<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM and Multicast in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-and-multicast/m-p/2269937#M347651</link>
    <description>&lt;P&gt;I have the following config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;multicast-routing&lt;/P&gt;&lt;P&gt;pim rp-address 10.200.59.10&lt;/P&gt;&lt;P&gt;I don't have any PIM neighbors, I just need to pass multicast stream from Vlan107 to Vlan126.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan107&lt;/P&gt;&lt;P&gt; nameif eDIN&lt;/P&gt;&lt;P&gt; security-level 40&lt;/P&gt;&lt;P&gt; ip address 10.90.23.254 255.255.254.0 standby 10.90.23.253&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan126&lt;/P&gt;&lt;P&gt; nameif OPE_TCE&lt;/P&gt;&lt;P&gt; security-level 20&lt;/P&gt;&lt;P&gt; ip address 10.11.40.1 255.255.0.0 standby 10.11.40.2&lt;/P&gt;&lt;P&gt; igmp static-group 226.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group eDIN_access_in in interface eDIN&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;access-list eDIN_access_in extended permit ip any host 226.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show access-list&lt;/P&gt;&lt;P&gt;access-list eDIN_access_in line 18 extended permit ip any host 226.1.1.1 (hitcnt=504349) 0x3cfe4253&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp; sh int vlan107 | incl input&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 13422433 packets input, 8096406276 bytes&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp; sh int vlan107 | incl input&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 13422499 packets input, 8096503432 bytes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# sh conn&lt;/P&gt;&lt;P&gt;0 in use, 13 most used&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;Multicast sessions:&lt;/P&gt;&lt;P&gt; Network Processor 1 connections&lt;/P&gt;&lt;P&gt; Network Processor 2 connections&lt;/P&gt;&lt;P&gt;IPv6 connections:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# sh mroute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Multicast Routing Table&lt;/P&gt;&lt;P&gt;Flags: D - Dense, S - Sparse, B - Bidir Group, s - SSM Group,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C - Connected, L - Local, I - Received Source Specific Host Report,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; P - Pruned, R - RP-bit set, F - Register flag, T - SPT-bit set,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; J - Join SPT&lt;/P&gt;&lt;P&gt;Timers: Uptime/Expires&lt;/P&gt;&lt;P&gt;Interface state: Interface, State&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(*, 226.1.1.1), 01:36:16/never, RP 10.200.59.10, flags: SCJ&lt;/P&gt;&lt;P&gt;&amp;nbsp; Incoming interface: Tunnel0&lt;/P&gt;&lt;P&gt;&amp;nbsp; RPF nbr: 10.200.59.10&lt;/P&gt;&lt;P&gt;&amp;nbsp; Outgoing interface list:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; OPE_TCE, Forward, 01:36:16/never&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't see (S,G) entry for my multicast stream. ANy help would be appreciated.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 02:01:24 GMT</pubDate>
    <dc:creator>anazarenko</dc:creator>
    <dc:date>2019-03-12T02:01:24Z</dc:date>
    <item>
      <title>FWSM and Multicast</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-multicast/m-p/2269937#M347651</link>
      <description>&lt;P&gt;I have the following config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;multicast-routing&lt;/P&gt;&lt;P&gt;pim rp-address 10.200.59.10&lt;/P&gt;&lt;P&gt;I don't have any PIM neighbors, I just need to pass multicast stream from Vlan107 to Vlan126.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan107&lt;/P&gt;&lt;P&gt; nameif eDIN&lt;/P&gt;&lt;P&gt; security-level 40&lt;/P&gt;&lt;P&gt; ip address 10.90.23.254 255.255.254.0 standby 10.90.23.253&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan126&lt;/P&gt;&lt;P&gt; nameif OPE_TCE&lt;/P&gt;&lt;P&gt; security-level 20&lt;/P&gt;&lt;P&gt; ip address 10.11.40.1 255.255.0.0 standby 10.11.40.2&lt;/P&gt;&lt;P&gt; igmp static-group 226.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group eDIN_access_in in interface eDIN&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;access-list eDIN_access_in extended permit ip any host 226.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show access-list&lt;/P&gt;&lt;P&gt;access-list eDIN_access_in line 18 extended permit ip any host 226.1.1.1 (hitcnt=504349) 0x3cfe4253&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp; sh int vlan107 | incl input&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 13422433 packets input, 8096406276 bytes&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp; sh int vlan107 | incl input&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 13422499 packets input, 8096503432 bytes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# sh conn&lt;/P&gt;&lt;P&gt;0 in use, 13 most used&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;Multicast sessions:&lt;/P&gt;&lt;P&gt; Network Processor 1 connections&lt;/P&gt;&lt;P&gt; Network Processor 2 connections&lt;/P&gt;&lt;P&gt;IPv6 connections:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# sh mroute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Multicast Routing Table&lt;/P&gt;&lt;P&gt;Flags: D - Dense, S - Sparse, B - Bidir Group, s - SSM Group,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C - Connected, L - Local, I - Received Source Specific Host Report,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; P - Pruned, R - RP-bit set, F - Register flag, T - SPT-bit set,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; J - Join SPT&lt;/P&gt;&lt;P&gt;Timers: Uptime/Expires&lt;/P&gt;&lt;P&gt;Interface state: Interface, State&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(*, 226.1.1.1), 01:36:16/never, RP 10.200.59.10, flags: SCJ&lt;/P&gt;&lt;P&gt;&amp;nbsp; Incoming interface: Tunnel0&lt;/P&gt;&lt;P&gt;&amp;nbsp; RPF nbr: 10.200.59.10&lt;/P&gt;&lt;P&gt;&amp;nbsp; Outgoing interface list:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; OPE_TCE, Forward, 01:36:16/never&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't see (S,G) entry for my multicast stream. ANy help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:01:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-multicast/m-p/2269937#M347651</guid>
      <dc:creator>anazarenko</dc:creator>
      <dc:date>2019-03-12T02:01:24Z</dc:date>
    </item>
    <item>
      <title>FWSM and Multicast</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-multicast/m-p/2269938#M347652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This means that the registration process has not finished yet,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Who is this guy &lt;SPAN style="font-size: 10pt;"&gt;10.200.59.10 ( Core router, etc),&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also you are running PIM sparse-mode on the FWSM and you do not see any neigbhorship, ofcourse you will not receive any traffic, you must build a PIM relationship between you and the device that connects to the RP address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Remember to rate all of the helpful posts. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;BR /&gt;For this community that's as important as a thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2013 18:45:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-multicast/m-p/2269938#M347652</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-06-21T18:45:18Z</dc:date>
    </item>
    <item>
      <title>FWSM and Multicast</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-multicast/m-p/2269939#M347653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.200.59.10 is FWSM itself.&lt;/P&gt;&lt;P&gt;I just need to pass the traffic from one VLAN to another one. (light version of PIM, without neighbors)&lt;/P&gt;&lt;P&gt;My subscriber is sitting in OPE_TCE VLAN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2013 18:59:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-multicast/m-p/2269939#M347653</guid>
      <dc:creator>anazarenko</dc:creator>
      <dc:date>2013-06-21T18:59:25Z</dc:date>
    </item>
    <item>
      <title>FWSM and Multicast</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-multicast/m-p/2269940#M347654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okey, got it,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically multicast traffic will only flow across the FWSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The source of the traffic is on the eDIN interface,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What happens if you apply captures and generate some traffic? Do u see the traffic reaching both interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you use the eDIN interface as the RP address ( As I do not see the 10.200.59.10 listed on the config, just want to be sure)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts. &lt;BR /&gt; &lt;BR /&gt;For this community that's as important as a thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2013 19:13:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-multicast/m-p/2269940#M347654</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-06-21T19:13:48Z</dc:date>
    </item>
    <item>
      <title>FWSM and Multicast</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-multicast/m-p/2269941#M347655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, today i managed to change RP to Vlan eDIN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MMFWIB11/eGON/act# sh mroute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Multicast Routing Table&lt;/P&gt;&lt;P&gt;Flags: D - Dense, S - Sparse, B - Bidir Group, s - SSM Group,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C - Connected, L - Local, I - Received Source Specific Host Report,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; P - Pruned, R - RP-bit set, F - Register flag, T - SPT-bit set,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; J - Join SPT&lt;/P&gt;&lt;P&gt;Timers: Uptime/Expires&lt;/P&gt;&lt;P&gt;Interface state: Interface, State&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(*, 226.1.1.1), 2d23h/never, RP 10.11.40.1, flags: SCJ&lt;/P&gt;&lt;P&gt;&amp;nbsp; Incoming interface: Tunnel1&lt;/P&gt;&lt;P&gt;&amp;nbsp; RPF nbr: 10.11.40.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Outgoing interface list:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; OPE_TCE, Forward, 2d23h/never&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# sh capture&lt;/P&gt;&lt;P&gt;capture vlan107 type raw-data access-list mcast interface eDIN[Buffer Full - 524220 bytes]&lt;/P&gt;&lt;P&gt;capture vlan126 type raw-data interface OPE_TCE[Capturing - 0 bytes]&lt;/P&gt;&lt;P&gt;# sh capture vlan107&lt;/P&gt;&lt;P&gt;132699 packets seen, 6244 packets captured&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 1: 08:53:28.323060160 802.1Q vlan#107 P0 10.10.11.2.53539 &amp;gt; 226.1.1.1.5001:&amp;nbsp; udp 1470&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 2: 08:53:28.323060180 802.1Q vlan#107 P0 10.10.11.2.53539 &amp;gt; 226.1.1.1.5001:&amp;nbsp; udp 1470&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#sh route | incl 10.10.11.2&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.11.2 255.255.255.255 [1/0] via 10.90.23.253, eDIN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and nothing on outgoing interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jun 2013 09:19:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-multicast/m-p/2269941#M347655</guid>
      <dc:creator>anazarenko</dc:creator>
      <dc:date>2013-06-24T09:19:46Z</dc:date>
    </item>
  </channel>
</rss>

