Hi
on a fortigate, have a multicast feed coming in over a GRE tunnel and passing out to an ethernet fine
Also want ssl vpn users to be able to subscribe, have igmp/pim enabled on gre/ethernet/ssl.root, can see the IGMP joins from both the ethernet and ssl.root interfaces (on the fortigate) but PIM never forwards out the ssl.root interface, just the ethernet, only ever shows the ethernet as a forwarding port, why does pim not also forward out the ssl.root interface.
thanks
Hello nanobot,
Thank you for using the Community Forum.
I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Regards,
Hello,
We are still looking for an answer to your question.
We will come back to you as soon as we get it.
Regards,
Hello,
I have found this documentation:
Could you please tell me if it helps?
Regards,
Hi,
To make Multicast stream forwarding over SSL-VPN you should configure IP address on ssl.root interface:
config system interface
edit "ssl.root"
set ip xxx.xxx.xxx.xxx/32
next
end
&Note: The IP address should be from the same pool as SSL-VPN clients IP pool (subnet)
&Note#2: Once one of the clients joins some igmp group, all clients will receive that group (channel) multicast traffic, which may be unwanted from security point of view and may cause performance problems on clients side.
$Note#3: All other traffic (unicast stream, ethernet) are working over SSL-VPN even there is not assigned IP address to ssl.root interface.
BR
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1113 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.