SonicWall Multicast Zone.
03/26/2020 37 People found this article helpful 487,742 Views
Description
SonicWall Multicast Zone.
Resolution
Question:
How does the SonicWall Multicast Zone work?
Answer:
The multicast zone is a special zone of SonicWall firewall. Its security type is 'Untrusted' (effectively equivalent to the WAN Zone in terms of trust). It also has very unique characteristics. Firstly, multicast zone can only be a destination zone. The reason for this is because a mulicast address (224.0.0.0 to 239.255.255.255) normally should never be a source address, only a destination address. Secondly, security services are not configurable on the Multicast Zone.
The default rules from other Zones to the Multicast Zone are as follows. From Zone | Source Address | Dest. Address | Service | Action | Description |
Trusted | Any | Any | IGMP (Group) | Allow | Allow IGMP queries, reports, and other messages from any source in this Zone. |
Trusted | Any | Any or Specific | Any | Allow | Allow Multicast data stream from any source in this Zone. |
Encrypted | Any | Any | IGMP (Group) | Allow | Allow IGMP queries, reports, and other messages from any source in this Zone. |
Encrypted | Any | Any or Specific | Any | Allow | Allow Multicast data stream from any source in this Zone. |
Untrusted | Any | Any | IGMP Membership | Allow | Allow only IGMP membership query messages from this Zone. |
Untrusted | Any | Any | IGMP (Group) | Deny | Deny IGMP queries, reports, and other messages from any source in this Zone. |
Untrusted | Any | Any or Specific | Any | Deny | Deny Multicast data stream from any source in this Zone. |
Public | Any | Any | IGMP Membership | Allow | Allow only IGMP membership query messages from this Zone. |
Public | Any | Any | IGMP (Group) | Deny | Deny IGMP queries, reports, and other messages from any source in this Zone. |
Public | Any | Any or Specific | Any | Allow | Allow Multicast data stream from any source in this Zone. |
Wireless | Any | Any | IGMP Membership | Allow | Allow only IGMP membership query messages from this Zone. |
Wireless | Any | Any | IGMP (Group) | Deny | Deny IGMP queries, reports, and other messages from any source in this Zone. |
Wireless | Any | Any or Specific | Any | Deny | Deny Multicast data stream from any source in this Zone. |
Note: 1. These defaults can be changed as needed. For example, the "Allow Multicast data stream" rules can be made more specific by creating a service (e.g. UDP port 8898) for your specific multicast data.
2. Disabling Multicast on the 'Firewall > Multicast' page will delete all default Multicast rules, even those that have been modified from their default settings.
3. User created Multicast rules will be hidden from the 'Firewall >Access Rules' page if Mutlicast is disabled, but they will not be deleted. Related Articles
Categories
Was This Article Helpful?
YESNO