PA multicast with Cisco

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PA multicast with Cisco

L0 Member

Hello,

We are having a multicast problem with our PA.  It is an informacast application that needs to use multicast. Our server is in the data center on Nexus.  

We saw that Multicast FIB on the Palo Alto FW was not being created.

We saw that multicast packets coming from the source to multicast group were not being marked with an egress interface, this probably is because we do not have the S,G FIB entry to determine the outgoing interface the FW must sent these packets

 

A Device will create S,G state once a PIM S,G join is received.

We did a packet capture on the PA Firewall and on the cisco Nexus7700 C7706 device, which is outside the PA.  

We see the pim join arrive to the PALO alto on the capture we took on the PA.

We see that  for Group: mcast group address a Join to source (S) was done to source addres. This PIM join is intended for upstream-neighbor  which is the ip of the PA FW on the outside vlan.

We also see this packet arrived on the correct vlan, with a valid neighbor on the PA.

 

Is there a reason why is the device not creating mcast FIB entry once the PIM join is received?

1 accepted solution

Accepted Solutions

L0 Member

There is a reverse path check done on the address for the rendevous point. If this is asymetric, pim wont work.

View solution in original post

1 REPLY 1

L0 Member

There is a reverse path check done on the address for the rendevous point. If this is asymetric, pim wont work.

  • 1 accepted solution
  • 2462 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!