Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multicast

    Scheduled Pinned Locked Moved NAT
    34 Posts 5 Posters 7.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by johnpoz

      Maybe if he sends some traffic to this device at 192.168.0.10, it multicasts the traffic that is sends on?

      @hsv really going to need a bit more info.. What is this device, or what software are you running on 192.168.0.10.. What sort of traffic is it?

      If you can not arp from pfsense, for this 192.168.0.10 address - then no your never going to be able to send it traffic.. To do anything with..

      From the out side I have 4 NAT rules to direct the trafic to 192.168.0.10

      Can you post those, so we can maybe glean some insight into what your trying to do exactly.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

      1 Reply Last reply Reply Quote 0
      • DaddyGoD
        DaddyGo
        last edited by

        @hsv said in Multicast:

        loadbalancer (MS)

        it could be something like that if we go after it better:

        https://docs.microsoft.com/en-us/windows-server/networking/technologies/network-load-balancing

        73d9b899-2ed2-4e76-bdca-7c466be69cfb-image.png

        e6cc0fa2-20dd-4a70-9fc1-4ccc2ff74669-image.png

        Cats bury it so they can't see it!
        (You know what I mean if you have a cat)

        1 Reply Last reply Reply Quote 0
        • H
          hsv
          last edited by

          Hi
          Yes the diagram is correct, but I only have 4 WAN, but I guess the problem will be the same.

          And yes pfsense can not resolve it to a MAC adresse.
          Why I do not know.

          I have no problem on a windows client make arp -a and see the mac address to be:
          03-bf-c0-a8-0b-e1

          Regards
          Henning

          DaddyGoD 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by johnpoz

            If pfsense can not arp then you have a connectivity issue..

            How do you have this actually connected to pfsense.

            If what your trying to do is the above, that has ZERO to do with multicast and pfsense.. What you loadbalancer does with unicast your traffic coming from the internet has nothing to do with pfsense talking to the LB..

            You need to figure out what the problem is with basic connectivity from pfsense 192.168.0.1 and this IP at 192.168.0.10 which is your LB.. If pfsense can not even arp for that IP then they are not actually connected via the same L2 network, ie switch cable plugged into pfsense port?

            How is 192.168.0.10 connected to this 192.168.0 network?

            Now if this 192.168.0.10 is some sort of VIP? If pfsense can not arp for that IP, then it is impossible for it to send it traffic If your saying its just not arping - then setup a static arp entry for it on pfsense.. this 03-bf-c0-a8-0b-e1 mac

            But there should be unicast mac for your cluster.. Why can you not use that?

            Some details of how you have everything connected will help us help you.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • H
              hsv
              last edited by

              Hi

              How do I add a static arp to the arp list?

              The setup is 3 virtual host where pfsense and a test windows server is placed on ESXi0 on ESXi1 and 2 the mail setup are running.
              From the test server I can ping and resolve the LB but on Pfsense I cannot.

              So the network is working. I have for testing setup the Windows Test server with VLAN also so looked from VMware the 2 server are setup the same way.

              Regards
              Henning

              1 Reply Last reply Reply Quote 0
              • DaddyGoD
                DaddyGo @hsv
                last edited by

                @hsv said in Multicast:

                es the diagram is correct,

                I used to deal with MS load balancer (especially multicast), long time ago...
                (we always use a hardware base load balancer, HA proxy )

                but I am interested in this topic... ๐Ÿ˜‰

                no this will not work under pfSense.... (100%)
                bring the theme under linux...

                https://github.com/google/seesaw

                Cats bury it so they can't see it!
                (You know what I mean if you have a cat)

                1 Reply Last reply Reply Quote 0
                • H
                  hsv
                  last edited by

                  Hi
                  I have also come to the same conclusion that multicast and Pfsense is not the way to go, and start to setup HAProxy.

                  But thanks for you suggestions.

                  Regards
                  Henning

                  DaddyGoD 1 Reply Last reply Reply Quote 0
                  • DaddyGoD
                    DaddyGo @hsv
                    last edited by DaddyGo

                    @hsv said in Multicast:

                    Pfsense is not the way to go, and start to setup HAProxy.

                    it took me a long time to understand what do you mean by original post, I apologize ๐Ÿ˜‰
                    just the way, it works...HA proxy ๐Ÿ‘ โœ‹

                    +++edit:
                    @hsv "but I only have 4 WAN, but I guess the problem will be the same."

                    this does not matter

                    Cats bury it so they can't see it!
                    (You know what I mean if you have a cat)

                    1 Reply Last reply Reply Quote 0
                    • n3xus_x3N
                      n3xus_x3 @DaddyGo
                      last edited by

                      @daddygo do you have any tutorial on how I can configure Multicast? I have CISCO SG300 with 2 Vlan
                      thanks

                      L DaddyGoD 2 Replies Last reply Reply Quote 0
                      • L
                        louis2 @n3xus_x3
                        last edited by

                        @n3xus_x3 Note that

                        • if source and destination is in the same vlan/subnet, it simply works. In case you have a bigger subnet and advanced switches you could/should use IGMP Snooping to prevent unnecessary traffic
                        • is your multicast source is in a different vlan/subnet, than:
                        • you need an application which forward the multicast messages between the involved vlan's. That is also where the problem is, since neither the actual IMGP-proxy nor the Netgate provided PIMD-version2 works!
                        • assuming you manage to get a working multicast deamon, you should configure pfSense to pass the related unicast traffic between the involved VLAN's

                        Personally I have multicast working between VLAN's based on an upcomming beta PIMD-version which I did compile myself (Trogobit (https://github.com/troglobit/pimd). So not so easy at all. I hope there will be a released and Netgate supported version in the future.

                        For info and in case you have the knowledge and are very brave, sources are on Trogobit (https://github.com/troglobit/pimd).

                        • Troglobit is working on an improved PIMD-version at the moment. It is beta and not supported by Netgate or Trogobit (not for FreeBSD), however in opposite to the actual pfSence IMGP-proxy and PIMD-version, it does work!
                        • To make it work you need some courage, knowledge, pfSence 2.5 and a FreeBSD development machine. If that is present, you can download the pimd source from github compile it and install it on your pfSense system from the commandline.
                        • To make it even more complex, .... the pfSense pimd application has two components beeing: the pfSense PIMD control/GUI- application and PIMD it-self. You also have to make some small changes to that pfSense PIMD control/GUI.
                        • Because it is still early beta!! and I do want to interfere with Troglobit or Netgate, I am >not< going to release my personal pimd-package in this stage. So for now you are on own.

                        My advice: unless someone has an alternative solution, I can only advice to wait or to place source and destination in the same vlan.

                        Louis

                        n3xus_x3N 1 Reply Last reply Reply Quote 1
                        • n3xus_x3N
                          n3xus_x3 @louis2
                          last edited by n3xus_x3

                          @louis2 Hi Louis2
                          thank you for the explanation . sorry but i'm slightly confused , I explain what I want to do

                          My pfsense configuration

                          Vlan50 192.168.50.0/24 (WiFi devices)
                          Vlan60 192.168.60.0/24 (CCTV)
                          LAN 192.168.1.0/24 ( IPTV , Emby)
                          LAN2 192.168.10.0/24 (wired systems)
                          DMZ 10.10.50.0/24

                          Currently only some devices that are in VLAN50 , have access to some IP addresses that are on the network VLAN60 and LAN

                          My question is , do I need to configure pFsense and the switch (Cisco SG300) for Multicast to work properly? i want multicast between VLAN50 , VLAN60 , LAN .

                          I apologize if I have been confused
                          Thanks
                          Mark

                          L 1 Reply Last reply Reply Quote 0
                          • L
                            louis2 @n3xus_x3
                            last edited by

                            @n3xus_x3

                            Since source and destination are in different VLAN's/subnets, without additional measures the communication will never work!

                            The source generates "hello I am a source" messages and distribute those in its own subnet/vlan. Those messages will never reach the client in the other subnet/vlan. So the client will not be aware of the source.

                            To change that you need an application which bridge the vlan's in regard to the multicast messages. And at this moment in time there is no working app available for pfSence to provide that function.

                            The only option I am aware of is the beta pimd version. But I would not advice to try that in your case.

                            Sincerely,

                            Louis

                            n3xus_x3N 1 Reply Last reply Reply Quote 1
                            • n3xus_x3N
                              n3xus_x3 @louis2
                              last edited by

                              @louis2
                              You have been very clear, Thanks for your help. I will wait for the Trogobit project to be ready

                              cheers
                              Mark

                              1 Reply Last reply Reply Quote 0
                              • DaddyGoD
                                DaddyGo @n3xus_x3
                                last edited by

                                @n3xus_x3 said in Multicast:

                                do you have any tutorial on how I can configure Multicast? I have CISCO SG300

                                Hi,

                                can also be solved on SG300, but MULTICAST handles it a little differently on it, I suggest the SG350 series it is a little more painless

                                BTW:
                                otherwise what are you using multicast for

                                Cats bury it so they can't see it!
                                (You know what I mean if you have a cat)

                                n3xus_x3N 1 Reply Last reply Reply Quote 0
                                • n3xus_x3N
                                  n3xus_x3 @DaddyGo
                                  last edited by

                                  @daddygo
                                  Hello , I use multicast for IPTV reception, and for Emby Server for local and remote transmission (VPN) of video content .
                                  i try to find some tutorials for my SG300

                                  DaddyGoD 1 Reply Last reply Reply Quote 0
                                  • DaddyGoD
                                    DaddyGo @n3xus_x3
                                    last edited by

                                    @n3xus_x3 said in Multicast:

                                    I use multicast for IPTV reception

                                    there are still 2 - 3 pieces of SG300-10 in our (AoIP system + multicast) system,... yet

                                    how can I help?
                                    describe it exactly

                                    BTW:
                                    IPTV in this regard, is deadly, ISP dependent...

                                    Cats bury it so they can't see it!
                                    (You know what I mean if you have a cat)

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.