Day One: Securing the Routing Engine v2 build firewall filters for RIP (page 74) and LDP (page 78). I do not understand why these filters include a term for IGMP. Here is the an example of the rip filter:
filter accept-rip {
term accept-rip {
from {
source-prefix-list {
router-ipv4;
router-ipv4-logical-systms;
}
destination-prefix-list {
rip;
}
protocol udp;
destination-port rip;
}
then {
count accept-rip;
accept;
}
}
term accept-rip-igmp {
from {
source-prefix-list {
router-ipv4;
router-ipv4-logical-systms;
}
destination-prefix-list {
rip;
}
protocol igmp;
}
then {
count accept-rip-igmp;
accept;
}
}
}