Skip to main content
sw2090
SuperUser
SuperUser
May 18, 2022
Question

Intra-Zone Multicasting

  • May 18, 2022
  • 8 replies
  • 3830 views

I ran into an issue here:

 

I have a zone with several members.

Now I need multicast forwarding for airprint between two members of that zone.

intra-zone-traffic is blocked (per default) which is wanted that way.

So any traffic has to be explicitely allowed by a policy.

 

Now I cannot create a multicast policy for that because of the zone. In multicast policy only the zone is available  not its members. 

So even mlticast policies from interfaces that are not member of the zone can only have the zone as source or destination interface. I consider this a security risk.

 

Does anyone have some tip how one can do intra-zone multicast forwarding then?

I additionaly have openend a ticket with TAC on this too

8 replies

seshuganesh
Staff
Staff
May 18, 2022

Hi Team,

 

You can check this article to enable multi cast forwarding and to prevent changing multcast ttl value

https://docs.fortinet.com/document/fortigate/7.2.0/administration-guide/968606/configuring-multicast-forwarding

 

sw2090
SuperUser
sw2090Author
SuperUser
May 18, 2022

yeah that describes the way one usually achieves that with :)

But that does not work for zone members. It woukd only work for the zone itself 

plus it does not work intra-zone because of identical source and destination iface since one can only select the zone.

 

Its a fail-by-design here and also creates security risks....

sw2090
SuperUser
sw2090Author
SuperUser
May 18, 2022

TAC have confirmed that indeed both FortiManager and FortiGate do lack this feature.

They told us to open a NFR on that probably.

brandonziots
Explorer
February 10, 2026

You can allow intra-zone multicast traffic with the following configuration:

 

config system zone
edit ZoneA
set intrazone allow
end
end

You can then sent your multicast policy interfaces to any/any and restrict traffic via the source and destination IPs. 

See https://community.fortinet.com/t5/FortiGate/Technical-Tip-Workaround-to-allow-the-multicast-traffic-to-flow/ta-p/203905/redirect_from_archived_page/true

sw2090
SuperUser
sw2090Author
SuperUser
February 10, 2026

@brandonziots no! This will allow any traffic between zone members without any policies which I consider an even bigger security risk than the above!

With that you have no more chance to regulate traffic between zone members!

brandonziots
Explorer
February 11, 2026

If you're allowing intrazone traffic between members you simply will then restrict traffic explicitly via firewall policies. Yes, this is less secure than an implicit deny intrazone, but the question was originally asking how to allow multicast between members of the same zone - and this is a published workaround.

sw2090
SuperUser
sw2090Author
SuperUser
February 10, 2026

Btw I don't know why the forum now shows me as thread starter?! I just replied to the thread....

 

sw2090
SuperUser
sw2090Author
SuperUser
February 11, 2026

@brandonziots yes but there is one big difference in here: the standard FGT way is you have to explicitely allow any traffic you want to flow (except from net-iternal traffic). If you allow Intra-Zone-Traffic in a zone you turn that around 180°. In this case any traffic between zone members is allowed except if you forbid it by policy!

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.