Guidelines for multicast routing

System requirements

Item

Description

Context mode

Supported in single context mode.

Firewall mode

Supported only in routed firewall mode. Transparent firewall mode is not supported.

IPv6

IPv6 is not supported.

Multicast group

The range of addresses from 224.0.0.0 to 224.0.0.255 is reserved for routing protocols and other topology discovery or maintenance protocols, such as gateway discovery and group membership reporting. Internet multicast routing from the 224.0.0/24 address range is not supported. When multicast routing is enabled for reserved addresses, an IGMP group is not created.

Clustering

In clustering, for IGMP and PIM, this feature is only supported on the primary unit.

Access control configuration

You must configure an access control or prefilter rule on the inbound security zone to allow traffic to the multicast host, such as 224.1.2.3. However, you cannot specify a destination security zone for the rule, or it cannot be applied to multicast connections during initial connection validation.

Interface and protocol management

Ensure proper configuration management when working with PIM-enabled interfaces and multicast routing protocols.

  • You cannot disable an interface with PIM configured on it. If you have configured PIM on the interface (see Configure PIM protocol), disabling the multicast routing and PIM does not remove the PIM configuration. You must remove (delete) the PIM configuration to disable the interface.

  • Multicast routing is not supported in ECMP.

  • Do not configure Firewall Threat Defense to simultaneously be a Rendezvous Point (RP) and a First Hop Router.

  • The HSRP standby IP address does not participate in PIM neighborship. If the RP router IP is routed through the HSRP standby IP address, multicast routing does not work in Firewall Threat Defense. To ensure multicast traffic passes through successfully, configure the route for the RP address to use an interface IP address rather than the HSRP standby IP address.

  • For a device using virtual routing, you can configure multicast only for its global virtual router and not for its user-defined virtual router.