The IP multicast has not been widely used by current internet service operators, and part of this relates to the nature of multicast, which is designed to allow any host to receive or send multicast traffic to the network. Internet service operators do not want to risk their network operation without sufficient control of the multicast sources and receivers and protection against the Denial of Service (DoS) attacks. In this paper we propose a scheme, which allows operators to add this control part to the existing networks. The solution is lightweight, independent of multicast routing protocols and it does not need modifications to the host interface, namely IGMP or MLD.