Fortinet black logo

Administration Guide

Create a new multicast policy

Create a new multicast policy

This section describes how to create a new multicast policy.

Multicasting consists of using a single source to send data to many receivers simultaneously, while conserving bandwidth and reducing network traffic.

See Multicast in the FortiOS Administration Guide for more information about multicasting.

Note

You must enable the visibility of this feature in Policy & Objects before it can be configured. To toggle feature visibility, go to Policy & Objects > Tools > Feature Visibility, and add or remove a checkmark for the corresponding feature.

Note

Starting in FortiManager 7.2.0, up to a maximum of 2560 multicast policies can be created.

To create a new Multicast policy:
  1. If using ADOMs, ensure that you are in the correct ADOM.
  2. Go to Policy & Objects > Policy Packages.
  3. In the tree menu for the policy package in which you will be creating the new policy, select either IPv4 Multicast Policy or IPv6 Multicast Policy.
  4. Click Create New.
  5. Enter the following information:

    Option

    Description

    Name

    Enter a unique name for the policy. Each policy must have a unique name.

    Incoming Interface

    Click the field then select interfaces.

    Click the remove icon to remove interfaces.

    New objects can be created by clicking the Create New icon in the Object Selector frame. See Create a new object for more information.

    Outgoing Interface

    Select outgoing interfaces in the same manner as Incoming Interface.

    Source Address

    Select the source firewall address.

    Destination Address

    Select the destination multicast addresses.

    Action

    Select an action for the policy to take: ACCEPT or DENY.

    Source NAT

    Enable or disable source NAT, then enter the source NAT IP Address.

    This option is only available when Action is Accept.

    Destination NAT

    Enter the destination NAT IP address.

    Protocol Option

    Select a protocol option: ANY, ICMP, IGMP, TCP, UDP, OSFP, or Others.

    Port Range

    Set the port range. This option is only available when Protocol Option is TCP or UDP.

    Protocol Number

    Enter the protocol number, from 1 to 256. This option is only available when Protocol Option is Others.

    Log Traffic

    Enable or disable traffic logging.

    Advanced Options

    Configure advanced options, see Advanced options below.

    For more information on advanced option, see the FortiOS CLI Reference.

    Change Note

    Add a description of the changes being made to the policy. This field is required.
  6. Click OK to create the policy. You can select to enable or disable the policy in the right-click menu. When disabled, a disabled icon will be displayed in the Seq.# column to the left of the number. By default, policies will be added to the bottom of the list, but above the implicit policy.
Advanced options

Option

Description

Default

auto-asic-offload

Enable or disable policy traffic ASIC offloading.

enable

comments

Add a description of the policy, such as its purpose, or the changes that have been made to it. A comment added here will overwrite the comment added in the above Comments field.

none

uuid

Enter the universally unique identifier (UUID). This value is automatically assigned but can be manually reset.

00000000-0000- 0000-0000- 000000000000

traffic-shaper

Select the traffic shaper to apply to traffic forwarded by the multicast policy.

This option is only available in an IPv4 multicast policy.

none

Create a new multicast policy

This section describes how to create a new multicast policy.

Multicasting consists of using a single source to send data to many receivers simultaneously, while conserving bandwidth and reducing network traffic.

See Multicast in the FortiOS Administration Guide for more information about multicasting.

Note

You must enable the visibility of this feature in Policy & Objects before it can be configured. To toggle feature visibility, go to Policy & Objects > Tools > Feature Visibility, and add or remove a checkmark for the corresponding feature.

Note

Starting in FortiManager 7.2.0, up to a maximum of 2560 multicast policies can be created.

To create a new Multicast policy:
  1. If using ADOMs, ensure that you are in the correct ADOM.
  2. Go to Policy & Objects > Policy Packages.
  3. In the tree menu for the policy package in which you will be creating the new policy, select either IPv4 Multicast Policy or IPv6 Multicast Policy.
  4. Click Create New.
  5. Enter the following information:

    Option

    Description

    Name

    Enter a unique name for the policy. Each policy must have a unique name.

    Incoming Interface

    Click the field then select interfaces.

    Click the remove icon to remove interfaces.

    New objects can be created by clicking the Create New icon in the Object Selector frame. See Create a new object for more information.

    Outgoing Interface

    Select outgoing interfaces in the same manner as Incoming Interface.

    Source Address

    Select the source firewall address.

    Destination Address

    Select the destination multicast addresses.

    Action

    Select an action for the policy to take: ACCEPT or DENY.

    Source NAT

    Enable or disable source NAT, then enter the source NAT IP Address.

    This option is only available when Action is Accept.

    Destination NAT

    Enter the destination NAT IP address.

    Protocol Option

    Select a protocol option: ANY, ICMP, IGMP, TCP, UDP, OSFP, or Others.

    Port Range

    Set the port range. This option is only available when Protocol Option is TCP or UDP.

    Protocol Number

    Enter the protocol number, from 1 to 256. This option is only available when Protocol Option is Others.

    Log Traffic

    Enable or disable traffic logging.

    Advanced Options

    Configure advanced options, see Advanced options below.

    For more information on advanced option, see the FortiOS CLI Reference.

    Change Note

    Add a description of the changes being made to the policy. This field is required.
  6. Click OK to create the policy. You can select to enable or disable the policy in the right-click menu. When disabled, a disabled icon will be displayed in the Seq.# column to the left of the number. By default, policies will be added to the bottom of the list, but above the implicit policy.
Advanced options

Option

Description

Default

auto-asic-offload

Enable or disable policy traffic ASIC offloading.

enable

comments

Add a description of the policy, such as its purpose, or the changes that have been made to it. A comment added here will overwrite the comment added in the above Comments field.

none

uuid

Enter the universally unique identifier (UUID). This value is automatically assigned but can be manually reset.

00000000-0000- 0000-0000- 000000000000

traffic-shaper

Select the traffic shaper to apply to traffic forwarded by the multicast policy.

This option is only available in an IPv4 multicast policy.

none