Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Reaching a Printer over vlan trunk

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    12 Posts 2 Posters 466 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tomic
      last edited by tomic

      Hi,
      i have a problem with my pfSense Netgate 4100 with 24.03-RELEASE (amd64) and I hope, that someone can give a solution for that.

      My netplan is
      Netplan.jpg

      Here are some screens of my pfsense configs.
      interfaces.jpg
      vlans.jpg
      vlan10_example.jpg
      firewall_rules.jpg

      Problem description:
      PC1 can’t reach Printer with Ports like 40/443 etc.. ICMP (ping) works.

      Any Ideas?

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @tomic
        last edited by

        @tomic why would you tag connection to printer - does the printer understand tags, did you set it for vlan 10 tag?

        The connection to your printer should be untagged, ie an access port in vlan 10. Yeah the connection from netgate would tagged if you carry more than 1 vlan to and from that switch. And trunk to access point makes sense if you have multiple vlans per ssid on the AP, etc.

        But to a single device like a printer it would be untagged almost always.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 2
        • T
          tomic
          last edited by

          @johnpoz thank you for your response
          The problem is also there if i connect the printer with the SSID with vlan10.
          But i will give it a try and connect the printer on an untagged vlan port of the switch.

          Another aspect of my problem is, that the cisco switch is also not reachable in other networks but from pfsense fw.
          PC (192.168.3.2x -----X----- Cisco Switch (192.168.2.2)
          Ping_client-to-switch.jpg

          pfSense (192.168.2.1 -----OK----- Cisco Switch (192.168.2.2)
          Ping_pfsense-to-switch.jpg

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @tomic
            last edited by

            @tomic to your cisco switch, is that the management IP or is that an svi on some other vlan?

            Did you set a gateway on your switch? Your not going to be able to talk to a device from another network if it has no gateway.. Also other issue could be mask is wrong on the switch, and it thinks your 192.168.3.x address local.

            No gateway is another possible issue with printers.. Is the IP set on the printer or via dhcp.. If it was connected to a tagged port it prob wouldn't get an IP via dhcp, etc.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • T
              tomic
              last edited by

              i included my cisco config
              running-config.txt

              i was not able to find an option, where i can set a gateway
              switch_IP_Config.jpg

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @tomic
                last edited by

                @tomic you would set it in routing

                routing.jpg

                Or with just the cli command

                from conf t
                ip default-gateway 192.168.9.253

                Where you would use your IP, which would be 192.168.2.1 I would guess

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • T
                  tomic
                  last edited by tomic

                  @johnpoz Thanks for the fast response - i tried the following, without success.

                  Here is the new route
                  Switch_route.jpg

                  Port VLAN Membership Table
                  vlan_membership.jpg

                  VLAN 10 Members
                  vlan10_membership.jpg

                  What i also tried:
                  I connected my pc with the the vlan50 port of the switch. My PC got an ip 192.168.50.22 correct. Ping from this pc to the printer 192.168.10.44 works, but 80/443 etc. doesn't work.

                  As you can see, the port (GE4) on the switch where the printer is connected has untagged vlan 10.

                  BUT: If i use my smartphone, which is connected to one of the Access Points in vlan10, i can open the ip of the printer in browser. So within vlan10 the communication works.

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @tomic
                    last edited by johnpoz

                    @tomic that route has zero to do with access to the printer.. That has to do with access to your switch for admin from another network

                    What are you firewall rules on interface your trying to access the printer from..

                    Your lan rules you posted - show that they have never even been evaluated.. See the 0/0 B in the states column

                    Does your printer have a gateway set - your not going to be able to talk to it if has no gateway.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    • T
                      tomic
                      last edited by tomic

                      What are you firewall rules on interface your trying to access the printer from..

                      • Allow any any on the LAN Interface and the specific vlan 10 interface
                        LAN_VLAN10_Firewall_Rules.jpg

                      At the moment, all Firewall rules are set to allow all.

                      The GW on the printer is set to 192.168.2.1. I also tried 192.168.10.1, which is also set on the netgate 4100.

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @tomic
                        last edited by

                        @tomic well if the printer has a 192.168.10 address the gateway sure wouldn't 192.168.2.anything

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • T
                          tomic
                          last edited by

                          @johnpoz as i described - i tried 192.168.2.1 and 192.168.10.1 as GW on the printer with the same result

                          johnpozJ 1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator @tomic
                            last edited by johnpoz

                            @tomic why you would of ever thought 192.168.2 would be an option is concerning..

                            Sniff on pfsense on the vlan 10 interface when you try and access the printer... Do you see pfsense send on the traffic, if so then its not a pfsense problem.

                            Also validate your printers mask is correct for your vlan 10 network, if its 192.168/16 and your trying to talk to it from say 192.168.2.x then the printer would think hey that is local and would never send the traffic back to pfsense to be routed back to your client trying to access the printer.

                            Your saying ping works - that points to maybe your using the wrong port to access the printer gui? Or it doesn't like remote access.. Can you access the printer gui from something on the vlan 10 network? To validate the gui is even working or enabled..

                            If that works, and you show sniffing pfsense sending the traffic - you could always source nat so printer thinks pfsense IP on its own network is talking to it.

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.