Skip to main content
greelanx
New Member
July 3, 2014
Question

Multicast forwarding

  • July 3, 2014
  • 6 replies
  • 28184 views
Hello, hopefully you can help me. I have a UPnP/DLNA media server running on my LAN (interface: internal) and would like to stream movies/music to my tablet which is connected to the FortiAP. I did some research and found the following: > When a UPnP capable device joins a network and wants to know what UPnP services are available on > the network, it sends out a discovery message to the multicast address 239.255.255.250 on port > 1900 via the UDP protocol. This message contains a header, similar to a HTTP request. This > protocol is sometimes referred to as HTTPU (HTTP over UDP). I searched the Fortinet KB and it says: > FortiGate devices do not support Universal Plug and Play (UPnP). > This includes FortiOS versions 2.36, 2.50, 2.80, 3.0, 4.0 and 5.0 Now I' m confused. Fortigate is able to do multicast routing / forwarding even TTL can be configured but it doesn' t support UPnP/DLNA which uses multicast? From the CLI manual: > set multicast-forward {enable | disable} > set multicast-ttl-notchange {enable | disable} I' m not so familar with multicast. So far as I know multicast ist a " one to many" communication. What I need is forwarding all multicast traffic from internal to wifi. e.g. 192.168.1.x => 172.16.1.x Note: I do NOT want to combine wifi and internal interfaces into a single subnet and will do that never as this makes no sense. Wifi and LAN should be seperated. So my question to the specialists: is it possible and if yes how? :-) Thank you!

    6 replies

    greelanx
    greelanxAuthor
    New Member
    July 7, 2014
    No one has an idea?
    wolvetk
    New Member
    January 30, 2015

    Have you tried:

     

    config firewall multicast-policy edit 0 set srcintf internal set dstintf wifi next end Bye André

    emnoc
    New Member
    January 30, 2015

    And ensure the the TTL is adequate and will not be exceeding  ( it needs to be greater than 1 ;) )

     

    Ken

    bshimkus
    New Member
    September 16, 2017

    emnoc wrote:

    And ensure the the TTL is adequate and will not be exceeding  ( it needs to be greater than 1 ;) )

     

    Ken

    How do you do this?

     

    bks

    emnoc
    New Member
    September 16, 2017

    Can you select the TTL? Since this a discovery usage I bet not. Discovery typically stay local on the LAN. Do a pcap and inspect the TTL.

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!