708
C
HAPTER
7: M
ULTICAST
C
OMMON
C
ONFIGURATION
C
OMMANDS
<3Com> reset igmp group interface ethernet0/0/0 all
Delete the group 225.0.0.1 on the interface Ethernet0/0/0.
<3Com> reset igmp group interface ethernet0/0/0 225.0.0.1
Delete the IGMP groups ranging between the network segment 225.1.1.0 and
225.1.1.255 on the interface Ethernet0/0/0.
<3Com> reset igmp group interface ethernet0/0/0 225.1.1.0
255.255.255.0
PIM Configuration
Commands
bsr-policy
Syntax
bsr-policy acl-number
undo bsr-policy
View
PIM view
Parameter
acl-number: ACL number used by BSR filter policy , ranging from 1 to 99.
Description
Using the bsr-policy command, you can restrict the range for valid BSR so as to
prevent BSR spoofing. Using the undo bsr-policy command, you can restore the
normal state without any range restriction and regard all the messages received
are valid.
In PIM SM network which uses BSR mechanism, any router can set itself as C-BSR
and will take charge of the authority of advertising BP information in the network
if it succeeds in competition. To prevent the valid BSR in the network from being
maliciously replaced, the following two measures should be taken:
■
Change RP mapping relationship to prevent the host from spoofing the router
by counterfeiting valid BSR packet. BSR packet is multicast packet with TTL of
1, so this kind of attack usually takes place on the edge router. BSR is in the
internal network and the host is in the external network, therefore, performing
neighbor check and RPF check to BSR packet can prevent this kind of attack.
■
If a router in the network is controlled by an attacker or an illegal router
accesses the network, the attacker can set the router to C-BSR and make it
succeed in competition and control the authority of advertising RP information
in the network. The router, after being configured as C-BSR, will automatically
advertise BSR information to the whole network. BSR packet is the multicast
packet which is forwarded hop by hop with TTL of 1. The whole network will
not be affected if the neighbor router does not receive the BSR information.
The solution is to configure bsr-policy on each router in the whole network to
restrict the range for legal BSR. For example, if only 1.1.1.1/32 and 1.1.1.2/32
Содержание Router 3031
Страница 6: ......
Страница 396: ...396 CHAPTER 4 LINK LAYER PROTOCOL Example Set the parameter of X 29 to 10 seconds 3Com x29 timer inviteclear time 10...
Страница 686: ...686 CHAPTER 6 ROUTING PROTOCOL...
Страница 758: ...758 CHAPTER 7 MULTICAST COMMON CONFIGURATION COMMANDS...