370
Follow these steps to configure an IPv6 multicast data filter:
To do...
Use the command...
Remarks
Enter system view
system-view
—
Enter IPv6 PIM view
pim ipv6
—
Configure an IPv6 multicast group
filter
source-policy
acl6-number
Required
No IPv6 multicast data filter by
default
NOTE:
•
Generally, a smaller distance from the filter to the IPv6 multicast source results in a more remarkable
filtering effect.
•
This filter works not only on independent IPv6 multicast data but also on IPv6 multicast data
encapsulated in register messages.
Configuring a hello message filter
Along with the wide applications of IPv6 PIM, the security requirement for the protocol is becoming
increasingly demanding. The establishment of correct IPv6 PIM neighboring relationships is a
prerequisite for secure application of IPv6 PIM. To guard against IPv6 PIM message attacks, you can
configure a legal source address range for hello messages on interfaces of routers to ensure the correct
IPv6 PIM neighboring relationships.
Follow these steps to configure a hello message filter:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter interface view
interface
interface-type interface-
number
—
Configure a hello message filter
pim
ipv6
neighbor-policy
acl6-
number
Required
No hello message filter by default.
NOTE:
When the hello message filter is configured, if hello messages of an existing IPv6 PIM neighbor fail to
pass the filter, the IPv6 PIM neighbor will be removed automatically when it times out.
Configuring IPv6 PIM hello options
In either an IPv6 PIM-DM domain or IPv6 PIM-SM domain, the hello messages sent among routers
contain the following configurable options:
•
DR_Priority—Priority for DR election for IPv6 PIM-SM only. The higher the priority is, the easier it is
for the router to win DR election. You can configure this parameter on all the routers in a multi-
access network directly connected to IPv6 multicast sources or receivers.
•
Holdtime—Timeout time of IPv6 PIM neighbor reachability state. When this timer times out, if the
router has received no hello message from an IPv6 PIM neighbor, it assumes that this neighbor has
expired or become unreachable.
Содержание A5500 EI Switch Series
Страница 12: ...xii Conventions 425 Index 427 ...