<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multicast with Chromecasts confusion in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multicast-with-chromecasts-confusion/m-p/286791#M76649</link>
    <description>&lt;P&gt;Sorry it is over a year, but I think this is still a relevant problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wasn't able to get this working with the PAN FW, but a solutions (or maybe more a workaround) is to use an Avahi Reflecter.&lt;/P&gt;&lt;P&gt;You basically setup a VM with multiple interfaces, depending on where you want your traffic to go.&lt;/P&gt;&lt;P&gt;This VM basically receives the mDNS traffic and will repeat it over the other networks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure to tighten the VM to only accept mDNS traffic, so it won't become a rogue router.&lt;/P&gt;&lt;P&gt;Also if you have Apple devices, make sure to turn of caching.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a lot of information to be found about this on the Internet, i.e.:&amp;nbsp;&lt;A href="http://chrisreinking.com/need-bonjour-across-vlans-set-up-an-avahi-gateway/" target="_blank"&gt;http://chrisreinking.com/need-bonjour-across-vlans-set-up-an-avahi-gateway/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Sep 2019 17:07:03 GMT</pubDate>
    <dc:creator>robmaas</dc:creator>
    <dc:date>2019-09-05T17:07:03Z</dc:date>
    <item>
      <title>Multicast with Chromecasts confusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multicast-with-chromecasts-confusion/m-p/223212#M64162</link>
      <description>&lt;P&gt;Background:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a trust zone on ethernet1/2 192..168.1.0/24 and an iot zone on ehternet1/4 10.10.10.0/24 and I want to be able to cast things from endpoints (mobile phones and laptops) to the chromecasts on the iot zone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seems like multicast (aka mDNS) is the trick however I am not sure I am going the right direction or if this is even possible usng the PA. I am seeing the multicast traffic and it is being allowed but the chromecasts are not showing up unless you are on the same subnet/zone as them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is my current multicast setup, hoping someone has had some luck with this and can point me in the right direction or spot the missing piece of this puzzle:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="multicast1.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16005i0E984AAB2A510215/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="multicast1.jpg" alt="multicast1.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="multicast2.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16006i9396AD2B26233620/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="multicast2.jpg" alt="multicast2.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Anything not pictured is just left as defaults...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Security policy:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="secpol.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16007i8458DC8529004478/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="secpol.jpg" alt="secpol.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am seeing traffic hit the policy,&amp;nbsp;but I am not seeing the chromecast devices when trying to cast from a device in the trust zone. I am either missing something I am overlooking or this is not going to work but I do see some results on google seraches from people getting this to work with other network equipment (pfsense, cisco, juniper, etc)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;TIA!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 17:38:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multicast-with-chromecasts-confusion/m-p/223212#M64162</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2021-03-03T17:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Multicast with Chromecasts confusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multicast-with-chromecasts-confusion/m-p/286791#M76649</link>
      <description>&lt;P&gt;Sorry it is over a year, but I think this is still a relevant problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wasn't able to get this working with the PAN FW, but a solutions (or maybe more a workaround) is to use an Avahi Reflecter.&lt;/P&gt;&lt;P&gt;You basically setup a VM with multiple interfaces, depending on where you want your traffic to go.&lt;/P&gt;&lt;P&gt;This VM basically receives the mDNS traffic and will repeat it over the other networks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure to tighten the VM to only accept mDNS traffic, so it won't become a rogue router.&lt;/P&gt;&lt;P&gt;Also if you have Apple devices, make sure to turn of caching.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a lot of information to be found about this on the Internet, i.e.:&amp;nbsp;&lt;A href="http://chrisreinking.com/need-bonjour-across-vlans-set-up-an-avahi-gateway/" target="_blank"&gt;http://chrisreinking.com/need-bonjour-across-vlans-set-up-an-avahi-gateway/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 17:07:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multicast-with-chromecasts-confusion/m-p/286791#M76649</guid>
      <dc:creator>robmaas</dc:creator>
      <dc:date>2019-09-05T17:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: Multicast with Chromecasts confusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multicast-with-chromecasts-confusion/m-p/286825#M76654</link>
      <description>&lt;P&gt;If mDNS is involved then the multicast group should be 224.0.0.251, destination port 5353. Another point&amp;nbsp;&lt;SPAN&gt;224.0.0.0/24 is reserved for link-local&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;multicast (e.g OSPF multicast) and cannot be routed between subnets, hence PIM option wont work. Reflector or proxy option should work for you but l haven't done it with Palo&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 21:01:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multicast-with-chromecasts-confusion/m-p/286825#M76654</guid>
      <dc:creator>myky</dc:creator>
      <dc:date>2019-09-05T21:01:50Z</dc:date>
    </item>
  </channel>
</rss>

