Solved

BGP advertised networks

Posted on 2014-03-27
1
319 Views
Last Modified: 2014-04-08
I have a private 10.10.0.0/16 subnet. That subnet is further extend to 25 /24 subnets within my internal network. My WAN is a MPLS network. My FW is doing BGP peering with the provider MPLS router.
Should I advertise a /16 or 25 /24 with the network statement.

Somebody told me, for security purposes, that I should advertise individual specific routes rather than a /16. I am not sure I agree with that. But I'd like to get your thought on this.

Thanks
0
Comment
Question by:leblanc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 17

Accepted Solution

by:
pergr earned 500 total points
ID: 39960932
If all those networks are on the same site, and you use a single router, and no other site is using networks within 10.10/16 - then you can advertise the /16.

It has nothing to do with security.

Only reason to use /24 is if you want to load balance different /24 to different links.
0

Featured Post

Creating Instructional Tutorials  

For Any Use & On Any Platform

Contextual Guidance at the moment of need helps your employees/users adopt software o& achieve even the most complex tasks instantly. Boost knowledge retention, software adoption & employee engagement with easy solution.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question