Contributor
•
3 Messages
3800HGV-B in DMZPlus Mode with Hardware firewall and Motorola VIP2250
Hello,
I am having an issue with the setup in the subject line. I will detail below.
I have a 3800HGV-B in DMZPlus mode. I have a hardware firewall ( fortigate 60c), connected to the LAN side of the 3800 with the public IP address assigned to its WAN interface. This is the purpose of having the DMZPlus mode. Currently, everything in the network functions fine.
However, I am having an issue with the DVR ( VIP2250 ). It is recieving a DHCP address from my fortigate. I also set the Uverse DNS to be sent with the dhcp server. I know this is necessary. I am able to get the box to work but only for a few seconds. It will play just fine and then cut out. If i change the channel and put it back, it will then start working again but only for a few seconds. This happens on every channel.
I have adjusted MTU and some other settings. This has not remedied the situation.
Does anyone have any ideas or a similiar setup where the IPTV device is not connected directly to the 3800?
Thanks
Accepted Solution
Official Solution
JefferMC
ACE - Expert
•
36.9K Messages
13 years ago
You do not want to put a router or firewall between the RG and the STB/DVR. You need for the RG to perform DHCP for them, and most routers/firewalls will not properly handle the multicast traffic that AT&T is using for their IPTV.
Evidence of that is your watching experience. When you change channels, you initially get a unicast feed just for your TV. Within the next 10 seconds, a multicast feed is started and your STB tries to switch to it. Your picture fails at that point.
Are you that worried about protecting your STB's from external attack?
0
0
tim_saldivar
Contributor
•
3 Messages
13 years ago
JefferMC,
Thank you for the reply!
I use my fortigate for a VPN's and a few other functions including external network security. Thus, I prefer to have the firewall applicance to be attached to the external network.
Thanks for your comment!
0
0
JefferMC
ACE - Expert
•
36.9K Messages
13 years ago
Gotcha. I would just recommend that you segment the AT&T IPTV network from your "real" network. The only issues with that will occur when you want to mix worlds:
0
0
tim_saldivar
Contributor
•
3 Messages
13 years ago
JefferMC,
Thanks for the advice. What was really bothering me was not understanding what the issue was but, multicast explains it.
0
0