Can't print from guest network/VLAN even w/ Access Control set.

Can't print from guest network/VLAN even w/ Access Control set.

Can't print from guest network/VLAN even w/ Access Control set.
Can't print from guest network/VLAN even w/ Access Control set.
2024-01-04 01:50:00 - last edited 2024-01-06 18:06:54
Model: EAP660 HD  
Hardware Version: V1
Firmware Version: 1.2.9

UPDATE 1/6/24 - ISSUE RESOLVED WITH STEPS BELOW FROM TP-LINK SUPPORT:

 

Including this information for anyone in the future struggling with a similar issue:

 

Please don't use Portal Do this instead;

1) Add the printer's IP Address in MAC group instead.
Go to Settings > Profiles > Groups > Create New Group >> select MAC Group and input the MAC Address & IP Address for the printer
2) Setup EAP ACL as follows (see attached picture)
Go to Settings > Network Security > ACL > EAP ACL
 

 

 

 

I am trying to allow a single printer to be accessible from Guest network. Printer is on Trusted VLAN 100, Guest network is VLAN 199. There is a firewall rule to allow the printer IP to be accessible from the Guest network.

 

I have the "Guest Network" option enabled for the Guest network. There is a static IP set for the printer and devices connected to the Trusted WiFi network can print without issue.

I created an exception under the Omada Controller -> Site Settings -> Authentication -> Portal -> Access Control -> Pre-Authentication Access menu for the printer, but it still doesn't work on its own. However, if I create and enable a Portal, suddenly it works. I do not want a portal.

 

Any ideas? Something the Portal being enabled is doing is fixing the issue. I don't understand what the deal is and I'm ripping my hair out here.

 

 


 

 

  0      
  0      
#1
Options
5 Reply
Re:Can't print from guest network/VLAN even w/ Access Control set.
2024-01-04 02:09:36

  @KMPLSV 

 

You can't tick the 'Guest' network box if you want the guests to have access to local resources, as guest mode prevents them from interacting with any private IP.  Instead, you'll have to create enough ACLs to emulate the behaviour...but you will lose the ability to isolate the users from each other.

<< Paying it forward, one juicy problem at a time... >>
  0  
  0  
#2
Options
Re:Can't print from guest network/VLAN even w/ Access Control set.
2024-01-04 04:13:55

  @d0ugmac1 

 

I use an OPNsense firewall/router. Guest and Trusted are on separate VLANs and there is a rule set to allow access to the printer from Guest VLAN. The setup worked properly with the UniFi setup so not sure what setting needs tweaking works. I'm going to try a support ticket with TP-Link.

  0  
  0  
#3
Options
Re:Can't print from guest network/VLAN even w/ Access Control set.
2024-01-04 12:43:49

  @KMPLSV 

 

As long as you don't tick the 'Guest Network' box for the TPlink AP/SSID, but map the SSID to the correct VLAN, it should behave as before.

<< Paying it forward, one juicy problem at a time... >>
  0  
  0  
#4
Options
Re:Can't print from guest network/VLAN even w/ Access Control set.
2024-01-04 13:29:14

  @d0ugmac1 

 

Correct. It does, but I want client isolation that the Guest box offers and it should work and it works when I enable the Portal, so something is making it work when Portal is enabled. Super frustrating to contemplate going back to UniFi over a damn printer. 

  0  
  0  
#5
Options
Re:Can't print from guest network/VLAN even w/ Access Control set.
2024-01-04 14:30:38

  @KMPLSV 

 

Can you not replace the Guest tickbox with a small group of ACLs in your pfSense?  Order of rules is usually important.

 

1. block Guest_DHCP_Pool <-> Guest DHCP_Pool (IP group) communication

2. allow Guest subnet <-> printer IP

3. block Guest subnet <-> Trusted subnet communication

 

 

 

<< Paying it forward, one juicy problem at a time... >>
  0  
  0  
#6
Options

Information

Helpful: 0

Views: 236

Replies: 5

Related Articles