224 MES1000, MES2000 Ethernet Switches
2. Configure VLAN users (VID 100), multicast-tv VLAN (VID 1000, 1001), control VLAN (VID 1200):
console(config)# vlan database
console(config-vlan)# vlan 100,1000-1001,1200
console(config-vlan)# exit
3. Configure user's port:
console(config)# interface fa1/0/1
console(config-if)# switchport mode customer
console(config-if)# switchport customer vlan 100
console(config-if)# switchport customer multicast-tv vlan add 1000,1001
console(config-if)# exit
4. Configure uplink port by allowing transfer of multi address traffic, traffic of users and control:
console(config)# interface gi1/0/1
console(config-if)# switchport mode trunk
console(config-if)# switchport trunk allowed vlan add 100,1000-1001,1200
console(config-if)# exit
5. Configure IGMP snooping globally and on interfaces, add marking rules of users' IGMP reports:
console(config)# ip igmp snooping
console(config)# ip igmp snooping vlan 100
console(config)# ip igmp snooping map cpe vlan 5 multicast-tv vlan 1000
console(config)# ip igmp snooping map cpe vlan 6 multicast-tv vlan 1001
6. Configure control interface:
console(config)# interface vlan 1200
console(config-if)# ip address 192.168.33.100 255.255.255.0
console(config-if)# exit
Configuration of IGMP Query Authorization via RADIUS
The example describes the configuration of IGMP query authorization via Radius server. Switch IP
address—10.113.113.2, Radius server IP address—10.113.113.1, client MAC address—00:1B:21:4F:F8:1F,
range of enabled multicast groups: 233.7.0.0/16, client port—FastEthernet 1/0/1
Radius server (freeRadius) Configuration
1. '/etc/freeradius/clients.conf' file contents
client 10.113.113.0/24 {
secret = mestest
nastype = cisco
shortname = private
}
2. '/etc/freeradius/users' file contents
001B214FF81F Cleartext-Password := "001B214FF81F", NAS-PORT == 1, Framed-
IP-Address =~ "233.7.*.*", NAS-IP-Address == "10.113.113.2"
Switch Settings
console(config)# bridge multicast filtering
console(config)# vlan database