12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Multicast<br />

Router Dynamic<br />

Overriding the multicast settings on an interface<br />

Multicast (PIM) interface options enable you to set operating parameters for<br />

<strong>FortiGate</strong> interfaces connected to PIM domains. For example, you can enable<br />

dense mode on an interface that is connected to a PIM-enabled network segment.<br />

When sparse mode is enabled, you can adjust the priority number that is used to<br />

advertise Rendezvous Point (RP) and/or Designated Router (DR) candidacy on<br />

the interface.<br />

Figure 162:Multicast interface settings<br />

Multicast destination NAT<br />

Interface<br />

Select the name of the root VDOM <strong>FortiGate</strong> interface to which<br />

these settings apply. The interface must be connected to a PIM<br />

version 2 enabled network segment.<br />

PIM Mode<br />

Select the mode of operation: Sparse Mode or Dense Mode. All<br />

PIM routers connected to the same network segment must be<br />

running the same mode of operation. If you select Sparse Mode,<br />

adjust the remaining options as described below.<br />

DR Priority<br />

Enter the priority number for advertising DR candidacy on the<br />

<strong>FortiGate</strong> interface. The range is from 1 to 4 294 967 295.<br />

This value is <strong>com</strong>pared to the DR interfaces of all other PIM<br />

routers on the same network segment, and the router having the<br />

highest DR priority is selected to be the DR.<br />

RP Candidate Select to enable or disable RP candidacy on the interface.<br />

RP Candidate Priority Enter the priority number for advertising RP candidacy on the<br />

<strong>FortiGate</strong> interface. The range is from 1 to 255.<br />

Multicast destination NAT (DNAT) allows you translate externally received<br />

multicast destination addresses to addresses that conform to an organization's<br />

internal addressing policy.<br />

Using this feature, users do not need to redistribute routes at the translation<br />

boundary into their network infrastructure for Reverse Path Forwarding (RPF) to<br />

work properly, and users can receive identical feeds from two ingress points in the<br />

network and route them independently.<br />

Multicast DNAT is configured in the CLI using the following <strong>com</strong>mand:<br />

config firewall multicast-policy<br />

edit p1<br />

set dnat <br />

set ...<br />

next<br />

end<br />

For more information, see the “firewall” chapter of the <strong>FortiGate</strong> CLI Reference.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

260 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!