<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mulitcast configuration CP3600 R81 without RP router in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153670#M25813</link>
    <description>&lt;P&gt;Do fw up_execute command on the firewall for src, dst and protocol and see what it shows.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-up_execute.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-up_execute.htm&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 23 Jul 2022 14:27:02 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-07-23T14:27:02Z</dc:date>
    <item>
      <title>Mulitcast configuration CP3600 R81 without RP router</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153626#M25797</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I have a scenario when 2 directly connected PC/Servers to a CP 3600 R81 Security Gateway send &lt;STRONG&gt;multicast traffic&lt;/STRONG&gt; that is supposed to be received on 3rd directly connected server, but to no success.&lt;/P&gt;&lt;P&gt;I have an error log that sais: "IP multicast routing failed (missing OS route)" while Static Multicast Default route is edited so it points to the 3rd server IP.&lt;/P&gt;&lt;P&gt;PIM enabled with IGMP v2 but still no go.&lt;/P&gt;&lt;P&gt;There is no &lt;SPAN&gt;Rendezvous Point (or any other device in between Security Gateway and PC/Servers) - this is testing enviroment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Any help is appreciated.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 11:16:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153626#M25797</guid>
      <dc:creator>Mladen</dc:creator>
      <dc:date>2022-07-22T11:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitcast configuration CP3600 R81 without RP router</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153627#M25798</link>
      <description>&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;Just as I enabled Bootstrap router option with no other configurables, my error changed to&amp;nbsp;&lt;/P&gt;&lt;P&gt;"IP multicast routing failed (too many packets received before route was resolved)".&lt;/P&gt;&lt;P&gt;As mentioned above, multicast route exists as described.&lt;/P&gt;&lt;P&gt;Any help.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 11:52:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153627#M25798</guid>
      <dc:creator>Mladen</dc:creator>
      <dc:date>2022-07-22T11:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitcast configuration CP3600 R81 without RP router</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153628#M25799</link>
      <description>&lt;P&gt;Is PIM enabled on the in &amp;amp; out interface?&lt;/P&gt;
&lt;P&gt;Does the security policy have rules allowing the multicast traffic?&lt;/P&gt;
&lt;P&gt;Refer also&amp;nbsp;&lt;SPAN&gt;sk169612&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 12:08:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153628#M25799</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-22T12:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitcast configuration CP3600 R81 without RP router</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153631#M25800</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;Yes PIM is enabled on all 3 interfaces. Eth1 and 2 are the source interfaces while Eth3 is the OUT interface. All IGMP versions are matching (V2 - no other configurations done here).&lt;/P&gt;&lt;P&gt;As for the rules, it is a testing scenario and the request is such that only one-way multicast traffic is allowed, so rule is in place that allows all interfaces to send to multicast range 224.0.0.0 - 239.255.255.255 (cleanup rule is changed to allow also in this initial phase).&lt;/P&gt;&lt;P&gt;I cant find anywhere a simple setup as mine as an example.&lt;/P&gt;&lt;P&gt;Thank you in advance&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 12:16:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153631#M25800</guid>
      <dc:creator>Mladen</dc:creator>
      <dc:date>2022-07-22T12:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitcast configuration CP3600 R81 without RP router</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153632#M25801</link>
      <description>&lt;P&gt;Also, basic connectivity is working. I can ping each interface.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 12:18:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153632#M25801</guid>
      <dc:creator>Mladen</dc:creator>
      <dc:date>2022-07-22T12:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitcast configuration CP3600 R81 without RP router</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153669#M25812</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;Still no change but one interesting thing, in an output from&amp;nbsp;&lt;EM&gt;fw monitor -e "net(239.0.0.0, 8), accept;"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I get just the 'i' when it come to FW layer, no 'I' 'o' 'O'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;eth1:i[44]: 10.41.8.4 -&amp;gt; 239.0.1.2 (UDP) len=58 id=12938&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;UDP: 59286 -&amp;gt; 20480&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_2] eth1:i[44]: 10.41.8.4 -&amp;gt; 239.0.1.2 (UDP) len=58 id=12941&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;UDP: 59286 -&amp;gt; 20480&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_2] eth1:i[44]: 10.41.8.4 -&amp;gt; 239.0.1.2 (UDP) len=58 id=12944&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;UDP: 59286 -&amp;gt; 20480&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_2] eth1:i[44]: 10.41.8.4 -&amp;gt; 239.0.1.2 (UDP) len=58 id=12948&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;UDP: 59286 -&amp;gt; 20480&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_2] eth1:i[44]: 10.41.8.4 -&amp;gt; 239.0.1.2 (UDP) len=58 id=12951&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;UDP: 59286 -&amp;gt; 20480&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_0] eth3:i[28]: 10.10.101.2 -&amp;gt; 239.255.255.250 (2) len=28 id=13778&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_0] eth3:I[28]: 10.10.101.2 -&amp;gt; 239.255.255.250 (2) len=28 id=13778&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_2] eth1:i[44]: 10.41.8.4 -&amp;gt; 239.0.1.2 (UDP) len=58 id=12954&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;UDP: 59286 -&amp;gt; 20480&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_1] eth3:i[28]: 10.10.101.2 -&amp;gt; 239.0.1.2 (2) len=28 id=45232&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_1] eth3:I[28]: 10.10.101.2 -&amp;gt; 239.0.1.2 (2) len=28 id=45232&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_2] eth1:i[44]: 10.41.8.4 -&amp;gt; 239.0.1.2 (UDP) len=58 id=12956&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;UDP: 59286 -&amp;gt; 20480&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_2] eth1:i[44]: 10.41.8.4 -&amp;gt; 239.0.1.2 (UDP) len=58 id=12930&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;UDP: 59286 -&amp;gt; 20480&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_2] eth1:i[44]: 10.41.8.4 -&amp;gt; 239.0.1.2 (UDP) len=58 id=12958&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;UDP: 59286 -&amp;gt; 20480&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_2] eth1:i[44]: 10.41.8.4 -&amp;gt; 239.0.1.2 (UDP) len=58 id=12960&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;UDP: 59286 -&amp;gt; 20480&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_2] eth1:i[44]: 10.41.8.4 -&amp;gt; 239.0.1.2 (UDP) len=58 id=12962&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;UDP: 59286 -&amp;gt; 20480&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_2] eth1:i[44]: 10.41.8.4 -&amp;gt; 239.0.1.2 (UDP) len=58 id=12964&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;UDP: 59286 -&amp;gt; 20480&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_2] eth1:i[44]: 10.41.8.4 -&amp;gt; 239.0.1.2 (UDP) len=58 id=12968&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;UDP: 59286 -&amp;gt; 20480&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;[vs_0][fw_2] eth1:i[44]: 10.41.8.4 -&amp;gt; 239.0.1.2 (UDP) len=58 id=12971&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;UDP: 59286 -&amp;gt; 20480&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;^C monitor: caught sig 2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;monitor: unloading&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Any thoughts?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2022 13:02:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153669#M25812</guid>
      <dc:creator>Mladen</dc:creator>
      <dc:date>2022-07-23T13:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitcast configuration CP3600 R81 without RP router</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153670#M25813</link>
      <description>&lt;P&gt;Do fw up_execute command on the firewall for src, dst and protocol and see what it shows.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-up_execute.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-up_execute.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2022 14:27:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153670#M25813</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-23T14:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitcast configuration CP3600 R81 without RP router</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153689#M25816</link>
      <description>&lt;P&gt;Hi, thank you for your reply, I did the command and here is the output: (both src -&amp;gt; multicast and src -&amp;gt; dst (listener))&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;[Expert@CIMACT_FW:0]# fw up_execute src=10.41.8.4 dst=239.0.1.2 ipp=103&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Rulebase execution ended successfully.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Overall status:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;----------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Active clob mask: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Required clob mask: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Match status: MATCH&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Match action: Accept&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;Per Layer:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Layer name: CIMACT_policy_package Network&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Layer id: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Match status: MATCH&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Match action: Accept&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Matched rule: 5&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Possible rules: 5 6 16777215&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;[Expert@CIMACT_FW:0]# fw up_execute src=10.41.8.4 dst=10.10.101.2 ipp=103&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Rulebase execution ended successfully.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Overall status:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;----------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Active clob mask: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Required clob mask: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Match status: MATCH&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Match action: Accept&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;Per Layer:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Layer name: CIMACT_policy_package Network&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Layer id: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Match status: MATCH&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Match action: Accept&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Matched rule: 2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Possible rules: 2 3 6 16777215&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Everything looks OK but multicast still doesnt go through.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Im guessing that my scenario somehow doesnt reflect any of the PIM on Gaia manual, since I have no routers as Rendezvous Points on both sides. i followed the Single GW on Static RP environment as it best describes my need and setup. I tried to add RPs as the IPs of my source and listener, but to no success.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Any help please&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jul 2022 11:41:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153689#M25816</guid>
      <dc:creator>Mladen</dc:creator>
      <dc:date>2022-07-24T11:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitcast configuration CP3600 R81 without RP router</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153692#M25817</link>
      <description>&lt;P&gt;That makes sense. Do you see any drops if you do fw zdebug and grep for those IP addresses?&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jul 2022 15:04:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153692#M25817</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-24T15:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitcast configuration CP3600 R81 without RP router</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153693#M25818</link>
      <description>&lt;P&gt;Will try that later and post, thank you for your help, really appreciate it.&lt;/P&gt;&lt;P&gt;But still I cant believe that CP cant route that traffic on its own, without RPs!?&lt;/P&gt;&lt;P&gt;Ill try setting IPs of CP interfaces on both sides as RPs and I'll post that too.&lt;/P&gt;&lt;P&gt;Thank you again.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jul 2022 15:15:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153693#M25818</guid>
      <dc:creator>Mladen</dc:creator>
      <dc:date>2022-07-24T15:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitcast configuration CP3600 R81 without RP router</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153696#M25819</link>
      <description>&lt;P&gt;You can also run command ip r g and then ip address, see if output makes sense.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;example -&amp;gt; ip r g 8.8.8.8&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jul 2022 15:33:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153696#M25819</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-24T15:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitcast configuration CP3600 R81 without RP router</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153790#M25877</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I tried&amp;nbsp;&lt;SPAN&gt;fw ctl zdebug but I didnt get any output (tried without ctl - syntax error).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When I tried the other command (ip r g) all is ok when I use IPs Unicast, but when I use 239.0.1.2 (Singlewire Multicast testing tool) - no output.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But there is something new, I changed scenario to&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;Single Gateway as Candidate Rendezvous Point and Bootstrap Router&lt;/PRE&gt;&lt;P&gt;and when I do fw monitor -e "net(239.0.0.0, 8), accept;" I do get 'i' and 'I' on the eth1 (incoming) but it goes nowhere with the error log "too many packets received before route was resolved".&lt;/P&gt;&lt;P&gt;Thanks again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 17:13:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153790#M25877</guid>
      <dc:creator>Mladen</dc:creator>
      <dc:date>2022-07-25T17:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitcast configuration CP3600 R81 without RP router</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153836#M25894</link>
      <description>&lt;P&gt;Hi all, new update&lt;/P&gt;&lt;P&gt;I have changed my PIM interfaces to be in DENSE mode since RPs and Bootstrap router setup IPs are confusing me in this simple setup (it seems like SPARSE mode setup scenario is more when networks are inbetween Secure Gateway and sources and listeners), all accordingly to manual.&lt;/P&gt;&lt;P&gt;Some command outputs:&lt;/P&gt;&lt;P&gt;CIMACT_FW&amp;gt; show pim summary&lt;/P&gt;&lt;P&gt;Instance ID is 0&lt;BR /&gt;Instance is running dense mode with state refresh&lt;BR /&gt;Address family of the interface is IPV4&lt;BR /&gt;Number of join/prune entries: 2&lt;/P&gt;&lt;P&gt;CIMACT_FW&amp;gt; show pim st&lt;BR /&gt;CIMACT_FW&amp;gt; show pim stats&lt;/P&gt;&lt;P&gt;PacketType Transmit Received TxErrors RxErrors&lt;BR /&gt;Hello 260 0 0 0&lt;BR /&gt;Register 0 0 0 0&lt;BR /&gt;RegisterStop 0 0 0 0&lt;BR /&gt;JoinPrune 9 0 0 0&lt;BR /&gt;Bootstrap 14 0 0 0&lt;BR /&gt;Assert 29 0 0 0&lt;BR /&gt;Graft 0 0 0 0&lt;BR /&gt;Graft Ack 0 0 0 0&lt;BR /&gt;Candidate RP 0 0 0 0&lt;BR /&gt;StateRefresh 0 0 0 0&lt;/P&gt;&lt;P&gt;CIMACT_FW&amp;gt; show igmp&lt;/P&gt;&lt;P&gt;IGMP State&lt;BR /&gt;Interfaces enabled 2&lt;BR /&gt;Next group age in 60 seconds&lt;BR /&gt;Multicast traceroute enabled&lt;BR /&gt;CIMACT_FW&amp;gt; show igmp summ&lt;BR /&gt;CIMACT_FW&amp;gt; show igmp summary&lt;/P&gt;&lt;P&gt;IGMP State&lt;BR /&gt;Interfaces enabled 2&lt;BR /&gt;Next group age in 54 seconds&lt;BR /&gt;Multicast traceroute enabled&lt;BR /&gt;CIMACT_FW&amp;gt; show mfc&lt;/P&gt;&lt;P&gt;Multicast Forwarding Cache State&lt;BR /&gt;Number of interfaces enabled: 2&lt;BR /&gt;Number of cache entries: 2&lt;BR /&gt;Kernel forwarding entry limit: unlimited&lt;BR /&gt;Number of kernel forwarding entries: 2&lt;BR /&gt;Cache entry average lifetime: 300 seconds&lt;BR /&gt;Prune average lifetime: 7200 seconds&lt;BR /&gt;Cache age cycle: 10 seconds&lt;BR /&gt;Next cache age: 3&lt;BR /&gt;Datarate update interval: 10 seconds&lt;BR /&gt;Multicast Protocol(Instance): PIM(0)&lt;/P&gt;&lt;P&gt;CIMACT_FW&amp;gt; show static-mroute&lt;/P&gt;&lt;P&gt;Static Multicast Routes:&lt;/P&gt;&lt;P&gt;0.0.0.0/0 via 10.10.101.2, eth3, cost 0, age 4191&lt;/P&gt;&lt;P&gt;On Log view i get drops with intermitten error varies from "too many packet received before route was resolved" and other "missing OS route".&lt;/P&gt;&lt;P&gt;On fw monitor -e "net(239.0.0.0, 8), accept;" all is the same, I can see just 'i' on eth1 interface.&lt;/P&gt;&lt;P&gt;Any new thoughts?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 10:48:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/153836#M25894</guid>
      <dc:creator>Mladen</dc:creator>
      <dc:date>2022-07-26T10:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitcast configuration CP3600 R81 without RP router</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/154240#M26101</link>
      <description>&lt;P&gt;Ok, just to update things. Turns out all is good with the config, removed the static multicast route and re-enabled the listening interface and lab started working right away, even after shuting down everything.&lt;/P&gt;&lt;P&gt;But after installing the production, traffic didnot pass through firewall, multicast group and pim joins are empty, ip mroute also.&lt;/P&gt;&lt;P&gt;After I did tcpdump on the incoming interface I see again just the 'i' and 'I', but what got me is that we are sending data on 224.0.0.3 and I see IGMP sending query/report on the same IP Multicast, could that be the issue?&lt;/P&gt;&lt;P&gt;Any help, can someone confirm with certainty that this is what is interfering with my setup?&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2022 10:47:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/154240#M26101</guid>
      <dc:creator>Mladen</dc:creator>
      <dc:date>2022-07-31T10:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitcast configuration CP3600 R81 without RP router</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/216242#M41233</link>
      <description>&lt;P&gt;Were you able to make it work finally ?&lt;/P&gt;&lt;P&gt;Having a similar issue with Singlewire Informacast tool&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 15:35:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitcast-configuration-CP3600-R81-without-RP-router/m-p/216242#M41233</guid>
      <dc:creator>Phil_Pasquier</dc:creator>
      <dc:date>2024-06-03T15:35:44Z</dc:date>
    </item>
  </channel>
</rss>

