The mld ipsec sa command specifies a security association (SA) using which an interface authenticates sent and received Multicast Listener Discovery (MLD) messages, including MLD Report, MLD Done, and MLD Query messages, to implement IP Security (IPsec) authentication.
The undo mld ipsec sa command restores the default configuration.
By default, no SA is specified for an interface, so that the interface does not authenticate sent or received MLD messages.
Parameter | Description | Value |
---|---|---|
sa-name | Specifies the name of an SA. |
It is a string of 1 to 15 case-sensitive characters, spaces not supported. The characters can be letters or numbers, hyphens (-) not supported. When double quotation marks are used around the string, spaces are allowed in the string. |
100ge sub-interface view, 100GE interface view, 10GE sub-interface view, 10GE interface view, 200GE sub-interface view, 25GE sub-interface view, 25GE interface view, 400GE sub-interface view, 400GE interface view, 40GE sub-interface view, 40GE interface view, 50GE sub-interface view, 50GE interface view, Eth-Trunk sub-interface view, Eth-Trunk interface view, FlexE interface view, GE optical interface view, GE sub-interface view, GE interface view, GE electrical interface view, Global VE sub-interface view, Loopback interface view, PW-VE sub-interface view, VE sub-interface view, VLANIF interface view
Usage Scenario
On a multicast network, forged MLD messages may be used to attack devices, causing devices unable to forward multicast traffic. To protect a device against attacks launched using forged MLD messages, run the mld ipsec sa command to configure an interface to authenticate sent and received MLD messages based on a specified SA.
Prerequisites
Precautions
If the mld ipsec sa command is run more than once, the latest configuration overrides the previous one. If the mld ipsec sa and mld query ipsec sa commands are both configured, the command configured later overrides the command configured earlier.
The function of this command is the same as the function of the ipsec sa command used in the MLD view. The configuration in the interface view takes precedence over the configuration in the MLD view. The configuration in the MLD view is used only when the configuration in the interface view is not available.<HUAWEI> system-view [~HUAWEI] multicast ipv6 routing-enable [*HUAWEI] ipsec sa sa1 [*HUAWEI-sa-sa1] quit [*HUAWEI] interface GigabitEthernet 0/1/0 [*HUAWEI-GigabitEthernet0/1/0] ipv6 enable [*HUAWEI-GigabitEthernet0/1/0] mld ipsec sa sa1