If you want to encrypt and authenticate the sent and received MLD messages, configure MLD IP Security (IPsec). MLD IPsec protects a device against attacks launched using forged MLD messages.
MLD IPsec provides a complete set of security protection mechanisms to authenticate the sent and received MLD messages, protecting devices against attacks launched using forged MLD messages.
MLD IPsec configured in the interface view has the same function as that configured in the MLD view, but their application scopes are different:
MLD IPsec configured in the interface view takes precedence over MLD IPsec configured in the MLD view. If no MLD IPsec configuration exists in the interface view, the interface uses the MLD IPsec configuration in the MLD view.
Before configuring MLD IPsec, complete the following tasks:
Configure basic IPsec functions.
If the ipsec sa and query ipsec sa commands are both configured, the command configured later overrides the command configured earlier.
If the mld ipsec sa and mld query ipsec sa commands are both configured, the command configured later overrides the command configured earlier.
Run the display mld interface [ interface-type interface-number | up | down ] [ verbose ] command to check the detailed MLD IPsec configuration on an interface.