Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
KMart
New Contributor

Guest Wifi access, but allow printer access on LAN

Hello all!

 

I am working on a 60E with three FortiAPs.  

 

I am looking to create a special guest wifi network that has a separate subnet, but be able to access one or more printers on the local LAN.  Is this possible?  Creating the guest wifi if easy, but I cannot seem to get a policy to work.

 

Thank you,

 

Kelly

 

2 Solutions
Toshi_Esumi
Esteemed Contributor III

Should be a simple policy Guest_WiFi_Interface/Subnet->LAN/Printer_Addr_Group. Please show what you have now.

View solution in original post

Toshi_Esumi
Esteemed Contributor III

Since each user need to know IP on the printers, I would just statically assign IPs to them and create an address objects then include them in an address group. Then user the destination in the policy toward LAN interface. The tunnel mode WiFI SSID should become as an interface so you can use it as the policies source interface.

Then when someone on the SSID, the user should be able to ping the printers.

If not, you need to sniff (diag sniffer packet) then run flow debug (diag debug flow) to figure out what's wrong. 

View solution in original post

4 REPLIES 4
Toshi_Esumi
Esteemed Contributor III

Should be a simple policy Guest_WiFi_Interface/Subnet->LAN/Printer_Addr_Group. Please show what you have now.

KMart

I think I may have it.  I'm still new to Fortigates.  :)

 

I created a new tunneling SSID for guest + printing.  I had gone into device inventory and named the printer instead of creating it in addresses.  So I created a printer address, then created a policy of Guestwifiprint on incoming, internal on outgoing interface.  Source is all, destination is printer address object, schedule always and service all.  I also have a policy allowing the guestwifiprint out through the WAN for Internet access.

 

This should work, right?

 

Thanks!

Toshi_Esumi
Esteemed Contributor III

Since each user need to know IP on the printers, I would just statically assign IPs to them and create an address objects then include them in an address group. Then user the destination in the policy toward LAN interface. The tunnel mode WiFI SSID should become as an interface so you can use it as the policies source interface.

Then when someone on the SSID, the user should be able to ping the printers.

If not, you need to sniff (diag sniffer packet) then run flow debug (diag debug flow) to figure out what's wrong. 

KMart

Thanks for the help!  It is a remote site, so I will be able to test next week.

 

Kelly

Labels
Top Kudoed Authors