3.3.6 MSDP SA Cache limit

Information

By default, the MSDP SA has no limit configured per peer. All (S, G) entries within the system capacities are allowed. If there is a reboot or HA switchover, the (S, G) cache allocation occurs based on first come first served basis. The (S, G) entries are allocated until they reach the system capacity or peer limit based on whichever is reached first and new sets of (S, G) requests are discarded.

The sa-limit command limits the overall number of (S, G) entries that a device can accept from specified MSDP peers and store in a SA-cache. When configured, the device maintains a per-peer count of (S, G) messages stored in the SA-cache and ignores new messages from a peer if the configured sa-limit for that peer has been reached. This command protects MSDP enabled devices from denial of service (DOS) attacks.

Solution

Configuration to enable MSDP SA cached limit -

switch(config)#router msdp
switch(config-msdp)#ip msdp peer <peer-address>
switch(config-msdp)#sa-limit <value>

Impact:

Configuring the MSDP SA cache limit mitigates the risk of denial-of-service (DoS) attacks by restricting excessive multicast source entries.It prevents attackers from overwhelming the system with excessive SA messages, preserving network stability.Proper limits ensure resilience against DoS threats while maintaining reliable multicast traffic handling.

See Also

https://workbench.cisecurity.org/benchmarks/24202

Item Details

Category: ACCESS CONTROL, RISK ASSESSMENT, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-17, 800-53|AC-17(1), 800-53|RA-5, 800-53|SC-7, 800-53|SI-4, CSCv7|12.2

Plugin: ArubaOS

Control ID: 5fbaabae943d30bd8aeaf40505a2606cb39034d425285744be108e7b0da4fd24