FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
nalexiou
Staff
Staff
Article Id 369157
Description This article describes the multicast modes that can be configured on FortiGate.
Scope FortiOS.
Solution

Multicast forwarding:

 

Multicast forwarding is a feature that allows multicast packets to be efficiently distributed between multicast routers and receivers.
It enables the simultaneous distribution of data to multiple recipients, making it ideal for applications like real-time streaming,
multimedia content delivery, audio/video conferencing, IPTV, online gaming, and content distribution networks (CDNs).
Multicast forwarding on a FortiGate device involves forwarding multicast IP packets to all interfaces and VLAN interfaces, except the receiving interface, which are allowed by a multicast firewall policy and when the TTL is 2 or higher.
To enable multicast forwarding, you can use the "multicast-forward" setting in NAT mode on a FortiGate device.
In this mode, the FortiGate does not run PIM nor IGMP for the groups.

 

Documentation:
Configuring multicast forwarding - FortiOS v7.6 documentation.
Technical Tip: Forwarding multicast traffic in NAT mode.


Multicast routing:

 

Multicast routing involves using a single multicast source to send data to multiple receivers simultaneously.
It allows for efficient data distribution to many recipients while conserving bandwidth and reducing network traffic.
Multicast routing is commonly used for one-way delivery of media streams, news feeds, financial information, and more.
The FortiGate can run Protocol Independent Multicast (PIM) with the upstream and downstream routers and IGMP with the LANs it’s the Gateway for, supporting PIM sparse mode and PIM dense mode to service multicast servers or receivers on the network segment to which it is connected.

 

See the documentation.


When multicast forwarding is enabled and PIM is configured at the same time, multicast routing takes precedence and multicast forwarding will be disabled.


The global command 'diagnose sys vd list' shows if Multicast forwarding is enabled.

 

multicast.PNG

 

In the variable 'mc_fwd', 0 means disabled and 1 means enabled.

Contributors