This isn't as dumb as it sounds at first glance, I promise! No, I'm not trying to print to a printer that is wirelessly connected to the same SSID, which would obviously be blocked by this setting.
I'm trying to set up a wireless network for guests to be able to print to one of our printers, which is wired to a "printers" VLAN. I've set up a tunnel-mode SSID with the relevant multicast firewall policies for mDNS and WSD/SSDP, unicast policies for IPP and RAW, and a Bonjour profile for printers.
So far, so good. iOS, Android, and Windows devices can all discover the printer and print. Until I enable the setting to block intra-SSID traffic, at which point none of them can see the printer anymore.
Is that setting simply incompatible with multicast forwarding, or what might be going on here? I really want it enabled since I don't want guest devices to be able to communicate with each other. Would an L3 firewall profile potentially work instead?
Source: r/fortinet · by /u/striving_sloth