Cisco Multicast Ping ICMP reply not traverse over Fortigate IPSec
Hi all
I am scratching my head for past days and would appreciate fellow community if anyone of you had similar experience.
I am trying to test multicast over Fortigate IPSec.
Fortigate version 7.4.3 using EVE-NG VM
Cisco IOL using EVE-NG
Diagram and configuration file is like this:
https://drive.google.com/drive/folders/1vKQwaPGqhGTgDzZmf8rGQZHmeRi9vST5?usp=drive_link
R6 join IGMP 224.5.5.5 using Lo0 (192.168.11.1)
R7 try to send ping 224.5.5.5 from Lo1 (192.168.22.1)
Fortigate configuration follow this:
with addition that I found out that I need to enable PIM at port 3 (connecting to cisco router). By doing this, the router and the fortigate are pim neighbors.
also, I found out that the fortigate has to be set with RP (which is set at R7 Lo1 192.168.21.1).
The thing is, the ICMP request to 224.5.5.5 from 192.168.22.1 can be sent to the right side fortigate, go through IPSec, and exit left side fortigate without issue, and R6 Lo0 reply the ping with source: 192.168.11.1 and destination 192.168.22.1. this Echo reply received by the left fortigate and never exit at the right side fortigate.
Is this ICMP reply (unicast) for multicast packet cannot work with IPSEC?
I do not think there should be any blockage in the policy as I allow all any any to and from ipsec interface.
Really appreciate if someone can share their experience thanks a lot!
