Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Reaching a Printer over vlan trunk

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    12 Posts 2 Posters 504 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator @tomic
      last edited by

      @tomic why would you tag connection to printer - does the printer understand tags, did you set it for vlan 10 tag?

      The connection to your printer should be untagged, ie an access port in vlan 10. Yeah the connection from netgate would tagged if you carry more than 1 vlan to and from that switch. And trunk to access point makes sense if you have multiple vlans per ssid on the AP, etc.

      But to a single device like a printer it would be untagged almost always.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 2
      • T
        tomic
        last edited by

        @johnpoz thank you for your response
        The problem is also there if i connect the printer with the SSID with vlan10.
        But i will give it a try and connect the printer on an untagged vlan port of the switch.

        Another aspect of my problem is, that the cisco switch is also not reachable in other networks but from pfsense fw.
        PC (192.168.3.2x -----X----- Cisco Switch (192.168.2.2)
        Ping_client-to-switch.jpg

        pfSense (192.168.2.1 -----OK----- Cisco Switch (192.168.2.2)
        Ping_pfsense-to-switch.jpg

        johnpozJ 1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @tomic
          last edited by

          @tomic to your cisco switch, is that the management IP or is that an svi on some other vlan?

          Did you set a gateway on your switch? Your not going to be able to talk to a device from another network if it has no gateway.. Also other issue could be mask is wrong on the switch, and it thinks your 192.168.3.x address local.

          No gateway is another possible issue with printers.. Is the IP set on the printer or via dhcp.. If it was connected to a tagged port it prob wouldn't get an IP via dhcp, etc.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • T
            tomic
            last edited by

            i included my cisco config
            running-config.txt

            i was not able to find an option, where i can set a gateway
            switch_IP_Config.jpg

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @tomic
              last edited by

              @tomic you would set it in routing

              routing.jpg

              Or with just the cli command

              from conf t
              ip default-gateway 192.168.9.253

              Where you would use your IP, which would be 192.168.2.1 I would guess

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • T
                tomic
                last edited by tomic

                @johnpoz Thanks for the fast response - i tried the following, without success.

                Here is the new route
                Switch_route.jpg

                Port VLAN Membership Table
                vlan_membership.jpg

                VLAN 10 Members
                vlan10_membership.jpg

                What i also tried:
                I connected my pc with the the vlan50 port of the switch. My PC got an ip 192.168.50.22 correct. Ping from this pc to the printer 192.168.10.44 works, but 80/443 etc. doesn't work.

                As you can see, the port (GE4) on the switch where the printer is connected has untagged vlan 10.

                BUT: If i use my smartphone, which is connected to one of the Access Points in vlan10, i can open the ip of the printer in browser. So within vlan10 the communication works.

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @tomic
                  last edited by johnpoz

                  @tomic that route has zero to do with access to the printer.. That has to do with access to your switch for admin from another network

                  What are you firewall rules on interface your trying to access the printer from..

                  Your lan rules you posted - show that they have never even been evaluated.. See the 0/0 B in the states column

                  Does your printer have a gateway set - your not going to be able to talk to it if has no gateway.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • T
                    tomic
                    last edited by tomic

                    What are you firewall rules on interface your trying to access the printer from..

                    • Allow any any on the LAN Interface and the specific vlan 10 interface
                      LAN_VLAN10_Firewall_Rules.jpg

                    At the moment, all Firewall rules are set to allow all.

                    The GW on the printer is set to 192.168.2.1. I also tried 192.168.10.1, which is also set on the netgate 4100.

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @tomic
                      last edited by

                      @tomic well if the printer has a 192.168.10 address the gateway sure wouldn't 192.168.2.anything

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • T
                        tomic
                        last edited by

                        @johnpoz as i described - i tried 192.168.2.1 and 192.168.10.1 as GW on the printer with the same result

                        johnpozJ 1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @tomic
                          last edited by johnpoz

                          @tomic why you would of ever thought 192.168.2 would be an option is concerning..

                          Sniff on pfsense on the vlan 10 interface when you try and access the printer... Do you see pfsense send on the traffic, if so then its not a pfsense problem.

                          Also validate your printers mask is correct for your vlan 10 network, if its 192.168/16 and your trying to talk to it from say 192.168.2.x then the printer would think hey that is local and would never send the traffic back to pfsense to be routed back to your client trying to access the printer.

                          Your saying ping works - that points to maybe your using the wrong port to access the printer gui? Or it doesn't like remote access.. Can you access the printer gui from something on the vlan 10 network? To validate the gui is even working or enabled..

                          If that works, and you show sniffing pfsense sending the traffic - you could always source nat so printer thinks pfsense IP on its own network is talking to it.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.