Skip to content
Avanet

Configure IGMP and MLD Snooping on Sophos Switch

IGMP and MLD Snooping prevent a Sophos Switch from forwarding multicast data unnecessarily to every port in a VLAN. IGMP Snooping monitors IPv4 group memberships, while MLD Snooping performs the same function for IPv6. The switch uses this information to create a list of ports that should receive multicast data and forwards the stream only to those ports.

Snooping is a Layer 2 function. It neither generates a multicast stream nor replaces multicast routing between VLANs. If a stream must cross a subnet boundary, an appropriate routing design is also required, such as a static multicast route on Sophos Firewall or PIM-SM.

⚠️ Important: An unsuitable IGMP/MLD version, a missing or incorrectly planned querier, or prematurely enabled Fast leave can interrupt reception. The general Status may apply across a switch or site; because Sophos does not document a precedence rule relative to the VLAN Status, editing only one VLAN row does not automatically constitute an isolated pilot. Before activation, you must therefore verify the possible scope and the presence of regular queries.

Quick procedure:

  1. For each VLAN, document the IP family, sender, group, receivers, multicast router, and existing querier.
  2. Open the switch in Sophos Fusion and handle IGMP and MLD separately under L3 protocols; according to Sophos, a site can also be selected for IGMP.
  3. Define the overall status and Report suppression; check the displayed Configuration source.
  4. Set the status, version, querier, timers, Fast leave, and Static ports for each VLAN.
  5. Observe the effective querier and regular general queries; then verify the group join, Group list, and payload traffic over the effective membership aging interval.
  6. If unrelated VLANs are affected, first restore the general Status; otherwise, restore only the latest change to the documented original values.

IGMP for IPv4, MLD for IPv6

TrafficMembership protocolSophos function
IPv4 multicastIGMPIGMP snooping
IPv6 multicastMLDMLD snooping

The functions are configured separately. Working IPv4 reception therefore proves nothing about IPv6, and vice versa. In a dual-stack VLAN, IGMP and MLD are validated as two separate test cases.

The Snooping Querier sends queries to which interested endpoints respond with Membership Reports. These reports provide the switch with the information it needs to build its forwarding list. Before enabling the querier, you must therefore determine whether another component in the VLAN already performs this role. The Sophos interface allows the querier to be enabled or disabled per VLAN, but it does not replace an inventory of the existing multicast design.

According to Sophos, Static ports are the ports connected to multicast-capable routers. Do not indiscriminately add receiver ports, all uplinks, or the sender’s ports here. The actual router path must be derived from the topology for each VLAN.

Prerequisites and change plan

The configuration in this article is performed through Sophos Fusion. The switch must therefore be registered and synchronised. Each switch managed through Sophos Fusion requires a valid Sophos Switch Support and Services subscription; without a valid subscription, the switch continues to operate and remains locally manageable, but changes through Sophos Fusion are not possible. The Fusion account used must have permission to modify the switch configuration of the relevant device or site. Local switch accounts and Fusion permissions are separate from each other.

Before making the change, also determine whether Sophos Fusion or the local interface has configuration authority. Not set delegates the relevant value to the local configuration and is therefore not a shortcut for an unknown target state. If the subscription or Fusion connection is unavailable during an incident, tested local management access must be available for diagnosis and rollback.

Before the change, record the following information for each affected VLAN:

  • VLAN ID and affected switch or site;
  • IPv4, IPv6, or dual stack;
  • multicast sender, group address, and application port of the test stream;
  • at least one controllable receiver and its physical switch port;
  • port connected to the multicast-capable router;
  • existing IGMP or MLD querier and its settings;
  • observed effective querier for each IP family, including source address, protocol version, and recurring General Queries;
  • required IGMP or MLD version of the participating devices;
  • current overall status and current VLAN status;
  • Report suppression, querier timers, Fast leave, Static ports, and the Configuration source of the general settings;
  • expected entry in the Group list, maintenance window, and rollback values.

If the general Status is to change from Disabled or Not set to Enabled, the preliminary assessment must cover every VLAN on which this could take effect on the selected switch. For each of these VLANs, determine the effective status, querier, version, and behaviour of the ports connected to multicast-capable routers. For a site-level change, this assessment applies to every included switch. If it has not been established which VLANs will become active as a result of the general status, stop the change.

A pilot genuinely limited to one VLAN is permissible only on a dedicated test/lab switch, where the manufacturer has confirmed the precedence rule for the target firmware, or after measurements on that exact firmware demonstrate that all non-pilot VLANs remain unaffected. Otherwise, plan, monitor, and make the activation reversible as a switch- or site-wide change, even if only one VLAN row is edited.

The VLAN and its port memberships must already work correctly. Snooping does not correct improper tagging. The Layer 2 design is covered in the guide Configure Sophos Switch VLANs securely.

For validation, the receiver application must actually be able to join a known group. A ping to a unicast address is not a multicast test. A saved configuration is not sufficient either: the decisive evidence is the learned group and the real stream at the intended receiver.

Compact test example

The following example illustrates only the mapping; replace the values with those from your own topology. In VLAN 30, 192.0.2.10 sends to the administratively assigned multicast group 239.1.1.10 on UDP port 5000. A single test device is connected to switch port 7. The multicast router and existing querier 192.0.2.1 are reachable through port 24.

Configure IGMP, not MLD, for this test. Port 24 belongs under Static ports as the router connection; the sender port and port 7 do not. Fast leave is suitable for port 7 only if exactly this single endpoint is directly connected there. Do not copy the version and timers from the example; derive them from the participating devices and the observed querier.

During validation, 239.1.1.10 must appear in the Group list after the join, the stream must remain stable on port 7, and it must not arrive unnecessarily on a controlled port without a receiver. The periodic querier check and membership aging interval are determined according to the Validation section.

Not set is not a distinct operating value

For Status, Version, Querier status, and Fast leave, Not set means that the setting configured locally on the switch is used. For status fields, the inherited local value may be enabled or disabled; for Version, the locally selected protocol version applies. Configuration source indicates the origin of the general snooping settings. Therefore, set explicit values for a target state defined through Sophos Fusion and verify their source after saving.

Controlled rollout

Follow these steps to keep activation under control:

  1. Record the original state at both configuration levels and the Configuration source of the general settings.
  2. If the general status is to be enabled, inventory every VLAN that could become active on every included switch. Do not proceed without a clearly established scope.
  3. Define a sender, a known group, and a controllable receiver for the test VLAN.
  4. For each IP family, use a packet capture or equivalent switch/router telemetry to observe the existing effective querier, its source address and protocol version, and recurring General Queries. A configured Querier status alone is not sufficient. If this evidence is unavailable, do not enable snooping or expand the rollout. The only exception is the planned initial use of the Sophos Switch as the querier; in that case, the check described below immediately after Save becomes the abort criterion.
  5. Configure only the required IP family; for dual stack, configure IGMP and MLD one after the other.
  6. Enable the general status only after the scope assessment has passed, and configure the test VLAN with the appropriate version.
  7. Enable the querier only according to the role plan. Multiple querier-capable devices may be configured; what matters is an observable elected or effective querier. If the Sophos Switch is intended to assume this role, observe its actual query source address and version in the VLAN after Save. Initially leave the timers at their documented original values.
  8. Leave Fast leave disabled during the initial test unless it is certain that exactly one endpoint is connected to the port.
  9. Select only the router connection under Static ports.
  10. Save, check the displayed values again, and verify the Configuration source for the general settings.
  11. Have the receiver join and perform the complete periodic validation described in the Validation section.
  12. Have the receiver leave in a controlled manner and observe the behaviour.
  13. Only after successful validation, including the membership aging interval, migrate additional VLANs one at a time.

Configure IGMP Snooping for IPv4

Open the following location in Sophos Fusion:

My Products > Switches > Switches > [Switch or site] > L3 protocols > IGMP snooping

Set the following fields in the sequence defined by the controlled rollout.

1. Configure general Settings

Under IGMP snooping > Settings, the following options are available:

  • Status
    • Enabled: Enable IGMP Snooping.
    • Disabled: Disable IGMP Snooping.
    • Not set: Use the locally configured status.
  • Report suppression: Limit the number of Membership Reports that the member sends to multicast-capable routers. Valid values range from 1 to 25.
  • Configuration source: Displays the origin of the general IGMP Snooping settings.

To enable IGMP Snooping, set Status: Enabled. For Report suppression, retain the documented original value unless a justified change has been planned and can be tested.

⚠️ Before the general Save: This change may affect the entire selected switch. At site level, it may affect every included switch. Select Save only after all VLANs that could become active through the general status have been recorded for every affected switch, their effective status, querier, version, and router-port behaviour have been verified, and the general rollback value has been documented. Abort the change if this evidence is unavailable.

Then select Save, reopen the saved values, and verify the Configuration source.

2. Edit the VLAN settings

In the VLAN table, open the planned VLAN using edit and set the following fields:

  • Status: Enabled, Disabled, or Not set;
  • Version: v1, v2, v3, or Not set;
  • Querier status: Enabled, Disabled, or Not set;
  • Fast leave: Enabled, Disabled, or Not set;
  • Querier interval (seconds): 60 to 600;
  • Response interval (seconds): 0 to 25;
  • Startup query counter: 2 to 5;
  • Startup query interval (seconds): 15 to 150;
  • Static ports: Ports connected to multicast-capable routers.

The Version must match the receivers and multicast router actually in use. Do not change it solely because another version has a higher number. Not set uses the local version and should therefore be selected deliberately only when that local value is known.

Set Querier status: Enabled only if the Sophos Switch is intended to assume the documented querier role in this VLAN. Do not optimise the timers speculatively: Querier interval defines the interval between general queries, while Response interval defines the response deadline for hosts. Startup query counter and Startup query interval control the number and frequency of IGMP queries after startup.

Enable Fast leave only if exactly one endpoint is connected to the relevant port. The switch then treats the port as a connection to precisely that endpoint. Multiple receivers may be connected behind another switch or another shared Layer 2 connection; leave Fast leave disabled there unless that design has been explicitly tested.

Under Static ports, select only the documented ports connected to the multicast-capable router. Finally, select Save.

Configure MLD Snooping for IPv6

For IPv6, open the separate location:

My Products > Switches > Switches > [Switch] > L3 protocols > MLD snooping

Set the following fields in the sequence defined by the controlled rollout.

1. Configure general Settings

Under MLD snooping > Settings, the following fields are available:

  • Status: Enabled, Disabled, or Not set;
  • Report suppression: Value from 1 to 25;
  • Configuration source: Displays the origin of the general MLD Snooping settings.

To enable MLD Snooping, explicitly set the status to Enabled. For Report suppression, retain the documented original value unless a justified change has been planned and can be tested.

⚠️ Before the general Save: This change may affect the entire selected switch. If the selected management scope includes multiple switches, the same assessment is required on every included switch. Select Save only after all VLANs that could become active through the general status have been recorded, their effective status, querier, version, and router-port behaviour have been verified, and the general rollback value has been documented. Abort the change if this evidence is unavailable.

Save with Save, then verify the displayed Configuration source.

2. Edit the VLAN settings

Open the intended VLAN using edit. The following options can be configured:

  • Status: Enabled, Disabled, or Not set;
  • Querier status: Enabled, Disabled, or Not set;
  • Querier interval (seconds): 60 to 600;
  • Version: v1, v2, or Not set;
  • Fast leave: Enabled, Disabled, or Not set;
  • Static ports: Ports connected to multicast-capable routers.

Sophos maps MLDv1 functionally to IGMPv2 and MLDv2 functionally to IGMPv3 for IPv4. This mapping helps with design but does not make the protocols interchangeable: MLD must still be used and tested separately in the IPv6 VLAN.

The same decision criteria as for IGMP apply to the querier, version, Fast leave, and Static ports: first clarify the existing querier role, select the version based on the participating devices, use Fast leave only for a port with a single endpoint, and statically select only genuine router ports. Then select Save.

Validation

Verify the effective querier and periodic state

Validation is performed separately for every tested VLAN and IP family. The configured Querier status or a single join is not evidence of a permanently effective querier. Before approval, a packet capture at a suitable measurement point or equivalent telemetry from the switch or router must show the following:

  1. General Queries from the elected or effective querier for this VLAN, including its source address and the IGMP or MLD version actually used;
  2. at least one additional General Query at the observed regular interval, not only Startup Queries immediately after saving;
  3. a Membership Report from the test receiver in response to a later General Query;
  4. the continuing entry in the Group list and an uninterrupted test stream throughout the applicable membership aging interval.

The observation period is not a universal fixed value. For IGMPv3 and MLDv2, derive it from the Robustness, Query Interval, and Query Response values actually advertised by the effective querier. The membership aging interval is calculated as Robustness Value × Query Interval + Query Response Interval. For older versions, use the values that are actually effective on the querier and target firmware. If the required parameters or the effective interval cannot be determined reliably, the test must not be considered successful.

If an external querier is intended to exist before the change, its periodic queries must be verified before snooping is enabled. If the Sophos Switch is instead to assume the querier role for the first time, document this in the change and rollback plan; immediately after Save, verify its source address, version, and recurring General Queries. If they do not appear or are incompatible, do not continue the rollout and restore the configuration according to the rollback plan. Multiple querier-capable devices may be configured; the requirement is not exactly one configured device, but an observable effective querier for each VLAN and IP family.

Verify group membership and payload traffic

The Group list under IGMP or MLD shows the detected multicast groups. Successful validation requires more than a visible entry:

  1. Document the original state of the Group list before the join.
  2. Start the receiver application and join the planned IPv4 or IPv6 group.
  3. Reload the Group list. The expected group must appear after the join.
  4. Start the test stream and verify the content, stability, and application functionality at the intended receiver.
  5. Verify that a port without an interested receiver does not receive the stream unnecessarily. Perform this negative test only with suitable measurement equipment or a controlled test device.
  6. During the membership aging interval determined above, observe a later General Query and the receiver’s response; then verify the Group list and stream again.
  7. Have the receiver leave. If Fast leave is enabled, pay particular attention to whether only the intended port with a single endpoint is affected.
  8. Repeat the test after a planned restart or resynchronisation if this exact behaviour is part of the change.

The Group list confirms detected membership but does not by itself confirm the end-to-end data path. Conversely, a briefly visible stream without a correctly learned group may indicate forwarding that is not yet stable or is too broad. Both observations must be considered together.

Configuration verification

For approval, document two elements together: first, the effective configuration state, including the overall and VLAN status, version, querier and timers, Fast leave, Static ports, Report suppression, and Configuration source; second, the operational evidence, including the query source and version, regular query interval, later Membership Report, Group list, and stable join, stream, and leave throughout the determined membership aging interval.

Recheck after firmware and topology changes

The Group list shows a dynamic operational state, not a permanent allowlist. Therefore, retest the join, Group list, payload traffic, and leave after changes to receivers, the multicast router, the VLAN path, or the protocol version, as well as after a firmware update. The same applies when configuration authority changes between local management and Sophos Fusion; for Not set, redetermine the currently effective local value.

Snooping remains limited to selective Layer 2 forwarding within the VLAN. It does not replace multicast routing, the generation or availability of the stream, or capacity planning along the sender, router, uplink, and receiver paths.

Troubleshoot by symptom

The Group list remains empty

  1. Verify that the receiver application has actually joined the correct group in the correct IP family.
  2. Check the overall status and VLAN status. Not set may inherit an unexpected local value.
  3. Check the Configuration source of the general settings and verify that the saved values are displayed after reopening the configuration.
  4. Match the IGMP or MLD version to the receiver and router.
  5. Determine whether a functioning querier exists in the VLAN. If the switch was planned as the querier, check its Querier status and interval.
  6. Check VLAN membership, tagging, and the physical receiver port.

The join initially works, but the group later disappears or the stream stops

  1. Use a packet capture or equivalent telemetry to verify whether General Queries from the expected effective querier are still arriving.
  2. Compare the source address and IGMP/MLD version of the observed queries with the documented role and version plan. An enabled Querier status alone is not operational evidence.
  3. Verify whether the receiver responds to a later General Query with a Membership Report.
  4. Compare the membership aging interval determined from the actually effective querier parameters with the time at which the group or stream was lost.
  5. If queries are missing or incompatible, stop the rollout and revert the latest change; do not alter timers experimentally.

The group is visible, but the receiver does not receive the stream

  • Ensure that the multicast sender, group, and application port match the test values.
  • Verify that the stream reaches the switch and that the receiver is listening on the same group and correct application port.
  • For traffic crossing VLAN boundaries, check multicast routing separately. Snooping does not create a route.
  • Compare Static ports with the actual port connected to the multicast-capable router.
  • Do not confuse IGMP and MLD; an IPv6 group does not appear because of an IGMP configuration.
  • Check the host firewall and receiver application before changing snooping timers.

The stream is still distributed to too many ports

  • Verify that snooping is effectively Enabled both globally and for the affected VLAN.
  • Check the Configuration source of the general settings; a visible Not set does not prove that the local function is active.
  • Verify that the expected group appears in the Group list and that the intended receiver receives the test stream.
  • Check Static ports for indiscriminately selected uplinks or receiver ports, and retain only the documented router connections.
  • Do not change Report suppression or timers as the first repair attempt. Check group learning, the VLAN, and the querier first.

Reception stops when another device leaves

  • Disable Fast leave on the shared port or restore it to the documented previous value.
  • Check whether another switch or multiple receivers are connected behind the port.
  • Reestablish the group with both receivers, then have only one receiver leave and verify the remaining stream.
  • Check the version and querier state if the behaviour persists with Fast leave disabled.

IPv4 works, but IPv6 does not

  • For IPv6, explicitly check MLD snooping and its VLAN table; IGMP applies only to IPv4.
  • Check the MLD version and querier separately.
  • Look for the IPv6 group in the MLD Group list, not in the IGMP list.
  • Test IPv6 multicast routing and the receiver application separately from the functioning IPv4 path.

After Save, the switch behaves differently than expected

  • Verify that the correct switch or site was edited.
  • Read the Configuration source of the general settings and compare the general and VLAN-specific values with the original state.
  • For Not set, determine the local value instead of repeatedly saving the same Fusion value.
  • Revert only the latest isolated change, then retest the join, Group list, and stream.

Rollback

Rollback restores the documented original values. Use Not set only when the local configuration is deliberately intended to apply again; it is not a general substitute for Disabled.

If changing the general Status affects an unrelated VLAN, the switch- or site-wide rollback path takes priority: immediately restore the general Status to its documented original value and select Save. For a site-level change, this applies to the affected management scope. Then validate the affected production VLANs using observed queries, the Group list, and a real stream. Only after this state is stable should individual VLAN options be investigated or restored.

If unrelated VLANs are not affected, perform the normal rollback step by step:

  1. Stop the test stream and document the final Group list, affected VLANs, and symptoms.
  2. In the affected IGMP or MLD VLAN, first restore the option changed most recently, such as Fast leave, Querier status, Version, timers, or Static ports.
  3. Set the VLAN Status to the documented original value: Enabled, Disabled, or Not set.
  4. If the overall status was part of the change, restore it to its previous value as well. Do not modify the other IP family or unrelated VLANs.
  5. Restore Report suppression to its previous value and select Save.
  6. Reopen the saved values and verify the Configuration source of the general settings.
  7. Have the previous production receiver join again and verify General Queries, the receiver’s response, the group list, and the stream for at least the previously determined effective membership aging interval.

If snooping is disabled completely, the selective forwarding configured here based on the learned port list no longer applies. This may cause multicast traffic to be distributed to more ports again and is therefore only a controlled temporary fallback, not a substitute for root-cause analysis. The change is complete only when the previous reception works reliably again, periodic queries and reports have been observed in the expected state, and the effective configuration source has been documented.