This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Devices in a security zone can't reach Chromecast in another zone using Multicast

Hello,

 

I have a Google Chromecast connected to a subnet/VLAN in the Sophos XG105 firewall and my Workstations on another subnet on the same firewall. In order for the workstations to find the Chromecast, they send packets to the multicast IP 239.255.255.250 port 1900 (UDP) however, these packets are being blocked by the firewall.

 

I've enabled Multicast Routing under Configure > Routing and added some multicast routing statements for specific IPs in my LAN zone (where the workstations are) but the multicast packets are being blocked by the firewall. The Rule ID hit, according to the Log viewer, is ID 0 which is the implicit deny at the end of the rule list because it couldn't match any other rule.

 

I did add a rule allowing all traffic from my LAN zone to the zone where the Chromecast is but it's still being blocked. My guess is that the firewall doesn't know that the destination IP, 239.255.255.250 is part of the destination zone and that's why it doesn't hit any rule but I'm not sure if this is correct.

 

Does anyone know what could be wrong in this case?

 

Regards,

 

 



This thread was automatically locked due to age.
Parents Reply
  • The destination IP is the multicast address so what would changing the rule to the Chromcast's IP do in this case? The firewall won't match the packet with that rule because the IP doesn't match.

     

    I can't change the destination zone to LAN because the Chromecast is not in this zone. Even if I change the destination zone to the Chromecast one, it still denies the packet.

     

    Andres

Children