FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] Conundrum - IGMP and IPSec

To: "Firewall Wizards Security Mailing List" <firewall-wizards@listserv.icsalabs.com>
Subject: Re: [fw-wiz] Conundrum - IGMP and IPSec
From: "Kurt Buff" <kurt.buff@gmail.com>
Date: Mon, 29 Jan 2007 14:25:56 -0800
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.icsalabs.com
In-reply-to: <11A24275-3651-4FB1-9823-B92F5D7785E2@charter.net>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
References: <a9f4a3860701261155kc11107cy7f9e3f36c8f07ffc@mail.gmail.com> <11A24275-3651-4FB1-9823-B92F5D7785E2@charter.net>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
Situation in the case is that we're implementing equipment that uses
multicast to talk between multiple instances of themselves - I'm not
clear yet whether there'll be a designated talker with multiple
listeners, or whether there'll be multiple talkers and multiple
listeners.

I'm reading the doco now - thanks for the tip. This should provide me
with a running start.

I'll be interested in finding out whether I can use a layer3 switch at
each end to do this, or if I need edge routers to set this up.

Kurt

On 1/28/07, Chris Myers <clmmacunix@charter.net> wrote:
> > Hi Kurt,
>
>         I am not sure what you are exactly needing to use the IGMP for, but
> most firewall and vpn solutions can do what you want to do. It's a
> matter of creating  the right tunnels or forwarding the right ports
> and protocols. Cisco is a solution, but Juniper can do it just as
> well. It really depends on the implementation you are needing IGMP
> for. IGMP is associated with multicast formats, so here is a Cisco
> doc that should get you started.
>
> > www.cisco.com/application/pdf/en/us/guest/netsol/ns171/c649/
> > ccmigration_09186a008074f26a.pdf
>
> Thank You,
> cmyers
>
> >
>
> On Jan 26, 2007, at 1:55 PM, Kurt Buff wrote:
>
> > Honorable Ones,
> >
> > I've been handed the task of getting IGMP traffic between remote
> > offices, over an IPSec tunnel.
> >
> > I have run into the apparently well-known issue of their not playing
> > nicely together, and was wondering if I could get recommendations on
> > making such a thing happen.
> >
> > We're looking at upgrading/replacing our current hardware soon anyway,
> > so recommendations as to brands that would help support this would be
> > useful, as would workarounds that don't require replacement of current
> > hardware, as I believe that would broaden the choices I have when I do
> > upgrade.
> >
> > I'm stumped, not least because my network-fu is not up to the
> > standards of many on this list, and would really appreciate some
> > pointers in the right direction.
> >
> >
> > Kurt
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>