IGMP Proxy - Internet Group Management Protocol Proxy
IGMP Proxy makes it possible to route multicast traffic between different network segments by acting as a proxy for IGMP messages from clients.
Overview
IGMP (Internet Group Management Protocol) is the protocol used to manage multicast groups in IPv4 networks.
IGMP Proxy:
- Sends IGMP host messages on behalf of connected clients
- Provides multicast routing without a full multicast routing protocol
- A simple alternative to PIM (Protocol Independent Multicast)
- Used to distribute IPTV, video streaming, and conferencing
Standards:
- RFC 2236 - IGMPv2
- RFC 3376 - IGMPv3
- RFC 9776 - IGMPv3 update (2025)
Use cases:
- IPTV services
- Video conferencing
- Multicast streaming video
- Enterprise broadcasting applications
- Financial data (market data feeds)
How IGMP Works
IGMP in the Network
IGMP versions:
IGMPv1 (RFC 1112):
- Basic functionality
- Join messages only
- Legacy version
IGMPv2 (RFC 2236):
- Leave Group messages
- Querier election mechanism
- Max Response Time field
- Fast removal from a group
IGMPv3 (RFC 3376, RFC 9776):
- Source-Specific Multicast (SSM)
- Include/Exclude modes
- Source filtering
IGMP Messages
Membership Query:
- Sent by the router to discover group members
- General Query - for all groups
- Group-Specific Query - for a specific group
Membership Report:
- Sent by a host to join a group
- Periodic refreshes
Leave Group (IGMPv2+):
- A host leaves a multicast group
- Fast unsubscription
Multicast Addresses
IPv4 multicast range: 224.0.0.0/4 (224.0.0.0 - 239.255.255.255)
Special addresses:
- 224.0.0.1 - All Hosts (all hosts in the subnet)
- 224.0.0.2 - All Routers (all routers)
- 224.0.0.5 - OSPF All Routers
- 224.0.0.6 - OSPF Designated Routers
- 224.0.0.9 - RIPv2
- 224.0.0.22 - IGMP
- 224.0.0.251 - mDNS
- 224.0.0.252 - LLMNR
Organization-Local: 239.0.0.0/8 - for private use
IPTV ranges (examples):
- 233.0.0.0/8 - SSM range
- 239.x.x.x - Organization-local
IGMP Proxy Concept
Architecture
Upstream Interface - the incoming interface:
- Connected to the source of multicast traffic
- Communicates with multicast data sources
- There can be only one upstream interface
- Usually the WAN interface or the provider-facing interface
Downstream Interface - the outgoing interfaces:
- Connected to client networks
- Distribute multicast data to receivers
- There can be one or more downstream interfaces
- Usually LAN interfaces
How the proxy works:
- A client sends an IGMP Join on a downstream interface
- IGMP Proxy receives the Join and records the subscription
- The proxy sends an IGMP Join on the upstream interface (on its own behalf)
- The multicast source starts sending traffic
- The proxy forwards multicast packets to the downstream interfaces that have active subscriptions
- On an IGMP Leave, the proxy updates the subscriptions
Benefits
IGMP Proxy vs Full Multicast Routing (PIM):
| Characteristic | IGMP Proxy | PIM |
|---|---|---|
| Configuration complexity | Low | High |
| Resources | Minimal | Significant |
| Topology | Simple | Any |
| Scalability | Limited | High |
| Use case | Edge networks | Core networks |
When to use IGMP Proxy:
- Simple topology (one source, several receivers)
- Home/office networks
- IPTV from a provider
- Limited resources
When to use PIM:
- Complex topology
- Multiple sources
- Redundancy is required
- Data center multicast
Basic Configuration
Simple IGMP Proxy
Scenario: IPTV from a provider over eth0 (WAN), clients on eth1 (LAN).
set protocols igmp-proxy interface eth0 role upstream
set protocols igmp-proxy interface eth1 role downstream
commit
saveExplanation:
- eth0 (upstream) - connected to the IPTV provider
- eth1 (downstream) - LAN with IPTV clients
Verifying the Basic Configuration
show protocols igmp-proxyOutput:
interface eth0 {
role upstream
}
interface eth1 {
role downstream
}Viewing active multicast groups:
show igmp groupsOutput:
Interface Address Group Uptime
eth1 192.168.1.254 239.0.1.10 00:05:23
eth1 192.168.1.254 239.0.1.11 00:03:45Restart IGMP Proxy
After changing the configuration:
restart igmp-proxyAdvanced Configuration
Alternate Subnets
Purpose: Defines alternative sources for multicast traffic.
Use cases:
- The multicast source is in a different subnet
- Traffic passes through NAT
- Remote multicast sources
Syntax:
set protocols igmp-proxy interface <interface> alt-subnet <network>Example:
set protocols igmp-proxy interface eth0 role upstream
set protocols igmp-proxy interface eth0 alt-subnet 10.0.0.0/23
set protocols igmp-proxy interface eth0 alt-subnet 172.16.0.0/16
set protocols igmp-proxy interface eth1 role downstream
commit
saveWhen to use alt-subnet:
- The multicast source has an address that is not from a directly connected subnet
- There is a router between the upstream interface and the source
- The IPTV provider uses centralized multicast servers
Multiple Downstream Interfaces
Scenario: Several LAN segments.
set protocols igmp-proxy interface eth0 role upstream
set protocols igmp-proxy interface eth1 role downstream
set protocols igmp-proxy interface eth2 role downstream
set protocols igmp-proxy interface eth3 role downstream
commit
saveUse cases:
- Multiple VLANs for clients
- Different physical segments
- Traffic separation by department
Threshold (TTL)
Threshold - the minimum TTL for forwarding multicast packets to an interface.
Syntax:
set protocols igmp-proxy interface <interface> threshold <ttl>Example:
set protocols igmp-proxy interface eth0 role upstream
set protocols igmp-proxy interface eth0 threshold 1
set protocols igmp-proxy interface eth1 role downstream
set protocols igmp-proxy interface eth1 threshold 1
commit
saveTTL values:
- 1 - local network only (default)
- 32 - within the organization
- 64 - within the region
- 128 - within the continent
- 255 - global
Use cases:
- Limiting the spread of multicast traffic
- Preventing leaks into external networks
- Controlling the scope
Disable Quick Leave
Quick Leave - fast removal from a group without additional checks.
Disabling:
set protocols igmp-proxy disable-quickleave
commit
saveDefault: Quick Leave is enabled.
When to disable it:
- Several clients on the same downstream interface
- You need to make sure all clients have left the group
- Preventing premature termination of a stream
Effect of disabling it:
- The proxy sends a Group-Specific Query before removing the group
- A delay of a few seconds on Leave
Configuration Examples
Example 1: IPTV from a Provider (Yandex Cloud)
Scenario:
- VyOS router in Yandex Cloud
- WAN (eth0) - connection to the IPTV provider (external network)
- LAN (eth1) - client network 192.168.1.0/24
- IPTV multicast groups in the 239.0.0.0/8 range
Topology:
[IPTV Provider] --- eth0 (WAN) --- [VyOS] --- eth1 (LAN) --- [IPTV Clients]
10.100.0.0/24 192.168.1.0/24
239.0.1.10 (Channel 1)
239.0.1.11 (Channel 2)VyOS configuration:
# Interfaces
set interfaces ethernet eth0 address 10.100.0.10/24
set interfaces ethernet eth0 description 'WAN - IPTV Provider'
set interfaces ethernet eth1 address 192.168.1.1/24
set interfaces ethernet eth1 description 'LAN - IPTV Clients'
# IGMP Proxy
set protocols igmp-proxy interface eth0 role upstream
set protocols igmp-proxy interface eth0 alt-subnet 10.0.0.0/8
set protocols igmp-proxy interface eth1 role downstream
# Firewall for IGMP
set firewall ipv4 input filter rule 100 action accept
set firewall ipv4 input filter rule 100 description 'Allow IGMP'
set firewall ipv4 input filter rule 100 protocol igmp
# Firewall for multicast traffic
set firewall ipv4 input filter rule 110 action accept
set firewall ipv4 input filter rule 110 description 'Allow multicast from provider'
set firewall ipv4 input filter rule 110 source address 10.100.0.0/24
set firewall ipv4 input filter rule 110 destination address 224.0.0.0/4
# NAT (if required)
set nat source rule 100 outbound-interface name eth0
set nat source rule 100 source address 192.168.1.0/24
set nat source rule 100 translation address masquerade
# Exclude multicast from NAT
set nat source rule 90 outbound-interface name eth0
set nat source rule 90 destination address 224.0.0.0/4
set nat source rule 90 translation address 10.100.0.10
# Static routes for multicast (if needed)
set protocols static route 239.0.0.0/8 interface eth0
commit
saveVerification:
show protocols igmp-proxy
show igmp groups
show igmp interface eth1
# On the client
# Subscribe to a channel: igmp join 239.0.1.10 eth1
# Check the stream: tcpdump -i eth1 -n host 239.0.1.10Result:
- Clients in 192.168.1.0/24 can subscribe to IPTV channels
- Multicast traffic passes through the proxy
- Optimized delivery (active subscriptions only)
Example 2: Enterprise Video Broadcasting (VK Cloud)
Scenario:
- VyOS in VK Cloud as a multicast router
- Video server in the DMZ (eth0): 10.50.0.0/24
- Office 1 (eth1): 192.168.10.0/24
- Office 2 (eth2): 192.168.20.0/24
- Video conferences in the 239.255.0.0/16 range
Topology:
[Video Server] --- eth0 (DMZ) --- [VyOS] --- eth1 (Office 1) --- [Users]
10.50.0.10 |
239.255.1.100 |
--- eth2 (Office 2) --- [Users]VyOS configuration:
# Interfaces
set interfaces ethernet eth0 address 10.50.0.1/24
set interfaces ethernet eth0 description 'DMZ - Video Servers'
set interfaces ethernet eth1 address 192.168.10.1/24
set interfaces ethernet eth1 description 'Office 1 - Users'
set interfaces ethernet eth2 address 192.168.20.1/24
set interfaces ethernet eth2 description 'Office 2 - Users'
# IGMP Proxy
set protocols igmp-proxy interface eth0 role upstream
set protocols igmp-proxy interface eth0 threshold 1
set protocols igmp-proxy interface eth1 role downstream
set protocols igmp-proxy interface eth1 threshold 1
set protocols igmp-proxy interface eth2 role downstream
set protocols igmp-proxy interface eth2 threshold 1
# Disable Quick Leave (multiple clients)
set protocols igmp-proxy disable-quickleave
# Firewall for IGMP
set firewall ipv4 name LAN-TO-ROUTER rule 100 action accept
set firewall ipv4 name LAN-TO-ROUTER rule 100 description 'Allow IGMP from clients'
set firewall ipv4 name LAN-TO-ROUTER rule 100 protocol igmp
set firewall ipv4 input filter rule 100 action accept
set firewall ipv4 input filter rule 100 description 'Allow IGMP'
set firewall ipv4 input filter rule 100 protocol igmp
# Firewall for multicast streams
set firewall ipv4 name DMZ-TO-LAN rule 100 action accept
set firewall ipv4 name DMZ-TO-LAN rule 100 description 'Allow multicast video'
set firewall ipv4 name DMZ-TO-LAN rule 100 source address 10.50.0.0/24
set firewall ipv4 name DMZ-TO-LAN rule 100 destination address 239.255.0.0/16
# QoS for video traffic (optional)
set qos policy shaper VIDEO-SHAPER bandwidth 100mbit
set qos policy shaper VIDEO-SHAPER default bandwidth 50%
set qos policy shaper VIDEO-SHAPER default queue-type fair-queue
set qos policy shaper VIDEO-SHAPER class 10 bandwidth 30%
set qos policy shaper VIDEO-SHAPER class 10 description 'Multicast Video'
set qos policy shaper VIDEO-SHAPER class 10 match MULTICAST ip destination address 239.255.0.0/16
set qos policy shaper VIDEO-SHAPER class 10 priority 1
set qos interface eth1 egress VIDEO-SHAPER
set qos interface eth2 egress VIDEO-SHAPER
commit
saveVerification:
show protocols igmp-proxy
show igmp groups
show igmp interface
show igmp statistics
# QoS statistics
show qos interface eth1
show qos interface eth2Monitoring multicast traffic:
# On the router
tcpdump -i eth0 -n host 239.255.1.100
# Interface statistics
show interfaces ethernet eth0
show interfaces ethernet eth1
show interfaces ethernet eth2Example 3: IGMP over a VPN Tunnel
Scenario:
- Main office with a multicast source
- Remote office over an IPsec VPN
- IGMP over a VTI interface
Topology:
[Multicast Source] --- eth1 --- [HQ VyOS] --- vti0 (VPN) --- [Remote VyOS] --- eth1 --- [Clients]
10.10.0.0/24 172.16.0.1/30 172.16.0.2/30 192.168.100.0/24HQ Router:
# VTI interface for the VPN
set interfaces vti vti0 address 172.16.0.1/30
# IGMP Proxy
set protocols igmp-proxy interface eth1 role upstream
set protocols igmp-proxy interface eth1 alt-subnet 10.10.0.0/24
set protocols igmp-proxy interface vti0 role downstream
set protocols igmp-proxy interface vti0 threshold 64
commit
saveRemote Router:
# VTI interface for the VPN
set interfaces vti vti0 address 172.16.0.2/30
# IGMP Proxy
set protocols igmp-proxy interface vti0 role upstream
set protocols igmp-proxy interface vti0 alt-subnet 10.10.0.0/24
set protocols igmp-proxy interface eth1 role downstream
commit
saveIPsec configuration (on both routers):
# Phase 1 (IKE)
set vpn ipsec ike-group IKE-GROUP proposal 1 encryption aes256
set vpn ipsec ike-group IKE-GROUP proposal 1 hash sha256
set vpn ipsec ike-group IKE-GROUP lifetime 28800
# Phase 2 (ESP)
set vpn ipsec esp-group ESP-GROUP proposal 1 encryption aes256
set vpn ipsec esp-group ESP-GROUP proposal 1 hash sha256
set vpn ipsec esp-group ESP-GROUP lifetime 3600
# Site-to-Site VPN with VTI
set vpn ipsec site-to-site peer 203.0.113.2 authentication mode pre-shared-secret
set vpn ipsec site-to-site peer 203.0.113.2 authentication pre-shared-secret 'SecureKey123!'
set vpn ipsec site-to-site peer 203.0.113.2 ike-group IKE-GROUP
set vpn ipsec site-to-site peer 203.0.113.2 vti bind vti0
commit
saveExample 4: IGMP with VLANs
Scenario:
- Provider on VLAN 100
- Clients on VLAN 10, 20, 30
VyOS configuration:
# VLAN interfaces
set interfaces ethernet eth0 vif 100 address 10.100.0.10/24
set interfaces ethernet eth0 vif 100 description 'VLAN 100 - Provider'
set interfaces ethernet eth1 vif 10 address 192.168.10.1/24
set interfaces ethernet eth1 vif 10 description 'VLAN 10 - Office A'
set interfaces ethernet eth1 vif 20 address 192.168.20.1/24
set interfaces ethernet eth1 vif 20 description 'VLAN 20 - Office B'
set interfaces ethernet eth1 vif 30 address 192.168.30.1/24
set interfaces ethernet eth1 vif 30 description 'VLAN 30 - Office C'
# IGMP Proxy
set protocols igmp-proxy interface eth0.100 role upstream
set protocols igmp-proxy interface eth0.100 alt-subnet 10.0.0.0/8
set protocols igmp-proxy interface eth1.10 role downstream
set protocols igmp-proxy interface eth1.20 role downstream
set protocols igmp-proxy interface eth1.30 role downstream
commit
saveOperational Commands
Show Commands
IGMP Proxy configuration:
show protocols igmp-proxyOutput:
interface eth0 {
alt-subnet 10.0.0.0/23
role upstream
threshold 1
}
interface eth1 {
role downstream
threshold 1
}IGMP Groups:
show igmp groupsOutput:
Interface Address Group Uptime Expires
eth1 192.168.1.1 239.0.1.10 00:10:15 00:04:23
eth1 192.168.1.1 239.0.1.11 00:05:33 00:04:45
eth2 192.168.2.1 239.0.1.10 00:08:42 00:04:18IGMP Interface:
show igmp interfaceOutput:
Interface State Address V Querier Query Timer Uptime
eth0 up 10.100.0.10 3 local 00:00:58 00:15:23
eth1 up 192.168.1.1 3 local 00:00:45 00:15:23
eth2 up 192.168.2.1 3 local 00:00:52 00:15:23Interface details:
show igmp interface eth1Output:
Interface eth1:
State: up
Address: 192.168.1.1
Version: 3
Querier: local
Query Interval: 125s
Query Timer: 00:00:58
Other Querier Present Timer: 00:00:00
Uptime: 00:15:23
Multicast routing: enabledIGMP Statistics:
show igmp statisticsOutput:
Interface eth1:
IGMP queries sent: 152
IGMP queries received: 0
IGMP reports sent: 45
IGMP reports received: 287
IGMP leaves sent: 12
IGMP leaves received: 35
IGMP v1 reports received: 0
IGMP v2 reports received: 156
IGMP v3 reports received: 131Management Commands
Restart IGMP Proxy:
restart igmp-proxyClear IGMP groups (reset subscriptions):
# There is no direct command in VyOS, use restart
restart igmp-proxyTroubleshooting
Clients Are Not Receiving Multicast Traffic
Problem: Subscribing to a multicast group does not work.
Checks:
IGMP Proxy is running:
show protocols igmp-proxyInterfaces are configured correctly:
show igmp interfaceMake sure that:
- There is only one upstream interface
- The downstream interfaces have the correct role
- Multicast routing is enabled
IGMP groups are visible:
show igmp groupsThere should be active subscriptions.
Multicast traffic reaches the upstream:
tcpdump -i eth0 -n host 239.0.1.10Firewall rules:
show firewallVerify that IGMP and multicast traffic is allowed:
set firewall ipv4 input filter rule 100 action accept set firewall ipv4 input filter rule 100 protocol igmp set firewall ipv4 input filter rule 110 action accept set firewall ipv4 input filter rule 110 destination address 224.0.0.0/4 commitRouting for multicast:
show ip route 239.0.1.10A static route may be required:
set protocols static route 239.0.0.0/8 interface eth0 commit
IGMP Join Does Not Reach the Upstream
Problem: The IGMP proxy is not sending a Join on the upstream interface.
Checks:
The downstream receives a Join from the client:
tcpdump -i eth1 -n igmpYou should see an IGMP Membership Report.
The upstream sends a Join:
tcpdump -i eth0 -n igmpAn IGMP Join for the group should be sent.
Alternate subnet is configured (if the source is in a different subnet):
set protocols igmp-proxy interface eth0 alt-subnet 10.0.0.0/8 commitRestart the proxy:
restart igmp-proxySystem logs:
show log | match igmp
Multicast Source in a Different Subnet
Problem: The multicast source has an IP that is not from the directly connected network of the upstream interface.
Solution: Use alt-subnet.
Example:
# Upstream interface: 10.100.0.10/24
# Multicast source: 172.16.50.100
set protocols igmp-proxy interface eth0 alt-subnet 172.16.0.0/16
commit
saveVerification:
show protocols igmp-proxy interface eth0Delay on Leave Group
Problem: After a Leave Group, traffic keeps flowing for a few seconds.
Cause: Quick Leave is disabled, or there are multiple clients on the interface.
Solution 1 - Enable Quick Leave (single client only):
delete protocols igmp-proxy disable-quickleave
commitSolution 2 - Adjust the IGMP Query Interval (reduce the interval):
# This is done on the provider's upstream router
# VyOS IGMP Proxy has no direct Query Interval settingsWorkaround - Restart the proxy after bulk changes:
restart igmp-proxyHigh Load from Multicast Traffic
Problem: Excessive multicast traffic is overloading the network.
Solution:
Threshold to limit propagation:
set protocols igmp-proxy interface eth1 threshold 1 commitQoS for prioritization:
set qos policy shaper MULTICAST-LIMIT bandwidth 50mbit set qos policy shaper MULTICAST-LIMIT class 10 bandwidth 20mbit set qos policy shaper MULTICAST-LIMIT class 10 match VIDEO ip destination address 239.0.0.0/8 set qos interface eth1 egress MULTICAST-LIMIT commitFirewall rate limiting:
set firewall ipv4 name LAN-LOCAL rule 100 action accept set firewall ipv4 name LAN-LOCAL rule 100 destination address 224.0.0.0/4 set firewall ipv4 name LAN-LOCAL rule 100 limit rate 10/second set firewall ipv4 input filter rule 100 jump-target LAN-LOCAL commit
IGMP Versions Do Not Match
Problem: Clients use IGMPv3, the provider uses IGMPv2.
Solution: VyOS IGMP Proxy supports automatic version conversion.
Check the version:
show igmp interface eth0The output shows:
Version: 2or
Version: 3Compatibility:
- IGMPv3 is backward compatible with IGMPv2
- IGMPv2 is backward compatible with IGMPv1
- The proxy adapts automatically
Multicast over NAT
Problem: Multicast does not work over NAT.
Solution: Exclude multicast from NAT, use alt-subnet.
Configuration:
# Exclude multicast from NAT
set nat source rule 90 outbound-interface name eth0
set nat source rule 90 destination address 224.0.0.0/4
set nat source rule 90 translation address <router-wan-ip>
# Main NAT rule
set nat source rule 100 outbound-interface name eth0
set nat source rule 100 source address 192.168.1.0/24
set nat source rule 100 translation address masquerade
# Alt-subnet for the upstream
set protocols igmp-proxy interface eth0 alt-subnet 10.0.0.0/8
commit
saveMonitoring and Logging
Continuous Monitoring
Monitoring IGMP groups:
watch -n 5 'show igmp groups'Monitoring multicast traffic:
# Inbound on the upstream
tcpdump -i eth0 -n multicast
# Outbound on the downstream
tcpdump -i eth1 -n multicast
# A specific group
tcpdump -i eth1 -n host 239.0.1.10Bandwidth monitoring:
# Install bmon
sudo apt update
sudo apt install bmon
# Run
bmon -p eth0,eth1
# Or use iftop
sudo iftop -i eth1 -f 'dst net 224.0.0.0/4'Logging
System logs:
show log tail 100 | match igmpSyslog for IGMP:
set system syslog global facility protocols level info
commitExternal syslog server:
set system syslog host 192.168.1.100 facility protocols level info
set system syslog host 192.168.1.100 port 514
commitViewing logs:
show log | match igmp
show log tail 50 | match "multicast|igmp"Best Practices
Configuration
Single upstream interface:
- IGMP Proxy requires exactly one upstream
- For redundancy, use VRRP + IGMP Proxy on both routers
Alt-subnet for providers:
- Always configure alt-subnet if the source is not in a directly connected network
- Include wide ranges (10.0.0.0/8)
Threshold management:
- Use threshold 1 for local networks
- Increase it for WAN tunnels
Quick Leave:
- Leave it enabled for home networks (single client)
- Disable it for enterprise networks (multiple clients)
Firewall:
- Always allow the IGMP protocol
- Allow multicast addresses (224.0.0.0/4)
- Use rate limiting for protection
Security
Firewall for IGMP:
set firewall ipv4 input filter rule 100 action accept set firewall ipv4 input filter rule 100 protocol igmp set firewall ipv4 input filter rule 100 source address 192.168.0.0/16Restricting multicast groups:
set firewall ipv4 input filter rule 110 action accept set firewall ipv4 input filter rule 110 destination address 239.0.0.0/16 set firewall ipv4 input filter rule 110 description 'Allow only company multicast'Rate limiting IGMP:
set firewall ipv4 input filter rule 100 limit rate 10/secondDrop unknown multicast:
set firewall ipv4 input filter rule 999 action drop set firewall ipv4 input filter rule 999 destination address 224.0.0.0/4 set firewall ipv4 input filter rule 999 description 'Drop unknown multicast'
Performance
QoS for video:
set qos policy shaper VIDEO bandwidth 100mbit set qos policy shaper VIDEO class 10 bandwidth 50% set qos policy shaper VIDEO class 10 match MULTICAST ip destination address 239.0.0.0/8 set qos policy shaper VIDEO class 10 priority 1 set qos interface eth1 egress VIDEO commitBandwidth monitoring:
- Regularly check usage via
show interfaces - Use external monitoring (Zabbix, Prometheus)
- Regularly check usage via
Hardware acceleration:
- Use hardware offloading if available
- Check
ethtool -k eth0for offload options
Scaling
Number of groups:
- IGMP Proxy supports hundreds of groups
- For thousands of groups, use PIM
Number of downstream interfaces:
- There is no hard limit
- Limited by the router’s performance
Bandwidth:
- Keep in mind that multicast is multiplied by the number of downstream interfaces
- A 10 Mbps stream over 5 interfaces = 50 Mbps from the router
Integration with Other Protocols
IGMP Proxy + OSPF
Scenario: IGMP Proxy on an edge router, OSPF for unicast routing.
# OSPF
set protocols ospf parameters router-id 10.0.0.1
set protocols ospf area 0 network 192.168.0.0/16
# IGMP Proxy
set protocols igmp-proxy interface eth0 role upstream
set protocols igmp-proxy interface eth1 role downstream
commitImportant: IGMP Proxy operates independently of OSPF.
IGMP Proxy + BGP
Scenario: BGP for the Internet, IGMP for multicast from the provider.
# BGP
set protocols bgp system-as 65001
set protocols bgp neighbor 203.0.113.1 remote-as 65000
# IGMP Proxy
set protocols igmp-proxy interface eth0 role upstream
set protocols igmp-proxy interface eth1 role downstream
commitIGMP Proxy + VPN (IPsec)
Scenario: Multicast over a VPN tunnel.
See Example 3 above - IGMP over VTI.
Key points:
- Use VTI (not a policy-based VPN)
- Configure alt-subnet for the remote network
- Increase the threshold for the VPN interface
IGMP Proxy + VRRP
Scenario: Redundancy with VRRP, IGMP Proxy on both routers.
Router 1:
# VRRP
set high-availability vrrp group 1 interface eth0
set high-availability vrrp group 1 vrid 1
set high-availability vrrp group 1 virtual-address 192.168.1.254/24
set high-availability vrrp group 1 priority 200
# IGMP Proxy
set protocols igmp-proxy interface eth0 role upstream
set protocols igmp-proxy interface eth1 role downstream
commitRouter 2:
# VRRP
set high-availability vrrp group 1 interface eth0
set high-availability vrrp group 1 vrid 1
set high-availability vrrp group 1 virtual-address 192.168.1.254/24
set high-availability vrrp group 1 priority 100
# IGMP Proxy
set protocols igmp-proxy interface eth0 role upstream
set protocols igmp-proxy interface eth1 role downstream
commitNote: Both routers run IGMP Proxy, but only the master is active.
Comparison with PIM
IGMP Proxy vs PIM-SM
| Characteristic | IGMP Proxy | PIM-SM |
|---|---|---|
| Complexity | Low | High |
| Configuration | Minimal | Extensive |
| Topology | Simple (tree) | Any (mesh) |
| Redundancy | Limited | Full |
| Scalability | Up to hundreds of groups | Thousands of groups |
| RP (Rendezvous Point) | Not required | Required |
| Multiple sources | Limited | Full support |
| CPU/Memory | Low | Medium |
| Use case | Edge networks | Core networks |
When to Use Which
IGMP Proxy:
- Home/office networks
- IPTV from a provider
- Simple topology (single source)
- Limited resources
PIM-SM:
- Data center multicast
- Multiple sources and receivers
- Redundancy is critical
- Complex topology
Diagnostics from the Client Side
Linux Client
Subscribing to a group:
# Install smcroute
sudo apt install smcroute
# Subscribe
sudo smcroute -j eth0 239.0.1.10
# View subscriptions
ip maddr show dev eth0Listening to multicast:
# Using socat
socat UDP4-RECV:5000,ip-add-membership=239.0.1.10:eth0 STDOUT
# Using VLC
vlc udp://@239.0.1.10:5000Sending multicast (testing):
# Send packets
echo "Test multicast" | socat - UDP4-DATAGRAM:239.0.1.10:5000,bind=:0Windows Client
Viewing multicast groups:
netsh interface ipv4 show joinsTesting with VLC:
- Open VLC Media Player
- Media → Open Network Stream
- Enter:
udp://@239.0.1.10:5000 - Play
Packet Capture
tcpdump for IGMP:
# All IGMP messages
sudo tcpdump -i eth1 -vv igmp
# IGMP with details
sudo tcpdump -i eth1 -vv -n igmp
# Save to a file
sudo tcpdump -i eth1 -w igmp-capture.pcap igmptcpdump for a multicast stream:
# A specific group
sudo tcpdump -i eth1 -n host 239.0.1.10
# All multicast
sudo tcpdump -i eth1 -n 'dst net 224.0.0.0/4'
# With a packet count
sudo tcpdump -i eth1 -n host 239.0.1.10 -c 100Wireshark filters:
igmp
ip.dst == 239.0.1.10
ip.dst >= 224.0.0.0 and ip.dst <= 239.255.255.255Automation and Scripts
Monitoring Script
Bash script to check IGMP groups:
#!/bin/bash
# igmp-monitor.sh
# Monitor IGMP groups
EXPECTED_GROUPS="239.0.1.10 239.0.1.11"
LOG_FILE="/var/log/igmp-monitor.log"
check_groups() {
local missing=0
for group in $EXPECTED_GROUPS; do
if ! sudo vtysh -c "show igmp groups" | grep -q "$group"; then
echo "$(date): WARNING - Group $group is missing" >> "$LOG_FILE"
missing=1
fi
done
if [ $missing -eq 0 ]; then
echo "$(date): OK - All groups present" >> "$LOG_FILE"
fi
return $missing
}
# Run the check
check_groups
# Print statistics
echo "Current IGMP groups:"
sudo vtysh -c "show igmp groups"Adding to cron:
# Every 5 minutes
*/5 * * * * /usr/local/bin/igmp-monitor.shAuto-restart Script
Script for automatic restart:
#!/bin/bash
# igmp-watchdog.sh
# Automatically restart IGMP Proxy
MAX_RETRY=3
RETRY_COUNT=0
check_igmp() {
# Check that IGMP Proxy is running
if pgrep -x "igmpproxy" > /dev/null; then
return 0
else
return 1
fi
}
while [ $RETRY_COUNT -lt $MAX_RETRY ]; do
if check_igmp; then
echo "$(date): IGMP Proxy is running"
exit 0
else
echo "$(date): IGMP Proxy not running, restarting..."
sudo /opt/vyatta/bin/vyatta-op-cmd-wrapper restart igmp-proxy
RETRY_COUNT=$((RETRY_COUNT + 1))
sleep 10
fi
done
echo "$(date): ERROR - Failed to restart IGMP Proxy after $MAX_RETRY attempts"
exit 1References and Resources
RFC Documents
- RFC 1112 - Host Extensions for IP Multicasting (IGMPv1)
- RFC 2236 - Internet Group Management Protocol, Version 2
- RFC 3376 - Internet Group Management Protocol, Version 3
- RFC 9776 - Internet Group Management Protocol, Version 3 (2025 update)
- RFC 4605 - Internet Group Management Protocol (IGMP) / Multicast Listener Discovery (MLD)-Based Multicast Forwarding (“IGMP/MLD Proxying”)
VyOS Documentation
Useful Tools
- igmpproxy - IGMP Proxy daemon (used by VyOS)
- smcroute - Multicast routing tool
- VLC - Media player with multicast support
- iperf - Network performance testing (multicast mode)
- tcpdump - Packet capture
- Wireshark - Packet analyzer
Community
Next Steps
After configuring IGMP Proxy, we recommend exploring:
- PIM (Protocol Independent Multicast) - for complex multicast topologies
- QoS (Quality of Service) - for prioritizing multicast traffic
- Firewall - for protecting multicast networks
- VPN (IPsec/WireGuard) - for multicast over tunnels
- VRRP - for redundancy
Conclusion
IGMP Proxy is an effective solution for distributing multicast traffic in simple topologies. Proper configuration of upstream/downstream interfaces, along with the use of alt-subnet and firewall rules, ensures stable operation of IPTV and video streaming in Yandex Cloud and VK Cloud networks.
Key points:
- One upstream, one or more downstream
- Alt-subnet for remote sources
- Firewall for IGMP and multicast
- QoS for prioritizing video traffic
- Monitoring of groups and bandwidth