Secure Printing Across VLAN's Question?

CudaPrime
New here

Secure Printing Across VLAN's Question?

Hi all, have a configuration question concerning printing across VLAN's

 

I have two VLAN's, one I have my printers on (VLAN 7) using a static IP address (e.g. 192.168.7.10)

And one (VLAN 3) my users connect to via Ethernet or Wi-Fi that issues IP addresses via DHCP (e.g. 192.168.3.x)

All inter-VLAN traffic is blocked e.g. rule, 192.168.0.0/16 - Any / 192.168.0.0/16 - Any

I want the users to be able to print but I want the communication to be as secure as possible.

 

I currently have a layer 3 firewall run in place before my block rule that is set to allow all traffic from any device on VLAN 3 to communicate to the IP on VLAN 7, for example, 192.168.7.10/32 - Any / 192.168.3.0/24 - Any

I believe limiting the communication ports would secure this even more, for example a layer 3 rule like this,

192.168.7.10/32 - 631 / 192.168.3.0/24 - 631

 

I have not tested this single port assignment yet, so am not sure if other ports will be needed, one of the printers is a Fiery and I've heard they may have other port requirements. The syntax is something I'll have to research for rules that include multiple ports.

 

That aside for now, can I get some insight on how other have configured their environments to make printing communication across their networks reasonably secure?

 

Thanks in advance!

1 Reply 1
BlakeRichardson
Kind of a big deal
Kind of a big deal

I would create a firewall rule that only allows the clients to access the printer/s that are needed and I would lock the rule down to use whichever protocol you use for printing. 

 

If you want to ensure things are secure make sure you enable IP filtering on the printers themselves. 

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels