Configuring PIM-SM
645
■
You can configure these parameters at three levels: global configuration level,
global scope level, and BSR admin-scope level.
■
By default, the global scope parameters and BSR admin-scope parameters are
those configured at the global configuration level.
■
Parameters configured at the global scope level or BSR admin-scope level have
higher priority than those configured at the global configuration level.
Performing basic C-BSR configuration
A PIM-SM domain can have only one BSR, but must have at least one C-BSR. Any
router can be configured as a C-BSR. Elected from C-BSRs, a BSR is responsible for
collecting and advertising RP information in the PIM-SM.
C-BSRs should be configured on routers in the backbone network. When
configuring a router as a C-BSR, make sure that router is PIM-SM enabled. The BSR
election process is as follows:
■
Initially, every C-BSR assumes itself to be the BSR of this PIM-SM domain, and
uses its interface IP address as the BSR address to send bootstrap messages.
■
When a C-BSR receives the bootstrap message of another C-BSR, it first
compares its own priority with the other C-BSR’s priority carried in the
message. The C-BSR with a higher priority wins. If there is a tie in the priority,
the C-BSR with a higher IP address wins. The loser uses the winner’s BSR
address to replace its own BSR address and no longer assumes itself to be the
BSR, while the winner keeps its own BSR address and continues assuming itself
to be the BSR.
Configuring a legal range of BSR addresses enables filtering of BSR messages
based on the address range, thus to prevent malicious hosts from initiating attacks
by disguising themselves as legitimate BSRs. To protect legitimate BSRs from being
maliciously replaced, preventive measures are taken specific to the following two
situations:
1
Some malicious hosts intend to fool routers by forging BSR messages and change
the RP mapping relationship. Such attacks often occur on border routers. Because
a BSR is inside the network whereas hosts are outside the network, you can
protect a BSR against attacks from external hosts by enabling border routers to
perform neighbor check and RPF check on BSR messages and discard unwanted
messages.
2
When a router in the network is controlled by an attacker or when an illegal router
is present in the network, the attacker can configure such a router to be a C-BSR
and make it win BSR election so as to gain the right of advertising RP information
in the network. After being configured as a C-BSR, a router automatically floods
the network with BSR messages. As a BSR message has a TTL value of 1, the whole
network will not be affected as long as the neighbor router discards these BSR
messages. Therefore, if a legal BSR address range is configured on all routers in the
entire network, all routers will discard BSR messages from out of the legal address
range, and thus this kind of attacks can be prevented.
The above-mentioned preventive measures can partially protect the security of
BSRs in a network. However, if a legal BSR is controlled by an attacker, the
above-mentioned problem will also occur.
Содержание 4800G Series
Страница 26: ...26 CHAPTER NETWORKING APPLICATIONS ...
Страница 30: ...30 CHAPTER 1 LOGGING IN TO AN ETHERNET SWITCH ...
Страница 62: ...62 CHAPTER 3 LOGGING IN THROUGH TELNET ...
Страница 70: ...70 CHAPTER 5 LOGGING IN THROUGH WEB BASED NETWORK MANAGEMENT SYSTEM ...
Страница 72: ...72 CHAPTER 6 LOGGING IN THROUGH NMS ...
Страница 82: ...82 CHAPTER 8 CONTROLLING LOGIN USERS ...
Страница 98: ...98 CHAPTER 9 VLAN CONFIGURATION ...
Страница 108: ...108 CHAPTER 10 VOICE VLAN CONFIGURATION ...
Страница 119: ...GVRP Configuration Examples 119 DeviceB display vlan dynamic No dynamic vlans exist ...
Страница 120: ...120 CHAPTER 11 GVRP CONFIGURATION ...
Страница 160: ...160 CHAPTER 17 PORT ISOLATION CONFIGURATION ...
Страница 172: ...172 CHAPTER 19 LINK AGGREGATION CONFIGURATION ...
Страница 196: ...196 CHAPTER 22 DLDP CONFIGURATION ...
Страница 240: ...240 CHAPTER 23 MSTP CONFIGURATION ...
Страница 272: ...272 CHAPTER 27 RIP CONFIGURATION ...
Страница 364: ...364 CHAPTER 29 IS IS CONFIGURATION ...
Страница 426: ...426 CHAPTER 31 ROUTING POLICY CONFIGURATION ...
Страница 442: ...442 CHAPTER 33 IPV6 RIPNG CONFIGURATION ...
Страница 466: ...466 CHAPTER 35 IPV6 IS IS CONFIGURATION ...
Страница 488: ...488 CHAPTER 36 IPV6 BGP CONFIGURATION ...
Страница 498: ...498 CHAPTER 37 ROUTING POLICY CONFIGURATION ...
Страница 540: ...540 CHAPTER 40 TUNNELING CONFIGURATION ...
Страница 552: ...552 CHAPTER 41 MULTICAST OVERVIEW ...
Страница 604: ...604 CHAPTER 43 MLD SNOOPING CONFIGURATION ...
Страница 628: ...628 CHAPTER 46 IGMP CONFIGURATION ...
Страница 699: ...Troubleshooting MSDP 699 4 Verify that the C BSR address is different from the anycast RP address ...
Страница 700: ...700 CHAPTER 48 MSDP CONFIGURATION ...
Страница 812: ...812 CHAPTER 57 DHCP SERVER CONFIGURATION ...
Страница 822: ...822 CHAPTER 58 DHCP RELAY AGENT CONFIGURATION ...
Страница 834: ...834 CHAPTER 61 BOOTP CLIENT CONFIGURATION ...
Страница 850: ...850 CHAPTER 63 IPV4 ACL CONFIGURATION ...
Страница 856: ...856 CHAPTER 64 IPV6 ACL CONFIGURATION ...
Страница 860: ...860 CHAPTER 65 QOS OVERVIEW ...
Страница 868: ...868 CHAPTER 66 TRAFFIC CLASSIFICATION TP AND LR CONFIGURATION ...
Страница 888: ...888 CHAPTER 69 PRIORITY MAPPING ...
Страница 894: ...894 CHAPTER 71 TRAFFIC MIRRORING CONFIGURATION ...
Страница 904: ...904 CHAPTER 72 PORT MIRRORING CONFIGURATION ...
Страница 930: ...930 CHAPTER 74 UDP HELPER CONFIGURATION ...
Страница 990: ...990 CHAPTER 79 FILE SYSTEM MANAGEMENT CONFIGURATION ...
Страница 1000: ...1000 CHAPTER 80 FTP CONFIGURATION ...
Страница 1020: ...1020 CHAPTER 82 INFORMATION CENTER CONFIGURATION ...
Страница 1038: ...1038 CHAPTER 84 SYSTEM MAINTAINING AND DEBUGGING ...
Страница 1046: ...1046 CHAPTER 85 DEVICE MANAGEMENT ...
Страница 1129: ...SSH Client Configuration Examples 1129 SwitchB ...
Страница 1130: ...1130 CHAPTER 88 SSH CONFIGURATION ...
Страница 1160: ...1160 CHAPTER 90 RRPP CONFIGURATION ...
Страница 1180: ...1180 CHAPTER 91 PORT SECURITY CONFIGURATION ...
Страница 1192: ...1192 CHAPTER 92 LLDP CONFIGURATION ...
Страница 1202: ...1202 CHAPTER 93 POE CONFIGURATION ...
Страница 1218: ...1218 CHAPTER 96 HTTPS CONFIGURATION ...