edit policy vrrp-hello-block
entry vrrp-block { if match all {
destination-address 224.0.0.18/32 ;
} then {
deny ;
}
}
config access-list vrrp-hello-block port x,y,z ingress
This policy should be applied in all ports - ports between core & downlink to Access Switches - where the access switches are connected dual home to both cores.