You can create ACL rules on all devices to filter BootStrap router (BSR) addresses. The devices then receive only the Bootstrap messages with the source addresses being in the valid BSR address range. Thus, BSR spoofing is prevented.
The system view is displayed.
Configure a basic numbered ACL.
A basic numbered ACL is created, and the basic numbered ACL view is displayed.
Rules are configured for the basic numbered ACL.
Configure a named ACL.
If a basic numbered ACL is used, run the rule command and set the source parameter to the source address range of multicast packets.
If a named ACL is used, run the rule command and set the source parameter to the source address range of multicast packets.
Return to the system view.
The PIM view is displayed.
A valid BSR address range is set.
If no ACL rule corresponding to the specified basic-acl-number exists, the router denies all Bootstrap messages.
The configuration is committed.