Skip to main content
pbarbieri
Visitor III
April 8, 2022
Solved

PIM multicast router

  • April 8, 2022
  • 4 replies
  • 3130 views

I have configured in my firewall different tunnel GRE all managed by PIM dense mode. I would like to enable PIM only for some specific tunnel GRE and let the other use the normal delivery of multicast without PIM (forward enable).  I tried to do that but when enable PIM multicast also the other tunnel GRE without multicast PIM do not deliver the multicast packet.

How can I create a mixed environment tunnell GRE with PIM and GRE without PIM to deliver multicast packet? Do you believe that using different VDOM this is possible? At the moment it seems that if I enable PIM multicast routing all the firewall has to be manage  with PIM, I cant use different interface for this. I have a firewall Fortigate 600e with 6.4.7 build 1911 firmware.

Best answer by akristof

Hello,

 

Thank you for your question. Yes, FortiGate does not allow mixing multicast forwarding and routing together. So in your case, as you suggested, VDOM will be the best solution, migrate interfaces to each vdom based on if you need forwarding or routing on that interface.

4 replies

akristof
Staff
akristofAnswer
Staff
April 8, 2022

Hello,

 

Thank you for your question. Yes, FortiGate does not allow mixing multicast forwarding and routing together. So in your case, as you suggested, VDOM will be the best solution, migrate interfaces to each vdom based on if you need forwarding or routing on that interface.

pbarbieri
pbarbieriAuthor
Visitor III
May 23, 2022

Hello Adrian, according to your last reply that has satisfied my question, kindly I would like to receive a further reply to a new my question with the same topic. Question is If the same interface of my firewall could be assigned to different VDOMs with different multicast methods by creating a sub-interface PIM and multicast forwarding. I have a group of node working with forwarding multicast and another group of node with PIM (dense or sparse is not important) but the physical interface connected to the WAN common is the same! Both the group of nodes working with GRE tunnels. I am not too much optimistic about a solution but I will try with your experience to have a reply. Thanks

akristof
Staff
Staff
May 23, 2022

Hello,

One interface can be assigned to one vdom only. Sub-interfaces on physical interface, like Vlans, can be member of different vdoms.

pbarbieri
pbarbieriAuthor
Visitor III
April 8, 2022

thank you very much for your support Adrian!

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!