KT 공유기를 빼고 EdgeRouter 4(ER-4)에 IPTV를 바로 연결하려면 IGMP Proxy와 멀티캐스트 방화벽 설정이 필요합니다. WAN(eth0)을 upstream, LAN(br0)을 downstream으로 두고, KT IPTV 멀티캐스트 대역과 IGMP를 WAN_IN·WAN_LOCAL에서 허용했습니다.
1. 배경
원래는 KT 공유기에 IPTV를 연결해 TV를 봤습니다. 이미 ER-4를 쓰고 있어서 불필요한 공유기를 빼기로 했는데, EdgeRouter에서 IPTV를 보려면 별도 설정이 필요합니다.

2. IGMP Proxy 설정
ER-4가 멀티캐스트를 받으려면 IGMP Proxy가 필요합니다. CLI에 접속해 설정 모드로 들어갑니다.
configure
WAN을 upstream, LAN을 downstream으로 지정합니다. 인터페이스 이름은 환경마다 다르니 맞게 바꿔야 합니다.
set protocols igmp-proxy interface eth0 role upstream
set protocols igmp-proxy interface eth0 threshold 1
set protocols igmp-proxy interface eth0 alt-subnet 0.0.0.0/0
set protocols igmp-proxy interface br0 role downstream
set protocols igmp-proxy interface br0 threshold 1
set protocols igmp-proxy interface br0 alt-subnet 0.0.0.0/0
upstream과 downstream은 사용자마다 다를 수 있으므로 각 환경에 맞게 설정해줍니다.
저장한 뒤 설정을 확인합니다.
commit ; save
# show protocols igmp-proxy
interface eth0 {
alt-subnet 0.0.0.0/0
role upstream
threshold 1
}
interface br0 {
alt-subnet 0.0.0.0/0
role downstream
threshold 1
}
3. 방화벽 설정
3.1 멀티캐스트 주소 그룹
방화벽을 통과시킬 KT IPTV 멀티캐스트 대역을 KTIPTV 주소 그룹으로 만듭니다.
set firewall group address-group KTIPTV address 233.13.231.0/24
set firewall group address-group KTIPTV address 233.14.173.0/24
set firewall group address-group KTIPTV address 233.15.200.0/24
set firewall group address-group KTIPTV address 233.15.220.0/24
set firewall group address-group KTIPTV address 233.18.158.0/24
set firewall group address-group KTIPTV address 233.19.187.0/24
set firewall group address-group KTIPTV address 233.115.200.0/24
# compare
[edit firewall]
+group {
+ address-group KTIPTV {
+ address 233.13.231.0/24
+ address 233.14.173.0/24
+ address 233.15.200.0/24
+ address 233.15.220.0/24
+ address 233.19.187.0/24
+ address 233.18.158.0/24
+ address 233.115.200.0/24
+ }
+}
3.2 WAN_IN 허용
set firewall name WAN_IN rule 30 action accept
set firewall name WAN_IN rule 30 protocol udp
set firewall name WAN_IN rule 30 destination group address-group KTIPTV
set firewall name WAN_IN rule 30 description "KTIPTV Multicast"
set firewall name WAN_IN rule 30 log disable
3.3 WAN_LOCAL 허용
set firewall name WAN_LOCAL rule 30 action accept
set firewall name WAN_LOCAL rule 30 protocol udp
set firewall name WAN_LOCAL rule 30 destination group address-group KTIPTV
set firewall name WAN_LOCAL rule 30 description "KTIPTV Multicast"
set firewall name WAN_LOCAL rule 30 log disable
3.4 IGMP 허용
set firewall name WAN_LOCAL rule 40 action accept
set firewall name WAN_LOCAL rule 40 protocol igmp
set firewall name WAN_LOCAL rule 40 log disable
set firewall name WAN_LOCAL rule 40 description "Allow IGMP"
3.5 기존 DROP 규칙 뒤로 이동
기존 DROP 규칙(rule 20)이 먼저 적용되지 않도록 번호를 100으로 바꿔 뒤로 보냅니다.
edit firewall name WAN_IN
rename rule 20 to rule 100
exit
edit firewall name WAN_LOCAL
rename rule 20 to rule 100
exit
3.6 저장
commit ; save
4. 확인
멀티캐스트 상태와 인터페이스별 멀티캐스트 송수신량을 확인할 수 있습니다.

멀티캐스트 상태

인터페이스별 멀티캐스트 송수신량
5. 정리
- EdgeRouter로 IPTV를 보려면 IGMP Proxy(upstream WAN, downstream LAN)가 필요합니다.
- KT IPTV 멀티캐스트 대역과 IGMP를 WAN_IN, WAN_LOCAL에서 허용해야 합니다.
- 새 규칙이 적용되도록 기존 DROP 규칙은 더 큰 번호로 옮깁니다.
참고
728x90
'Hardware > 네트워크 장비' 카테고리의 다른 글
| [TP-Link] T1700G-28TQ 스위치를 SNMP로 Zabbix에서 모니터링 (0) | 2022.10.14 |
|---|---|
| [EdgeRouter] ER-4를 SNMP로 Zabbix에서 모니터링 (0) | 2022.10.10 |
| [TP-Link] T1700G-28TQ 스위치에서 IGMP Snooping 설정 (0) | 2022.01.09 |
| [NETGEAR] GS724Tv4 스위치 LACP 설정 (0) | 2021.07.14 |
| [TP-Link] T1700G-28TQ 스위치 LACP 설정 (0) | 2021.07.14 |
서울
--:--:--
-전체 글
-카테고리
오늘 방문