NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
cboling
May 21, 2019Tutor
Allow Multicast forwarding on NetGear M4300-8x8f switch
I need to be able to forwared IEEE802.1x. EAPOLs through my M4300, but Multicast is giving me problems. I was able to enable EAPOL flood mode on the Security -> Port Authentication setting, but since the START packet goes to a multicast/slow-protocol address, it never makes it through the switch.
If I use a packet generator and change the START packet destination MAC to an individual address or broadcast, it makes it through without any issues.
I have also disable IGMP snooping and rebooted as some other netgear devices had that suggestion for multicast, but it did not help out on the M4300
Any ideas?
On the 802.1x config page I have:
Admin Mode: Disable
VLAN Assigment Mode: Disabled
EAPOL Flood Mode: Enabled
My firmware version is recent: 12.0.7.12
6 Replies
cboling wrote:
I have also disable IGMP snooping and rebooted as some other netgear devices had that suggestion for multicast, but it did not help out on the M4300
Users typically create these problems because they tend to tick the "block unknown muticast" (guess because it sounds good and secure?) along with enabling IGMP snooping. I slowly start to feel this control should be renamed to "block unregistered multicast" or the like.
LaurentMa that's one for you!
- cbolingTutor
The M4300 does not have a specific option to block unknown multicast addresses.
Also, I modified my test application to generate an EAPOL Start message with a multicast address other than the standard 01-80-C2-00-00-03 multicast address (used 01-88-CC-00-00-03) and this multicast address makes its way through the switch.
So the problem appears to be the 'Flood EAPOL Mode - Enabled' lets the EAPOL EtherType (0x888E) through, but not the reserved multicast address. Perhaps some 'slow-protocol' multicast code in the switch since EAPOLs typicallly should typically be blocked/processed at the ingress MAC.
- LaurentMaNETGEAR ExpertHi cboling
Thank you for reporting this issue. We have several fixes in development for our M4300 series that address unknown Multicast handling and other IGMP enhancements. I would like to escalate your case to our QA, Tech Support and Engineering departments. I am sending you a private message with my email address, so that you can send me the tech-support file of your M4300-8X8F switch. To do so, GUI Maintenance /Exoort/HTTP File Export and select tech-support in the drop-down menu.
With this TS file, we'll have all logs and other debug outputs for understanding better the root cause. We are committed to a fix and we'll work with you with Engineering builds until we're sure the problem is solved.
Of course we'll report the results on the Community here.
Thank you,
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!