Skip to Content.
Sympa Menu

wg-multicast - Re: Recommended MSDP ACL

Subject: All things related to multicast

List archive

Re: Recommended MSDP ACL


Chronological Thread 
  • From: Beau Williamson <>
  • To: (Kevin C. Almeroth), ,
  • Cc:
  • Subject: Re: Recommended MSDP ACL
  • Date: Mon, 06 Dec 1999 09:01:36 -0800

At 02:33 PM 12/5/1999, Kevin C. Almeroth wrote:
>Does anybody else have any suggestions/comments/recommendations?
>
>-Kevin
>
>>>Here is the current recommendation:
>>>
>>>access-list 111 deny ip any host 224.0.2.2
>>>access-list 111 deny ip any host 224.0.1.3
>>>access-list 111 deny ip any host 224.0.1.24
>>>access-list 111 deny ip any host 224.0.1.22
>>>access-list 111 deny ip any host 224.0.1.2
>>>access-list 111 deny ip any host 224.0.1.35
>>>access-list 111 deny ip any host 224.0.1.60
>>>access-list 111 deny ip any host 224.0.1.39
>>>access-list 111 deny ip any host 224.0.1.40
>>>access-list 111 deny ip any 239.0.0.0 0.255.255.255
>>>access-list 111 deny ip 10.0.0.0 0.255.255.255 any
>>>access-list 111 deny ip 127.0.0.0 0.255.255.255 any
>>>access-list 111 deny ip 172.0.0.0 0.255.255.255 any <<<<<<<
>>>access-list 111 deny ip 192.0.0.0 0.255.255.255 any <<<<<<<
>>>access-list 111 permit ip any any
>
Shep, et al,

Uh, aren't the last two entries a bit too broad in scope? Shouldn't they
really be:

access-list 111 deny ip 172.16.0.0 0.15.255.255 any
access-list 111 deny ip 192.168.0.0 0.0.255.255 any

to match RFC1918 ranges?

Also, are you using these in 'sa-filter' lists or 'sa redistribute' lists or
both?

Beau




Archive powered by MHonArc 2.6.16.

Top of Page