The range of valid Candidate-Rendezvous Point (C-RP) addresses and range of IPv6 multicast groups that each C-RP serves can be configured to filter packets on all Candidate-BootStrap Routers (C-BSRs) by using an IPv6 ACL. The BSR adds the C-RP information contained in an Advertisement message received from a C-RP to the RP-Set only when the address of the C-RP and IPv6 multicast groups that the C-RP serves are within the configured ranges respectively. This prevents C-RP spoofing.
The system view is displayed.
An advanced ACL6 is created, and the advanced ACL6 view is displayed.
Rules are configured for the advanced ACL6.
Run the rule command, set the source parameter to a valid C-RP source address range, and set the destination parameter to a multicast group address range to be served by C-RPs.
Return to the system view.
The IPv6 PIM view is displayed.
The range of valid C-RP addresses and the range of IPv6 multicast groups that a C-RP serves are set.
If the C-RP address or the address of a multicast group that a C-RP serves contained in an Advertisement message is not within the range defined by an IPv6 ACL or no action is defined in the IPv6 ACL for processing such an Advertisement message, the BSR discards the Advertisement message and does not add the C-RP information carried by the Advertisement message to the RP-Set.
If only advanced-acl6-number or acl6-name acl6-name is set but no IPv6 ACL is set, the BSR denies all Advertisement messages.
The configuration is committed.