.x.x> - - BGP aggregator attribute: AS number or IP address of an aggregation. - -.. cfgcmd:: set policy route-map rule <1-65535> set as-path exclude - <1-4294967295 | all> - - Drop AS-NUMBER from the BGP AS path. - - If ``all`` is specified, remove all AS numbers from the AS_PATH of the BGP - path's NLRI. - -.. cfgcmd:: set policy route-map rule <1-65535> set as-path prepend - <1-4294967295> - - Prepend the given string of AS numbers to the AS_PATH of the BGP path's NLRI. - -.. cfgcmd:: set policy route-map rule <1-65535> set as-path - prepend-last-as - - Prepend the existing last AS number (the leftmost ASN) to the AS_PATH. - -.. cfgcmd:: set policy route-map rule <1-65535> set atomic-aggregate - - BGP atomic aggregate attribute. - -.. cfgcmd:: set policy route-map rule <1-65535> set community - - - Add or replace BGP community attribute in format ``<0-65535:0-65535>`` - or from well-known community list - -.. cfgcmd:: set policy route-map rule <1-65535> set community none - - Delete all BGP communities - -.. cfgcmd:: set policy route-map rule <1-65535> set community delete - - - Delete BGP communities matching the community-list. - -.. cfgcmd:: set policy route-map rule <1-65535> set large-community - - - Add or replace BGP large-community attribute in format - ``<0-4294967295:0-4294967295:0-4294967295>`` - -.. cfgcmd:: set policy route-map rule <1-65535> set large-community none - - Delete all BGP large-communities - -.. cfgcmd:: set policy route-map rule <1-65535> set large-community delete - - - Delete BGP communities matching the large-community-list. - -.. cfgcmd:: set policy route-map rule <1-65535> set extcommunity bandwidth - <1-25600|cumulative|num-multipaths> - - Set extcommunity bandwidth - -.. cfgcmd:: set policy route-map rule <1-65535> set extcommunity bandwidth-non-transitive - - The link bandwidth extended community is encoded as non-transitive - -.. cfgcmd:: set policy route-map rule <1-65535> set extcommunity rt - - - Set route target value in format ``<0-65535:0-4294967295>`` or ````. - -.. cfgcmd:: set policy route-map rule <1-65535> set extcommunity soo - - - Set site of origin value in format ``<0-65535:0-4294967295>`` or ````. - -.. cfgcmd:: set policy route-map rule <1-65535> set extcommunity none - - Clear all BGP extcommunities. - -.. cfgcmd:: set policy route-map rule <1-65535> set distance <0-255> - - Locally significant administrative distance. - - -.. cfgcmd:: set policy route-map rule <1-65535> set ip-next-hop - - - Nexthop IP address. - -.. cfgcmd:: set policy route-map rule <1-65535> set ip-next-hop - unchanged - - Set the next-hop as unchanged. Pass through the route-map without - changing its value - -.. cfgcmd:: set policy route-map rule <1-65535> set ip-next-hop - peer-address - - Set the BGP nexthop address to the address of the peer. For an incoming - route-map this means the ip address of our peer is used. For an - outgoing route-map this means the ip address of our self is used to - establish the peering with our neighbor. - -.. cfgcmd:: set policy route-map rule <1-65535> set ipv6-next-hop - - - Nexthop IPv6 address. - -.. cfgcmd:: set policy route-map rule <1-65535> set ipv6-next-hop - peer-address - - Set the BGP nexthop address to the address of the peer. For an incoming - route-map this means the ip address of our peer is used. For an - outgoing route-map this means the ip address of our self is used to - establish the peering with our neighbor. - -.. cfgcmd:: set policy route-map rule <1-65535> set ipv6-next-hop - prefer-global - - For Incoming and Import Route-maps if we receive a v6 global and v6 LL - address for the route, then prefer to use the global address as the - nexthop. - -.. cfgcmd:: set policy route-map rule <1-65535> set local-preference - <0-4294967295> - - Set BGP local preference attribute. - -.. cfgcmd:: set policy route-map rule <1-65535> set metric - <+/-metric|0-4294967295|rtt|+rtt|-rtt> - - Set the route metric. When used with BGP, set the BGP attribute MED - to a specific value. Use ``+/-`` to add or subtract the specified value - to/from the existing/MED. Use ``rtt`` to set the MED to the round trip - time or ``+rtt/-rtt`` to add/subtract the round trip time to/from the MED. - -.. cfgcmd:: set policy route-map rule <1-65535> set metric-type - - - Set OSPF external metric-type. - -.. cfgcmd:: set policy route-map rule <1-65535> set origin - - - Set BGP origin code. - -.. cfgcmd:: set policy route-map rule <1-65535> set originator-id - - - Set BGP originator ID attribute. - -.. cfgcmd:: set policy route-map rule <1-65535> set src - - - Set source IP/IPv6 address for route. - -.. cfgcmd:: set policy route-map rule <1-65535> set table <1-200> - - Set prefixes to table. - -.. cfgcmd:: set policy route-map rule <1-65535> set tag <1-65535> - - Set tag value for routing protocol. - -.. cfgcmd:: set policy route-map rule <1-65535> set weight - <0-4294967295> - - Set BGP weight attribute - -List of well-known communities -============================== - * ``local-as`` - Well-known communities value NO_EXPORT_SUBCONFED 0xFFFFFF03 - * ``no-advertise`` - Well-known communities value NO_ADVERTISE 0xFFFFFF02 - * ``no-export`` - Well-known communities value NO_EXPORT 0xFFFFFF01 - * ``graceful-shutdown`` - Well-known communities value GRACEFUL_SHUTDOWN 0xFFFF0000 - * ``accept-own`` - Well-known communities value ACCEPT_OWN 0xFFFF0001 - * ``route-filter-translated-v4`` - Well-known communities value ROUTE_FILTER_TRANSLATED_v4 0xFFFF0002 - * ``route-filter-v4`` - Well-known communities value ROUTE_FILTER_v4 0xFFFF0003 - * ``route-filter-translated-v6`` - Well-known communities value ROUTE_FILTER_TRANSLATED_v6 0xFFFF0004 - * ``route-filter-v6`` - Well-known communities value ROUTE_FILTER_v6 0xFFFF0005 - * ``llgr-stale`` - Well-known communities value LLGR_STALE 0xFFFF0006 - * ``no-llgr`` - Well-known communities value NO_LLGR 0xFFFF0007 - * ``accept-own-nexthop`` - Well-known communities value accept-own-nexthop 0xFFFF0008 - * ``blackhole`` - Well-known communities value BLACKHOLE 0xFFFF029A - * ``no-peer`` - Well-known communities value NOPEER 0xFFFFFF04 diff --git a/docs/configuration/policy/route.md b/docs/configuration/policy/route.md new file mode 100644 index 00000000..b3ef6540 --- /dev/null +++ b/docs/configuration/policy/route.md @@ -0,0 +1,424 @@ +# Route and Route6 Policy + +IPv4 route and IPv6 route policies are defined in this section. These route +policies can then be associated to interfaces. + +## Rule-Sets + +A rule-set is a named collection of rules that can be applied to an interface. +Each rule is numbered, has an action to apply if the rule is matched, and the +ability to specify the criteria to match. Data packets go through the rules +from 1 - 999999, at the first match the action of the rule will be executed. + +```{cfgcmd} set policy route \ description \ + +``` +```{cfgcmd} set policy route6 \ description \ + +Provide a rule-set description. +``` + +```{cfgcmd} set policy route \ default-log +``` + +```{cfgcmd} set policy route6 \ default-log + +Option to log packets hitting default-action. +``` + +```{cfgcmd} set policy route \ interface \ +``` + +```{cfgcmd} set policy route6 \ interface \ + +Apply routing policy to interface +``` + +```{cfgcmd} set policy route \ rule \ description \ +``` + +```{cfgcmd} set policy route6 \ rule \ description \ + +Provide a description for each rule. +``` + +```{cfgcmd} set policy route \ rule \ log \ +``` + +```{cfgcmd} set policy route6 \ rule \ log \ + +Option to enable or disable log matching rule. +``` + +### Matching criteria + +There are a lot of matching criteria options available, both for +`policy route` and `policy route6`. These options are listed +in this section. + +```{cfgcmd} set policy route \ rule \ connection-mark \<1-2147483647\> +``` + +```{cfgcmd} set policy route6 \ rule \ connection-mark \<1-2147483647\> + +Set match criteria based on connection mark. +``` + +```{cfgcmd} set policy route \ rule \ mark \ +``` + +```{cfgcmd} set policy route6 \ rule \ mark \ + +Match based on the firewall mark (fwmark), where \ can be: + * \<0-2147483647\> a single fwmark + * !\<0-2147483647\> everything except a single fwmark + * <start-end> a range of marks + * !<start-end> everything except the range of marks + +:::{note} +When using the ``set table`` or ``set vrf`` commands the mark +settings are ignored and overwritten with a table-specific mark that +is set to 0x7FFFFFFF - the id of the table/VRF. +::: +``` + +```{cfgcmd} set policy route \ rule \ source address \ +``` + +```{cfgcmd} set policy route \ rule \ destination address \ +``` + +```{cfgcmd} set policy route6 \ rule \ source address \ +``` + +```{cfgcmd} set policy route6 \ rule \ destination address \ + +Set match criteria based on source or destination ipv4|ipv6 address, where +<match_criteria> could be: +``` + +For ipv4: +: - \: IP address to match. + - \: Subnet to match. + - \-\: IP range to match. + - !\: Match everything except the specified address. + - !\: Match everything except the specified subnet. + - !\-\: Match everything except the specified range. + +And for ipv6: +: - \: IPv6 address to match. + - \: IPv6 prefix to match. + - \-\: IPv6 range to match. + - !\: Match everything except the specified address. + - !\: Match everything except the specified prefix. + - !\-\: Match everything except the + specified range. + +```{cfgcmd} set policy route \ rule \ source group \ \ +``` + +```{cfgcmd} set policy route \ rule \ destination group \ \ +``` + +```{cfgcmd} set policy route6 \ rule \ source group \ \ +``` + +```{cfgcmd} set policy route6 \ rule \ destination group \ \ + +Set match criteria based on source or destination groups, where <text> +would be the group name/identifier. Prepend character '!' for inverted +matching criteria. +``` + +```{cfgcmd} set policy route \ rule \ destination port \ +``` + +```{cfgcmd} set policy route6 \ rule \ destination port \ + +Set match criteria based on destination port, where \ could +be: +* <port name>: Named port (any name in /etc/services, e.g., http). +* \<1-65535\>: Numbered port. +* <start>-<end>: Numbered port range (e.g., 1001-1005). + +Multiple destination ports can be specified as a comma-separated list. The +whole list can also be "negated" using '!'. For example: +'!22,telnet,http,123,1001-1005' +``` + +```{cfgcmd} set policy route \ rule \ disable +``` + +```{cfgcmd} set policy route6 \ rule \ disable + +Option to disable rule. +``` + +```{cfgcmd} set policy route \ rule \ dscp \ +``` + +```{cfgcmd} set policy route6 \ rule \ dscp \ +``` + +```{cfgcmd} set policy route \ rule \ dscp-exclude \ +``` + +```{cfgcmd} set policy route6 \ rule \ dscp-exclude \ + +Match based on dscp value criteria. Multiple values from 0 to 63 +and ranges are supported. +``` + +```{cfgcmd} set policy route \ rule \ fragment \ +``` + +```{cfgcmd} set policy route6 \ rule \ fragment \ + +Set IP fragment match, where: +* match-frag: Second and further fragments of fragmented packets. +* match-non-frag: Head fragments or unfragmented packets. +``` + +```{cfgcmd} set policy route \ rule \ icmp \ +``` + +```{cfgcmd} set policy route6 \ rule \ icmpv6 \ + +Match based on icmp|icmpv6 code and type. +``` + +```{cfgcmd} set policy route \ rule \ icmp type-name \ +``` + +```{cfgcmd} set policy route6 \ rule \ icmpv6 type-name \ + +Match based on icmp|icmpv6 type-name criteria. Use tab for information +about what type-name criteria are supported. +``` + +```{cfgcmd} set policy route \ rule \ ipsec \ +``` + +```{cfgcmd} set policy route6 \ rule \ ipsec \ + +Set IPSec inbound match criterias, where: +* match-ipsec: match inbound IPsec packets. +* match-none: match inbound non-IPsec packets. +``` + +```{cfgcmd} set policy route \ rule \ limit burst \<0-4294967295\> +``` + +```{cfgcmd} set policy route6 \ rule \ limit burst \<0-4294967295\> + +Set maximum number of packets to allow in excess of rate. +``` + +```{cfgcmd} set policy route \ rule \ limit rate \ +``` + +```{cfgcmd} set policy route6 \ rule \ limit rate \ + +Set maximum average matching rate. Format for rate: integer/time_unit, where +time_unit could be any one of second, minute, hour or day.For example +1/second implies rule to be matched at an average of once per second. +``` + +```{cfgcmd} set policy route \ rule \ protocol \ +``` + +```{cfgcmd} set policy route6 \ rule \ protocol \ + +Match a protocol criteria. A protocol number or a name which is defined in: +``/etc/protocols``. Special names are ``all`` for all protocols and +``tcp_udp`` for tcp and udp based packets. The ``!`` negates the selected +protocol. +``` + +```{cfgcmd} set policy route \ rule \ packet-length \ +``` + +```{cfgcmd} set policy route6 \ rule \ packet-length \ +``` + +```{cfgcmd} set policy route \ rule \ packet-length-exclude \ +``` + +```{cfgcmd} set policy route6 \ rule \ packet-length-exclude \ + +Match based on packet length criteria. Multiple values from 1 to 65535 +and ranges are supported. +``` + +```{cfgcmd} set policy route \ rule \ packet-type \[broadcast | host | multicast | other\] +``` + +```{cfgcmd} set policy route6 \ rule \ packet-type \[broadcast | host | multicast | other\] + +Match based on packet type criteria. +``` + +```{cfgcmd} set policy route \ rule \ recent count \<1-255\> +``` + +```{cfgcmd} set policy route6 \ rule \ recent count \<1-255\> +``` + +```{cfgcmd} set policy route \ rule \ recent time \<1-4294967295\> +``` + +```{cfgcmd} set policy route6 \ rule \ recent time \<1-4294967295\> + +Set parameters for matching recently seen sources. This match could be used +by seeting count (source address seen more than <1-255> times) and/or time +(source address seen in the last <0-4294967295> seconds). +``` + +```{cfgcmd} set policy route \ rule \ state \ +``` + +```{cfgcmd} set policy route6 \ rule \ state \ + +Set match criteria based on session state. +``` + +```{cfgcmd} set policy route \ rule \ tcp flags \ +``` + +```{cfgcmd} set policy route6 \ rule \ tcp flags \ + +Set match criteria based on tcp flags. Allowed values for TCP flags: SYN ACK +FIN RST URG PSH ALL. When specifying more than one flag, flags should be +comma-separated. For example : value of 'SYN,!ACK,!FIN,!RST' will only match +packets with the SYN flag set, and the ACK, FIN and RST flags unset. +``` + +```{cfgcmd} set policy route \ rule \ time monthdays \ +``` + +```{cfgcmd} set policy route6 \ rule \ time monthdays \ +``` + +```{cfgcmd} set policy route \ rule \ time startdate \ +``` + +```{cfgcmd} set policy route6 \ rule \ time startdate \ +``` + +```{cfgcmd} set policy route \ rule \ time starttime \ +``` + +```{cfgcmd} set policy route6 \ rule \ time starttime \ +``` + +```{cfgcmd} set policy route \ rule \ time stopdate \ +``` + +```{cfgcmd} set policy route6 \ rule \ time stopdate \ +``` + +```{cfgcmd} set policy route \ rule \ time stoptime \ +``` + +```{cfgcmd} set policy route6 \ rule \ time stoptime \ +``` + +```{cfgcmd} set policy route \ rule \ time weekdays \ +``` + +```{cfgcmd} set policy route6 \ rule \ time weekdays \ +``` + +```{cfgcmd} set policy route \ rule \ time utc +``` + +```{cfgcmd} set policy route6 \ rule \ time utc + +Time to match the defined rule. +``` + +```{cfgcmd} set policy route rule \ ttl \ \<0-255\> + +Match time to live parameter, where 'eq' stands for 'equal'; 'gt' stands for +'greater than', and 'lt' stands for 'less than'. +``` + +```{cfgcmd} set policy route6 rule \ hop-limit \ \<0-255\> + +Match hop-limit parameter, where 'eq' stands for 'equal'; 'gt' stands for +'greater than', and 'lt' stands for 'less than'. +``` + +### Actions + +When matching all patterns defined in a rule, then different actions can +be made. This includes dropping the packet, modifying certain data, or +setting a different routing table. + +```{cfgcmd} set policy route \ rule \ action drop +``` + +```{cfgcmd} set policy route6 \ rule \ action drop + +Set rule action to drop. +``` + +```{cfgcmd} set policy route \ rule \ set connection-mark \<1-2147483647\> +``` + +```{cfgcmd} set policy route6 \ rule \ set connection-mark \<1-2147483647\> + +Set a specific connection mark. +``` + +```{cfgcmd} set policy route \ rule \ set dscp \<0-63\> +``` + +```{cfgcmd} set policy route6 \ rule \ set dscp \<0-63\> + +Set packet modifications: Packet Differentiated Services Codepoint (DSCP) +``` + +```{cfgcmd} set policy route \ rule \ set mark \<1-2147483647\> +``` + +```{cfgcmd} set policy route6 \ rule \ set mark \<1-2147483647\> + +Set a specific packet mark. +``` + +```{cfgcmd} set policy route \ rule \ set table \
+``` + +```{cfgcmd} set policy route6 \ rule \ set table \
+ +Set the routing table to forward packet with. + +:::{note} +When using the ``set table`` or ``set vrf`` commands matching +against the mark is not possible, because it gets overwritten with a +table-specific mark that is 0x7FFFFFFF - the id of the table/VRF. +::: +``` + +```{cfgcmd} set policy route \ rule \ set tcp-mss \<500-1460\> +``` + +```{cfgcmd} set policy route6 \ rule \ set tcp-mss \<500-1460\> + +Set packet modifications: Explicitly set TCP Maximum segment size value. +``` + +```{cfgcmd} set policy route \ rule \ set vrf \ +``` + +```{cfgcmd} set policy route6 \ rule \ set vrf \ + +Set the VRF to forward packet with. + +:::{note} +When using the ``set table`` or ``set vrf`` commands matching +against the mark is not possible, because it gets overwritten with a +table-specific mark that is 0x7FFFFFFF - the id of the table/VRF. +::: +``` \ No newline at end of file diff --git a/docs/configuration/policy/route.rst b/docs/configuration/policy/route.rst deleted file mode 100644 index 1ddd04cf..00000000 --- a/docs/configuration/policy/route.rst +++ /dev/null @@ -1,306 +0,0 @@ -####################### -Route and Route6 Policy -####################### - -IPv4 route and IPv6 route policies are defined in this section. These route -policies can then be associated to interfaces. - -********* -Rule-Sets -********* - -A rule-set is a named collection of rules that can be applied to an interface. -Each rule is numbered, has an action to apply if the rule is matched, and the -ability to specify the criteria to match. Data packets go through the rules -from 1 - 999999, at the first match the action of the rule will be executed. - -.. cfgcmd:: set policy route description -.. cfgcmd:: set policy route6 description - - Provide a rule-set description. - -.. cfgcmd:: set policy route default-log -.. cfgcmd:: set policy route6 default-log - - Option to log packets hitting default-action. - -.. cfgcmd:: set policy route interface -.. cfgcmd:: set policy route6 interface - - Apply routing policy to interface - -.. cfgcmd:: set policy route rule description -.. cfgcmd:: set policy route6 rule description - - Provide a description for each rule. - -.. cfgcmd:: set policy route rule log -.. cfgcmd:: set policy route6 rule log - - Option to enable or disable log matching rule. - -Matching criteria -================= - -There are a lot of matching criteria options available, both for -``policy route`` and ``policy route6``. These options are listed -in this section. - -.. cfgcmd:: set policy route rule connection-mark <1-2147483647> -.. cfgcmd:: set policy route6 rule connection-mark <1-2147483647> - - Set match criteria based on connection mark. - -.. cfgcmd:: set policy route rule mark -.. cfgcmd:: set policy route6 rule mark - - Match based on the firewall mark (fwmark), where can be: - - * <0-2147483647> a single fwmark - * !<0-2147483647> everything except a single fwmark - * a range of marks - * ! everything except the range of marks - - .. note:: When using the ``set table`` or ``set vrf`` commands the mark - settings are ignored and overwritten with a table-specific mark that - is set to 0x7FFFFFFF - the id of the table/VRF. - -.. cfgcmd:: set policy route rule source address - -.. cfgcmd:: set policy route rule destination address - -.. cfgcmd:: set policy route6 rule source address - -.. cfgcmd:: set policy route6 rule destination address - - - Set match criteria based on source or destination ipv4|ipv6 address, where - could be: - -For ipv4: - * : IP address to match. - * : Subnet to match. - * -: IP range to match. - * !: Match everything except the specified address. - * !: Match everything except the specified subnet. - * !-: Match everything except the specified range. - -And for ipv6: - * : IPv6 address to match. - * : IPv6 prefix to match. - * -: IPv6 range to match. - * !: Match everything except the specified address. - * !: Match everything except the specified prefix. - * !-: Match everything except the - specified range. - -.. cfgcmd:: set policy route rule source group - -.. cfgcmd:: set policy route rule destination group - -.. cfgcmd:: set policy route6 rule source group - -.. cfgcmd:: set policy route6 rule destination group - - - Set match criteria based on source or destination groups, where - would be the group name/identifier. Prepend character '!' for inverted - matching criteria. - -.. cfgcmd:: set policy route rule destination port -.. cfgcmd:: set policy route6 rule destination port - - Set match criteria based on destination port, where could - be: - - * : Named port (any name in /etc/services, e.g., http). - * <1-65535>: Numbered port. - * -: Numbered port range (e.g., 1001-1005). - - Multiple destination ports can be specified as a comma-separated list. The - whole list can also be "negated" using '!'. For example: - '!22,telnet,http,123,1001-1005' - -.. cfgcmd:: set policy route rule disable -.. cfgcmd:: set policy route6 rule disable - - Option to disable rule. - -.. cfgcmd:: set policy route rule dscp -.. cfgcmd:: set policy route6 rule dscp -.. cfgcmd:: set policy route rule dscp-exclude -.. cfgcmd:: set policy route6 rule dscp-exclude - - Match based on dscp value criteria. Multiple values from 0 to 63 - and ranges are supported. - -.. cfgcmd:: set policy route rule fragment - -.. cfgcmd:: set policy route6 rule fragment - - - Set IP fragment match, where: - - * match-frag: Second and further fragments of fragmented packets. - * match-non-frag: Head fragments or unfragmented packets. - -.. cfgcmd:: set policy route rule icmp -.. cfgcmd:: set policy route6 rule icmpv6 - - Match based on icmp|icmpv6 code and type. - -.. cfgcmd:: set policy route rule icmp type-name -.. cfgcmd:: set policy route6 rule icmpv6 type-name - - Match based on icmp|icmpv6 type-name criteria. Use tab for information - about what type-name criteria are supported. - -.. cfgcmd:: set policy route rule ipsec - -.. cfgcmd:: set policy route6 rule ipsec - - - Set IPSec inbound match criterias, where: - - * match-ipsec: match inbound IPsec packets. - * match-none: match inbound non-IPsec packets. - -.. cfgcmd:: set policy route rule limit burst <0-4294967295> -.. cfgcmd:: set policy route6 rule limit burst <0-4294967295> - - Set maximum number of packets to alow in excess of rate. - -.. cfgcmd:: set policy route rule limit rate -.. cfgcmd:: set policy route6 rule limit rate - - Set maximum average matching rate. Format for rate: integer/time_unit, where - time_unit could be any one of second, minute, hour or day.For example - 1/second implies rule to be matched at an average of once per second. - -.. cfgcmd:: set policy route rule protocol - -.. cfgcmd:: set policy route6 rule protocol - - - Match a protocol criteria. A protocol number or a name which is defined in: - ``/etc/protocols``. Special names are ``all`` for all protocols and - ``tcp_udp`` for tcp and udp based packets. The ``!`` negates the selected - protocol. - -.. cfgcmd:: set policy route rule packet-length -.. cfgcmd:: set policy route6 rule packet-length -.. cfgcmd:: set policy route rule packet-length-exclude -.. cfgcmd:: set policy route6 rule packet-length-exclude - - Match based on packet length criteria. Multiple values from 1 to 65535 - and ranges are supported. - -.. cfgcmd:: set policy route rule packet-type [broadcast | host - | multicast | other] -.. cfgcmd:: set policy route6 rule packet-type [broadcast | host - | multicast | other] - - Match based on packet type criteria. - -.. cfgcmd:: set policy route rule recent count <1-255> -.. cfgcmd:: set policy route6 rule recent count <1-255> -.. cfgcmd:: set policy route rule recent time <1-4294967295> -.. cfgcmd:: set policy route6 rule recent time <1-4294967295> - - Set parameters for matching recently seen sources. This match could be used - by seeting count (source address seen more than <1-255> times) and/or time - (source address seen in the last <0-4294967295> seconds). - -.. cfgcmd:: set policy route rule state - -.. cfgcmd:: set policy route6 rule state - - - Set match criteria based on session state. - -.. cfgcmd:: set policy route rule tcp flags -.. cfgcmd:: set policy route6 rule tcp flags - - Set match criteria based on tcp flags. Allowed values for TCP flags: SYN ACK - FIN RST URG PSH ALL. When specifying more than one flag, flags should be - comma-separated. For example : value of 'SYN,!ACK,!FIN,!RST' will only match - packets with the SYN flag set, and the ACK, FIN and RST flags unset. - -.. cfgcmd:: set policy route rule time monthdays -.. cfgcmd:: set policy route6 rule time monthdays -.. cfgcmd:: set policy route rule time startdate -.. cfgcmd:: set policy route6 rule time startdate -.. cfgcmd:: set policy route rule time starttime -.. cfgcmd:: set policy route6 rule time starttime -.. cfgcmd:: set policy route rule time stopdate -.. cfgcmd:: set policy route6 rule time stopdate -.. cfgcmd:: set policy route rule time stoptime -.. cfgcmd:: set policy route6 rule time stoptime -.. cfgcmd:: set policy route rule time weekdays -.. cfgcmd:: set policy route6 rule time weekdays -.. cfgcmd:: set policy route rule time utc -.. cfgcmd:: set policy route6 rule time utc - - Time to match the defined rule. - -.. cfgcmd:: set policy route rule ttl <0-255> - - Match time to live parameter, where 'eq' stands for 'equal'; 'gt' stands for - 'greater than', and 'lt' stands for 'less than'. - -.. cfgcmd:: set policy route6 rule hop-limit <0-255> - - Match hop-limit parameter, where 'eq' stands for 'equal'; 'gt' stands for - 'greater than', and 'lt' stands for 'less than'. - -Actions -======= - -When mathcing all patterns defined in a rule, then different actions can -be made. This includes droping the packet, modifying certain data, or -setting a different routing table. - -.. cfgcmd:: set policy route rule action drop -.. cfgcmd:: set policy route6 rule action drop - - Set rule action to drop. - -.. cfgcmd:: set policy route rule set connection-mark - <1-2147483647> -.. cfgcmd:: set policy route6 rule set connection-mark - <1-2147483647> - - Set a specific connection mark. - -.. cfgcmd:: set policy route rule set dscp <0-63> -.. cfgcmd:: set policy route6 rule set dscp <0-63> - - Set packet modifications: Packet Differentiated Services Codepoint (DSCP) - -.. cfgcmd:: set policy route rule set mark <1-2147483647> -.. cfgcmd:: set policy route6 rule set mark <1-2147483647> - - Set a specific packet mark. - -.. cfgcmd:: set policy route rule set table
-.. cfgcmd:: set policy route6 rule set table
- - Set the routing table to forward packet with. - - .. note:: When using the ``set table`` or ``set vrf`` commands matching - against the mark is not possible, because it gets overwritten with a - table-specific mark that is 0x7FFFFFFF - the id of the table/VRF. - -.. cfgcmd:: set policy route rule set tcp-mss <500-1460> -.. cfgcmd:: set policy route6 rule set tcp-mss <500-1460> - - Set packet modifications: Explicitly set TCP Maximum segment size value. - -.. cfgcmd:: set policy route rule set vrf -.. cfgcmd:: set policy route6 rule set vrf - - Set the VRF to forward packet with. - - .. note:: When using the ``set table`` or ``set vrf`` commands matching - against the mark is not possible, because it gets overwritten with a - table-specific mark that is 0x7FFFFFFF - the id of the table/VRF. diff --git a/docs/configuration/policy/rst-access-list.rst b/docs/configuration/policy/rst-access-list.rst new file mode 100644 index 00000000..0af9b911 --- /dev/null +++ b/docs/configuration/policy/rst-access-list.rst @@ -0,0 +1,70 @@ +################## +Access List Policy +################## + +Filtering is used for both input and output of the routing information. Once +filtering is defined, it can be applied in any direction. VyOS makes filtering +possible using acls and prefix lists. + +Basic filtering can be done using access-list and access-list6. + +************* +Configuration +************* + +Access Lists +============ + +.. cfgcmd:: set policy access-list + + This command creates the new access list policy, where must be + a number from 1 to 2699. + +.. cfgcmd:: set policy access-list description + + Set description for the access list. + +.. cfgcmd:: set policy access-list rule <1-65535> action + + + This command creates a new rule in the access list and defines an action. + +.. cfgcmd:: set policy access-list rule <1-65535> + + + This command defines matching parameters for access list rule. Matching + criteria could be applied to destination or source parameters: + + * any: any IP address to match. + * host: single host IP address to match. + * inverse-match: network/netmask to match (requires network be defined). + * network: network/netmask to match (requires inverse-match be defined). + +IPv6 Access List +================ + +Basic filtering could also be applied to IPv6 traffic. + +.. cfgcmd:: set policy access-list6 + + This command creates the new IPv6 access list, identified by + +.. cfgcmd:: set policy access-list6 description + + Set description for the IPv6 access list. + +.. cfgcmd:: set policy access-list6 rule <1-65535> action + + This command creates a new rule in the IPv6 access list and defines an + action. + +.. cfgcmd:: set policy access-list6 rule <1-65535> source + + + This command defines matching parameters for IPv6 access list rule. Matching + criteria could be applied to source parameters: + + * any: any IPv6 address to match. + * exact-match: exact match of the network prefixes. + * network: network/netmask to match (requires inverse-match be defined) BUG, + NO invert-match option in access-list6 \ No newline at end of file diff --git a/docs/configuration/policy/rst-as-path-list.rst b/docs/configuration/policy/rst-as-path-list.rst new file mode 100644 index 00000000..ceeb8e01 --- /dev/null +++ b/docs/configuration/policy/rst-as-path-list.rst @@ -0,0 +1,33 @@ +#################### +BGP - AS Path Policy +#################### + +VyOS provides policies commands exclusively for BGP traffic filtering and +manipulation: **as-path-list** is one of them. + +************* +Configuration +************* + +policy as-path-list +=================== + +.. cfgcmd:: set policy as-path-list + + Create as-path-policy identified by name . + +.. cfgcmd:: set policy as-path-list description + + Set description for as-path-list policy. + +.. cfgcmd:: set policy as-path-list rule <1-65535> action + + Set action to take on entries matching this rule. + +.. cfgcmd:: set policy as-path-list rule <1-65535> description + + Set description for rule. + +.. cfgcmd:: set policy as-path-list rule <1-65535> regex + + Regular expression to match against an AS path. For example "64501 64502". diff --git a/docs/configuration/policy/rst-community-list.rst b/docs/configuration/policy/rst-community-list.rst new file mode 100644 index 00000000..ee2da03c --- /dev/null +++ b/docs/configuration/policy/rst-community-list.rst @@ -0,0 +1,35 @@ +#################### +BGP - Community List +#################### + +VyOS provides policies commands exclusively for BGP traffic filtering and +manipulation: **community-list** is one of them. + +************* +Configuration +************* + +policy community-list +===================== + +.. cfgcmd:: set policy community-list + + Creat community-list policy identified by name . + +.. cfgcmd:: set policy community-list description + + Set description for community-list policy. + +.. cfgcmd:: set policy community-list rule <1-65535> action + + + Set action to take on entries matching this rule. + +.. cfgcmd:: set policy community-list rule <1-65535> description + + Set description for rule. + +.. cfgcmd:: set policy community-list rule <1-65535> regex + + + Regular expression to match against a community-list. \ No newline at end of file diff --git a/docs/configuration/policy/rst-examples.rst b/docs/configuration/policy/rst-examples.rst new file mode 100644 index 00000000..6c5c592a --- /dev/null +++ b/docs/configuration/policy/rst-examples.rst @@ -0,0 +1,213 @@ +########### +BGP Example +########### + +**Policy definition:** + +.. code-block:: none + + # Create policy + set policy route-map setmet rule 2 action 'permit' + set policy route-map setmet rule 2 set as-path prepend '2 2 2' + + # Apply policy to BGP + set protocols bgp system-as 1 + set protocols bgp neighbor 203.0.113.2 address-family ipv4-unicast route-map import 'setmet' + set protocols bgp neighbor 203.0.113.2 address-family ipv4-unicast soft-reconfiguration 'inbound' + +Using 'soft-reconfiguration' we get the policy update without bouncing the +neighbor. + +**Routes learned before routing policy applied:** + +.. code-block:: none + + vyos@vos1:~$ show ip bgp + BGP table version is 0, local router ID is 192.168.56.101 + Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, + r RIB-failure, S Stale, R Removed + Origin codes: i - IGP, e - EGP, ? - incomplete + + Network Next Hop Metric LocPrf Weight Path + *> 198.51.100.3/32 203.0.113.2 1 0 2 i < Path + + Total number of prefixes 1 + +**Routes learned after routing policy applied:** + +.. code-block:: none + + vyos@vos1:~$ show ip bgp + BGP table version is 0, local router ID is 192.168.56.101 + Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, + r RIB-failure, S Stale, R Removed + Origin codes: i - IGP, e - EGP, ? - incomplete + + Network Next Hop Metric LocPrf Weight Path + *> 198.51.100.3/32 203.0.113.2 1 0 2 2 2 2 i + + Total number of prefixes 1 + vyos@vos1:~$ + +You now see the longer AS path. + +################# +Transparent Proxy +################# + +The following example will show how VyOS can be used to redirect web +traffic to an external transparent proxy: + +.. code-block:: none + + set policy route FILTER-WEB rule 1000 destination port 80 + set policy route FILTER-WEB rule 1000 protocol tcp + set policy route FILTER-WEB rule 1000 set table 100 + +This creates a route policy called FILTER-WEB with one rule to set the +routing table for matching traffic (TCP port 80) to table ID 100 +instead of the default routing table. + +To create routing table 100 and add a new default gateway to be used by +traffic matching our route policy: + +.. code-block:: none + + set protocols static table 100 route 0.0.0.0/0 next-hop 10.255.0.2 + +This can be confirmed using the ``show ip route table 100`` operational +command. + +Finally, to apply the policy route to ingress traffic on our LAN +interface, we use: + +.. code-block:: none + + set policy route FILTER-WEB interface eth1 + +################ +Multiple Uplinks +################ + +VyOS Policy-Based Routing (PBR) works by matching source IP address +ranges and forwarding the traffic using different routing tables. + +Routing tables that will be used in this example are: + +* ``table 10`` Routing table used for VLAN 10 (192.168.188.0/24) +* ``table 11`` Routing table used for VLAN 11 (192.168.189.0/24) +* ``main`` Routing table used by VyOS and other interfaces not + participating in PBR + +.. figure:: /_static/images/pbr_example_1.* + :scale: 80 % + :alt: PBR multiple uplinks + + Policy-Based Routing with multiple ISP uplinks + (source ./draw.io/pbr_example_1.drawio) + +Add default routes for routing ``table 10`` and ``table 11`` + +.. code-block:: none + + set protocols static table 10 route 0.0.0.0/0 next-hop 192.0.1.1 + set protocols static table 11 route 0.0.0.0/0 next-hop 192.0.2.2 + +Add policy route matching VLAN source addresses + +.. code-block:: none + + set policy route PBR rule 20 set table '10' + set policy route PBR rule 20 description 'Route VLAN10 traffic to table 10' + set policy route PBR rule 20 source address '192.168.188.0/24' + + set policy route PBR rule 30 set table '11' + set policy route PBR rule 30 description 'Route VLAN11 traffic to table 11' + set policy route PBR rule 30 source address '192.168.189.0/24' + +Apply routing policy to **inbound** direction of out VLAN interfaces + +.. code-block:: none + + set policy route 'PBR' interface eth0.10 + set policy route 'PBR' interface eth0.11 + + +**OPTIONAL:** Exclude Inter-VLAN traffic (between VLAN10 and VLAN11) +from PBR + +.. code-block:: none + + set firewall group network-group VLANS-GR description 'VLANs networks' + set firewall group network-group VLANS-GR network '192.168.188.0/24' + set firewall group network-group VLANS-GR network '192.168.189.0/24' + + set policy route PBR rule 10 description 'VLAN10 <-> VLAN11 shortcut' + set policy route PBR rule 10 destination group network-group 'VLANS-GR' + set policy route PBR rule 10 set table 'main' + +These commands allow the VLAN10 and VLAN11 hosts to communicate with +each other using the main routing table. + +Local route +=========== + +The following example allows VyOS to use :abbr:`PBR (Policy-Based Routing)` +for traffic, which originated from the router itself. That solution for multiple +ISP's and VyOS router will respond from the same interface that the packet was +received. Also, it used, if we want that one VPN tunnel to be through one +provider, and the second through another. + +* ``203.0.113.254`` IP addreess on VyOS eth1 from ISP1 +* ``192.168.2.254`` IP addreess on VyOS eth2 from ISP2 +* ``table 10`` Routing table used for ISP1 +* ``table 11`` Routing table used for ISP2 + + +.. code-block:: none + + set policy local-route rule 101 set table '10' + set policy local-route rule 101 source address '203.0.113.254' + set policy local-route rule 102 set table '11' + set policy local-route rule 102 source address '192.0.2.254' + set protocols static table 10 route 0.0.0.0/0 next-hop '203.0.113.1' + set protocols static table 11 route 0.0.0.0/0 next-hop '192.0.2.2' + +Add multiple source IP in one rule with same priority + +.. code-block:: none + + set policy local-route rule 101 set table '10' + set policy local-route rule 101 source address '203.0.113.254' + set policy local-route rule 101 source address '203.0.113.253' + set policy local-route rule 101 source address '198.51.100.0/24' + +########################### +Clamp MSS for a specific IP +########################### + +This example shows how to target an MSS clamp (in our example to 1360 bytes) +to a specific destination IP. + +.. code-block:: none + + set policy route IP-MSS-CLAMP rule 10 description 'Clamp TCP session MSS to 1360 for 198.51.100.30' + set policy route IP-MSS-CLAMP rule 10 destination address '198.51.100.30/32' + set policy route IP-MSS-CLAMP rule 10 protocol 'tcp' + set policy route IP-MSS-CLAMP rule 10 set tcp-mss '1360' + set policy route IP-MSS-CLAMP rule 10 tcp flags 'SYN' + +To apply this policy to the correct interface, configure it on the +interface the inbound local host will send through to reach our +destined target host (in our example eth1). + +.. code-block:: none + + set policy route IP-MSS-CLAMP interface eth1 + +You can view that the policy is being correctly (or incorrectly) utilised +with the following command: + +.. code-block:: none + + show policy route statistics diff --git a/docs/configuration/policy/rst-extcommunity-list.rst b/docs/configuration/policy/rst-extcommunity-list.rst new file mode 100644 index 00000000..c413b8b5 --- /dev/null +++ b/docs/configuration/policy/rst-extcommunity-list.rst @@ -0,0 +1,40 @@ +############################# +BGP - Extended Community List +############################# + +VyOS provides policies commands exclusively for BGP traffic filtering and +manipulation: **extcommunity-list** is one of them. + +************* +Configuration +************* + +policy extcommunity-list +======================== + +.. cfgcmd:: set policy extcommunity-list + + Creat extcommunity-list policy identified by name . + +.. cfgcmd:: set policy extcommunity-list description + + Set description for extcommunity-list policy. + +.. cfgcmd:: set policy extcommunity-list rule <1-65535> action + + + Set action to take on entries matching this rule. + +.. cfgcmd:: set policy extcommunity-list rule <1-65535> description + + + Set description for rule. + +.. cfgcmd:: set policy extcommunity-list rule <1-65535> regex + + Regular expression to match against an extended community list, where text + could be: + + * : Extended community list regular expression. + * : Route Target regular expression. + * : Site of Origin regular expression. diff --git a/docs/configuration/policy/rst-index.rst b/docs/configuration/policy/rst-index.rst new file mode 100644 index 00000000..0394eb21 --- /dev/null +++ b/docs/configuration/policy/rst-index.rst @@ -0,0 +1,54 @@ +:lastproofread: 2021-07-12 + +.. include:: /_include/need_improvement.txt + +###### +Policy +###### + +Policies are used for filtering and traffic management. With policies, network +administrators could filter and treat traffic +according to their needs. + +There could be a wide range of routing policies. Some examples are listed +below: + +* Filter traffic based on source/destination address. +* Set some metric to routes learned from a particular neighbor. +* Set some attributes (like AS PATH or Community value) to advertised routes + to neighbors. +* Prefer a specific routing protocol routes over another routing protocol + running on the same router. + +Policies, in VyOS, are implemented using FRR filtering and route maps. Detailed +information of FRR could be found in http://docs.frrouting.org/ + +*************** +Policy Sections +*************** + +.. toctree:: + :maxdepth: 1 + :includehidden: + + access-list + prefix-list + route + route-map + local-route + as-path-list + community-list + extcommunity-list + large-community-list + +******** +Examples +******** + +Examples of policies usage: + +.. toctree:: + :maxdepth: 1 + :includehidden: + + examples \ No newline at end of file diff --git a/docs/configuration/policy/rst-large-community-list.rst b/docs/configuration/policy/rst-large-community-list.rst new file mode 100644 index 00000000..0c57fd4a --- /dev/null +++ b/docs/configuration/policy/rst-large-community-list.rst @@ -0,0 +1,36 @@ +########################## +BGP - Large Community List +########################## + +VyOS provides policies commands exclusively for BGP traffic filtering and +manipulation: **large-community-list** is one of them. + +************* +Configuration +************* + +policy large-community-list +=========================== + +.. cfgcmd:: set policy large-community-list + + Create large-community-list policy identified by name . + +.. cfgcmd:: set policy large-community-list description + + Set description for large-community-list policy. + +.. cfgcmd:: set policy large-community-list rule <1-65535> action + + + Set action to take on entries matching this rule. + +.. cfgcmd:: set policy large-community-list rule <1-65535> description + + + Set description for rule. + +.. cfgcmd:: set policy large-community-list rule <1-65535> regex + + + Regular expression to match against a large community list. diff --git a/docs/configuration/policy/rst-local-route.rst b/docs/configuration/policy/rst-local-route.rst new file mode 100644 index 00000000..a3e42816 --- /dev/null +++ b/docs/configuration/policy/rst-local-route.rst @@ -0,0 +1,87 @@ +################## +Local Route Policy +################## + +Policies for local traffic are defined in this section. + +************* +Configuration +************* + +Local Route IPv4 +================ + +.. cfgcmd:: set policy local-route rule <1-32765> set table <1-200|main> + + Set the routing table to use for forwarding matching packets. + +.. cfgcmd:: set policy local-route rule <1-32765> set vrf + + Set the VRF to use for forwarding matching packets. + +.. cfgcmd:: set policy local-route rule <1-32765> protocol + + Match specified protocol (name or number). + +.. cfgcmd:: set policy local-route rule <1-32765> fwmark <1-2147483647> + + Match specified firewall mark (fwmark). + +.. cfgcmd:: set policy local-route rule <1-32765> source address + + Match specified source address or prefix. + +.. cfgcmd:: set policy local-route rule <1-32765> source port <1-65535> + + Match specified source port. + +.. cfgcmd:: set policy local-route rule <1-32765> destination address + + Match specified destination address or prefix. + +.. cfgcmd:: set policy local-route rule <1-32765> destination port <1-65535> + + Match specified destination port. + +.. cfgcmd:: set policy local-route rule <1-32765> inbound-interface + + Match specified inbound interface. + +Local Route IPv6 +================ + +.. cfgcmd:: set policy local-route6 rule <1-32765> set table <1-200|main> + + Set the routing table to use for forwarding matching packets. + +.. cfgcmd:: set policy local-route6 rule <1-32765> set vrf + + Set the VRF to use for forwarding matching packets. + +.. cfgcmd:: set policy local-route6 rule <1-32765> protocol + + Match specified protocol (name or number). + +.. cfgcmd:: set policy local-route6 rule <1-32765> fwmark <1-2147483647> + + Match specified firewall mark (fwmark). + +.. cfgcmd:: set policy local-route6 rule <1-32765> source address + + Match specified source address or prefix. + +.. cfgcmd:: set policy local-route6 rule <1-32765> source port <1-65535> + + Match specified source port. + +.. cfgcmd:: set policy local-route6 rule <1-32765> destination address + + Match specified destination address or prefix. + +.. cfgcmd:: set policy local-route6 rule <1-32765> destination port <1-65535> + + Match specified destination port. + +.. cfgcmd:: set policy local-route6 rule <1-32765> inbound-interface + + Match specified inbound interface. \ No newline at end of file diff --git a/docs/configuration/policy/rst-prefix-list.rst b/docs/configuration/policy/rst-prefix-list.rst new file mode 100644 index 00000000..98df1b9b --- /dev/null +++ b/docs/configuration/policy/rst-prefix-list.rst @@ -0,0 +1,112 @@ +################## +Prefix List Policy +################## + +Prefix lists provides the most powerful prefix based filtering mechanism. In +addition to access-list functionality, ip prefix-list has prefix length range +specification. + +If no ip prefix list is specified, it acts as permit. If ip prefix list is +defined, and no match is found, default deny is applied. + +Prefix filtering can be done using prefix-list and prefix-list6. + +************* +Configuration +************* + +IPv4 Prefix Lists (prefix-list) +============ + +.. cfgcmd:: set policy prefix-list + + This command creates the new prefix-list policy, identified by . + +.. cfgcmd:: set policy prefix-list description + + Set description for the prefix-list policy. + +.. cfgcmd:: set policy prefix-list rule <1-65535> action + + This command creates a new rule in the prefix-list and defines an action. + +.. cfgcmd:: set policy prefix-list rule <1-65535> description + + Set description for rule in the prefix-list. + +.. cfgcmd:: set policy prefix-list rule <1-65535> prefix + + Prefix to match against. + +.. cfgcmd:: set policy prefix-list rule <1-65535> ge <0-32> + + Netmask greater than length. + +.. cfgcmd:: set policy prefix-list rule <1-65535> le <0-32> + + Netmask less than length + +Example: IPv4 Prefix Lists (prefix-list) +============ + +This example creates an IPv4 prefix-list named PL4-EXAMPLE-NAME, defines 3 +rules each with 1 prefix, and matches le (less than/equal to) /32. + +.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 10 action 'permit' +.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 10 le '32' +.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 10 prefix '192.0.2.0/24' +.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 20 action 'permit' +.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 20 le '32' +.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 20 prefix '198.51.100.0/24' +.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 30 action 'permit' +.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 30 le '32' +.. cfgcmd:: set policy prefix-list PL4-EXAMPLE-NAME rule 30 prefix '203.0.113.0/24' + +IPv6 Prefix Lists (prefix-list6) +================= + +.. cfgcmd:: set policy prefix-list6 + + This command creates the new IPv6 prefix-list policy, identified by . + +.. cfgcmd:: set policy prefix-list6 description + + Set description for the IPv6 prefix-list policy. + +.. cfgcmd:: set policy prefix-list6 rule <1-65535> action + + This command creates a new rule in the IPv6 prefix-list and defines an + action. + +.. cfgcmd:: set policy prefix-list6 rule <1-65535> description + + Set description for rule in IPv6 prefix-list. + +.. cfgcmd:: set policy prefix-list6 rule <1-65535> prefix + + + IPv6 prefix. + +.. cfgcmd:: set policy prefix-list6 rule <1-65535> ge <0-128> + + Netmask greater than length. + +.. cfgcmd:: set policy prefix-list6 rule <1-65535> le <0-128> + + Netmask less than length + +Example: IPv6 Prefix Lists (prefix-list6) +============ + +This example creates an IPv6 prefix-list6 named PL6-EXAMPLE-NAME, defines 3 +rules each with 1 prefix, and matches le (less than/equal to) /128. + +.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 10 action 'permit' +.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 10 le '128' +.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 10 prefix '2001:db8:0:0::/64' +.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 20 action 'permit' +.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 20 le '128' +.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 20 prefix '2001:db8:0:1::/64' +.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 30 action 'permit' +.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 30 le '128' +.. cfgcmd:: set policy prefix-list6 PL6-EXAMPLE-NAME rule 30 prefix '2001:db8:0:2::/64' \ No newline at end of file diff --git a/docs/configuration/policy/rst-route-map.rst b/docs/configuration/policy/rst-route-map.rst new file mode 100644 index 00000000..a2313466 --- /dev/null +++ b/docs/configuration/policy/rst-route-map.rst @@ -0,0 +1,383 @@ +################ +Route Map Policy +################ + +Route map is a powerfull command, that gives network administrators a very +useful and flexible tool for traffic manipulation. + +************* +Configuration +************* + +Route Map +========= + +.. cfgcmd:: set policy route-map + + This command creates a new route-map policy, identified by . + +.. cfgcmd:: set policy route-map description + + Set description for the route-map policy. + +.. cfgcmd:: set policy route-map rule <1-65535> action + + Set action for the route-map policy. + +.. cfgcmd:: set policy route-map rule <1-65535> call + + Call another route-map policy on match. + +.. cfgcmd:: set policy route-map rule <1-65535> continue <1-65535> + + Jump to a different rule in this route-map on a match. + +.. cfgcmd:: set policy route-map rule <1-65535> description + + Set description for the rule in the route-map policy. + +.. cfgcmd:: set policy route-map rule <1-65535> match as-path + + BGP as-path list to match. + +.. cfgcmd:: set policy route-map rule <1-65535> match community + community-list + + BGP community-list to match. + +.. cfgcmd:: set policy route-map rule <1-65535> match community + exact-match + + Set BGP community-list to exactly match. + +.. cfgcmd:: set policy route-map rule <1-65535> match extcommunity + + + BGP extended community to match. + +.. cfgcmd:: set policy route-map rule <1-65535> match interface + + First hop interface of a route to match. + +.. cfgcmd:: set policy route-map rule <1-65535> match ip address + access-list <1-2699> + + IP address of route to match, based on access-list. + +.. cfgcmd:: set policy route-map rule <1-65535> match ip address + prefix-list + + IP address of route to match, based on prefix-list. + +.. cfgcmd:: set policy route-map rule <1-65535> match ip address + prefix-len <0-32> + + IP address of route to match, based on specified prefix-length. + Note that this can be used for kernel routes only. + Do not apply to the routes of dynamic routing protocols (e.g. BGP, + RIP, OSFP), as this can lead to unexpected results.. + +.. cfgcmd:: set policy route-map rule <1-65535> match ip nexthop + access-list <1-2699> + + IP next-hop of route to match, based on access-list. + +.. cfgcmd:: set policy route-map rule <1-65535> match ip nexthop + address + + IP next-hop of route to match, based on ip address. + +.. cfgcmd:: set policy route-map rule <1-65535> match ip nexthop + prefix-len <0-32> + + IP next-hop of route to match, based on prefix length. + +.. cfgcmd:: set policy route-map rule <1-65535> match ip nexthop + prefix-list + + IP next-hop of route to match, based on prefix-list. + +.. cfgcmd:: set policy route-map rule <1-65535> match ip nexthop + type + + IP next-hop of route to match, based on type. + +.. cfgcmd:: set policy route-map rule <1-65535> match ip route-source + access-list <1-2699> + + IP route source of route to match, based on access-list. + +.. cfgcmd:: set policy route-map rule <1-65535> match ip route-source + prefix-list + + IP route source of route to match, based on prefix-list. + +.. cfgcmd:: set policy route-map rule <1-65535> match ipv6 address + access-list + + IPv6 address of route to match, based on IPv6 access-list. + +.. cfgcmd:: set policy route-map rule <1-65535> match ipv6 address + prefix-list + + IPv6 address of route to match, based on IPv6 prefix-list. + +.. cfgcmd:: set policy route-map rule <1-65535> match ipv6 address + prefix-len <0-128> + + IPv6 address of route to match, based on specified prefix-length. + Note that this can be used for kernel routes only. + Do not apply to the routes of dynamic routing protocols (e.g. BGP, + RIP, OSFP), as this can lead to unexpected results.. + +.. cfgcmd:: set policy route-map rule <1-65535> match ipv6 nexthop + + + Nexthop IPv6 address to match. + +.. cfgcmd:: set policy route-map rule <1-65535> match large-community + large-community-list + + Match BGP large communities. + +.. cfgcmd:: set policy route-map rule <1-65535> match local-preference + <0-4294967295> + + Match local preference. + +.. cfgcmd:: set policy route-map rule <1-65535> match metric <1-65535> + + Match route metric. + +.. cfgcmd:: set policy route-map rule <1-65535> match origin + + + Boarder Gateway Protocol (BGP) origin code to match. + +.. cfgcmd:: set policy route-map rule <1-65535> match peer + + Peer IP address to match. + +.. cfgcmd:: set policy route-map rule <1-65535> match protocol + + Source protocol to match. + * ``babel`` - Babel routing protocol (Babel) + * ``bgp`` - Border Gateway Protocol (BGP) + * ``connected`` - Connected routes (directly attached subnet or host) + * ``isis`` - Intermediate System to Intermediate System (IS-IS) + * ``kernel`` - Kernel routes + * ``ospf`` - Open Shortest Path First (OSPFv2) + * ``ospfv3`` - Open Shortest Path First (IPv6) (OSPFv3) + * ``rip`` - Routing Information Protocol (RIP) + * ``ripng`` - Routing Information Protocol next-generation (IPv6) (RIPng) + * ``static`` - Statically configured routes + * ``table`` - Non-main Kernel Routing Table + * ``vnc`` - Virtual Network Control (VNC) + +.. cfgcmd:: set policy route-map rule <1-65535> match rpki + + + Match RPKI validation result. + +.. cfgcmd:: set policy route-map rule <1-65535> match source-vrf + + Source VRF to match. + +.. cfgcmd:: set policy route-map rule <1-65535> match tag <1-65535> + + Route tag to match. + +.. cfgcmd:: set policy route-map rule <1-65535> on-match goto <1-65535> + + Exit policy on match: go to rule <1-65535> + +.. cfgcmd:: set policy route-map rule <1-65535> on-match next + + Exit policy on match: go to next sequence number. + +.. cfgcmd:: set policy route-map rule <1-65535> set aggregator + <1-4294967295|x.x.x.x> + + BGP aggregator attribute: AS number or IP address of an aggregation. + +.. cfgcmd:: set policy route-map rule <1-65535> set as-path exclude + <1-4294967295 | all> + + Drop AS-NUMBER from the BGP AS path. + + If ``all`` is specified, remove all AS numbers from the AS_PATH of the BGP + path's NLRI. + +.. cfgcmd:: set policy route-map rule <1-65535> set as-path prepend + <1-4294967295> + + Prepend the given string of AS numbers to the AS_PATH of the BGP path's NLRI. + +.. cfgcmd:: set policy route-map rule <1-65535> set as-path + prepend-last-as + + Prepend the existing last AS number (the leftmost ASN) to the AS_PATH. + +.. cfgcmd:: set policy route-map rule <1-65535> set atomic-aggregate + + BGP atomic aggregate attribute. + +.. cfgcmd:: set policy route-map rule <1-65535> set community + + + Add or replace BGP community attribute in format ``<0-65535:0-65535>`` + or from well-known community list + +.. cfgcmd:: set policy route-map rule <1-65535> set community none + + Delete all BGP communities + +.. cfgcmd:: set policy route-map rule <1-65535> set community delete + + + Delete BGP communities matching the community-list. + +.. cfgcmd:: set policy route-map rule <1-65535> set large-community + + + Add or replace BGP large-community attribute in format + ``<0-4294967295:0-4294967295:0-4294967295>`` + +.. cfgcmd:: set policy route-map rule <1-65535> set large-community none + + Delete all BGP large-communities + +.. cfgcmd:: set policy route-map rule <1-65535> set large-community delete + + + Delete BGP communities matching the large-community-list. + +.. cfgcmd:: set policy route-map rule <1-65535> set extcommunity bandwidth + <1-25600|cumulative|num-multipaths> + + Set extcommunity bandwidth + +.. cfgcmd:: set policy route-map rule <1-65535> set extcommunity bandwidth-non-transitive + + The link bandwidth extended community is encoded as non-transitive + +.. cfgcmd:: set policy route-map rule <1-65535> set extcommunity rt + + + Set route target value in format ``<0-65535:0-4294967295>`` or ````. + +.. cfgcmd:: set policy route-map rule <1-65535> set extcommunity soo + + + Set site of origin value in format ``<0-65535:0-4294967295>`` or ````. + +.. cfgcmd:: set policy route-map rule <1-65535> set extcommunity none + + Clear all BGP extcommunities. + +.. cfgcmd:: set policy route-map rule <1-65535> set distance <0-255> + + Locally significant administrative distance. + + +.. cfgcmd:: set policy route-map rule <1-65535> set ip-next-hop + + + Nexthop IP address. + +.. cfgcmd:: set policy route-map rule <1-65535> set ip-next-hop + unchanged + + Set the next-hop as unchanged. Pass through the route-map without + changing its value + +.. cfgcmd:: set policy route-map rule <1-65535> set ip-next-hop + peer-address + + Set the BGP nexthop address to the address of the peer. For an incoming + route-map this means the ip address of our peer is used. For an + outgoing route-map this means the ip address of our self is used to + establish the peering with our neighbor. + +.. cfgcmd:: set policy route-map rule <1-65535> set ipv6-next-hop + + + Nexthop IPv6 address. + +.. cfgcmd:: set policy route-map rule <1-65535> set ipv6-next-hop + peer-address + + Set the BGP nexthop address to the address of the peer. For an incoming + route-map this means the ip address of our peer is used. For an + outgoing route-map this means the ip address of our self is used to + establish the peering with our neighbor. + +.. cfgcmd:: set policy route-map rule <1-65535> set ipv6-next-hop + prefer-global + + For Incoming and Import Route-maps if we receive a v6 global and v6 LL + address for the route, then prefer to use the global address as the + nexthop. + +.. cfgcmd:: set policy route-map rule <1-65535> set local-preference + <0-4294967295> + + Set BGP local preference attribute. + +.. cfgcmd:: set policy route-map rule <1-65535> set metric + <+/-metric|0-4294967295|rtt|+rtt|-rtt> + + Set the route metric. When used with BGP, set the BGP attribute MED + to a specific value. Use ``+/-`` to add or subtract the specified value + to/from the existing/MED. Use ``rtt`` to set the MED to the round trip + time or ``+rtt/-rtt`` to add/subtract the round trip time to/from the MED. + +.. cfgcmd:: set policy route-map rule <1-65535> set metric-type + + + Set OSPF external metric-type. + +.. cfgcmd:: set policy route-map rule <1-65535> set origin + + + Set BGP origin code. + +.. cfgcmd:: set policy route-map rule <1-65535> set originator-id + + + Set BGP originator ID attribute. + +.. cfgcmd:: set policy route-map rule <1-65535> set src + + + Set source IP/IPv6 address for route. + +.. cfgcmd:: set policy route-map rule <1-65535> set table <1-200> + + Set prefixes to table. + +.. cfgcmd:: set policy route-map rule <1-65535> set tag <1-65535> + + Set tag value for routing protocol. + +.. cfgcmd:: set policy route-map rule <1-65535> set weight + <0-4294967295> + + Set BGP weight attribute + +List of well-known communities +============================== + * ``local-as`` - Well-known communities value NO_EXPORT_SUBCONFED 0xFFFFFF03 + * ``no-advertise`` - Well-known communities value NO_ADVERTISE 0xFFFFFF02 + * ``no-export`` - Well-known communities value NO_EXPORT 0xFFFFFF01 + * ``graceful-shutdown`` - Well-known communities value GRACEFUL_SHUTDOWN 0xFFFF0000 + * ``accept-own`` - Well-known communities value ACCEPT_OWN 0xFFFF0001 + * ``route-filter-translated-v4`` - Well-known communities value ROUTE_FILTER_TRANSLATED_v4 0xFFFF0002 + * ``route-filter-v4`` - Well-known communities value ROUTE_FILTER_v4 0xFFFF0003 + * ``route-filter-translated-v6`` - Well-known communities value ROUTE_FILTER_TRANSLATED_v6 0xFFFF0004 + * ``route-filter-v6`` - Well-known communities value ROUTE_FILTER_v6 0xFFFF0005 + * ``llgr-stale`` - Well-known communities value LLGR_STALE 0xFFFF0006 + * ``no-llgr`` - Well-known communities value NO_LLGR 0xFFFF0007 + * ``accept-own-nexthop`` - Well-known communities value accept-own-nexthop 0xFFFF0008 + * ``blackhole`` - Well-known communities value BLACKHOLE 0xFFFF029A + * ``no-peer`` - Well-known communities value NOPEER 0xFFFFFF04 diff --git a/docs/configuration/policy/rst-route.rst b/docs/configuration/policy/rst-route.rst new file mode 100644 index 00000000..1ddd04cf --- /dev/null +++ b/docs/configuration/policy/rst-route.rst @@ -0,0 +1,306 @@ +####################### +Route and Route6 Policy +####################### + +IPv4 route and IPv6 route policies are defined in this section. These route +policies can then be associated to interfaces. + +********* +Rule-Sets +********* + +A rule-set is a named collection of rules that can be applied to an interface. +Each rule is numbered, has an action to apply if the rule is matched, and the +ability to specify the criteria to match. Data packets go through the rules +from 1 - 999999, at the first match the action of the rule will be executed. + +.. cfgcmd:: set policy route description +.. cfgcmd:: set policy route6 description + + Provide a rule-set description. + +.. cfgcmd:: set policy route default-log +.. cfgcmd:: set policy route6 default-log + + Option to log packets hitting default-action. + +.. cfgcmd:: set policy route interface +.. cfgcmd:: set policy route6 interface + + Apply routing policy to interface + +.. cfgcmd:: set policy route rule description +.. cfgcmd:: set policy route6 rule description + + Provide a description for each rule. + +.. cfgcmd:: set policy route rule log +.. cfgcmd:: set policy route6 rule log + + Option to enable or disable log matching rule. + +Matching criteria +================= + +There are a lot of matching criteria options available, both for +``policy route`` and ``policy route6``. These options are listed +in this section. + +.. cfgcmd:: set policy route rule connection-mark <1-2147483647> +.. cfgcmd:: set policy route6 rule connection-mark <1-2147483647> + + Set match criteria based on connection mark. + +.. cfgcmd:: set policy route rule mark +.. cfgcmd:: set policy route6 rule mark + + Match based on the firewall mark (fwmark), where can be: + + * <0-2147483647> a single fwmark + * !<0-2147483647> everything except a single fwmark + * a range of marks + * ! everything except the range of marks + + .. note:: When using the ``set table`` or ``set vrf`` commands the mark + settings are ignored and overwritten with a table-specific mark that + is set to 0x7FFFFFFF - the id of the table/VRF. + +.. cfgcmd:: set policy route rule source address + +.. cfgcmd:: set policy route rule destination address + +.. cfgcmd:: set policy route6 rule source address + +.. cfgcmd:: set policy route6 rule destination address + + + Set match criteria based on source or destination ipv4|ipv6 address, where + could be: + +For ipv4: + * : IP address to match. + * : Subnet to match. + * -: IP range to match. + * !: Match everything except the specified address. + * !: Match everything except the specified subnet. + * !-: Match everything except the specified range. + +And for ipv6: + * : IPv6 address to match. + * : IPv6 prefix to match. + * -: IPv6 range to match. + * !: Match everything except the specified address. + * !: Match everything except the specified prefix. + * !-: Match everything except the + specified range. + +.. cfgcmd:: set policy route rule source group + +.. cfgcmd:: set policy route rule destination group + +.. cfgcmd:: set policy route6 rule source group + +.. cfgcmd:: set policy route6 rule destination group + + + Set match criteria based on source or destination groups, where + would be the group name/identifier. Prepend character '!' for inverted + matching criteria. + +.. cfgcmd:: set policy route rule destination port +.. cfgcmd:: set policy route6 rule destination port + + Set match criteria based on destination port, where could + be: + + * : Named port (any name in /etc/services, e.g., http). + * <1-65535>: Numbered port. + * -: Numbered port range (e.g., 1001-1005). + + Multiple destination ports can be specified as a comma-separated list. The + whole list can also be "negated" using '!'. For example: + '!22,telnet,http,123,1001-1005' + +.. cfgcmd:: set policy route rule disable +.. cfgcmd:: set policy route6 rule disable + + Option to disable rule. + +.. cfgcmd:: set policy route rule dscp +.. cfgcmd:: set policy route6 rule dscp +.. cfgcmd:: set policy route rule dscp-exclude +.. cfgcmd:: set policy route6 rule dscp-exclude + + Match based on dscp value criteria. Multiple values from 0 to 63 + and ranges are supported. + +.. cfgcmd:: set policy route rule fragment + +.. cfgcmd:: set policy route6 rule fragment + + + Set IP fragment match, where: + + * match-frag: Second and further fragments of fragmented packets. + * match-non-frag: Head fragments or unfragmented packets. + +.. cfgcmd:: set policy route rule icmp +.. cfgcmd:: set policy route6 rule icmpv6 + + Match based on icmp|icmpv6 code and type. + +.. cfgcmd:: set policy route rule icmp type-name +.. cfgcmd:: set policy route6 rule icmpv6 type-name + + Match based on icmp|icmpv6 type-name criteria. Use tab for information + about what type-name criteria are supported. + +.. cfgcmd:: set policy route rule ipsec + +.. cfgcmd:: set policy route6 rule ipsec + + + Set IPSec inbound match criterias, where: + + * match-ipsec: match inbound IPsec packets. + * match-none: match inbound non-IPsec packets. + +.. cfgcmd:: set policy route rule limit burst <0-4294967295> +.. cfgcmd:: set policy route6 rule limit burst <0-4294967295> + + Set maximum number of packets to alow in excess of rate. + +.. cfgcmd:: set policy route rule limit rate +.. cfgcmd:: set policy route6 rule limit rate + + Set maximum average matching rate. Format for rate: integer/time_unit, where + time_unit could be any one of second, minute, hour or day.For example + 1/second implies rule to be matched at an average of once per second. + +.. cfgcmd:: set policy route rule protocol + +.. cfgcmd:: set policy route6 rule protocol + + + Match a protocol criteria. A protocol number or a name which is defined in: + ``/etc/protocols``. Special names are ``all`` for all protocols and + ``tcp_udp`` for tcp and udp based packets. The ``!`` negates the selected + protocol. + +.. cfgcmd:: set policy route rule packet-length +.. cfgcmd:: set policy route6 rule packet-length +.. cfgcmd:: set policy route rule packet-length-exclude +.. cfgcmd:: set policy route6 rule packet-length-exclude + + Match based on packet length criteria. Multiple values from 1 to 65535 + and ranges are supported. + +.. cfgcmd:: set policy route rule packet-type [broadcast | host + | multicast | other] +.. cfgcmd:: set policy route6 rule packet-type [broadcast | host + | multicast | other] + + Match based on packet type criteria. + +.. cfgcmd:: set policy route rule recent count <1-255> +.. cfgcmd:: set policy route6 rule recent count <1-255> +.. cfgcmd:: set policy route rule recent time <1-4294967295> +.. cfgcmd:: set policy route6 rule recent time <1-4294967295> + + Set parameters for matching recently seen sources. This match could be used + by seeting count (source address seen more than <1-255> times) and/or time + (source address seen in the last <0-4294967295> seconds). + +.. cfgcmd:: set policy route rule state + +.. cfgcmd:: set policy route6 rule state + + + Set match criteria based on session state. + +.. cfgcmd:: set policy route rule tcp flags +.. cfgcmd:: set policy route6 rule tcp flags + + Set match criteria based on tcp flags. Allowed values for TCP flags: SYN ACK + FIN RST URG PSH ALL. When specifying more than one flag, flags should be + comma-separated. For example : value of 'SYN,!ACK,!FIN,!RST' will only match + packets with the SYN flag set, and the ACK, FIN and RST flags unset. + +.. cfgcmd:: set policy route rule time monthdays +.. cfgcmd:: set policy route6 rule time monthdays +.. cfgcmd:: set policy route rule time startdate +.. cfgcmd:: set policy route6 rule time startdate +.. cfgcmd:: set policy route rule time starttime +.. cfgcmd:: set policy route6 rule time starttime +.. cfgcmd:: set policy route rule time stopdate +.. cfgcmd:: set policy route6 rule time stopdate +.. cfgcmd:: set policy route rule time stoptime +.. cfgcmd:: set policy route6 rule time stoptime +.. cfgcmd:: set policy route rule time weekdays +.. cfgcmd:: set policy route6 rule time weekdays +.. cfgcmd:: set policy route rule time utc +.. cfgcmd:: set policy route6 rule time utc + + Time to match the defined rule. + +.. cfgcmd:: set policy route rule ttl <0-255> + + Match time to live parameter, where 'eq' stands for 'equal'; 'gt' stands for + 'greater than', and 'lt' stands for 'less than'. + +.. cfgcmd:: set policy route6 rule hop-limit <0-255> + + Match hop-limit parameter, where 'eq' stands for 'equal'; 'gt' stands for + 'greater than', and 'lt' stands for 'less than'. + +Actions +======= + +When mathcing all patterns defined in a rule, then different actions can +be made. This includes droping the packet, modifying certain data, or +setting a different routing table. + +.. cfgcmd:: set policy route rule action drop +.. cfgcmd:: set policy route6 rule action drop + + Set rule action to drop. + +.. cfgcmd:: set policy route rule set connection-mark + <1-2147483647> +.. cfgcmd:: set policy route6 rule set connection-mark + <1-2147483647> + + Set a specific connection mark. + +.. cfgcmd:: set policy route rule set dscp <0-63> +.. cfgcmd:: set policy route6 rule set dscp <0-63> + + Set packet modifications: Packet Differentiated Services Codepoint (DSCP) + +.. cfgcmd:: set policy route rule set mark <1-2147483647> +.. cfgcmd:: set policy route6 rule set mark <1-2147483647> + + Set a specific packet mark. + +.. cfgcmd:: set policy route rule set table
+.. cfgcmd:: set policy route6 rule set table
+ + Set the routing table to forward packet with. + + .. note:: When using the ``set table`` or ``set vrf`` commands matching + against the mark is not possible, because it gets overwritten with a + table-specific mark that is 0x7FFFFFFF - the id of the table/VRF. + +.. cfgcmd:: set policy route rule set tcp-mss <500-1460> +.. cfgcmd:: set policy route6 rule set tcp-mss <500-1460> + + Set packet modifications: Explicitly set TCP Maximum segment size value. + +.. cfgcmd:: set policy route rule set vrf +.. cfgcmd:: set policy route6 rule set vrf + + Set the VRF to forward packet with. + + .. note:: When using the ``set table`` or ``set vrf`` commands matching + against the mark is not possible, because it gets overwritten with a + table-specific mark that is 0x7FFFFFFF - the id of the table/VRF. -- cgit v1.2.3