Configuring SA Message Transmission
595
Configuring a Rule for
Filtering Received and
Forwarded SA Messages
Besides the creation of source information, controlling multicast source information
allows you to control the forwarding and reception of source information. You can
control the reception of SA messages using the MSDP inbound filter (corresponding
to the
import
keyword); you can control the forwarding of SA messages by using
either the MSDP outbound filter (corresponding to the
export
argument) or the TTL
threshold. By default, an MSDP peer receives and forwards all SA messages.
MSDP inbound/outbound filter implements the following functions:
■
Filtering out all (S, G) entries
■
Receiving/forwarding only the SA messages permitted by advanced ACL rules
An SA message carrying encapsulated data can reach the specified MSDP peer
outside the domain only when the TTL in its IP header exceeds the threshold;
therefore, you can control the forwarding of SA messages that carry encapsulated
data by configuring the TTL threshold.
Configuring SA Message
Cache
With the SA message caching mechanism enabled on the router, the group that a
new member subsequently joins can obtain all active sources directly from the SA
cache and join the corresponding SPT source tree, instead of waiting for the next SA
message.
You can configure the number of SA entries cached in each MSDP peer on the router
by executing the following command, but the number must be within the system
limit. The system sets the maximum number of SA messages cached in each MSDP
peer and the maximum number of SA messages cached in all MSDP peers on the
router; these thresholds must not exceed the system limits. To protect a router against
Deny of Service (DoS) attacks, you can manually configure the maximum number of
SA messages cached on the router. Generally, the configured number of SA messages
cached should be less than the system limit.
Table 651: Configure a rule for filtering received and forwarded SA messages
Operation
Command
Description
Enter system view
system-view
-
Enter MSDP view
msdp
-
Configure the filtering list for
receiving or forwarding SA
messages from the specified
MSDP peer
peer
peer-address
sa-policy
{
import
|
export
} [
acl
acl-number
]
Optional
By default, no filtering is
imposed on SA messages to be
received or forwarded, namely all
SA messages from MSDP peers
are received or forwarded
.
Configure the minimum TTL
for the multicast packets sent
to the specified MSDP peer
peer
peer-address
minimum-ttl
ttl-value
Optional
By default, the value of TTL
threshold is 0.
Table 652
Configure SA message cache
Operation
Command
Description
Enter system view
system-view
-
Enter MSDP view
msdp
-
Enable SA message
caching mechanism
cache-sa-enable
Optional
By default, the SA message caching
mechanism is enabled.
Summary of Contents for 5500 SI - Switch - Stackable
Page 24: ...24 ABOUT THIS GUIDE...
Page 50: ...50 CHAPTER 1 GETTING STARTED...
Page 54: ...54 CHAPTER 2 ADDRESS MANAGEMENT CONFIGURATION...
Page 78: ...78 CHAPTER 3 PORT OPERATION...
Page 88: ...88 CHAPTER 4 XRN CONFIGURATION...
Page 122: ...122 CHAPTER 8 VLAN VPN CONFIGURATION...
Page 216: ...216 CHAPTER 15 SSH TERMINAL SERVICES...
Page 268: ...268 CHAPTER 16 IP ROUTING PROTOCOL OPERATION...
Page 308: ...308 CHAPTER 17 NETWORK PROTOCOL OPERATION...
Page 349: ...349...
Page 350: ...350 CHAPTER 18 MULTICAST PROTOCOL...
Page 522: ...522 CHAPTER 22 FILE SYSTEM MANAGEMENT...
Page 584: ...584 CHAPTER 30 PASSWORD CONTROL CONFIGURATION OPERATIONS...
Page 600: ...600 CHAPTER 31 MSDP CONFIGURATION...
Page 614: ...614 CHAPTER 32 CLUSTERING...
Page 670: ...670 CHAPTER C AUTHENTICATING THE SWITCH 5500 WITH CISCO SECURE ACS...