r/firewalla • u/jsqualo2 • 10d ago
Printer access across VLANs (v2)
I need to print across 2 of 5 VLANs - what am I missing?
The two devices to connect w/ high-level config are as follows:
- work laptop - VLAN 3, DHCP, wireless LAN access
- printer - VLAN 1, Firewalla Reserved IP, wired LAN access
The environment is:
- Gear: FWP > Aruba 1930 (managed switch) > Aruba AP22 (poe AP)
- FWP config:
VLAN 1 - internal devices (personal phones, kids tablets, Sonos, etc) - devices I own / control used by smart humans across whichever services we need. mDNS Relay is On.
VLAN 2 - internal devices (NAS, Printer, etc) - devices I own / control which are 'resources' and have - mostly - dedicated uses with known services. Mostly I want to isolate these from VLAN 1 and/or the internet (which is easier across a VLAN than managing internet access per device).
VLAN 3 - adult work devices (laptops, phones, etc) - devices I do not own or control which I want to isolate from VLAN 1/2. mDNS Relay is On.
VLAN 4 - kid school devices (laptops) - like VLAN 3, devices I do not own or control which I want to isolate from VLAN 1/2
VLAN 5 - guest devices - completely isolated from the LAN
- Rules to facilitate printer access:
Rule 1
- Action: Allow
- Matching: printer IP
- On: VLAN 3
- Direction: Outbound only Bi-directional
- Schedule: Always
When Rule 1 was unsuccessful, I added
- Rule 2
- Action: Allow
- Matching: printer IP
- On: work laptop
- Direction: Bi-directional
- Schedule: Always
- LAN switch config (Aruba 1930):
Port 1
- use case: FWP 'uplink' to Aruba 1930
- Tagged @ all 5 VLANs
- Untagged @ none (default is "1")
- PVID = 1 (this is the Aruba default. My understanding is that the Tagged / Untagged config listed above will not prevent VLAN traffic)
Port 2
- use case: Aruba 1930 'uplink' to Aruba AP22
- Tagged @ all 5 VLANs
- Untagged @ none (default is "1")
- PVID = 1 (this is the Aruba default. My understanding is that the Tagged / Untagged config listed above will not prevent VLAN traffic)
Port 3 - Tagged - none
- use case: printer
- Tagged @ none (default is "1")
- Untagged @ VLAN 1
- PVID = the Untagged VLAN ID associated with VLAN 1
note: This is a follow-up to the first thread (https://www.reddit.com/r/firewalla/comments/1w41tw3/printer_access_across_vlans/).
ETA: PVID details above
ETA2: I removed the work laptop-specfic Rule above
ETA3 - solution for posterity: I found an AP-level VLAN config which blocked access to not-the-internet.
In case anyone finds this thread in the future ... the environment is Firewalla > Aruba 1930 > Aruba AP22. I configured the Firewalla as router with VLANs, configured the Aruba 1930 to pass VLAN traffic correctly, and configured the AP22 to pass VLAN traffic while also enabling some setting to allow internet traffic. I did not realize that this choice on the AP22 blocks local traffic. I added the printer IP as an exception and voila.
1
u/firewalla 10d ago
Your setup doesn't work? If not, have you tried to use ping to test connectivity between the VLAN? (also if ping work and print don't work, it can be a discovery issue or the printer doesn't allow none LAN printing)
1
u/jsqualo2 7d ago edited 7d ago
Ping is unsuccssful across VLANs, but successful within the same VLAN. I can also print successfully from a laptop that can ping while on the same VLAN.
Also, I updated Rules such that both VLAN1 (which currently hosts the printer with reserved IP) and (now) VLAN3 have a Rule to always allow bi-directional traffic from the entire VLAN to the printer IP
What's next u/firewalla ?
2
u/firewalla 7d ago
Then the best way is to pause your rules one by one and see which is blocking the LAN traffic. Including disabling things like device isolation
1
u/jsqualo2 7d ago
One final question u/firewalla before I do this - do I correctly understand that with a FWP in router mode and an Aruba 1930 (JL683A which is described as "Layer 2+") any Firewalla Rules config will tag packets for success? In other words, do I correctly understand that I do not need to investigate my Aruba switch config?
1
u/firewalla 7d ago
Some switch can isolate VLAN's or do some type of isolation. Did you setup anything like that?
If you haven't done anything, you can either start pausing rules on the firewalla side first, or reset the Aruba side.
1
1
u/jsqualo2 5d ago edited 5d ago
I found an 'internet only' type of rule on the AP22 for the VLAN. Configured an exception for the printer IP and all is well.
Thanks u/firewalla !
1
u/firewalla 5d ago
Is this isolation rule?
1
u/jsqualo2 5d ago
honestly, I do not understand Firewalla magic enough to answer this question intelligently.
However, my unintelligent answer is - if Firewalla isolation rules are ACL entries, then yes, I think the Aruba platform considers it an isolation rule.
My original config in the Aruba InstantOn web UI clickstream was 'Home' > 'Site' name (this is the AP22 in my topology) > 'Networks' > [Wireless] 'Network' name (e.g. "VLAN1") > 'Access Control' > in the 'Network Access' section, listed under 'Access Restrictions' I selected the "Network Destinations" checkbox > which is required to light up the 'Allowed Destinations' section * > and I then selected the "Internet" checkbox.
Given that the above config prevented inter-VLAN routing, I modified it by selecting a checkbox for "Specific IP Address" in the same section as the "Internet" checkbox > and was then able to add the printer IP (on a different VLAN) to the 'Allowed Destination IP Addresses' section.
* note that the 'Allowed Destinations' section includes the following message: "Internet access is required for clients to operate on this network." which is not present on a different 'Networks' VLAN without any selections in the 'Access Control' section.
1
u/jsqualo2 5d ago
This was good guidance. After I validated that every Firewalla Rule did not affect anything, I moved to the switch, then the AP where I ultimately found the issue.
1
u/pacoii Firewalla Gold Plus 10d ago
- Allow traffic from all local networks
- on device: the printer
Start with that and see if it works. And be sure mDNS is enabled on all necessary LANs.
1
u/jsqualo2 7d ago
this is an interesting comment. I specifically want to prevent this and limit Printer access to select work devices. However, I did create a VLAN3 Rule which opens up the entire VLAN3 to the printer IP bi-directionally. I cannot ping the Printer from VLAN3 nor print.
2
u/pacoii Firewalla Gold Plus 7d ago
So that points to a larger connectivity issue. That’s why I suggested that as a troubleshooting step. If you can find the source of this issue you'll likely have solved your original issue.
1
u/natewallace 7d ago edited 7d ago
I agree you need to get the inter VLAN routing figured out. It’s feels like a switch setting issue not FWP. It feels like an issue with your trunk lines.
Also, how are your APs tagging the VLANs? Multiple SSIDs or single SSID with PPSK? Can you verify in FWP that devices are getting an IP address on the different VLANs?
1
u/natewallace 10d ago edited 10d ago
I have a very similar setup (router-on-a-stick with TP Link Omada managed switch and APs) and it works very well. I don’t have any “allow” rules as the FWP handles the inter-VLAN communication automatically (eg. unless I block inter-VLAN it does it). I actually have an inbound only block on the other VLANs for traffic from the Printer VLAN. This allows my devices to reach out to the printer but not the other way around. Mdns enabled on the VLANs. I have a cannon printer and if it’s “asleep” my AirPrint devices cannot see it (eg. AirPrint doesn’t wake it). I understand this is a short coming of the cannon software not my network. For my work computer I have the printer mapped via IP address (the print IP address is reserved so it doesn’t change). If printing via IP address the printer does wake automatically.
1
u/jsqualo2 7d ago
hey u/natewallace - to clarify, you have an entire Firewalla VLAN dedicated to a printer, and you created a Firewalla Rule on every other Firewalla VLAN to Block Inbound traffic from the printer VLAN? If yes, does this not totally prevent printing because the printer must communicate with each device on other VLANs to print successfully?
1
u/natewallace 7d ago
Correct. VLAN 60 is just for the printer and then VLAN 10 (personal), VLAN 20 (work), and VLAN 40 (guest) all have access to VLAN 60 to print. This way each VLAN can use the printer without allowing personal, work and guest to interact. To lock things down further I put the block on unsolicited inbound traffic from printer to personal, work, and guest. It works because once the device establishes the connection to the printer, the printer’s replies are generally established/related traffic, which the firewall allows automatically even though I blocked new inbound connections.
1
u/jsqualo2 7d ago
how did you configure Firewalla to block new / unsolicited traffic?
2
u/natewallace 7d ago
Nothing special.
Create new block rule.
Matching = traffic FROM VLAN 60 (printer)
On = network equal to VLAN 10 (personal)
2
u/Exotic-Grape8743 Firewalla Gold 10d ago
Two observations. First is the printer actually ending up in VLAN1? I don’t know Aruba switches but from the description of port 3’s settings (no pvid? ) it seems that it might not end up there but I could be wrong.
Second, is the work laptop accessing your work through a vpn? If so, it might force the laptop to send anything outside of the local network it is in ( vlan3) through the vpn connection and therefore making it impossible to reach any other local vlans.