sa-filter
sa-filter{in|out}ip-addr[route-mapmap-tag[rp-route-maprp-map-tag]]no sa-filter{in|out}ip-addr[route-mapmap-tag[rp-route-maprp-map-tag]]sa-filteroriginate[route-mapmap-tag]no sa-filteroriginate[route-mapmap-tag]Source-Active filters are not configured.
MSDP VRF configuration mode
Router MSDP configuration mode
The default filter action is deny. If you want to permit some source-group pairs, use a route map. A permit action in the route map allows the device to advertise the matching source-group pairs. A deny action in the route map drops the source-group pairs from advertisements.
The following example configures extended access-control lists (ACLs) to be used in the route map definition and use them to configure a route map that denies source-group with source address 10.x.x.x and any group address, while permitting everything else.
device# configure terminal device(config)# ip access-list extended 123 device(config-ext-ipacl-123)# device(config-ext-ipacl-123)# permit ip 10.0.0.0 0.255.255.255 any device(config-ext-ipacl-123)# exit device(config)# ip access-list extended 125 device(config-ext-ipacl-125)# permit ip any any device(config-ext-ipacl-125)# exit device(config)# route-map msdp_map deny 1 device(config-routemap msdp_map)# match ip address 123 device(config-routemap msdp_map)# exit device(config)# route-map msdp_map permit 2 device(config-routemap msdp_map)# match ip address 125 device(config-routemap msdp_map)# exit
The following example configures a filter that filters self-originated outbound SA messages on a route map.
device(config)# router msdp device(config-msdp-router)# sa-filter originate route-map msdp_map
The following example configures an SA filter on a VRF.
device(config)# router msdp vrf blue device(config-msdp-router-vrf blue)# sa-filter in 2.2.2.99 device(config-msdp-router-vrf blue)# sa-filter in 2.2.2.97 route-map msdp_map device(config-msdp-router-vrf blue)# sa-filter in 2.2.2.96 route-map msdp2_map rproute-map msdp2_rp_map