441
•
Determine the DSCP value for PIM messages.
Configuring an IPv6 multicast data filter
In either an IPv6 PIM-DM domain or an IPv6 PIM-SM domain, routers can examine passing-by IPv6
multicast data based on the configured filtering rules and determine whether to continue forwarding
the IPv6 multicast data. In other words, IPv6 PIM routers can act as IPv6 multicast data filters. These
filters can help implement traffic control and also control the information available to downstream
receivers to enhance data security.
Generally, a smaller distance from the filter to the IPv6 multicast source results in a more remarkable
filtering effect.
To configure an IPv6 multicast data filter:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter public network IPv6
PIM view or VPN instance
IPv6 PIM view.
pim ipv6
[
vpn-instance
vpn-instance-name
]
N/A
3.
Configure an IPv6 multicast
group filter.
source-policy
acl6-number
No IPv6 multicast data filter by
default.
This filter works not only on
independent IPv6 multicast data
but also on IPv6 multicast data
encapsulated in register
messages.
Configuring a hello message filter
Along with the wide applications of IPv6 PIM, the security requirement for the protocol is becoming
increasingly demanding. The establishment of correct IPv6 PIM neighboring relationships is a
prerequisite for secure application of IPv6 PIM. To guide against IPv6 PIM message attacks, you can
configure a legal source address range for hello messages on interfaces of routers to ensure the
correct IPv6 PIM neighboring relationships.
To configure a hello message filter:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
N/A
3.
Configure a hello message
filter.
pim
ipv6
neighbor-policy
acl6-number
No hello message filter by default.
NOTE:
With the hello message filter configured, if hello messages of an existing IPv6 PIM neighbor fail to
pass the filter, the IPv6 PIM neighbor will be removed automatically when it times out.