03-08-2011 12:12 PM - edited 03-11-2019 01:03 PM
folks
i setting up an asa (5540) to allow multicast traffic from an upstream server, on a DMZ interface, through to the inside interface so i'm doing a bit of preparatory investigation
the streaming server is 10.12.65.12 and i have an mroute statement
mroute 10.12.65.0 255.255.0 DMZ
the DMZ interface has a security-level 0
i have multicast routing enabled and igmp enabled on the DMZ and Inside interfaces and i can see a PIM neighbour on the outside
one of the multicast addresses is 239.192.65.10
my problem
when i run
packet-tracer in dmz udp 10.63.65.12 58657 239.192.61.10 1234
i get the following
Result:
input-interface: DMZ
input-status: up
input-line-status: up
Action: drop
Drop-reason: (security-failed) Early security checks failed
i've only seen a couple of posts about this but there are no resolutions so i'm particularly keen to get this sorted before i have to deliver the streaming media
has anyone any ideas or views?
thanks to anyone taking the time to read this or to reply
greatly appreciated
03-08-2011 12:14 PM
folks
apologies there's an error in the mroute statement
should be
mroute 10.12.65.0 255.255.255.0 DMZ
06-17-2013 03:37 PM
Hello ,
The packet tracer drop is expected:
Remember to rate all of the helpful posts.
For this community that's as important as a thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide