Filtering Incoming and Outgoing Source-Active Messages

The following example configures filters for incoming Source-Active messages from three MSDP neighbors:

  • For peer 2.2.2.99, all source-group pairs in Source-Active messages from the neighbor are filtered (dropped).
  • For peer 2.2.2.97, all source-group pairs except those with source address matching 10.x.x.x and group address of 235.10.10.1 are permitted.
  • For peer 2.2.2.96, all source-group pairs except those associated with RP 2.2.42.3 are permitted.

To configure filters for incoming Source-Active messages, enter commands at the MSDP VRF configuration level.

To configure filters for outbound Source-Active messages, enter the optional out keyword.

The following commands configure extended ACLs. The ACLs will be used in route maps, which will be used by the Source-Active filters.

device(config)# ip access-list extended 123 
device(config-ext-ipacl-123)# permit ip 10.0.0.0 0.255.255.255 host 235.10.10.1
device(config-ext-ipacl-123)# exit
device(config)# ip access-list extended 124 
device(config-ext-ipacl-124)# permit ip host 2.2.42.3 any
device(config-ext-ipacl-124)# exit
device(config)# ip access-list extended 125 
device(config-ext-ipacl-125)# permit ip any any
device(config-ext-ipacl-125)# exit

The following commands configure the route maps.

device(config)# route-map msdp_map deny 1
device(config-routemap msdp_map)# match ip address 123
device(config-routemap msdp_map)# exit
device(config)# route-map msdp_map permit 2
device(config-routemap msdp_map)# match ip address 125
device(config-routemap msdp_map)# exit
device(config)# route-map msdp2_map permit 1
device(config-routemap msdp2_map)# match ip address 125
device(config-routemap msdp2_map)# exit
device(config)# route-map msdp2_rp_map deny 1
device(config-routemap msdp2_rp_map)# match ip route-source 124
device(config-routemap msdp2_rp_map)# exit
device(config)# route-map msdp2_rp_map permit 2
device(config-routemap msdp2_rp_map)# match ip route-source 125
device(config-routemap msdp2_rp_map)# exit

To specify VRF information, enter the following commands at the MSDP VRF configuration level.

device(config)# router msdp vrf blue
device(config-msdp-router-vrf blue)# sa-filter in 2.2.2.99
device(config-msdp-router-vrf blue)# sa-filter in 2.2.2.97 route-map msdp_map
device(config-msdp-router-vrf blue)# sa-filter in 2.2.2.96 route-map msdp2_map rp-route-map msdp2_rp_map 

The sa-filter commands configure the following filters:

  • The first line of the sa-filter command drops all source-group pairs received from neighbor 2.2.2.99.
    Note: The default action is to deny all source-group pairs from the specified neighbor. If you want to permit some pairs, use route maps.
  • The second line of the sa-filter command drops source-group pairs received from neighbor 2.2.2.97 if the pairs have source addresses matching 10.x.x.x and group address 235.10.10.1.
  • The third line of the sa-filter command accepts all source-group pairs except those associated with RP 2.2.42.3.