SV-221136r622190_rule
V-221136
SRG-NET-000019-RTR-000013
CISC-RT-000830
CAT III
10
Configure the switch to filter PIM register messages received from a multicast DR for any undesirable multicast groups and sources. The example below will deny any multicast streams for groups 239.5.0.0/16 and allow from only sources x.1.2.6 and x.1.2.7.
Step 1: Configure a route map to filter multicast groups and sources as shown in the example below:
SW1(config)# route-map PIM_REGISTER_FILTER deny 10
SW1(config-route-map)# match ip multicast group 239.5.0.0/16
SW1(config-route-map)# route-map PIM_REGISTER_FILTER permit 20
SW1(config-route-map)# match ip multicast source x.1.2.6/32
SW1(config-route-map)# route-map PIM_REGISTER_FILTER permit 30
SW1(config-route-map)# match ip multicast source x.1.2.7/32
SW1(config-route-map)# route-map PIM_REGISTER_FILTER permit 40
SW1(config-route-map)# match ip multicast group-range 232.0.0.0 to 233.255.255.255
SW1(config-route-map)# route-map PIM_REGISTER_FILTER deny 50
SW1(config-route-map)# match ip multicast source 0.0.0.0/0
SW1(config-route-map)# exit
Step 2: Configure a multicast register policy referencing the configured route map.
SW1(config)# ip pim register-policy PIM_REGISTER_FILTER
SW1(config)# end
Verify that the RP switch is configured to filter PIM register messages. The example below will deny any multicast streams for groups 239.5.0.0/16 and allow from only sources x.1.2.6 and x.1.2.7.
ip pim register-policy PIM_REGISTER_FILTER
…
…
…
route-map PIM_REGISTER_FILTER deny 10
match ip multicast group 239.5.0.0/16
route-map PIM_REGISTER_FILTER permit 20
match ip multicast source x.1.2.6/32
route-map PIM_REGISTER_FILTER permit 30
match ip multicast source x.1.2.7/32
route-map PIM_REGISTER_FILTER permit 40
match ip multicast group-range 232.0.0.0 to 233.255.255.255
route-map PIM_REGISTER_FILTER deny 50
match ip multicast source 0.0.0.0/0
If the RP switch peering with PIM-SM switches is not configured with a policy to block registration messages for any undesirable multicast groups and sources, this is a finding.
V-221136
False
CISC-RT-000830
Verify that the RP switch is configured to filter PIM register messages. The example below will deny any multicast streams for groups 239.5.0.0/16 and allow from only sources x.1.2.6 and x.1.2.7.
ip pim register-policy PIM_REGISTER_FILTER
…
…
…
route-map PIM_REGISTER_FILTER deny 10
match ip multicast group 239.5.0.0/16
route-map PIM_REGISTER_FILTER permit 20
match ip multicast source x.1.2.6/32
route-map PIM_REGISTER_FILTER permit 30
match ip multicast source x.1.2.7/32
route-map PIM_REGISTER_FILTER permit 40
match ip multicast group-range 232.0.0.0 to 233.255.255.255
route-map PIM_REGISTER_FILTER deny 50
match ip multicast source 0.0.0.0/0
If the RP switch peering with PIM-SM switches is not configured with a policy to block registration messages for any undesirable multicast groups and sources, this is a finding.
M
4075