Configuring Pim Silent; Establishing The Configuration Task - Huawei Quidway S9300 Configuration Manual - Multicast

Terabit routing switch
Hide thumbs Also See for Quidway S9300:
Table of Contents

Advertisement

4 PIM-SM Configuration
According to the preceding information, PIM BFD is enabled on VLANIF 15 and the detection
parameters of BFD are set.

4.14 Configuring PIM Silent

This section describes how to configure PIM silent to protect hosts against attacks.

4.14.1 Establishing the Configuration Task

Applicable Environment
The S9300 directly connected to a host needs to be enabled with PIM. You can establish a PIM
neighbor relation on the interface to process various PIM messages. There are potential risks in
security for this configuration. When a host maliciously generates PIM Hello messages and
sends a large number of packets, the S9300 may break down.
You can set the interface of the S9300 to PIM silent state to protect the S9300 against this type
of attacks. When the interface is in the PIM silent state, the interface is disabled from receiving
and forwarding any PIM packet. All PIM-IP neighbors and PIM state machines on the interface
are deleted. The interface functions as the static DR and immediately takes effect. IGMP on the
interface is not affected.
PIM silent is applicable only to the interfaces of an S9300 directly connected to the host network
segment that is connected only to this S9300.
l
l
Pre-configuration Tasks
Before configuring PIM silent, complete the following tasks:
l
l
l
4-46
PIM BFD min-rx-interval: 100 ms
PIM BFD detect-multiplier: 20
PIM dr-switch-delay timer : not configured
Number of routers on link not using DR priority: 0
Number of routers on link not using LAN delay: 0
Number of routers on link not using neighbor tracking: 0
CAUTION
If the interface connected to another S9300 is set to be silent, the PIM neighbor relation
cannot be established and a multicast failure may occur.
If the host network segment is connected to multiple S9300s and PIM silent is enabled on
the interfaces of multiple S9300s, the interfaces become static DRs. Therefore, multiple
DRs exist in this network segment, which causes multicast faults.
Configuring the unicast routing protocol to ensure that IP routes between nodes are
reachable
2.4 Configuring Basic IGMP Functions
4.4 Configuring Basic PIM-SM Functions
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Multicast
Issue 01 (2009-07-28)

Advertisement

Table of Contents
loading

Table of Contents