Troubleshoot multicast routing over an SVTI tunnel
Provides troubleshooting guidance for multicast routing issues over SVTI tunnels in Secure Firewall environments, including symptoms, causes, and resolution steps.
Troubleshoot multicast traffic issues
-
Symptoms:
-
Unicast connectivity across VTI tunnel works fine.
-
Multicast stream never starts even when the receiver device sends an IGMP join.
-
LHR does not receive multicast traffic even though the source device is active.
Possible cause: Reverse Path Forwarding (RPF) check failed because the return path to the source did not point to the VTI tunnel.
Resolution:
-
Perform a ping between tunnel endpoints to ensure basic connectivity and if SVTI is up.
-
Run show pim interface to verify if PIM is enabled in the SVTI.
-
Run show pim neighbor to ensure PIM adjacency is established across the tunnel.
-
Run show mroute to verify the incoming and outgoing interfaces.
-
Run show route <source-ip> to ensure that the RPF path points to the VTI.
-
Use clear commands
-
clear pim topology and clear igmp group: Resets the multicast state for any recovery.
-
clear mroute <multicast_ipaddress>: Clears entries for a specific multicast group.
Use debug commands
Note | Use debug commands only during low network traffic periods and for specific troubleshooting or TAC sessions, as they increase CPU usage. |
-
debug pim: Debugs PIM configuration and events.
-
debug igmp: Debugs IGMP configuration and events.
-
debug mfib: Debugs MFIB configuration and events.