How does IGMP proxy work on Aruba controllers?

Aruba Employee
Aruba Employee

Product and Software: This article applies to ArubaOS 3.4 and later.


Why is IGMP proxy useful?


IGMP proxy is useful in mobility environments where the client needs to subscribe to multicast streams from his home agent (HA) and foreign agents (FAs). Until version 3.3.2.x, ArubaOS supported only IGMP snooping, which is effective only as long as the client is in his home agent VLAN. Because of mobility, the client IP remains same even when it roams. The IGMP membership is not extended to his FA VLAN and so the client loses subscription to the multicast stream. IGMP proxy addresses this issue.


How does IGMP proxy work?


Whenever the client roams away from his HA to a FA, the HA communicates all current group memberships of the mobile client to the FA in the registration message.


The HA mobility process queries PIM for group membership and it receives a HA discovery message from the FA. After discovery, when the FA sends a registration request to the HA, the HA fills in all multicast groups in a registration reply.


FA mobility fetches group membership from the reply and pushes it to the local PIM process. The local PIM process performs a proxy join so that the mobility client can directly get downstream multicast traffic from the foreign network

The upstream router is not aware of the client memberships. The controller processes the IGMP control messages on behalf of the clients. It acts as host for all multicast groups that the client is interested in.


All mobility controllers must be connected to the upstream router. This way the multicast streams are flooded directly to the client in FA from the upstream router instead of going through IP-IP tunnel.

At maximum mobility, IGMP proxy supports eight multicast groups per host and a total of 256 multicast groups per controller.


Note: IGMP snooping and IGMP proxy cannot be enabled on an interface at the same time.

Configuration requires that you enable IGMP proxy on the VLAN interface with the controller uplink interface.




interface vlan 30
ip igmp proxy gigabitethernet 1/0



To check the IGMP proxy state for a VLAN, issue this command:


(ARUBA) #show ip igmp interface

IGMP Interface Table
VLAN Addr Netmask MAC Address IGMP Snooping Querier Destination IGMP Proxy
---- ---- ------- ----------- ---- -------- ------- ----------- ----------
16 00:0b:86:61:21:50 disabled disabled CP disabled
400 00:0b:86:61:21:50 disabled disabled CP enabled
211 00:0b:86:61:21:50 disabled disabled CP disabled
140 00:0b:86:61:21:50 disabled disabled CP disabled
300 00:0b:86:61:21:50 disabled disabled CP enabled



To check the group information the controller has issued for a VLAN, say vlan1, issue this command:


(3200-1) #show ip igmp proxy-group vlan 1

IGMP Proxy Group Table


VLAN Addr Group Num Members

---- ---- ----- -----------

1 3

1 1

1 1


To display the group information for mobile clients that are away from the controller, issue this command:


(ARUBA)# show ip igmp proxy-mobility-group

Version history
Revision #:
1 of 1
Last update:
‎07-02-2014 06:27 AM
Updated by:
Labels (1)
Search Airheads
Showing results for 
Search instead for 
Did you mean: