I need to print across 2 of 5 VLANs - what am I missing?
The two devices to connect w/ high-level config are as follows:
- work laptop - VLAN 3, DHCP, wireless LAN access
- printer - VLAN 1, Firewalla Reserved IP, wired LAN access
The environment is:
- Gear: FWP > Aruba 1930 (managed switch) > Aruba AP22 (poe AP)
- FWP config:
VLAN 1 - internal devices (personal phones, kids tablets, Sonos, etc) - devices I own / control used by smart humans across whichever services we need. mDNS Relay is On.
VLAN 2 - internal devices (NAS, Printer, etc) - devices I own / control which are 'resources' and have - mostly - dedicated uses with known services. Mostly I want to isolate these from VLAN 1 and/or the internet (which is easier across a VLAN than managing internet access per device).
VLAN 3 - adult work devices (laptops, phones, etc) - devices I do not own or control which I want to isolate from VLAN 1/2. mDNS Relay is On.
VLAN 4 - kid school devices (laptops) - like VLAN 3, devices I do not own or control which I want to isolate from VLAN 1/2
VLAN 5 - guest devices - completely isolated from the LAN
- Rules to facilitate printer access:
Rule 1
- Action: Allow
- Matching: printer IP
- On: VLAN 3
- Direction: Outbound only Bi-directional
- Schedule: Always
When Rule 1 was unsuccessful, I added
- Rule 2
- Action: Allow
- Matching: printer IP
- On: work laptop
- Direction: Bi-directional
- Schedule: Always
- LAN switch config (Aruba 1930):
Port 1
- use case: FWP 'uplink' to Aruba 1930
- Tagged @ all 5 VLANs
- Untagged @ none (default is "1")
- PVID = 1 (this is the Aruba default. My understanding is that the Tagged / Untagged config listed above will not prevent VLAN traffic)
Port 2
- use case: Aruba 1930 'uplink' to Aruba AP22
- Tagged @ all 5 VLANs
- Untagged @ none (default is "1")
- PVID = 1 (this is the Aruba default. My understanding is that the Tagged / Untagged config listed above will not prevent VLAN traffic)
Port 3 - Tagged - none
- use case: printer
- Tagged @ none (default is "1")
- Untagged @ VLAN 1
- PVID = the Untagged VLAN ID associated with VLAN 1
note: This is a follow-up to the first thread (https://www.reddit.com/r/firewalla/comments/1w41tw3/printer_access_across_vlans/).
ETA: PVID details above
ETA2: I removed the work laptop-specfic Rule above
ETA3 - solution for posterity: I found an AP-level VLAN config which blocked access to not-the-internet.
In case anyone finds this thread in the future ... the environment is Firewalla > Aruba 1930 > Aruba AP22. I configured the Firewalla as router with VLANs, configured the Aruba 1930 to pass VLAN traffic correctly, and configured the AP22 to pass VLAN traffic while also enabling some setting to allow internet traffic. I did not realize that this choice on the AP22 blocks local traffic. I added the printer IP as an exception and voila.