PCNSE
NSE
StrongSwan
PCNSE
NSE
StrongSwan
ORIGINAL: emnoc Okay let' s start from the top; The IPTV box is it an adapter for your TV? or server some other role ?The IPTV box is a Set-Top Box with Ethernet connection and HDMI connection (to the TV). It is a client role.
How does it get it' s content ?It gets an IP Address from the DHCP server on my LAN, asks for an ini file from a remote webserver, then starts to join multicast groups.
Is the content provided by your service provider?Yes, although my ISP gets the contents from an IPTV-Provider (netstream.com).
Is that the WAN?Yes, it' s wan1.
if it' s WAN1, do you see any mcast queriers within the WAN connection? ( diag sniffer packet or tcpdump igmp ) If you do have this, than your IPTV box must subscribed to this and ask for the channel and listing using IGMP and subscriptions to at least 233.60.157.112. The FGT needs to forward that request out and thru the WAN. The best bet is for the FGT to proxy the IGMP request(s) from IPTV device to your upstream? Does the IPTV device works when not behind the FGT device? Do you have any problems with link saturation for the mcast data? It will or could saturated the WAN connection depending on the content being delievered. So keep that in mind. Lastly, if the IPTV device is an adapterized to your TV, do you really need to secure it in a DMZ?About the last thing (dmz): it is only the " dmz port" of the Fortigate unit, just to separate it from my WLAN/LAN and being able to test it with its own DHCP (I also needed to set domain name and a DHCP option to get it work). What I see is this: FWF60C-Bonny # get router info multicast igmp groups IGMP Connected Group Membership Group Address Interface Uptime Expires Last Reporter 224.0.1.140 wan1 22:58:24 00:04:02 84.55.249.100 233.60.157.101 wan1 22:58:30 00:04:01 84.55.249.100 233.60.157.102 wan1 22:58:30 00:04:01 84.55.249.100 233.60.157.112 wan1 22:58:30 00:04:02 84.55.249.100 239.129.0.2 wan1 00:57:08 00:04:02 84.55.249.100 224.0.1.140 dmz 01d20h59m 00:04:04 10.10.10.1 233.60.157.102 dmz 01d20h58m 00:04:11 10.10.10.50 239.129.0.2 dmz 00:52:48 00:04:04 10.10.10.50 239.129.0.4 dmz 00:01:06 00:04:01 10.10.10.50 As you can see, the IPTV box (dmz-port) asks for some multicast group to join and wan1 permits that. The multicasts on 239.129.0.x are the streams for each single tv channel (.2 is channel 2, .4 is channel 4, and so on). I could achieve the above result by manually adding some multicast IPs, which IS NOT my goal. Also, if I add more then 2 streams/multicast IPs, then I get saturated and nothing works anymore (which is obvious, as my Fortigate is then passing down to the dmz MANY streams at the same time, but I can watch only 1 channel at a time!) ;-) So, what else? I' m almost getting desperate, but not willing to give up as Fortigate is for sure able to handle this kind of setup. Regards, F.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1743 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.