Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    23.01.b.20230106.0600 IGMP proxy stops TV stream

    Scheduled Pinned Locked Moved General pfSense Questions
    139 Posts 18 Posters 60.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      To do that you would need to reinstall back to 22.05 where the igmpproxy pkg was 0.3.1. There's no easy way to just downgrade the pkg by itself.

      M 1 Reply Last reply Reply Quote 0
      • H
        haraldinho @michiel
        last edited by

        Hi @michiel , I am also using a Netgate (6100) together with KPN IPTV. I assume that the problem that you face is that when you pause the recorded stream for a while, it won't properly restart. The box controls show the stream is running again, but the image hangs. Is this right?

        I have this issue too, but I can assure you it is not linked to the latest version of igmpproxy. It has always been there in my setup, also in previous releases of pfSense. If you go back to igmpproxy-0.3_1.pkg you will get other, much worse issues, so I do not recommend that.

        If I remember correctly from when I was digging into the pausing issue when I started using KPN IPTV, it is also reported by 'regular' users of the KPN supplied modem/router.

        What did you tweak to get pausing live TV working? I am curious. That worked for me straight away.

        The pausing issue is quite annoying, would love to get rid of it.

        M 1 Reply Last reply Reply Quote 0
        • M
          michiel @stephenw10
          last edited by

          @stephenw10 OK, thank you!

          M 1 Reply Last reply Reply Quote 0
          • M
            michiel @haraldinho
            last edited by

            @haraldinho Pausing live TV started working after several reboots. That was all :). I followed the instruction of Github "Eigen router":

            https://github.com/Eigenrouter/eigenrouter/blob/main/guides/pfsense/KPN/pfSense-with-vlan.md

            I recently learned that 0.0.0.0/0 for upstream IGMP suffices; I changed that after live pausing was working. Pausing recorded programs still not working. The player counts the time backwards, picture freezes, and that's it!

            I guess I have to live with it?

            1 Reply Last reply Reply Quote 0
            • M
              michiel @michiel
              last edited by

              @michiel But please see comment of Haraldinho... seems that there is still a bug with pfsenseplus on Netgate and pausing recorded programs. I just got confirmation of other KPN customers - with self build routers with pfsense - they do not have that problem. So, can you please look into this and come up with a solution?

              T H 2 Replies Last reply Reply Quote 0
              • T
                thebear @michiel
                last edited by

                @michiel there is no bug in the IGMP proxy. That proces is just stupid forwarding MC traffic.

                Do you provide KPN DNS servers to your STB?

                It could be the cause we are missing some configuration parts? The TV config is somehow reversed engineered over the years.

                I’m also a KPN customer could you explain me in Dutch what you experience? I don’t have the recording subscription. Is the behavior different when you use the provider modem? Could you test that for us and report back?

                If I know what you see I can try to rebuild it over here an capture the network traffic.

                VIP5202 or KPN+ STB?

                M 1 Reply Last reply Reply Quote 1
                • M
                  michiel @thebear
                  last edited by

                  @thebear Hi, dank voor je hulp alvast. Ik heb de VIP5202 en heb IPTV opgezet via VLAN. Bij de DHCP settings van de de VLAN heb ik DNS 195.121.1.34 en 195.121.1.66 opgenomen.

                  De Fritzbox heb ik losgekoppeld, het probleem had ik daarmee niet.

                  T 1 Reply Last reply Reply Quote 0
                  • T
                    thebear @michiel
                    last edited by

                    @michiel and only with recorded programs? Not the paused programs?

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      michiel @thebear
                      last edited by

                      @thebear Ja, dat klopt. In eerste instantie ook met live TV, maar nu alleen met opgenomen programma's... Kan ik een log raadplegen en hier posten?

                      T 1 Reply Last reply Reply Quote 0
                      • T
                        thebear @michiel
                        last edited by

                        @michiel nee dat is te complex als je niet zelf de TV beidend. Ik wil wel 1 poging doen, dan moet je een packetcapture maken op de VLAN interface waar je TV op kijkt. Full aanvinken en Count op 0 en dan de juiste TV interface selecteren.

                        Daarna kan je die file delen met mij, niet te lang wachten met zappen want het wordt dan een (te) groot bestand.

                        Net getest en als ik live tv pauzeer dan druk ik op play, en dan start hij na een seconden of 6 foutloos.

                        Je kan ook nog in je firewall logs kijken of daar iets wordt geblokkeerd vanuit de source interface van je TV interface.

                        1 Reply Last reply Reply Quote 0
                        • H
                          haraldinho @michiel
                          last edited by haraldinho

                          @michiel I dove into the issue and I think I might have found a solution.

                          0c58ca29-9607-40de-b40f-27ce785a3bf9-image.png

                          These are my adjusted mappings under NAT --> Outbound based on the blogpost I found from the travelling tech guy, where his NAT rules were different than mine.

                          https://travellingtechguy.blog/using-your-own-pfsense-router-with-kpn-fiber-and-kpn-itv/

                          Initially I had only the bottom mapping. I disabled it, and replaced them with the three topmost rules based on the blog post. Until now this seems to have fixed the issue for me, but I need some more testing. Can't do too much testing now as the Misses is also watching tv with me 😉 .

                          Obviously you should replace 192.168.70.0/24 with your specific subnet.

                          T M 2 Replies Last reply Reply Quote 0
                          • T
                            thebear @haraldinho
                            last edited by

                            @haraldinho indeed the NAT is wrong in the first guide, that's what I mentioned with reversed engineered...everyone is making a guide for the clickbait with good intentions.

                            Still the second guide is not 100% correct, in that guide are the commonly used proxy upstream address used in the NAT config. The correct configuration for the proxy is the one from the first guide (in fact 0.0.0.0/0 splitter over two subnets).

                            The correct NAT rule is the one below, you only need to NAT the traffic to the route you receive from the DHCP advertisement from KPN. And that's a single subnet.

                            With these both configuration parts you are more persistent to future changes from the ISP side.

                            bc5bfe43-2412-473f-bdc0-a01a1d076b6c-image.png

                            75a158a7-4973-4e1a-b3dd-8de269af54a4-image.png

                            1 Reply Last reply Reply Quote 0
                            • M
                              michiel @haraldinho
                              last edited by michiel

                              @haraldinho Thank you for diving into this. I added these rules to NAT --> Outbound, but still have the same issue. So I tried the option of @thebear but also that is not working. Live TV pauses and restarts. Recorded programs don't.

                              D9136E8C-87AF-4666-9322-0A5BF277D198_4_5005_c.jpeg

                              769D32B7-CC8B-4837-891E-2340FC3FC843_4_5005_c.jpeg

                              I do see these entries in my logging....

                              F30354E1-8591-406B-9B21-35D40B7A044F.jpeg

                              H 1 Reply Last reply Reply Quote 0
                              • H
                                haraldinho @michiel
                                last edited by

                                @michiel I celebrated too soon. After some testing this morning, the problem of resuming recordings appears to still exist. I also applied the settings from @thebear and still the problem exists... Now I'm quite determined to get this solved 😠

                                H 1 Reply Last reply Reply Quote 0
                                • H
                                  haraldinho @haraldinho
                                  last edited by

                                  Now what I did not do yesterday evening because the family was watching tv, I did do this morning: reboot the firewall. But first I changed my settings to those of @thebear from his previous post. And guess what: it appears to work now. I did three tests: pause 5 seconds, pause 5 minutes and pause for 10 minutes. All successfully restarted the recorded stream. @michiel did you do a reboot after changing your settings and if not, can you try that?

                                  M 1 Reply Last reply Reply Quote 0
                                  • H
                                    haraldinho
                                    last edited by haraldinho

                                    Found some more evidence of what went wrong in the firewall logs:
                                    f474eb5e-809f-4e97-bb38-164e4bd2007b-image.png

                                    I rebooted my device around 11:21. Before the reboot, you see that some address in the 213.75.112.x range is getting blocked. After the reboot, this block does not appear anymore. I was doing my testing after this period.

                                    Unfortunately and in all honesty, I don't fully grasp all the settings that are required for IPTV, but it appears that the changes I made based on @thebear's settings made a change after the reboot.

                                    I wonder though what the https request are that the box is trying to do and that get blocked... What functionality does this block? Anybody any clue?

                                    H 1 Reply Last reply Reply Quote 0
                                    • H
                                      haraldinho @haraldinho
                                      last edited by haraldinho

                                      Ok, pasting 45.57.40.1:443 into a browser leads to a site with a blocked Netflix certificate. So that gives some idea into what the box tries to do. The other IP, 52.19.109.21:443 does not reveal any information as far as I can see.

                                      T 1 Reply Last reply Reply Quote 0
                                      • M
                                        michiel @haraldinho
                                        last edited by michiel

                                        @haraldinho I did several reboots. I noticed earlier that reboots help in applying the firewall rules. I think (not sure) that is has to do with the stating tables?
                                        However, reboot did not solve it. I just applied the exact same settings as @thebear and will reboot later this day. Kids are online now :).

                                        You did change the IP addresses to your own VLAN? So where the bear says 127*, you are using 192* in outbound rules and downstream proxy?

                                        T 2 Replies Last reply Reply Quote 0
                                        • T
                                          thebear @michiel
                                          last edited by

                                          Can you guys build the firewall rules like this:

                                          IPTV_WAN
                                          f466c9d3-dd92-429a-9c7a-2e086c9fcc16-image.png

                                          IPTV_LAN
                                          2922b990-f743-440e-9643-8e22a94a8748-image.png

                                          The screenshot showing that regular internet traffic is blocked, so also your DNS and TCP traffic which is needed to communicate with the streaming platform.

                                          M H 2 Replies Last reply Reply Quote 0
                                          • T
                                            thebear @michiel
                                            last edited by

                                            @michiel said in 23.01.b.20230106.0600 IGMP proxy stops TV stream:

                                            @haraldinho I did several reboots. I noticed earlier that reboots help in applying the firewall rules. I think (not sure) that is has to do with the stating tables?

                                            You can press the X next to a FW rule, to release the current state and rebuild the traffic without a reboot.

                                            1 Reply Last reply Reply Quote 2
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.