04-03-2023 07:06 AM
Hello,
I am having issues troubleshooting why the Cisco FirePower 2140 is dropping almost all Multicast frames. The way we have this set up is we have a device that is generating the Multicast Traffic and we have a Firepower 2140 that is configured with 4 Zones and ACL's that allow all traffic between zones. I also have the very basic multicast setup where I just enabled multicast IGMP and PIM on all interfaces and have create a an ACL that allows traffic sourcing from any zone/interface to forward to a multicast group IP 239.0.1.2. In our case the Traffic generator send the traffic to the FirePower and the firepower forwards the traffic through its interfaces and back to the traffic generator. But for some reason we are dropping almost 99% of the multicast traffic. IPS on the firepower is set to alert only and group joining appears to work properly. Is there anything i am missing that would cause the FirePower to drop almost all frames regardless of size?
Thank You in advanced for you assistance!
Solved! Go to Solution.
04-03-2023 09:48 AM
check the config if you using FMC to manage FTD :
check some troubleshooting :
04-03-2023 09:48 AM
check the config if you using FMC to manage FTD :
check some troubleshooting :
04-03-2023 12:06 PM
We have the items described in the document above configured. Multicast Routing is enabled, the Join Group is created for the 4 interfaces that we use. I have an ACL that is permitting those interfaces/zones to talk to the 239.0.1.2 IP. Some of the frames make it through but majority are dropped or lost and i just need help to figure out why that would occur.
Thank You!
04-03-2023 01:46 PM
Try placing the access rules in pre-filter policy instead of the ACP policy. This might be dropped by security intelligence, or perhaps a bug.
04-04-2023 11:20 AM
I tried adding a pre-filter rule for the multicast traffic and applying that pre-filter rule to the Access Control Policy. This for what ever reason causes the Ports on the FirePower to shut down and while it allowed a bit more traffic its still loosing 99 percent of multicast traffic.
Any other ideas on what could be causing this?
Thank You!
04-07-2023 08:32 AM
I am thinking that perhaps the processing of the Multicast traffic is being done differently than standard TCP traffic. Perhaps on one of the dataplanes and that plane is unable to process that much traffic. Does anyone know where Multicast traffic is processed on the Firepower 2140. I am having a hard time finding information on that?
Thank You!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide