Install the app
How to install the app on iOS

Follow along with the video below to see how to install our site as a web app on your home screen.

Note: This feature may not be available in some browsers.

Mesh, VLANs and Firewall Rules

21
10
NAS
DS920+, DS215j
Router
  1. RT6600ax
Operating system
  1. Windows
Mobile operating system
  1. Android
I have an Epson ET-8550 printer connected to a VLAN called IoT. Our PCs and laptops connect to their own secured VLAN ("PCPN"). I have firewall rules set up in SRM 1.3.2 that allows devices on PCPN to print to the printer on IoT - and it works fine. However there's an issue.

The printer is in the same room as a Synology mesh point - a WRX560 with the lastest version of SRM installed - to which the printer connects to the IoT VLAN wirelessly. A Windows 11 laptop used in the same room as the printer connects wirelessly to the PCPN VLAN also through the WRX560. But when I try to print from the laptop to the printer, it fails, saying the printer isn't available. However if I move the laptop to the room that has the main Synology router in it (an RT6600ax) the laptop connects to the PCPN VLAN through that router, and it will print on to the ET8550 (still wirelessly connected to the IoT VLAN through the WRX560 elsewhere in the house) with no problem. It appears that the firewall rules don't get processed if both the laptop and the printer are connected to their separate VLANs through the WRX560.

Is this expected behaviour? Perhaps a Synology "quirk"? beyond taking the printer off the IoT VLAN and putting it on to the PCPN VLAN so no firewall rules are needed I can't think of any other solutions.

Advice greatly appreciated - thanks.

This post includes affiliate links. As an Amazon Associate, SynoForum.com may earn a commission if you make a purchase — at no extra cost to you.
It helps support our community! Learn more...

 
How are you connecting the back haul / uplink between the RT6600ax and WRX560? If it’s wirelessly then it should work, likewise if they are wired directly. But if you have used a switch in between then that could be the issue. It would need to be a managed switch with VLANs configured. Then also firewall rules on the RT6600ax that control inter-VLAN connections.
 
The WRX560 is connected to the RT6600ax by ethernet - using the 2.5 Gbps sockets on both units. The connection is direct - no switches - just a single cable. The firewall rules work - as long as the laptop connects to the RT6600ax and not the WRX560 (to which the printer is connected wirelessly). The socket on the RT6600ax is configured as a trunk port.

I can ping the printer from the laptop through the WRX560, but not reliably - 1-2 pings out of four work; the others time out. Connected to the RT6600ax pinging works every time and more quickly.
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

Oh My! I must still be tired from the multiple flights!!! 👍 Thank You! QC Revision. Connects via QC on...
Replies
4
Views
60
I'm finding that if I have a firewall rule: TCP/IP ALLOW, Source IP of Router, to ALL destinations.... and...
Replies
0
Views
178
Do have 2 other routers on LAN. (Neither Synology): One is in garage, wired, at .20, And is a 5Ghz WIFI...
Replies
9
Views
348
Well make sure you don’t have a time server issue before update. (He said - based on experience!) Now...
Replies
11
Views
907
Yes, but if you go your way, you get no feedback! I don’t see it as better control at all, unless it had...
Replies
6
Views
568

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending content in this forum

Back
Top