<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multicast issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multicast-issue/m-p/421712#M93990</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="multicast.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35211i2F2AF4F90E50A719/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="multicast.png" alt="multicast.png" /&gt;&lt;/span&gt;AE1.1 is the static RP(10.1.1.1/24) and ae1.1 has 10.1.1.1/24 assigned to it. All the 10.0.0.0/8 routes are served by this sub interface and RP configured on switch is 10.1.1.1&lt;/P&gt;&lt;P&gt;AE1.2 hosts the mcast server and AE1.2 has gateway of 172.16.0.1/24.&lt;/P&gt;&lt;P&gt;Multicast clients in 10.5.0.0/24 are able to join MCAST streamed on 172.16.0.20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AE1.3 connects to a separate switch vrf routing table and RP configured on switch for this vrf is 10.1.1.1. AE1.3 has 192.168.0.1/24 and server 192.168.0.0/16. This switch vrf does not see the mcast group served by 172.16.0.20 although it is a PIM neighbor in PA. None of the clients then cannot get access to stream hosted on 172.16.0.20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i add multiple remote RP's instead only 1 gets chosen. Since IGMP messages are sent to only 1 RP this is out of question.&lt;/P&gt;&lt;P&gt;Zones for which firewall is directly itself is the gateway multicast works. There are other interfaces AE1.4,5,6 and multicast works in all of them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the real problem is clients are not able to join from zones for which switch has to join PA-RP from another zone, although PA shows them as neighbors. And I don't see this as a limitation of VRF's on cisco switch as both vrf's become PIM neighbor on their respective interfaces towards PA. &lt;STRONG&gt;Cisco switch in the xyz VRF does not receive information from PA about available sources.&lt;/STRONG&gt;&amp;nbsp;Although is see in the xyz vrf clients wanting to joint the group which works well in ABC vrf.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know if this can be solved by multiple virtual routers and if that is even supported, and i even tried to test this but was not successful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA&lt;/P&gt;&lt;P&gt;------------------------------&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;interface address secondary address up time expiry time generation id dr priority&lt;BR /&gt;--------- ------- ----------------- ------- ----------- ------------- -----------&lt;BR /&gt;ae2.56 10.1.1.20 0.0.0.0 5827.95 90.49 3611216514 1&lt;BR /&gt;ae2.6 192.168.1.4 0.0.0.0 5800.72 91.54 2738550118 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(*, G):&lt;/P&gt;&lt;P&gt;group RP up time upstream join st upstream join timer RPF interface RPF next hop&lt;BR /&gt;----- -- ------- ---------------- ------------------- ------------- ------------&lt;BR /&gt;239.255.100.101 10.1.1.1 4792.17 Joined 0.00 0 0.0.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;===============================&lt;/P&gt;&lt;P&gt;VRF ABC&lt;/P&gt;&lt;P&gt;--------------------&lt;/P&gt;&lt;P&gt;(*, 239.255.100.101), 1d02h/00:02:35, RP 10.1.1.1, flags: S&lt;BR /&gt;Incoming interface: Vlan6, RPF nbr 10.1.6.10&lt;BR /&gt;Outgoing interface list:&lt;BR /&gt;Vlan607, Forward/Sparse, 01:18:00/00:02:35&lt;/P&gt;&lt;P&gt;(172.16.0.20, 239.255.100.101), 00:02:19/00:00:40, flags: T&lt;BR /&gt;Incoming interface: Vlan6, RPF nbr 10.1.1.1&lt;BR /&gt;Outgoing interface list:&lt;BR /&gt;Vlan607, Forward/Sparse, 00:02:19/00:03:08&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;VRF XYZ&lt;/P&gt;&lt;P&gt;---------------------&lt;BR /&gt;(*, 239.255.255.250), 00:01:38/00:02:51, RP 10.1.1.1, flags: S&lt;BR /&gt;Incoming interface: Null, RPF nbr 0.0.0.0&lt;BR /&gt;Outgoing interface list:&lt;BR /&gt;Vlan256, Forward/Sparse, 00:01:38/00:02:51&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jul 2021 23:01:11 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2021-07-23T23:01:11Z</dc:date>
    <item>
      <title>Multicast issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multicast-issue/m-p/421712#M93990</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="multicast.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35211i2F2AF4F90E50A719/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="multicast.png" alt="multicast.png" /&gt;&lt;/span&gt;AE1.1 is the static RP(10.1.1.1/24) and ae1.1 has 10.1.1.1/24 assigned to it. All the 10.0.0.0/8 routes are served by this sub interface and RP configured on switch is 10.1.1.1&lt;/P&gt;&lt;P&gt;AE1.2 hosts the mcast server and AE1.2 has gateway of 172.16.0.1/24.&lt;/P&gt;&lt;P&gt;Multicast clients in 10.5.0.0/24 are able to join MCAST streamed on 172.16.0.20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AE1.3 connects to a separate switch vrf routing table and RP configured on switch for this vrf is 10.1.1.1. AE1.3 has 192.168.0.1/24 and server 192.168.0.0/16. This switch vrf does not see the mcast group served by 172.16.0.20 although it is a PIM neighbor in PA. None of the clients then cannot get access to stream hosted on 172.16.0.20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i add multiple remote RP's instead only 1 gets chosen. Since IGMP messages are sent to only 1 RP this is out of question.&lt;/P&gt;&lt;P&gt;Zones for which firewall is directly itself is the gateway multicast works. There are other interfaces AE1.4,5,6 and multicast works in all of them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the real problem is clients are not able to join from zones for which switch has to join PA-RP from another zone, although PA shows them as neighbors. And I don't see this as a limitation of VRF's on cisco switch as both vrf's become PIM neighbor on their respective interfaces towards PA. &lt;STRONG&gt;Cisco switch in the xyz VRF does not receive information from PA about available sources.&lt;/STRONG&gt;&amp;nbsp;Although is see in the xyz vrf clients wanting to joint the group which works well in ABC vrf.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know if this can be solved by multiple virtual routers and if that is even supported, and i even tried to test this but was not successful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA&lt;/P&gt;&lt;P&gt;------------------------------&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;interface address secondary address up time expiry time generation id dr priority&lt;BR /&gt;--------- ------- ----------------- ------- ----------- ------------- -----------&lt;BR /&gt;ae2.56 10.1.1.20 0.0.0.0 5827.95 90.49 3611216514 1&lt;BR /&gt;ae2.6 192.168.1.4 0.0.0.0 5800.72 91.54 2738550118 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(*, G):&lt;/P&gt;&lt;P&gt;group RP up time upstream join st upstream join timer RPF interface RPF next hop&lt;BR /&gt;----- -- ------- ---------------- ------------------- ------------- ------------&lt;BR /&gt;239.255.100.101 10.1.1.1 4792.17 Joined 0.00 0 0.0.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;===============================&lt;/P&gt;&lt;P&gt;VRF ABC&lt;/P&gt;&lt;P&gt;--------------------&lt;/P&gt;&lt;P&gt;(*, 239.255.100.101), 1d02h/00:02:35, RP 10.1.1.1, flags: S&lt;BR /&gt;Incoming interface: Vlan6, RPF nbr 10.1.6.10&lt;BR /&gt;Outgoing interface list:&lt;BR /&gt;Vlan607, Forward/Sparse, 01:18:00/00:02:35&lt;/P&gt;&lt;P&gt;(172.16.0.20, 239.255.100.101), 00:02:19/00:00:40, flags: T&lt;BR /&gt;Incoming interface: Vlan6, RPF nbr 10.1.1.1&lt;BR /&gt;Outgoing interface list:&lt;BR /&gt;Vlan607, Forward/Sparse, 00:02:19/00:03:08&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;VRF XYZ&lt;/P&gt;&lt;P&gt;---------------------&lt;BR /&gt;(*, 239.255.255.250), 00:01:38/00:02:51, RP 10.1.1.1, flags: S&lt;BR /&gt;Incoming interface: Null, RPF nbr 0.0.0.0&lt;BR /&gt;Outgoing interface list:&lt;BR /&gt;Vlan256, Forward/Sparse, 00:01:38/00:02:51&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 23:01:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multicast-issue/m-p/421712#M93990</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2021-07-23T23:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: Multicast issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multicast-issue/m-p/422282#M94048</link>
      <description>&lt;P&gt;This was resolved after moving the RP from AE1.1 to AE1.2.&amp;nbsp;Not sue if this is some protocol limitation or firewall/switch issue. In the working solution here all vrf instances on directly connected switch are equal(2 hops) away from RP interface, while they were not when AE1.1 was the RP.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 07:33:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multicast-issue/m-p/422282#M94048</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2021-07-27T07:33:25Z</dc:date>
    </item>
  </channel>
</rss>

