Point-to-multipoint (switch-to-switch) topology

In a multipoint topology with N nodes, each node needs a single Tx-SC and N Rx-SCs, one for each of the peers. For example, 64 Rx-SAs per security zone translates to 32 Rx-SCs, which breaks down to only 32 peers (only 33 nodes in the multipoint topology per security zone, where each node has one Tx-SC and 32 Rx-SCs).

Figure 1. Switch multipoint-to-switch multipoint topology

In the preceding figure, when the 34th node joins the multipoint topology, the other 33 nodes that are already part of this domain do not have SAs to create an Rx-SC for this 34th node. However, the 34th node has a Tx-SC and accepts 32 peers. The 34th node starts to transmit and encrypt the PDUs based on its Tx-SC but, because the other nodes do not have an SC for this SAI, they drop all Rx PDUs.

To ensure that a multicast domain for a single security zone does not exceed 32 peers or the total of all the nodes in a security zone CA domain, Nokia recommends not exceeding 33 nodes. This is the same as if a security zone has four CAs; the total of all nodes in the four CAs must be 33 or less.