cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
441
Views
0
Helpful
1
Replies

Defining PIM-SSM Sources

Chad Parish
Level 1
Level 1

So I am researching SSM and while I have a pretty firm understanding of how it works once sources have been identified and mapped to groups in order to create channels, I am unable to find any documention detailing the methods for identifying sources.  In ASM, sources announce themselves via IGMP to their DR who then forwards it along to the domain's RP which in turn lets the other various DR's know about the source.  But with SSM it seems that one must manually map each potential source to a group.  Is there a dynamic way for this to happen?

Also, while SSM provides better security then ASM due to the additional requirement of providing a unicast source IP along with the multicast group IP, what is to stop someone from simply configuring their own device as a source to send out malicious data?  

Last question.  Assuming you are also running PIM-SM alongside of SSM in your network because not all clients are IGMPv3 ready, does the source send out both a mapped channel advert to the other DRs as well as a different Group IP to the RP so that it can in turn alert DRs on behalf of those potentiol receivers unable to participate using IGMPv3?

1 Reply 1

pgasparovic
Level 1
Level 1

Hi man,

possibly you have answered the question for yourself without no-one here in last 4 months, but anyway :

- sources don't use IGMP, their data simply arrive at source PE interface and depending on PIM mode, other things in network happen, in different directions (to be very brief)

- apps/endpoints learn of source out-of-band (typically HTTP way to some server)

- of course, there is also possible e.g. DNS mapping of SSM sources to group, and for my case coming accid. across your thread to see if someone reported bug as Bug tool does not show any, I have that stupid bug on 7600 15.4S IOS, and can't move any further. :-DD

- to my knowledge, you can't run PIM SSM in parallel with other modes for groups, that have been allocated for SSM, from single router p.o.w. It's quite logical, this is the most direct mode. Again, source is not "announced" or "advertised" somewhere to receiver segments.

Hopefully I was quite correct :)

BR

Peter