i'm trying to blackhole a single IPv6 on my upstream (HE) via a filter rule attached to the BGP instance with out-filter.
Unfortunately and no matter what I try, it seems I cant get this it to work. Maybe any hints?
Attached my current config.
Thanks in advance
Code: Select all
[rtradmin@core] /ipv6 address> print where interface=bridge1
Flags: X - disabled, I - invalid, D - dynamic, G - global, L - link-local
# ADDRESS FROM-POOL INTERFACE ADVERTISE
0 G 2001:623:420:6666::1/128 bridge1 no
[rtradmin@core] /routing bgp instance> print
Flags: * - default, X - disabled
0 * name="default" as=12345 router-id=x.x.x.x redistribute-connected=no redistribute-static=no redistribute-rip=no
redistribute-ospf=no redistribute-other-bgp=no out-filter=blackhole-out client-to-client-reflection=yes ignore-as-path-len=no
routing-table=""
[rtradmin@core] /routing filter> print where chain=blackhole-out
Flags: X - disabled
0 chain=blackhole-out prefix=2001:623:420:6666::1/128 bgp-communities="" address-family=ipv6 invert-match=no action=accept
set-type=blackhole set-bgp-prepend-path="" set-bgp-communities=6939:666
1 chain=blackhole-out invert-match=no action=discard set-bgp-prepend-path=""