Monday, June 4, 2018

Firewalling multicast traffic

I have a LAN with multiple video encoders transmitting the videos on multicast which runs over multiple Juniper SRX routers on /30 (routed) links and OSPF between all areas. I am getting a point-to-point layer 2 connection installed to connect to a third party company.

I need to let the 3rd party receive the multicast stream for 1 particular stream.

What firewall rules do I need to put in to allow the one stream only through? Should the policy be "from LAN to 3rdparty" or "from 3rdparty to LAN"? Also, should the source / destination address be the multicast address or the origin IP address? Is there anything else I should consider when doing this?

Network diagram: https://i.imgur.com/nmIt7SE.png

If I've left anything out please let me know. I've never connected to 3rd parties like this before so welcome all feedback.



No comments:

Post a Comment