112
A filter can filter not only independent multicast data but also multicast data encapsulated in register
messages. Generally, a filter nearer to the multicast source has a better filtering effect.
To configure a multicast data filter:
Ste
Command Remarks
1. Enter system view.
system-view N/A
2. Enter PIM view.
pim [ vpn-instance
vpn-instance-name ]
N/A
3. Configure a multicast data
filter:
source-policy acl-number
By default, no multicast data filter is
configured.
Configuring a hello message filter
Along with the wide applications of PIM, the security requirement for the protocol is becoming
increasingly demanding. The establishment of correct PIM neighboring relationships is the prerequisite
for secure application of PIM.
To guard against PIM message attacks, you can configure a legal source address range for hello
messages on interfaces of routers to ensure the correct PIM neighboring relationships.
To configure a hello message filter:
Ste
Command
Remarks
1. Enter system view.
system-view
N/A
2. Enter interface view.
interface interface-type
interface-number
N/A
3. Configure a hello message
filter.
pim neighbor-policy acl-number
By default, no hello message filter
exists.
If a PIM neighbor's hello messages
cannot pass the filter, the neighbor
is automatically removed when its
maximum number of hello attempts
is reached.
Configuring PIM hello message options
In either a PIM-DM domain or a PIM-SM domain, hello messages exchanged among routers contain the
following configurable options:
• DR_Priority (for PIM-SM only)—Priority for DR election. The device with the highest priority wins the
DR election. You can configure this option for all the routers in a shared-media LAN that directly
connects to the multicast source or the receivers.
• Holdtime—PIM neighbor lifetime. If a router does not receive a hello message from a neighbor
when the neighbor lifetime timer expires, it regards the neighbor failed or unreachable.
• LAN_Prune_Delay—Delay of pruning a downstream interface on a shared-media LAN. This option
consists of LAN delay, override interval, and neighbor tracking support (namely, the capability to
disable join message suppression).