Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

One Printer, Two V-lans?

Posted on 2013-01-07
5
Medium Priority
?
358 Views
Last Modified: 2013-01-14
Okay so I have a Server 2011 SBS. This has all of our print shares on it.

We have two networks:

Normal: 192.168.20.0 /24  vlan 20
Guest: 192.168.30.0 /24     vlan 30

Printer is on: Normal: 192.168.20.10 vlan 20

I want to share this printer between both of these networks and vlans, so both the guest and normal users can print to it.

We have a Cisco ASA 5510, and cisco 2960 switches.

The Guest network is actually used for on our Aruba wireless network.

I'm a bit of a noob for this, any help?
0
Comment
Question by:Pancake_Effect
5 Comments
 
LVL 4

Accepted Solution

by:
tpitch-ssemc earned 500 total points
ID: 38752567
I think you'd have to have a printer that supports trunking. I don't know that such a thing exists. Does the printer have a USB or Parallell port? If so, get a Jet Direct (or other print server device) and connect to it via that port. Then you can put the Jet Direct print server on the Guest VLAN.
0
 
LVL 37

Assisted Solution

by:Neil Russell
Neil Russell earned 500 total points
ID: 38752579
Best solution is to put your Printer on a third VLAN and ensure that Both the other 2 VLANS can talk with that new VLAN.
0
 
LVL 12

Assisted Solution

by:DLeaver
DLeaver earned 500 total points
ID: 38752601
You could add a static route between the vlans to allow printing traffic to go to the printer and then add an acl to prevent any unauthorized access outside of the printer.
0
 
LVL 20

Assisted Solution

by:rauenpc
rauenpc earned 500 total points
ID: 38752727
In most cases, the guest vlan is an interface on the 5510, even if all traffic goes through another device like a wireless controller. The most simple config method is to give the guest interface a lower security rating than the inside so that, by default, guests cannot access the inside network. The security rating on guest is higher than the outside/internet interface so that they can, by default, access the internet. Usually, when guest needs to access a small portion of the inside network for things like DNS, DHCP, or printers, you would just need to explicitly allow that traffic on the ASA's guest interface. Depending on the OS version on the ASA, you may need to configure a NAT/NONAT to allow the traffic to get through as well. I assume they are, but make sure all printers to be accessed by guest are statically configured.

If you don't know how to configure the ACL and/or NAT, post a scrubbed config of your firewall and we can probably figure out what is needed.
0
 
LVL 4

Author Closing Comment

by:Pancake_Effect
ID: 38774915
Thanks everyone for the feedback. I'm thinking I'm going to talk to our network engineer about it. It seems like the third vlan or the guest network might be the easiest route. Again thanks!
0

Featured Post

 The Evil-ution of Network Security Threats

What are the hacks that forever changed the security industry? To answer that question, we created an exciting new eBook that takes you on a trip through hacking history. It explores the top hacks from the 80s to 2010s, why they mattered, and how the security industry responded.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Make the most of your online learning experience.
This month, Experts Exchange’s free Course of the Month is focused on CompTIA IT Fundamentals.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…

877 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question