Restricting Multicast Traffic using IGMP Snooping (HSRP and

From: Heywood Jablome (magicdongwong@hotmail.com)
Date: Thu Oct 21 2004 - 12:34:30 GMT-3


I have a question regarding the restriction of multicast traffic on user
segments. The topology consists of a 6509 with dual MSFC's, as well as a
7120, and a 2621 that are acting as RPs via auto-rp. The routers are
running in PIM sparse-dense mode with auto-rp set up for load sharing as
follows:

7120: RP for 224.0.0.0 7.255.255.255
2621: RP for 232.0.0.0 7.255.255.255

All devices have the RP's successfully mapped, and multicast traffic is
being passed in sparse mode, except for 224.0.1.39 and 224.0.1.40, for
auto-rp. So far so good?

Here's where I'm not getting it:

I have the 6509's configured to use igmp snooping to restrict multicast
traffic (set igmp enable), and the MSFCs are running HSRP on user segments.
I have noticed that on user segments (which hang off of VLAN interfaces on
the 6509s), if you fire up a sniffer, you can still see the HSRP (224.0.0.2)
and OSPF traffic (224.0.0.5). As I understand it, the switch should only be
forwarding multicast traffic to ports that have received an IGMP join
message for those specific groups. Is that correct?

So the question is:

Is this operating properly, and if so, is there a way to restrict user
segments from receiving the HSRP and OSPF traffic without hindering
functionality? (I was thinking a MAC filter on user ports, but I wanted to
get some input first).

Thanks!



This archive was generated by hypermail 2.1.4 : Sat Nov 06 2004 - 17:11:51 GMT-3