Introduction
From my last post on PIM BiDir I got some great comments from my friend Peter Palúch. I still had some concepts that weren’t totally clear to me and I don’t like to leave unfinished business. There is also a lack of resources properly explaining the behavior of PIM BiDir. For that reason I would like to clarify some concepts and write some more about the potential gains of PIM BiDir is. First we must be clear on the terminology used in PIM BiDir.
Terminology
Rendezvous Point Address (RPA) – The RPA is an address that is used as the root of the distribution tree for a range of multicast groups. This address must be routable in the PIM domain but does not have to reside on a physical interface or device.
Rendezvous Point Link (RPL) – It is the physical link to which the RPA belongs. The RPL is the only link where DF election does not take place. The RFC also says “In BIDIR-PIM, all multicast traffic to groups mapping to a specific RPA is forwarded on the RPL of that RPA.” In some scenarios where the RPA is virtual, there may not be an RPL though.
Tom Waechter steps down from the newly minted company.
B2B email scams are all the rage.
Not sure why this command has to be so obscure, but I stumbled on this while writing a training course tonight – quite a nice way to see if packets are hitting your policies:
imtech@srx220-1-POD3> show security policies hit-count Logical system: root-logical-system Index From zone To zone Name Policy count 1 VR3a VR3b P1 0 2 VR3a untrust 3to1VPN 8320 3 VR3a untrust P1 3249 4 VR3b VR3a P1 0 5 VR3b untrust P1 0 6 untrust junos-host P1 8 7 untrust VR3a 1to3 5523 8 untrust VR3a P1 5 9 untrust VR3b permit-to-3b 0 10 untrust VR3b DEFAULT-DENY 16
Not sure why this command has to be so obscure, but I stumbled on this while writing a training course tonight – quite a nice way to see if packets are hitting your policies:
imtech@srx220-1-POD3> show security policies hit-count Logical system: root-logical-system Index From zone To zone Name Policy count 1 VR3a VR3b P1 0 2 VR3a untrust 3to1VPN 8320 3 VR3a untrust P1 3249 4 VR3b VR3a P1 0 5 VR3b untrust P1 0 6 untrust junos-host P1 8 7 untrust VR3a 1to3 5523 8 untrust VR3a P1 5 9 untrust VR3b permit-to-3b 0 10 untrust VR3b DEFAULT-DENY 16