If you want to authenticate sent and received IPv4 PIM messages, configure IPv4 PIM IP Security (IPsec). IPv4 PIM IPsec protects a device against attacks launched using forged IPv4 PIM messages.
IPv4 PIM IPsec provides a complete set of security protection mechanisms to authenticate the sent and received IPv4 PIM messages, protecting devices against attacks launched using forged IPv4 PIM messages.
IPv4 PIM IPsec configured in the interface view has the same effect as that configured in the IPv4 PIM view, but their application scopes are different:
IPv4 PIM IPsec configured in the interface view takes precedence over IPv4 PIM IPsec configured in the IPv4 PIM view. If no IPv4 PIM IPsec configuration exists in the interface view, the interface uses the IPv4 PIM IPsec configuration in the IPv4 PIM view.
If the ipsec sa and hello ipsec sa commands are both configured, the command configured later overrides the command configured earlier.
If the pim ipsec sa and pim hello ipsec sa commands are both configured, the command configured later overrides the command configured earlier.
Run the display pim [ vpn-instance vpn-instance-name ] interface [ interface-type interface-number | up | down ] verbose command to check the detailed IPv4 PIM IPsec configuration on an interface.
# Display the IPv4 PIM IPsec configuration on GE 0/1/0. The command output shows that IPv4 PIM IPsec has been configured on GE 0/1/0, the SA is named sa1.