Apple AirPlay and AirPrint

Apple AirPlay and AirPrint

Apple AirPlay and AirPrint
Apple AirPlay and AirPrint
2025-04-29 15:49:29
Tags: #Apple AirPlay AirPrint
Model: OC200  
Hardware Version: V1
Firmware Version: 1.34.2 Build 20250110 Rel.75707 (Stable)

Hello,


AirPlay:

My AppleTV is in Home VLAN 30 /Network per LAN (wired)

also i have installed on win pc the app "AirServer" to share the iphone screen on win pc.

PC is conected with wifi to Home VLAN 30.

 

In this case setup with no mDNS and no acl rules.

I can reach both it with my iphone over wifi network Home VLAN 30 but i can also reach the airplay over my guest VLAN 50 network without do anything with mdns.
For me it's ok, but normaly it shouldn't work without mdns? 

 

AirPrint:

My Brother DCP-L3550CDW is in Home VLAN 30 /Network per Wifi

this work only in same vlan?

 

Actually i can not reach my Printer through the guest network VLAN 50,  does this works only in the same vlan?

I have tried to setup with mdns but without success.

 

AirPrint + WireGuard.
Does AirPrint works also over WireGuard VPN connection?


 

My Setup is

OC200 v1

1.34.2 Build 20250110 Rel.75707 (Stable)
5.15.8.12

ER605 v2.0

 

2.2.6 Build 20240718 Rel.82712

SG3428 v2.30

2.30.7 Build 20250307 Rel.72795

SG2210P v5.20

5.20.10 Build 20250307 Rel.72554

EAP653(EU) v1.0

1.1.3 Build 20250326 Rel. 59878

ER605 v2.0 OC200 V1 TL-SG3428 v2.0 TL-SG2210P v5.20 TL-SG105E v5 EAP245(EU) v4.0 (1x) EAP653(EU) v1.0 (3x) Modem - Fritz!Box 7490 (DSL 100 / DS Lite tunnel)
  0      
  0      
#1
Options
4 Reply
Re:Apple AirPlay and AirPrint
2025-04-29 16:40:19 - last edited 2025-04-29 16:40:34

  @nurix 

 

From what I've gathered those apple protocols mostly work under the same vlan/subnet. 

I can not teach anyone anything - I can only make them think - Socrates
  0  
  0  
#2
Options
Re:Apple AirPlay and AirPrint
2025-04-29 21:25:21

Ok now it work from another vlan but without any blocking acl rule

--> have to use Device Type = Gateway

 

I did found this guideline https://www.tp-link.com/us/support/faq/4294/

 

I want to block all traffic from guest to home

 

Step 3. Check ACL rules.

ACL rules can block mDNS forwarding between LAN interfaces. Check whether the Gateway/Switch/EAP is configured with ACL rules prohibiting different LANs from accessing each other.

mDNS uses UDP 5353 to transmit packets. If you want to configure an ACL rule to prohibit inter-LAN access and want mDNS to work properly,

create an ACL rule based on IP group to allow UDP 5353. For details, refer to the ACL User Guide.

 

Here is not clear which type of rule?

 

IP-Group or IP-Port-Group?

 

Did create IP-Port-Group with UDP but this not working????

 

Source 

192.168.50.0 / 24 Port 5353

 

Destination

192.168.30.30 / 32 Port 5353

 

Protocols

UDP

 

 

ER605 v2.0 OC200 V1 TL-SG3428 v2.0 TL-SG2210P v5.20 TL-SG105E v5 EAP245(EU) v4.0 (1x) EAP653(EU) v1.0 (3x) Modem - Fritz!Box 7490 (DSL 100 / DS Lite tunnel)
  0  
  0  
#3
Options
Re:Apple AirPlay and AirPrint
2025-04-29 21:53:05 - last edited 2025-04-29 21:53:43

  @nurix 

 

you can't open individual ports on Omada routers LAN to LAN, yes i know, it's crazy but that's how it is. you can close all traffic between vlan but as said you can't open individual ports.

you also can't use ip groups or ip port groups from LAN to LAN ACL. only network to network.

so what you are trying to do doesn't work with router ACL

 

 

  0  
  0  
#4
Options
Re:Apple AirPlay and AirPrint
2025-04-30 04:50:12 - last edited 2025-04-30 04:52:33

  @MR.S 

 

you are right.

 

I get it work only when i create IP-Group and i relay have to add tcp, only upd is not enough.

 

 

with tcp the printer is immediately available and is displayed directly as a printer

 

Without UDP, you first have to search for a printer.

And it show's your pronter as known printers
The printer is then found, but the supply level indicator isn't loaded, which is a sign that you can't print.

 

 

 

 

funny is that in tp link guideline, they create ip port group to solve this issue.

https://community.tp-link.com/en/business/forum/topic/620754

 

 

 

Question to tp link:

is there anything planned to get this worked as you explain in the guidelines?

Or do i do something complete wrong?

 

 

 

by the way maybe it's usefull, did found some other services with wireshark

_soundtouch._tcp.local
_pdl-datastream._tcp.local
_rdlink._tcp.local
_uscan._tcp.local
_raop._tcp.local
_googlecast._tcp.local
_viziocast._tcp.local
_amzn-alexa._tcp.local
_matter._tcp.local
_matterc._udp.local

ER605 v2.0 OC200 V1 TL-SG3428 v2.0 TL-SG2210P v5.20 TL-SG105E v5 EAP245(EU) v4.0 (1x) EAP653(EU) v1.0 (3x) Modem - Fritz!Box 7490 (DSL 100 / DS Lite tunnel)
  0  
  0  
#5
Options