3.3.5 MSDP Authentication & SA Filtering

Information

The Multicast Source Discovery Protocol (MSDP) connects multiple PIM-SM domains, enabling RPs to share multicast source information using SA messages over TCP. It simplifies interdomain multicast routing by supporting an interdomain source tree instead of a shared tree.

MSDP is crucial for efficient interdomain multicast routing in multi-domain networks. MD5 authentication secures peer connections, while ACL-based SA filtering allows precise traffic control, improving network performance and mitigating security risks.

Solution

Configuration to enable Authentication -

switch(config)# router msdp
switch(config-msdp)# ip msdp peer <ip-address>
switch(config-msdp-peer)# password plaintext <password>

User can prevent the incoming and outgoing SA messages on MSDP router by creatingincoming and outgoing filter lists using an ACL.

Configuration to associate ACL -

switch(config-msdp-peer)# sa-filter in access-list <acl-name>
switch(config-msdp-peer)# sa-filter out access-list <acl-name>

Impact:

MSDP enhances multicast scalability by enabling cross-domain source discovery while reducing configuration complexity. Features like MD5 authentication and SA filtering improve security, optimize traffic flow, and prevent unauthorized or unnecessary data processing.

See Also

https://workbench.cisecurity.org/benchmarks/24202