Created on
06-18-2020
10:10 AM
Edited on
12-05-2024
01:45 AM
By
Jean-Philippe_P
Description
This article describes how to configure Apple Airprint between two subnets configured on different interfaces.
Scope
FortiGate.
Solution
Configuration.
edit "internal1"
set vdom "root"
set ip 192.168.1.1 255.255.255.0
set allowaccess ping https ssh snmp http fgfm ftm
set type physical
set device-identification enable
next
edit "internal7"
set vdom "root"
set ip 192.168.2.1 255.255.255.0
set allowaccess ping https ssh
set type physical
set device-identification enable
next
end
Configuring Multicast Policies:
config firewall multicast-policy
edit 1
set logtraffic enable
set srcintf "internal1"
set dstintf "internal7"
set srcaddr "all"
set dstaddr "Bonjour" --> Bonjour is used by Apple, please configure this as per requirements
set protocol 17
set end-port 5353
next
edit 2
set logtraffic enable
set srcintf "internal7"
set dstintf "internal1"
set srcaddr "all"
set dstaddr "Bonjour"
set protocol 17
set end-port 5353
next
end
Multicast policies can also be configured via GUI by enabling it in the System -> Feature visibility -> Multicast Policy.
Check if multicast routing is enabled or not:
config router multicast
set multicast-routing disable
end
Note:
If multicast routing is enabled, the traffic is received on the internal1 interface but not forwarded out of the internal7 interface.
The reason is that the destination IP, with the packets received on FortiGate, is part of the 'Local Network Control Block' and by default, it is not forwarded out of the L3 interface.
It is also necessary to have a normal IPv4 firewall policy between these 2 different interfaces as once the device is detected the traffic becomes unicast traffic.
Related article:
Technical Note : Extending AirPlay and AirPrint communication
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.