Quote from: sjjh on July 31, 2026, 07:17:49 PMObviously negating 10.0.0.0/8 also catches multicast 224.0.0.251.Sure.
QuoteThus I'm wondering what is best practice?Should work. So why not?
- Adding another rule covering mDNS/mutlicast and more than one interface (to make it a global rule) and moving it above the allow internet rule
QuoteShould work as well, but requires a following rule, which allows mDNS.
- Altering the allow internet rule to not match mDNS/multicast (not sure how)
Quote from: nero355 on July 31, 2026, 12:53:46 PMAs someone who really hates mDNS forcing devices like that I would like to suggest the following :While I do understand your rationale and agree with your dislike, I'm still hoping that it should be easier and less maintenance to allow mDNS between two VLANs than administering yet another device on the net.
- Setup a CUPS Printer Server by using something like a Raspberry Pi 2B/3B or a small Intel Atom NUC running Linux.
Quote from: julsssark on July 31, 2026, 03:49:55 PMUse Firewall->Log Files->Live View and watch traffic going to and from the printer.That might have brought me one step closer. I activated logging for all rules on the firewall. One hit (using port 5353) caught my eyes, as it was passed by a rule I didn't have on my mind: We're using following rule to allow outgoing internet traffic: