25 Prefix-Lists & Distribute-Lists
These are the tools that filter routes by prefix. A prefix-list defines which prefixes to match (including by prefix length); a distribute-list is the command that attaches a filter to a routing protocol and sets its direction. This note also contrasts how filtering is applied in IGPs versus BGP.
Prefix-lists
A prefix-list matches routes by their network prefix and can also match on prefix length, which a standard ACL cannot do cleanly. Each entry has a sequence number and a permit or deny action, evaluated top-down with an implicit deny at the end.
Prefix length matching uses two optional keywords:
ge(greater-than-or-equal): matches prefixes with a mask length greater than or equal to the value.le(less-than-or-equal): matches prefixes with a mask length less than or equal to the value.
Without ge or le, the match is on the exact prefix and length specified. With them, a range of lengths is matched.
Distribute-lists
The distribute-list is the command that applies a filter to a routing protocol and defines the direction. On its own, an ACL, prefix-list, or route-map filters nothing until a distribute-list (or, in BGP, a neighbor statement) attaches it.
Variants of the filtering criterion:
- ACL (standard or extended).
prefixwith a prefix-list.route-map(the most powerful; can also set attributes).gatewaywith a prefix-list: filters by the route’s next-hop/gateway rather than by the prefix. It matches on where the route came from, not what network it is.
Direction:
incontrols what enters the router (routes learned from a neighbor), filtered before entering the table.outcontrols what leaves the router (routes advertised), filtered before advertising.
IGP vs BGP application
This is a common point of confusion. The attachment mechanism differs by protocol:
- In IGPs (EIGRP, OSPF), filtering is applied with
distribute-list. - In BGP, a route-map or prefix filter is typically applied directly to the neighbor:
neighbor <ip> route-map <name> {in | out}neighbor <ip> prefix-list <name> {in | out}
The concept of in/out is identical in both cases; only the attachment command changes.
Filter by prefix vs filter by AS-PATH
Prefix-based filtering answers “which network,” while AS-PATH filtering (note 26) answers “which path.” They are complementary:
- prefix-list / distribute-list → filter by prefix (the destination).
- filter-list with AS-PATH ACL → filter by AS-PATH (the path).
Self-check
Q1 — What can a prefix-list match that a standard ACL cannot cleanly?
A) The next-hop
B) The prefix length (withge/le)
C) The AS-PATH
D) The community
Respuesta
B is correct. A prefix-list can match on prefix length using
geandle, matching a range of mask lengths, which a standard ACL cannot do cleanly.
- A) False — next-hop matching is the
gatewaydistribute-list variant.- C) False — AS-PATH matching uses an AS-PATH ACL.
- D) False — community matching uses a community-list.
Q2 — What is the role of a distribute-list?
A) To define which prefixes exist
B) To attach a filter (ACL, prefix-list, route-map, or gateway) to a protocol and set its direction
C) To originate routes into BGP
D) To set the Router ID
Respuesta
B is correct. The distribute-list attaches a filter to a routing protocol and defines
in/out; the filter itself does nothing until attached.
- A) False — defining prefixes is the prefix-list’s job; distribute-list applies it.
- C) False — origination is done with
network, redistribution, or aggregation.- D) False — it does not set the Router ID.
Q3 — What does the
gatewaydistribute-list variant filter on?A) The prefix length
B) The route’s next-hop/gateway (where it came from)
C) The community
D) The Local Preference
Respuesta
B is correct. The
gatewayvariant filters by the route’s next-hop/gateway, matching where the route came from rather than which network it is.
- A) False — prefix length is matched by a prefix-list.
- C) False — communities are matched by a community-list.
- D) False — Local Preference is not a distribute-list criterion.
Q4 — How is prefix/route-map filtering typically applied in BGP versus an IGP?
A) Both use
distribute-list
B) IGPs usedistribute-list; BGP typically applies it directly to the neighbor (neighbor ... route-map/prefix-list in|out)
C) Both apply it directly to the neighbor
D) BGP cannot filter by prefix
Respuesta
B is correct. IGPs attach filters with
distribute-list; BGP typically attaches route-maps or prefix filters per-neighbor. Thein/outconcept is the same; only the command differs.
- A) False — BGP typically uses the neighbor statement, not distribute-list.
- C) False — IGPs use distribute-list, not per-neighbor attachment.
- D) False — BGP filters by prefix using prefix-lists per neighbor.