CISC-RT-000850 - The Cisco multicast Rendezvous Point (RP) must be configured to rate limit the number of Protocol Independent Multicast (PIM) Register messages.

Information

When a new source starts transmitting in a PIM Sparse Mode network, the Designated Router (DR) will encapsulate the multicast packets into register messages and forward them to the RP using unicast.

This process can be taxing on the CPU for both the DR and the RP if the source is running at a high data rate and there are many new sources starting at the same time. This scenario can potentially occur immediately after a network failover.

The rate limit for the number of register messages should be set to a relatively low value based on the known number of multicast sources within the multicast domain.

Solution

Configure the RP to rate limit the number of multicast register states.

RP/0/0/CPU0:R2(config)#router pim
RP/0/0/CPU0:R2(config-pim)#address-family ipv4
RP/0/0/CPU0:R2(config-pim-default-ipv4)#maximum register-states 250
RP/0/0/CPU0:R2(config-pim-default-ipv4)#end

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Cisco_IOS-XR_Router_Y24M07_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5, CAT|II, CCI|CCI-002385, Rule-ID|SV-216813r856450_rule, STIG-ID|CISC-RT-000850, STIG-Legacy|SV-105971, STIG-Legacy|V-96833, Vuln-ID|V-216813

Plugin: Cisco

Control ID: 2f4e4feb81dec381a0587c6aab0005bc9349ce2077e88749d819482e449c5bb9