Example of Verifying the System is not Caching Local Sources
When you apply this filter, the SA cache is not affected immediately. When sources that are denied by the
ACL time out, they are not refreshed. Until they time out, they continue to reside in the cache. To apply
the redistribute filter to entries already present in the SA cache, first clear the SA cache. You may
optionally store denied sources in the rejected SA cache.
R1(conf)#do show run msdp
!
ip multicast-msdp
ip msdp peer 192.168.0.3 connect-source Loopback 0
ip msdp redistribute list mylocalfilter
ip msdp cache-rejected-sa 1000
R1_E600(conf)#do show run acl
!
ip access-list extended mylocalfilter
seq 5 deny ip host 239.0.0.1 host 10.11.4.2
seq 10 deny ip any any
R1_E600(conf)#do show ip msdp sa-cache
R1_E600(conf)#do show ip msdp sa-cache rejected-sa
MSDP Rejected SA Cache
1 rejected SAs received, cache-size 1000
UpTime GroupAddr SourceAddr RPAddr LearnedFrom Reason
00:02:20 239.0.0.1 10.11.4.2 192.168.0.1 local Redistribute
Preventing MSDP from Caching a Remote Source
To prevent MSDP from caching a remote source, use the following commands.
1. OPTIONAL: Cache sources that the SA filter denies in the rejected SA cache.
CONFIGURATION mode
ip msdp cache-rejected-sa
2. Prevent the system from caching remote sources learned from a specific peer based on source and
group.
CONFIGURATION mode
ip msdp sa-filter list out peer list ext-acl
Example of Verifying the System is not Caching Remote Sources
As shown in the following example, R1 is advertising source 10.11.4.2. It is already in the SA cache of R3
when an ingress SA filter is applied to R3. The entry remains in the SA cache until it expires and is not
stored in the rejected SA cache.
[Router 3]
R3(conf)#do show run msdp
!
ip multicast-msdp
ip msdp peer 192.168.0.1 connect-source Loopback 0
ip msdp sa-filter in 192.168.0.1 list myremotefilter
R3(conf)#do show run acl
!
ip access-list extended myremotefilter
seq 5 deny ip host 239.0.0.1 host 10.11.4.2
R3(conf)#do show ip msdp sa-cache
MSDP Source-Active Cache - 1 entries
GroupAddr SourceAddr RPAddr LearnedFrom Expire UpTime
239.0.0.1 10.11.4.2 192.168.0.1 192.168.0.1 1 00:03:59
584 Multicast Source Discovery Protocol (MSDP)