Solved

Sharing printer between to VLANs using Netgear ProSecure UTM25

Posted on 2013-06-27
20
876 Views
Last Modified: 2013-07-29
Hello,

I am having issues in sharing a printer used on VLAN1 (Static IP LAN) with VLAN2 (DHCP Wireless mesh network). Both VLANs have intervlan routing enabled as well. Here is  the current setup. What am I doing wrong? The printer's IP is 10.0.0.209. I would like wireless users on VLAN2 be able to print to it.

settings
0
Comment
Question by:be1ieve1111
  • 8
  • 8
20 Comments
 
LVL 17

Expert Comment

by:lruiz52
ID: 39282989
From looking at the attachement you have both Port 1 and 2 as members of both vlans. that may be your issue.
0
 

Author Comment

by:be1ieve1111
ID: 39285121
I have since changed the membership for VLAN to port 1 and VLAN2 to port 2 and it still did not make a difference. Thanks for you input!
0
 
LVL 6

Expert Comment

by:pgstephan
ID: 39303451
Hi mate, did you enable InterVLAN routing for your "Wireless" VLAN?
Also, can you do me a favour and try to ping the 10.0.0.254 from any machine in your Wireless VLAN?
Can you also try to ping 10.0.255.255 and 20.0.255.255 in both VLANs. I want to see if you have any problem bridging between these VLANs.

Can you also show us a snapshot of the "edit" action in your VLAN rules tab?
I doubt the VLAN rules policy, it's not looking very right... I would expect it to do filtering based on VLANs rather than IP addresses.

Port the snapshot and I'll tell you what exactly is wrong.
0
 

Author Comment

by:be1ieve1111
ID: 39308290
pgstephan, Thanks for your response!

I enabled interVLAN routing for both VLANs. (Attached screenshots)

I can ping 10.0.0.254 via CMD without issues on wireless, but I cannot access it via the internet browser while on wireless.

10.0.255.255 and 20.0.255.255 cannot be reached by either VLAN. I don't think there is anything at those addresses?

Also adding the screenshot of the two rules I made for the printer at 10.0.0.209 on VLAN1
Untitled.png
0
 
LVL 6

Expert Comment

by:pgstephan
ID: 39309151
Hi mate,
That means the problems is solved, since you're able to ping across from the wireless VLAN.

You probably have a proxy set in your web browser that's why you can ping 10.0.0.254 but you can't access it from the browser (try clearing all proxy settings in your browser).

10.0.255.255 and 20.0.255.255 will not be reached anyway (they're both broadcast IP addresses). All I needed was to see if the broadcast domain is really limited to your VLAN (no vlan leaking between the 2).

In the Edit VLAN-VLAN service, you need to add another rule with the Destination VLAN user as (10.0.0.209). Because traffic is bidirectional right? So you had from the printer, now you need to allow a rule for the "to" the printer.

Let me know how it goes.
0
 

Author Comment

by:be1ieve1111
ID: 39311226
Hey,

Well, as far as the VLAN rules go, If you look at my picture in last port, I have 2 rules. One below the first. One is to 10.0.0.209 from ANY and one to ANY from 10.0.0.209.

I also cleared all proxy settings and I still cannot connect to 10.0.0.209 or 10.0.0.254. When wired onto VLAN1 I can connect 10.0.0.209 and it shows real time printer use. I used both IE and Firefox with cleared proxy settings but I wasn't able to connect to either via wireless.

Again, thanks a lot for all your help!


EDIT: I think I was mistaken earlier about being able to ping 10.0.0.254 via wireless. I just tried to  ping it and got 100% loss and no changes were made to anything.
0
 
LVL 6

Expert Comment

by:pgstephan
ID: 39313513
I'll ignore the fact that you can't manage your device from the Wireless VLAN (this could be a management setting where you can only manage the box from the main VLAN).

This is now looking like your printer's default gateway is not correct, so the problem might be in the return traffic from the printer.

How does your printer get its IP address? Is it static or dynamic through DHCP?

I'd recommend you put a static entry for the printer in your DHCP and reconfigure the printer to receive its IP address via DHCP.
If it's static, then make sure the default-gateway on the printer is set to the router's routed interface in the printer VLAN.

Let me know how it goes, I'm quite interested to fix this challenge...
0
 

Author Comment

by:be1ieve1111
ID: 39314490
Everything on VLAN1 is assigned static IP addresses as well as the printer. I am attaching picture of the printer's tcp/ip settings. I am going to add VLAN rules for a different printer to make sure it's my network settings and not the printer itself. The printer has to remain static since all the PCs on VLAN1 are setup to look for it at 10.0.0.209.

The printer in question was a OCE printer, I also added VLAN rules for a HP4000 printer on 10.0.0.210 and I still wasn't able to connect to it via wireless.

Also is it okay if both VLANs are on the same subnet?  255.255.0.0
20130710-090657.jpg
0
Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

 
LVL 6

Expert Comment

by:pgstephan
ID: 39314506
Yes, there is no problem with both VLANs to have the same subnet mask.

Can i ask you please to go in the VLAN rules and click on the "edit' bottom and show us a snapshot of the input? Thx
0
 
LVL 6

Expert Comment

by:pgstephan
ID: 39314544
Can you show me the "LAN Settings" tab for the Wireless VLAN? Thx
0
 

Author Comment

by:be1ieve1111
ID: 39314558
pgstephan,

Here are all 4 VLAN rules in edit mode!
Untitled.png
0
 
LVL 6

Expert Comment

by:pgstephan
ID: 39314625
Can you show me the 'advanced' tag in the routing section?

This is a layer-3 problem, I can't believe that it took us that long to nail it down!
0
 
LVL 6

Expert Comment

by:pgstephan
ID: 39314640
Under the Network Config, can you send me the snapshot of the Routing tab??? and WAN Settings...
There will probably be something wrong in the Routing tab :D
0
 

Author Comment

by:be1ieve1111
ID: 39314771
Thanks again for your help! Here it is.
Untitled.png
0
 

Author Comment

by:be1ieve1111
ID: 39364774
I've requested that this question be deleted for the following reason:

No answer
0
 
LVL 6

Accepted Solution

by:
pgstephan earned 500 total points
ID: 39361355
Mate,
Can you please add a new rule under the VLAN rules as follows:
Source: ANY
Destionation; ANY

Also TRY THESE 4 RULES (if they work I'll probably be able to explain it):
(I'm not sure what the vlan interface is for the wireless vlan, if it's not 20.0.0.254, please swap it with the right one below):

Source: ANY
Destination: 10.0.0.254

Source: 10.0.0.254
Destination: ANY

Source: 20.0.0.254
Destination: ANY

Source: ANY
Destination: 20.0.0.254
0
 

Author Closing Comment

by:be1ieve1111
ID: 39364775
Thanks for all your help!
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

Suggested Solutions

Microservice architecture adoption brings many advantages, but can add intricacy. Selecting the right orchestration tool is most important for business specific needs.
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
Viewers will learn how to properly install and use Secure Shell (SSH) to work on projects or homework remotely. Download Secure Shell: Follow basic installation instructions: Open Secure Shell and use "Quick Connect" to enter credentials includi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now