25 Prefix-Lists & Distribute-Lists

These are the tools that filter routes by prefix. A prefix-list defines which prefixes to match (including by prefix length); a distribute-list is the command that attaches a filter to a routing protocol and sets its direction. This note also contrasts how filtering is applied in IGPs versus BGP.

Prefix-lists

A prefix-list matches routes by their network prefix and can also match on prefix length, which a standard ACL cannot do cleanly. Each entry has a sequence number and a permit or deny action, evaluated top-down with an implicit deny at the end.

Prefix length matching uses two optional keywords:

  • ge (greater-than-or-equal): matches prefixes with a mask length greater than or equal to the value.
  • le (less-than-or-equal): matches prefixes with a mask length less than or equal to the value.

Without ge or le, the match is on the exact prefix and length specified. With them, a range of lengths is matched.

Distribute-lists

The distribute-list is the command that applies a filter to a routing protocol and defines the direction. On its own, an ACL, prefix-list, or route-map filters nothing until a distribute-list (or, in BGP, a neighbor statement) attaches it.

Variants of the filtering criterion:

  • ACL (standard or extended).
  • prefix with a prefix-list.
  • route-map (the most powerful; can also set attributes).
  • gateway with a prefix-list: filters by the route’s next-hop/gateway rather than by the prefix. It matches on where the route came from, not what network it is.

Direction:

  • in controls what enters the router (routes learned from a neighbor), filtered before entering the table.
  • out controls what leaves the router (routes advertised), filtered before advertising.

IGP vs BGP application

This is a common point of confusion. The attachment mechanism differs by protocol:

  • In IGPs (EIGRP, OSPF), filtering is applied with distribute-list.
  • In BGP, a route-map or prefix filter is typically applied directly to the neighbor:
    • neighbor <ip> route-map <name> {in | out}
    • neighbor <ip> prefix-list <name> {in | out}

The concept of in/out is identical in both cases; only the attachment command changes.

Filter by prefix vs filter by AS-PATH

Prefix-based filtering answers “which network,” while AS-PATH filtering (note 26) answers “which path.” They are complementary:

  • prefix-list / distribute-list → filter by prefix (the destination).
  • filter-list with AS-PATH ACL → filter by AS-PATH (the path).

Self-check

Q1 — What can a prefix-list match that a standard ACL cannot cleanly?

A) The next-hop
B) The prefix length (with ge / le)
C) The AS-PATH
D) The community

Q2 — What is the role of a distribute-list?

A) To define which prefixes exist
B) To attach a filter (ACL, prefix-list, route-map, or gateway) to a protocol and set its direction
C) To originate routes into BGP
D) To set the Router ID

Q3 — What does the gateway distribute-list variant filter on?

A) The prefix length
B) The route’s next-hop/gateway (where it came from)
C) The community
D) The Local Preference

Q4 — How is prefix/route-map filtering typically applied in BGP versus an IGP?

A) Both use distribute-list
B) IGPs use distribute-list; BGP typically applies it directly to the neighbor (neighbor ... route-map/prefix-list in|out)
C) Both apply it directly to the neighbor
D) BGP cannot filter by prefix