# IP Prefix-List Question Part-2

**URL:** <https://legacy-community.ine.com/t/ip-prefix-list-question-part-2/2487>\
**Category:** CCNP Enterprise\
**Tags:** networking\
**Created:** [June 19, 2022, 11:42pm UTC](https://legacy-community.ine.com/t/ip-prefix-list-question-part-2/2487 "2022-06-19T23:42:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![major133-ac9365513dd](https://avatars.discourse-cdn.com/v4/letter/m/f4b2a3/32.png) [@major133-ac9365513dd](https://legacy-community.ine.com/u/major133-ac9365513dd)\
**Post date:** [June 19, 2022, 11:42pm UTC](https://legacy-community.ine.com/t/ip-prefix-list-question-part-2/2487/1 "2022-06-19T23:42:56Z")

</div>

Hi Everyone  
how to deny all routes have the first 3-octets 10.100.20 and subnet mask range 24-\>29 ?

i`ve two solutions to do that

solution#1  
10.100.20.0/24

10.100.20.0/24 ge 25 le 29

solution#2

10.100.20.0/24 le 29

but what is the difference between both solutions (solution#1 and solution#2)

10.100.20.0/24

10.100.20.0/24 ge 25 le 29

vs

10.100.20.0/24 le 29

???

---

<div class="post-metadata">

**Author:** ![kbogart-81b6c89deee9](https://avatars.discourse-cdn.com/v4/letter/k/4af34b/32.png) [@kbogart-81b6c89deee9](https://legacy-community.ine.com/u/kbogart-81b6c89deee9)\
**Post date:** [July 7, 2022, 1:37pm UTC](https://legacy-community.ine.com/t/ip-prefix-list-question-part-2/2487/2 "2022-07-07T13:37:40Z")

</div>

Hello major133,

Both solutions you wrote will work, but the second solution is the more elegant one.

In reality, if a router sends you a routing update about a prefix, and indicates that the first 24-bits of that prefix are:  
00001010 01100100 00010100 (10.100.20)

…then that update will NEVER contain an associated mask anything less than a /24 (otherwise there would be no need to specify all 24-bits in the prefix). So that’s why your second solution is the best one.
