sa-filter

Configures filters for incoming and outgoing Source-Active (SA) messages from and to multicast source discovery protocol (MSDP) neighbors.
Syntax
sa-filter{in|out}ip-addr[route-mapmap-tag[rp-route-maprp-map-tag]]
no sa-filter{in|out}ip-addr[route-mapmap-tag[rp-route-maprp-map-tag]]
sa-filteroriginate[route-mapmap-tag]
no sa-filteroriginate[route-mapmap-tag]
Command Default

Source-Active filters are not configured.

Parameters
in
Specifies filtering incoming SA messages.
out
Specifies filtering self-originated and forwarded outbound SA messages.
ip-addr
specifies the IP address of the MSDP neighbor that the filtered SA messages are sent to of received from.
originate
Specifies filtering self-originated outbound SA messages.
route-mapmap-tag
Specifies a route map. The device applies the filter to source-group pairs that match the route map.
rp-route-maprp-map-tag
Specifies a route map to use for filtering based on Rendezvous Point (RP) address. Use this parameter if you want to filter SA messages based on their originating RP.
Modes

MSDP VRF configuration mode

Router MSDP configuration mode

Usage Guidelines

The default filter action is deny. If you want to permit some source-group pairs, use a route map. A permit action in the route map allows the device to advertise the matching source-group pairs. A deny action in the route map drops the source-group pairs from advertisements.

The no form of this command removes the SA filters.

Examples

The following example configures extended access-control lists (ACLs) to be used in the route map definition and use them to configure a route map that denies source-group with source address 10.x.x.x and any group address, while permitting everything else.

device# configure terminal
device(config)# ip access-list extended 123
device(config-ext-ipacl-123)#
device(config-ext-ipacl-123)# permit ip 10.0.0.0 0.255.255.255 any
device(config-ext-ipacl-123)# exit
device(config)# ip access-list extended 125 
device(config-ext-ipacl-125)# permit ip any any
device(config-ext-ipacl-125)# exit
device(config)# route-map msdp_map deny 1
device(config-routemap msdp_map)# match ip address 123
device(config-routemap msdp_map)# exit
device(config)# route-map msdp_map permit 2
device(config-routemap msdp_map)# match ip address 125
device(config-routemap msdp_map)# exit

The following example configures a filter that filters self-originated outbound SA messages on a route map.

device(config)# router msdp
device(config-msdp-router)# sa-filter originate route-map msdp_map

The following example configures an SA filter on a VRF.

device(config)# router msdp vrf blue
device(config-msdp-router-vrf blue)# sa-filter in 2.2.2.99
device(config-msdp-router-vrf blue)# sa-filter in 2.2.2.97 route-map msdp_map
device(config-msdp-router-vrf blue)# sa-filter in 2.2.2.96 route-map msdp2_map rproute-map msdp2_rp_map