IGMP snooping when Multicast filtering enabled?

Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions
Author Message
MonarchX
DD-WRT User


Joined: 26 Sep 2009
Posts: 119

PostPosted: Thu Nov 19, 2020 16:47    Post subject: IGMP snooping when Multicast filtering enabled? Reply with quote
Does it make sense to enable IGMP Snooping on the router when Multicast filtering is also enabled on the same router?
Sponsor
MonarchX
DD-WRT User


Joined: 26 Sep 2009
Posts: 119

PostPosted: Sat Nov 21, 2020 23:53    Post subject: Reply with quote
Bump...
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6870
Location: Romerike, Norway

PostPosted: Sun Nov 22, 2020 9:46    Post subject: Reply with quote
Do you have an IPTV server streaming on another interface? Untick when the WAN is the source interface.
MonarchX
DD-WRT User


Joined: 26 Sep 2009
Posts: 119

PostPosted: Sun Nov 22, 2020 11:28    Post subject: Reply with quote
No. I want DD-WRT to either filter/drop/block or functionally-break all inbound, outbound, WAN and LAN multicast packets or at least reduce all inbound, outbound, WAN and LAN multicast traffic.

In DD-WRT (v44809 3.X with Kernel 4.4) I enabled:
- Shortcut Forwarding Engine
- Multicast Filtering (WAN)
- IGMP Snooping (VLAN1)
- PBR (LAN Interface) Catch All P2P Protocols
- PBR (LAN Interface) to filter/drop/block ICMP, all TCP and UDP ports (except for DNS, NTP, HTTP, HTTPS, required VPN bootstrap, and VPN ports).

In PC OS I set software firewall to block:
- All inbound traffic
- All outbound ICMP, IGMP, TCP and UDP ports (except for DNS, NTP, HTTP, HTTPS, required VPN bootstrap, and VPN ports)

From what I understand, my software firewall prevent inbound and outbound multicast packets from reaching LAN, and DD-WRT settings prevent inbound and outbound multicast traffic from reaching WAN, but I am confused about IGMP Snooping for VLAN1. Does it snoop on IGMP traffic coming from PC to LAN or does it snoop on IGMP traffic coming from WAN to LAN?
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6870
Location: Romerike, Norway

PostPosted: Sun Nov 22, 2020 15:20    Post subject: Reply with quote
Your PC or IPTV box sends a request to join the Multicast Group. Igmpproxy then only forwards the multicast to those interfaces that have nodes that have requested it. When the last client leaves the group, forward is stopped on that interface.
MonarchX
DD-WRT User


Joined: 26 Sep 2009
Posts: 119

PostPosted: Sun Nov 22, 2020 15:33    Post subject: Reply with quote
That did not answer my question though... IGMP Proxy is not the same as IGMP Snooping... Both of them are supposed to reduce IGMP traffic and allow it to communicate only with devices that use IGMP multicast signals.

It is possible that "Filter Multicast" is enough to prevent inbound multicast packets to DD-WRT router. If that is so, then what happens if both "Filter Multicast" and "IGMP Snooping" are enabled?
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6870
Location: Romerike, Norway

PostPosted: Sun Nov 22, 2020 17:35    Post subject: Reply with quote
IGMP Proxy is the process that do the IGMP Snooping.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum