1.73 CISC-RT-000940

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The Cisco Multicast Source Discovery Protocol (MSDP) switch must be configured to limit the amount of source-active messages it accepts on a per-peer basis.

GROUP ID: V-221146
RULE ID: SV-221146r999755

To reduce any risk of a denial-of-service (DoS) attack from a rogue or misconfigured MSDP switch, the switch must be configured to limit the number of source-active messages it accepts from each peer.

Solution

Configure the switch to limit the amount of source-active messages it accepts from each peer.

SW1(config)# ip msdp sa-limit x.1.28.2 nnn
SW1(config)# end

See Also

https://workbench.cisecurity.org/benchmarks/22581