Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSDP Multicast on internal networks

I have a UTM box at home, running 9.503-4.

Behind this is a switch, going to my home network. This includes a HDHomeRun device ( https://www.silicondust.com/ ) and a Plex server.

Since switching to the UTM box, the HDHomeRun device does not work whatsoever, no matter what any->any->any allow rules or whatever I put in.

Running setup, it appears that SSDP Multicast is needed. http://www.silicondust.com/support/hdhomerun/testfail/upnp_multicast_recv/

 

I know this is a UPnP component, and that UPnP has security issues as it allows users to punch through firewalls, but this does not need to be natted or leave my internal network.

 

Is there any workaround to make this possible?

 

Thanks!



This thread was automatically locked due to age.
Parents
  • Richard, try #1 in Rulz - any hints there?  If that doesn't give you a hint about how to resolve this, show us a stick diagram of your topology with IPs noted like 192.168.x.11 and 72.x.y.211.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Richard, try #1 in Rulz - any hints there?  If that doesn't give you a hint about how to resolve this, show us a stick diagram of your topology with IPs noted like 192.168.x.11 and 72.x.y.211.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
  • Sorry I didn't reply back here....

    My original config had 3xLAN ports on my gateway on a bridge, and 1 used as WAN.

    By instead only using 1 of the LAN ports and sitting an 8 port switch under the UTM, I bypassed this issue as the clients on the internal network can talk to each other without going via the UTM!!

     

    Probably not the most elegant solution, but I'm happy with it for now.