Configuration Methods
This section covers the common configuration methods to pass the multicast traffic through the FWSM. The following are three common ways of configuring:
• Multicast through firewall in single context routed mode
• Multicast through firewall via GRE
• Multicast through transparent firewall in multiple context mode
Method 1: Configuration Example for Multicast Through Firewall in Single Context Routed Mode
To understand method 1, refer to Figure 16-1, which illustrates a configuration example of multicast through single context routed mode.
Figure 16-1 Configuration Example of Multicast Through Single Context Routed Mode in FWSM
Figure 16-1 Configuration Example of Multicast Through Single Context Routed Mode in FWSM
Example 16-1 shows the configuration of multicast through FWSM using the 3.1 code release. The FWSM mode is in single context routed mode. The RP's IP address in this example is 1.1.1.1 and is on the outside interface of the FWSM. The receiver is on the outside interface and the source is on the inside interface of the FWSM. This example replicates the data center environment, where the source is on the inside interface connecting the data center and the receivers, and RP is at the outside interface of the data center. The RP can also be on the inside interface of the data center, and the FWSM can also participate as an RP. This may require detailed discussion between the security and networking teams to resolve potential operational issues.
Example 16-1 Configuration Example of Multicast Through Single Context Routed Mode in FWSM (Code Version 3.1)
FWSM# show run FWSM Version 3.1(3)6 !
hostname FWSM
enable password 8Ry2YjIyt7RRXU24 encrypted ! Stepl: Enable multicast routing on the FWSM multicast-routing names !
interface Vlan20 nameif outside security-level 0
ip address 10.1.11.1 255.255.255.0
interface Vlan21 nameif inside security-level 100 ip address 10.1.1.1 255.255.255.0
Example 16-1 Configuration Example of Multicast Through Single Context Routed Mode in FWSM (Code Version 3.1) (Continued)
|
! Step2: This command configures RP's IP address defined |
in the network |
|
pim rp-address 1.1.1.1 |
|
|
ftp mode passive |
|
|
access-list 101 extended permit ip any any |
|
|
access-list 101 extended permit igmp any any |
|
|
pager lines 24 |
|
|
mtu outside 1500 |
|
|
mtu inside 1500 |
|
|
no failover |
|
|
icmp permit any outside |
|
|
icmp permit any inside |
|
|
arp timeout 14400 |
|
|
nat (inside) 0 0.0.0.0 0.0.0.0 |
|
|
static (inside,outside) 10.1.1.0 10.1.1.0 netmask 255.255 |
.255.0 |
|
access-group 101 in interface outside |
|
|
access-group 101 out interface outside |
|
|
access-group 101 in interface inside |
|
|
access-group 101 out interface inside |
|
|
! The default route takes care of reachability to RP's IP |
address 1.1.1.1 at the |
|
! outside security domain |
|
|
route outside 0.0.0.0 0.0.0.0 10.1.11.2 1 |
The show mroute command verifies the multicast state on the FWSM:
Verify (*,G),(S,G) state, RP information, and the flags. Explanation of multicast flags is beyond the scope of this book.
FWSM# show mroute 239.1.1.1
Multicast Routing Table
Flags: D - Dense, S - Sparse, B - Bidir Group, s - SSM Group,
C - Connected, L - Local, I - Received Source Specific Host Report, P - Pruned, R - RP-bit set, F - Register flag, T - SPT-bit set, J - Join SPT Timers: Uptime/Expires Interface state: Interface, State (*, 239.1.1.1), 1d21h/never, RP 1.1.1.1, flags: SPC Incoming interface: outside RPF nbr: 10.1.11.2 Outgoing interface list: (10.1.1.2, 239.1.1.1), 00:12:36/00:03:23, flags: ST Incoming interface: inside RPF nbr: 10.1.1.2 Outgoing interface list:
outside, Forward, 00:00:28/00:03:12 Outgoing interface list: outside, Forward, 00:00:13/00:03:16
NOTE After enabling multicast-routing, PIM and IGMP are enabled by default on the interface. No explicit command is needed to enable PIM or IGMP.
If the RP is defined at the inside security domain, a static translation is required for the RP's IP address. Remember, a static translation is required when a less-secured domain accesses a more-secured domain.
Method 2: Configuration Example for Multicast Through Firewall via GRE
To understand method 2, refer to Figure 16-2, which illustrates a configuration example for multicast through firewall via GRE.
Figure 16-2 Configuration Example for Multicast Through Firewall via GRE
Figure 16-2 Configuration Example for Multicast Through Firewall via GRE
This is another method for multicast to traverse through the FWSM. The pass-through of GRE traffic will need careful configuration on the routing part for congruency and RPF checks for multicast reachability. The FWSM has to be configured for reachability of unicast routing flow, between the two security zones. FWSM should have ACL configuration to allow GRE packets to traverse the FWSM. Example 16-2 shows the configuration to achieve multicast through FWSM via GRE.
PFC3bofcat6kB: This is the next hop device connected to the FWSM and has the configuration of the GRE tunnel and the receiver at the outside security domain.
Example 16-2 Configuration Example for Multicast Through Firewall via GRE
PFC3bofcat6kB#show run hostname PFC3bofcat6kB ! Enable multicast on the router ip multicast-routing
! For testing, you can use igmp join-group to have the loopback 200 act as a receiver ! for 239.1.1.3. Note that the traffic will be process switched for 239.1.1.3. PIM ! sparse mode should be enabled on the interface, interface Loopback200 ip address 10.1.50.1 255.255.255.255 ip pim sparse-mode ip igmp join-group 239.1.1.3
! Enable GRE tunnel with destination of the first Layer 3 router at the inside ! interface of the FWSM. Enable pim sparse-mode. VLAN 20 is the SVI interface which ! is also defined at the FWSM's outside VLAN. You need to define the SVI interface on ! the switch, interface Tunnel0 ip address 10.1.40.2 255.255.255.252 ip pim sparse-mode tunnel source Vlan20 tunnel destination 10.1.1.2
interface Vlan20 ip address 10.1.11.2 255.255.255.0
!Routing for the multicast source and the RP will need to pass through the tunnel ip route 1.0.0.0 255.0.0.0 Tunnel0 ip route 10.1.1.0 255.255.255.0 10.1.11.1 ip route 10.1.3.0 255.255.255.0 Tunnel0
! RP's IP address for the multicast domain is 1.1.1.1. This IP address for the RP ! is defined at the inside security domain.
ip pim rp-address 1.1.1.1
Firewall at Cat6kB (FWSM configuration): For passing GRE, ACL configuration is needed. No special multicast configuration is needed at the FWSM. FWSM# show run : Saved
hostname FWSM
enable password 8Ry2YjIyt7RRXU24 encrypted names !
interface Vlan20 nameif outside security-level 0
ip address 10.1.11.1 255.255.255.0
interface Vlan21 nameif inside security-level 100
Example 16-2 Configuration Example for Multicast Through Firewall via GRE (Continued)
ip address 10.1.1.1 255.255.255.0 ftp mode passive
! Access list will allow GRE. In production networks, a more specific access list
! for allowing GRE is needed. GRE uses protocol 47
access-list 101 extended permit ip any any access-list 101 extended permit igmp any any pager lines 24
mtu outside 1500
mtu inside 1500
no failover mroute 10.1.1.2 255.255.255.255 inside icmp permit any outside icmp permit any inside no asdm history enable arp timeout 14400
static (inside,outside) 10.1.40.0 10.1.40.0 netmask 255.255.255.0
! Access list is applied on the interfaces access-group 101 in interface outside access-group 101 out interface outside access-group 101 in interface inside access-group 101 out interface inside route outside 0.0.0.0 0.0.0.0 10.1.11.2 1_
Cat6k6a: This is the next hop Layer 3 device for the FWSM at the inside security domain and is also configured as an RP. cat6k6a# show run ! Enable multicast routing ip multicast-routing
! igmp_join-group defines another receiver at the inside security domain 239.1.1.1 ! and also Loopback 0 is configured with the IP address for the RP. PIM sparse mode ! should be enabled on the interface. interface Loopback0 ip address 1.1.1.1 255.255.255.255 ip pim sparse-mode ip igmp join-group 239.1.1.1
! Enable GRE tunnel with destination of the first Layer 3 router at the outside ! interface of the FWSM. PIM sparse mode should be enabled on the interface. ! Vlan 21 is the SVI interface defined at the inside VLAN of the FWSM. interface Tunnel0 ip address 10.1.40.1 255.255.255.252 ip pim sparse-mode tunnel source Vlan21 tunnel destination 10.1.11.2
interface FastEthernet2/1 ip address 10.1.3.2 255.255.255.252
ip pim sparse-mode !
interface Vlan21 ip address 10.1.1.2 255.255.255.0
! Configuration to reach the receiver at the outside security domain through the ! tunnel
Example 16-2 Configuration Example for Multicast Through Firewall via GRE (Continued)
ip route 10.1.50.1 255.255.255.255 Tunnel0
! Configure the RP's IP address ip pim rp-address 1.1.1.1
cat6k6a#
E-R3745-B: Router configured with a receiver at the inside security domain
|
E-R3745-B# show run |
|||
|
hostname E-R3745-B |
|||
|
! Enable multicast routing |
|||
|
ip multicast-routing |
|||
|
! For testing, you can use igmp join-group to |
have |
the FastEthernet 1/0 act as a |
|
|
! receiver for 239.1 |
1.2. Note that the traffic |
will |
be process switched. PIM sparse |
|
! mode should be enabled on the interface. |
|||
|
interface FastEthernet1/0 |
|||
|
ip address 10.1.3.1 |
255.255.255.252 |
||
|
ip pim sparse-mode |
|||
|
ip igmp join-group |
239.1.1.2 |
||
|
speed auto i |
|||
|
ip route 0.0.0.0 0.0 |
.0.0 10.1.3.2 |
||
|
! Configure RP's IP |
address |
||
|
ip pim rp-address 1. |
1.1.1 |
||
|
E-R3745-B# |
|||
Method 3: Configuration Example for Multicast Through Transparent Firewall in Multiple Context Mode
To understand method 3, refer to Figure 16-3, which illustrates a configuration example of multicast through a transparent firewall in multiple context mode.
Figure 16-3 Configuration Example of Multicast Through Transparent Firewall in Multiple Context Mode
Figure 16-3 Configuration Example of Multicast Through Transparent Firewall in Multiple Context Mode
In this example, the FWSM is in multiple context mode. The contexts of the FWSM are configured for transparent mode. In multiple context mode, the support for multicast is achieved through transparent firewall. The RP is in the inside security zone. The FWSM is running code version 3.1. The FWSM does not need any configuration, except ACL entries. In the 3.1 code version or later, the performance is optimized for this configuration.
Example 16-3 shows the support of multicast in multiple context mode using transparent firewall.
Example 16-3 Configuration of Multicast Through Transparent Firewall in Multiple Context Mode
! System configuration of FWSM is in multiple context mode. This does not need any ! specific configuration to pass multicast traffic through the FWSM FWSM# show run : Saved
resource acl-partition 12 hostname FWSM
enable password 8Ry2YjIyt7RRXU24 encrypted !
interface Vlan30 !
interface Vlan31 !
passwd 2KFQnbNIdI.2KYOU encrypted class default limit-resource IPSec 5 limit-resource Mac-addresses 65535 limit-resource ASDM 5 limit-resource SSH 5
Example 16-3 Configuration of Multicast Through Transparent Firewall in Multiple Context Mode (Continued)
limit-resource Telnet 5 limit-resource All 0
ftp mode passive pager lines 24 no failover no asdm history enable arp timeout 14400 console timeout 0 admin-context admin context admin config-url disk:/admin.cfg
context A
allocate-interface Vlan30 allocate-interface Vlan31 config-url disk:/A.cfg
prompt hostname context
Cryptochecksum:1415c3d58fb402ff51afc7ce292f874f : end
Context A configuration: ! To Access context A FWSM# changeto context A FWSM/A# show run
! Firewall is in transparent mode firewall transparent hostname A
enable password 8Ry2YjIyt7RRXU24 encrypted names !
interface Vlan30 nameif outside bridge-group 1 security-level 0
interface Vlan31 nameif inside bridge-group 1 security-level 100
! For management purposes, have an IP address assigned to the BVI interface BVI1 ip address 10.1.1.100 255.255.255.0
passwd 2KFQnbNIdI.2KYOU encrypted
! Access list in this example is not specific, you can use multicast source and
! destination specific access list defined, to be more specific access-list 100 extended permit ip any any access-list 100 extended permit udp any any access-list 101 ethertype permit bpdu
Example 16-3 Configuration of Multicast Through Transparent Firewall in Multiple Context Mode (Continued)
mtu outside 1500 mtu inside 1500 monitor-interface outside monitor-interface inside no asdm history enable arp timeout 14400
access-group 101 in interface outside access-group 100 in interface outside access-group 100 out interface outside access-group 101 in interface inside access-group 100 in interface inside access-group 100 out interface inside route outside 0.0.0.0 0.0.0.0 10.1.1.1 1 telnet 10.1.1.2 255.255.255.255 inside telnet timeout 5 ssh timeout 5 !
class-map inspection_default match default-inspection-traffic
policy-map global_policy class inspection_default inspect dns maximum-length 512 inspect ftp inspect h323 h225 inspect h323 ras inspect rsh inspect smtp inspect sqlnet inspect skinny inspect sunrpc inspect xdmcp inspect sip inspect netbios inspect tftp
service-policy global_policy global Cryptochecksum:ac2c109d3861e051064dbaa9f777dfd7 : end
PFC3bofcat6kB: Router at the outside security domain PFC3bofcat6kB# show run firewall multiple-vlan-interfaces firewall module 4 vlan-group 2 firewall vlan-group 2 30-34
! Enable multicast on the router ip multicast-routing !
vlan 10,20-24,30-31,34
! For testing, you can use igmp join-group to have the Loopback 200 act as a receiver ! for 239.1.1.3. Note that the traffic will be process switched. PIM sparse mode
Example 16-3 Configuration of Multicast Through Transparent Firewall in Multiple Context Mode (Continued)
! should be enabled on the interface. interface Loopback200 ip address 10.1.50.1 255.255.255.255 ip pim sparse-mode ip igmp join-group 239.1.1.3
! Connects to the FWSM outside interface and has pim sparse mode enabled interface Vlan30
ip address 10.1.1.1 255.255.255.0 ip pim sparse-mode
! Configure the RP's IP address. RP propagation method is static ip pim rp-address 1.1.1.1
PFC3bofcat6kB#_
cat6k6a: Router at the inside security domain of the FWSM cat6k6a#show run hostname cat6k6a ! Enable multicast routing ip multicast-routing !
! Configure IP address for the RP (1.1.1.1), located at the inside security domain interface Loopback0 ip address 1.1.1.1 255.255.255.255 ip pim sparse-mode
interface GigabitEthernet1/1 switchport switchport access vlan 31 no ip address
interface FastEthernet2/1 ip address 10.1.3.2 255.255.255.252 ip pim sparse-mode
! Enable PIM on all the interfaces to maintain congruency interface Vlan31 ip address 10.1.1.2 255.255.255.0 ip pim sparse-mode ! Configure RP's IP address ip pim rp-address 1.1.1.1 cat6k6a#
In multiple context mode, transparent firewall is the best way to make the multicast packet pass through the FWSM. No special configuration is required in the FWSM. ACL is configured to allow multicast traffic to pass through the FWSM. In this example, the configuration in Layer 3 routers is simple. The transparent mode fits in an environment where a need exists for multiple context mode and multicast support.
Continue reading here: Option 1 Symmetric Routing Through Firewalls
Was this article helpful?