Thursday, September 20, 2018

Question about Microsoft NLB traffic isolation

Hello.

We are in the process of setting up Microsoft NLB (IGMP Multicast).

The question: is it possible to isolate multicast traffic within VLAN except for the ports specified in the IGMP configuration on the switch?

It means that other hosts should not see the multicast traffic within this vlan.

Switch: WS-C2960S-24TD-L

IOS: C2960S Software (C2960S-UNIVERSALK9-M), Version 15.2 (2a) E1

IGMP multicast config:

arp 192.168.0.222 0100. ***. *** ARPA

ip igmp snooping vlan 666 static **. **. ***. 222 int po8

mac address-table static 0100. ***. *** vlan 666 interface port-channel 8

When I run ping 192.168.0.222(NLB address) from 192.168.1.1 this traffic can be seen on the host 192.168.0.200 in the same VLAN:

"192.168.1.1 192.168.0.222 ICMP ICMP: Echo Request Message, From 192.168.1.1 To 192.168.0.222 {IPv4: 1}"

Is it possible to isolate multicast traffic with Microsoft NLB (except placing every NLB cluster into its own VLAN)?

Thank you in advance.



No comments:

Post a Comment