Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mario_thenetworkguy
New Contributor

Auto Discovery Printers

 

I have a printer located in one VLAN and a macOS laptop connected to another VLAN.

The printer is connected via Ethernet, while the laptop connects through a FortiAP (Wi-Fi).


As both devices are on different VLANs, the laptop fails to automatically discover the printer and displays a “Check Internet Connectivity” message. However, when I manually add the printer’s IP address, it connects successfully. There is a firewall policy to allow traffic between thoses two VLANs (Any services).

It appears that the discovery packets (likely mDNS / AirPrint traffic) are not being forwarded between the two VLANs.

Can you please help how to solve this issue ? 

2 REPLIES 2
AEK
SuperUser
SuperUser

I guess the discover uses broadcast or multicast, by default is not allowed on FGT.

I didn't do that before but I think you can allow it with a multicast policy.

 

AEK
AEK
filiaks1
Contributor II

What @AEK  mentioned could be true but just to see what is blocked better do a capture and follow the traffic flow to see what needs allowing:

 

 

Using the packet capture tool | FortiGate / FortiOS 7.6.4 | Fortinet Document Library

Performing a sniffer trace or packet capture | FortiGate / FortiOS 7.6.4 | Fortinet Document Library

Debugging the packet flow | FortiGate / FortiOS 7.6.4 | Fortinet Document Library

 

 

If you see multicast then see Troubleshooting issues with multicast rou... - Fortinet Community

 

 

Also if during your investigation you see that GARP is used then maybe you will need proxy arp How Proxy-ARP works - Fortinet Community as I wonder the printer and PC being on different subnets/vlans to not be part of the issue. 

 

Also you need to get familiar with your printer as well as it could be not the firewall issue also why can't you just push the printer IP address through Active Directory policy to all PC? Better yet the DNS of the printer and if you have IPAM when the IP of the printer changes to change also the DNS record automatically if your printers gets IP from a DHCP this will be nice.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors