Wired

 View Only
last person joined: 16 hours ago 

Expand all | Collapse all

MULTICAST MAC-ADDRESS support for firewall cluster: ip arp-mcast-replies

This thread has been viewed 3 times
  • 1.  MULTICAST MAC-ADDRESS support for firewall cluster: ip arp-mcast-replies

    Posted Jan 23, 2024 12:24 AM

    Hello

    we have an existing 2 watchguard firewall cluster in active/active mode. And the cluster uses MULTICAST MAC- ADDRESS for all interfaces that send network traffic.

    Currently we have an existing Aruba Core (6) switches  stacked and we plan to migrate the SVI and routing to 6300M Stack and use it as a core switch.

    Now the existing core switch use this (ip arp-mcast-replies)  to communicate with watchguard and on the 6300M we can't find this command may we know the equivalent of this command with the firmware version of ArubaOS-CX_6400-6300_10_10_1091.



  • 2.  RE: MULTICAST MAC-ADDRESS support for firewall cluster: ip arp-mcast-replies

    Posted Feb 05, 2024 09:32 AM

    It lools like that specific command allows your multicast table to accept mac entries in the reserved list of multicast mac addresses. I'm not sure i've seen anything exactly like that in the aruba O/S world, but I believe enabling IGMP on your aruba switches will automatically allow your switches to receive that traffic. IGMP is disabled by default. enabling that on your VLAN's should allow those vlan's to receive multicast traffic.

    at your SVI interface, just do a ip igmp enable

    if you are moving your L3 layer down to a group of Aruba cores, you probably need to have a multicast strategy. The Aruba cores may not handle multicast the same way your old cores did. Does your firewall cluster really need to be involved in your multicast groups?

    Your core switches should be running a muilticast routing protocol, like PIM, with a group management protocol, like IGMP running on the VLANs. PIM should handle your multicast routing, and IGMP should handle the pruning of your multicast groups at the access layer switches, so only machines participating in multicast groups receives the multicast traffic. Your core switches will run the IGMP querier at the SVI and you disable this at your access layer switches.

    There is a multicast guide for AOS-CX that you can download and check out. There's also a multicast deployment and troubleshooting guide i'd look for.

    https://www.arubanetworks.com/techdocs/AOS-CX/10.08/PDF/multicast_6200-6300-6400-8xxx.pdf

    https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedAttachments/76420FC8-812B-4E76-80C9-5DBA6093C3E2-1-AOS-CX%20Multicast%20deployment%20and%20troubleshooting%20guide.pdf