OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 18.1 Legacy Series »
  • Multicast traffic
« previous next »
  • Print
Pages: [1]

Author Topic: Multicast traffic  (Read 3587 times)

dcol

  • Hero Member
  • *****
  • Posts: 557
  • Karma: 46
    • View Profile
Multicast traffic
« on: March 30, 2018, 12:31:13 am »
What is generally the best practice for IGMP Multicast traffic. Allow or block on the internal networks?
I do see occasional hits from a WiFi router, which are now blocked with a default deny rule.
Logged

dcol

  • Hero Member
  • *****
  • Posts: 557
  • Karma: 46
    • View Profile
Re: Multicast traffic
« Reply #1 on: March 31, 2018, 08:17:34 pm »
Bump, anyone.....
Logged

elektroinside

  • Hero Member
  • *****
  • Posts: 574
  • Karma: 51
    • View Profile
Re: Multicast traffic
« Reply #2 on: March 31, 2018, 09:54:50 pm »
Allow on the local net :) It's actually a tool to improve network traffic in some cases.
Logged
OPNsense v18 | HW: Gigabyte Z370N-WIFI, i3-8100, 8GB RAM, 60GB SSD, | Controllers: 82575GB-quad, 82574, I221, I219-V | PPPoE: RDS Romania | Down: 980Mbit/s | Up: 500Mbit/s

Team Rebellion Member

dcol

  • Hero Member
  • *****
  • Posts: 557
  • Karma: 46
    • View Profile
Re: Multicast traffic
« Reply #3 on: March 31, 2018, 09:57:53 pm »
That's what I thought. I will create a floating rule including all my internal interfaces, but not to WAN, to allow IGMP.
Thanks
« Last Edit: April 01, 2018, 06:30:37 pm by dcol »
Logged

elektroinside

  • Hero Member
  • *****
  • Posts: 574
  • Karma: 51
    • View Profile
Re: Multicast traffic
« Reply #4 on: March 31, 2018, 10:15:52 pm »
You're welcome. Go ahead, although, just as a side note, in very secured setups, all (except the very minimum) TCP/IP processed stuff are disabled, including IGMP. And also worth mentioning that older OSs are vulnerable (regarding IGMP) but patches are available :)
Logged
OPNsense v18 | HW: Gigabyte Z370N-WIFI, i3-8100, 8GB RAM, 60GB SSD, | Controllers: 82575GB-quad, 82574, I221, I219-V | PPPoE: RDS Romania | Down: 980Mbit/s | Up: 500Mbit/s

Team Rebellion Member

mimugmail

  • Hero Member
  • *****
  • Posts: 6299
  • Karma: 434
    • View Profile
Re: Multicast traffic
« Reply #5 on: April 01, 2018, 06:53:53 am »
It only works in the local LAN if you don't use multicast routing (which is currently unsupported), so you can either create a rule for allowing or a rule for dropping with logging disabled.
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 18.1 Legacy Series »
  • Multicast traffic
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2