[c-nsp] Best practise/security design for BGP and OSPF

Saku Ytti saku at ytti.fi
Tue May 23 06:16:24 EDT 2017


On 23 May 2017 at 13:06,  <adamv0025 at netconsultings.com> wrote:

> Router listening for all IS m-cast MAC addresses on all interfaces rather than solely on interfaces actually configured with ISIS seems like a bug.

Not all HW support per-port punt-masks. So if you have to punt ISIS
frames on one interface, you may need to punt them on all interfaces.
I know that 7600 will happily punt ISIS/CLNS on all interfaces. Back
in 11.4R5 Juniper MX dd this too, with just 'inet' family configured,
but that was fixed.

-- 
  ++ytti


More information about the cisco-nsp mailing list