Skip to content
DnsLister Forum

Where domain hunters compare notes

Printer access across VLANs (v2)

I need to print across 2 of 5 VLANs – what am I missing?

The two devices to connect w/ high-level config are as follows:
1. work laptop – VLAN 3, DHCP, wireless LAN access
2. printer – VLAN 1, Firewalla Reserved IP, wired LAN access

The environment is:
1. Gear: FWP > Aruba 1930 (managed switch) > Aruba AP22 (poe AP)

  1. FWP config:
    VLAN 1 – internal devices (personal phones, kids tablets, Sonos, etc) – devices I own / control used by smart humans across whichever services we need. mDNS Relay is On.
    VLAN 2 – internal devices (NAS, Printer, etc) – devices I own / control which are 'resources' and have – mostly – dedicated uses with known services. Mostly I want to isolate these from VLAN 1 and/or the internet (which is easier across a VLAN than managing internet access per device).
    VLAN 3 – adult work devices (laptops, phones, etc) – devices I do not own or control which I want to isolate from VLAN 1/2. mDNS Relay is On.
    VLAN 4 – kid school devices (laptops) – like VLAN 3, devices I do not own or control which I want to isolate from VLAN 1/2
    VLAN 5 – guest devices – completely isolated from the LAN

  2. Rules to facilitate printer access:
    – Rule 1
    – Action: Allow
    – Matching: printer IP
    – On: VLAN 3
    – Direction: Outbound only
    – Schedule: Always

When Rule 1 was unsuccessful, I added
– Rule 2
– Action: Allow
– Matching: printer IP
– On: work laptop
– Direction: Bi-directional
– Schedule: Always

  1. LAN switch config (Aruba 1930):

Port 1
– use case: FWP 'uplink' to Aruba 1930
– Tagged @ all 5 VLANs
– Untagged @ none (default is "1")

Port 2
– use case: Aruba 1930 'uplink' to Aruba AP22
– Tagged @ all 5 VLANs
– Untagged @ none (default is "1")

Port 3 – Tagged – none
– use case: printer
– Tagged @ none (default is "1")
– Untagged @ VLAN 1

note: This is a follow-up to the first thread (https://www.reddit.com/r/firewalla/comments/1w41tw3/printer\_access\_across\_vlans/).

Source: r/firewalla · by /u/jsqualo2

Leave a Reply

Your email address will not be published. Required fields are marked *