Rule ID
SV-273637r1110898_rule
Version
V1R1
CCIs
MSDP peering between networks enables sharing of multicast source information. Enclaves with an existing multicast topology using PIM-SM can configure their RP routers to peer with MSDP routers. As a first step of defense against a denial-of-service (DoS) attack, all RP routers must limit the multicast forwarding cache to ensure that router resources are not saturated managing an overwhelming number of PIM and MSDP source-active entries.
View the "show default value" output for the msdp-sa-cache value. If that number is zero, this is a finding.
Configure the "system-max msdp-sa-cache" value to be above zero. (Reboot may be required to take effect.) ICX(config)#system-max msdp-sa-cache 1024