Filtering Advertised Source-Active Messages

The following example configures the device to advertise all source-group pairs except the ones that have source address 10.x.x.x.

The following commands configure extended ACLs to be used in the route map definition.

device(config)# ip access-list extended 123 
device(config-ext-ipacl-123)# permit ip 10.0.0.0 0.255.255.255 any
device(config-ext-ipacl-123)# ip access-list extended 125
device(config-ext-ipacl-125)# permit ip any any
device(config-ext-ipacl-125)# exit

The following commands use the previously configured ACLs to configure a route map that denies source-group with source address 10.x.x.x and any group address, while permitting everything else.

device(config)# route-map msdp_map deny 1
device(config-routemap msdp_map)# match ip address 123
device(config-routemap msdp_map)# exit
device(config)# route-map msdp_map permit 2
device(config-routemap msdp_map)# match ip address 125
device(config-routemap msdp_map)# exit

The following commands configure the Source-Active filter.

device(config)# router msdp
device(config-msdp-router)# sa-filter originate route-map msdp_map

To specify VRF information, enter the following commands at the MSDP VRF configuration level.

device(config)# router msdp vrf blue
device(config-msdp-router-vrf blue)# sa-filter originate route-map msdp_map

This example specifies a route map. The router applies the filter to source-group pairs that match the route map.

Note: The default filter action is deny. If you want to permit some source-group pairs, use a route map. A permit action in the route map allows the device to advertise the matching source-group pairs. A deny action in the route map drops the source-group pairs from advertisements.