To configure FortiGate-500A_3
1. Configure multicast routing.
config router multicast config interface
edit port5
set pim-mode sparse-mode next
edit port6
set pim-mode sparse-mode next
edit lo0
set pim-mode sparse-mode set rp-candidate enable
set rp-candidate-priority 255 next
edit lan
set pim-mode sparse-mode next
end
set multicast-routing enable config pim-sm-global
set bsr-candidate enable set bsr-interface lo0
end end
2. Add multicast security policies.
config firewall multicast-policy edit 1
set dstintf port5 set srcintf port6
next edit 2
set dstintf port6 set srcintf port5
next edit 3
set dstintf port6 set srcintf lan
next edit 4
set dstintf lan set srcintf port6
next edit 5
set dstintf port5 set srcintf lan
next edit 6
set dstintf lan set srcintf port5
next end
To configure FortiGate-500A_4
1. Configure multicast routing.
config router multicast config interface
edit port6
set pim-mode sparse-mode next
edit lan
set pim-mode sparse-mode next
edit port1
set pim-mode sparse-mode next
edit lo0
set pim-mode sparse-mode set rp-candidate enable
config join-group edit 236.1.1.1 next
end
set rp-candidate-priority 1 next
end
set multicast-routing enable config pim-sm-global
set bsr-allow-quick-refresh enable set bsr-candidate enable set bsr-interface lo0
set bsr-priority 1 end
end
2. Add multicast security policies.
config firewall policy edit 1
set srcintf lan set dstintf port6 set srcaddr all set dstaddr all set action accept
set schedule always set service ANY
next edit 2
set srcintf port6 set dstintf lan set srcaddr all set dstaddr all set action accept
set schedule always set service ANY
next edit 3
set srcintf port1 set dstintf port6 set srcaddr all set dstaddr all set action accept
set schedule always set service ANY
next edit 4
set srcintf port6 set dstintf port1 set srcaddr all set dstaddr all set action accept
set schedule always set service ANY
next edit 5
set srcintf port1 set dstintf lan set srcaddr all set dstaddr all set action accept
set schedule always set service ANY
next edit 6
set srcintf lan set dstintf port1 set srcaddr all set dstaddr all set action accept
set schedule always set service ANY
next edit 7
set srcintf port1 set dstintf port1 set srcaddr all set dstaddr all set action accept
set schedule always set service ANY
next edit 8
set srcintf port6 set dstintf lo0 set srcaddr all set dstaddr all set action accept
set schedule always set service ANY
next edit 9
set srcintf port1
set dstintf lo0 set srcaddr all set dstaddr all set action accept
set schedule always set service ANY
next edit 10
set srcintf lan set dstintf lo0 set srcaddr all set dstaddr all set action accept
set schedule always set service ANY
next end