157
To do...
Use the command...
Remarks
Configure a multicast group filter
source-policy
acl-number
Required
No multicast data filter by default.
NOTE:
•
Generally, a smaller distance from the filter to the multicast source results in a more remarkable
filtering effect.
•
This filter works not only on independent multicast data but also on multicast data encapsulated in
register messages.
Configuring a hello message filter
Along with the wide applications of PIM, the security requirement for the protocol is becoming
increasingly demanding. The establishment of correct PIM neighboring relationships is the prerequisite
for secure application of PIM. You can configure a legal source address range for hello messages on
interfaces of routers to ensure the correct PIM neighboring relationships, guarding against PIM message
attacks.
Follow these steps to configure a hello message filter:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter interface view
interface
interface-type interface-
number
—
Configure a hello message filter
pim neighbor-policy
acl-number
Required
No hello message filter by
default.
NOTE:
With the hello message filter configured, if hello messages of an existing PIM neighbor fail to pass the
filter, the PIM neighbor will be removed automatically when it times out.
Configuring PIM hello options
In either a PIM-DM domain or a PIM-SM domain, the hello messages sent among routers contain the
following options:
•
DR_Priority (for PIM-SM only)—Priority for DR election. The device with the highest priority wins the
DR election. You can configure this parameter on all the routers in a multi-access network directly
connected to multicast sources or receivers.
•
Holdtime—The timeout time of PIM neighbor reachability state. When this timer times out, if the
router has received no hello message from a neighbor, it assumes that this neighbor has expired or
become unreachable.
•
LAN_Prune_Delay—The delay of prune messages on a multi-access network. This option consists of
LAN-delay (namely, prune message delay), override-interval, and neighbor tracking flag. If the
LAN-delay or override-interval values of different PIM routers on a multi-access subnet are different,
Содержание A5500 EI Switch Series
Страница 12: ...xii Conventions 425 Index 427 ...