164
them, and the TCP connection is closed without any connection setup retry. The configuration information,
however, remain unchanged.
A TCP connection is required in the following situations:
• When a new MSDP peer is created
• When you reactivate a previously deactivated MSDP peer connection
• When a previously failed MSDP peer attempts to resume operation
You can adjust the interval between MSDP peering connection retries.
To enhance MSDP security, you can configure an MD5 authentication password for the TCP connection
to be established with an MSDP peer. If the MD5 authentication fails, the TCP connection cannot be
established.
IMPORTANT:
The MSDP peers involved in the MD5 authentication must have the same authentication method and
password. Otherwise, the authentication fails and the TCP connection cannot be established.
To configure MSDP peer connection control:
Ste
Remarks
1. Enter system view.
system-view N/A
2. Enter MSDP view.
msdp N/A
3. Deactivate an MSDP peer.
shutdown peer-address
Optional.
Active by default.
4. Configure the interval
between MSDP peer
connection retries.
timer retry interval
Optional.
30 seconds by default.
5. Configure an MD5
authentication key for the TCP
connection to be established
with an MSDP peer.
peer peer-address password
{ cipher | simple } password
Optional.
By default, MD5 authentication is
not performed before an TCP
connection is established.
Configuring SA messages related parameters
Before you configure SA message delivery, complete the following tasks:
• Configure any unicast routing protocol so that all devices in the domain are interoperable at the
network layer.
• Configure basic MSDP functions.
• Determine the ACL rules for filtering SA request messages.
• Determine the ACL rules as SA message creation rules.
• Determine the ACL rules for filtering SA messages to be received and forwarded.
• Determine the TTL threshold for multicast packet encapsulation in SA messages.
• Determine the maximum number of (S, G) entries learned from the specified MSDP peer that the
router can cache.