Question:
How does the SonicWall Multicast Zone work?
Answer:
The multicast zone is a special zone of SonicWall firewall. Its security type is 'Untrusted' (effectively equivalent to the WAN Zone in terms of trust). It also has very unique characteristics. Firstly, multicast zone can only be a destination zone. The reason for this is because a mulicast address (224.0.0.0 to 239.255.255.255) normally should never be a source address, only a destination address. Secondly, security services are not configurable on the Multicast Zone.
From Zone | Source Address | Dest. Address | Service | Action | Description |
Trusted | Any | Any | IGMP (Group) | Allow | Allow IGMP queries, reports, and other messages from any source in this Zone. |
Trusted | Any | Any or Specific | Any | Allow | Allow Multicast data stream from any source in this Zone. |
Encrypted | Any | Any | IGMP (Group) | Allow | Allow IGMP queries, reports, and other messages from any source in this Zone. |
Encrypted | Any | Any or Specific | Any | Allow | Allow Multicast data stream from any source in this Zone. |
Untrusted | Any | Any | IGMP Membership | Allow | Allow only IGMP membership query messages from this Zone. |
Untrusted | Any | Any | IGMP (Group) | Deny | Deny IGMP queries, reports, and other messages from any source in this Zone. |
Untrusted | Any | Any or Specific | Any | Deny | Deny Multicast data stream from any source in this Zone. |
Public | Any | Any | IGMP Membership | Allow | Allow only IGMP membership query messages from this Zone. |
Public | Any | Any | IGMP (Group) | Deny | Deny IGMP queries, reports, and other messages from any source in this Zone. |
Public | Any | Any or Specific | Any | Allow | Allow Multicast data stream from any source in this Zone. |
Wireless | Any | Any | IGMP Membership | Allow | Allow only IGMP membership query messages from this Zone. |
Wireless | Any | Any | IGMP (Group) | Deny | Deny IGMP queries, reports, and other messages from any source in this Zone. |
Wireless | Any | Any or Specific | Any | Deny | Deny Multicast data stream from any source in this Zone. |