If you want to authenticate the sent and received IGMP messages, configure IGMP IP Security (IPsec). IGMP IPsec protects a device against attacks launched using forged IGMP messages.
IGMP IPsec provides a complete set of security protection mechanisms to authenticate the sent and received IGMP messages, protecting devices against attacks launched using forged IGMP messages.
IGMP IPsec configured in the interface view has the same function as that configured in the IGMP view, but their application scopes are different:
IGMP IPsec configured in the interface view takes precedence over IGMP IPsec configured in the IGMP view. If no IGMP IPsec configuration exists in the interface view, the interface uses the IGMP IPsec configuration in the IGMP view.
If the ipsec sa and query ipsec sa commands are both configured, the command configured later overrides the command configured earlier.
If the igmp ipsec sa and igmp query ipsec sa commands are both configured, the command configured later overrides the command configured earlier.
Run the display igmp [ vpn-instance vpn-instance-name ] interface [ interface-type interface-number | up | down ] verbose command to check the detailed configuration on an interface.