Configuring A Multicast User Control Policy - HP A5500 SI Switch Series Configuration Manual

Hide thumbs Also See for A5500 SI Switch Series:
Table of Contents

Advertisement

Configuring a multicast user control policy

Multicast user control policies are configured on access switches to allow only authorized users to
receive requested multicast traffic flows. This helps restrict users from ordering certain multicast-on-
demand programs.
In practice, a device first needs to perform authentication (802.1X authentication, for example) on
connected hosts through a RADIUS server. Then, the device uses the configured multicast user control
policy to perform multicast access control on authenticated users.
After receiving an IGMP report from a host, the access switch matches the multicast group address
and multicast source address carried in the report with the configured policies. If a match is found,
the host is allowed to join the multicast group. Otherwise, the join report is dropped by the access
switch.
After receiving an IGMP leave message from a host, the access switch matches the multicast group
and source addresses with the policies. If a match is found, the host is allowed to leave the group.
Otherwise, the leave message is dropped by the access switch.
Follow these steps to configure a multicast user control policy
To do...
Enter system view
Create a user profile and enter its
view
Configure a multicast user control
policy
Return to system view
Enable the created user profile
NOTE:
For more information about the user-profile and user-profile enable commands, see the
Command Reference.
A multicast user control policy is functionally similar to a multicast group filter. A difference is that a
control policy can control both multicast joining and leaving of users based on authentication and
authorization, but a multicast group filter is configured on a port to control only multicast joining but
not leaving of users without authentication or authorization.
Use the command...
system-view
user-profile profile-name
igmp-snooping access-policy acl-
number
quit
user-profile profile-name enable
35
Remarks
Required
No policy is configured by
default. That is, a host can join or
leave a valid multicast group at
any time.
Required
Disabled by default.
Security

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

A5500 ei switch series

Table of Contents