Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Dallas
New Contributor

VLAN & Multicasting

Hi All, looking for some help, I have a network setup and I have VLAN' d the environment using the fortigate 110c as the router, when I run a multicast I get flooding happening across the entire network, any suggestions where to start looking? cheers
5 REPLIES 5
emnoc
Esteemed Contributor III

Yeah do you have switches that do igmp snooping? What mcast address is flooding your network? What multicast protocol are you using? ( dense sparse ) What version of code are you using? How did you enable mcast and mcast routing + policies ?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Dallas
New Contributor

the core switch is a HP 8212 it does have IGMP enabled... I am using PIM-Dense mode I am using v4.0,build0639,120906 (MR3 Patch 10) I enabled multicasting using the web interface, I created the policies the same way
emnoc
Esteemed Contributor III

SO COOL, but what about the mcast grp ( dst_address) Can you give us a snippet of the groups and traffic? show firewall multicast-policy get firewall multicast-policy

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Dallas
New Contributor

this is the outpu of sh firewall multicast-policy config firewall multicast-policy edit 1 set dstintf " switch" set srcintf " L_Block" next edit 2 set dstintf " L_Block" set srcintf " switch" next edit 3 set dstintf " switch" set srcintf " A_Block" next edit 4 set dstintf " A_Block" set srcintf " switch" next edit 5 set dstintf " switch" set srcintf " Admin" next edit 6 set dstintf " Admin" set srcintf " switch" next edit 7 set dstintf " switch" set srcintf " B_Block" next edit 8 set dstintf " B_Block" set srcintf " switch" next edit 9 set dstintf " switch" set srcintf " E_Block" next edit 10 set dstintf " E_Block" set srcintf " switch" next edit 11 set dstintf " switch" set srcintf " G_Block" next edit 12 set dstintf " G_Block" set srcintf " switch" next edit 13 set dstintf " switch" set srcintf " H-Block" next edit 14 set dstintf " H-Block" set srcintf " switch" next edit 15 set dstintf " switch" set srcintf " ICTServices" next edit 16 set dstintf " ICTServices" set srcintf " switch" next edit 17 set dstintf " switch" set srcintf " S_Block" next edit 18 set dstintf " S_Block" set srcintf " switch" next edit 19 set dstintf " switch" set srcintf " Staff" next edit 20 set dstintf " Staff" set srcintf " switch" next end
emnoc
Esteemed Contributor III

So what mcast groups are you allowing? And the one(s) that flooding everything? Also if your switch is truely set for igmp snooping it should see your firewall as a mcast-router and show all unique subscriptions to the hosts. I would do a diag sniffer with the keyowrd igmp ( pro to 1 ) and make sure that igmp is working correctly. You Also need to review your mcast-fwpolicies for the correct SRCs and DSTs.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors