Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Vlans & Cisco AP - browsing computers

Status
Not open for further replies.

tw09873

MIS
Oct 24, 2012
2
US
I have a Cisco 1138AG AP directly connected to a Fortigate 80c. I have two vlans on the AP, one for employees, one for guests. On the Fortigate I have firewall policies set for the employee vlan to access the internal LAN and the internet, and the guest vlan to only access the internet. I also have a reverse policy allowing the internal LAN to access the employee vlan. Everything is working fine, however when connected to the employee vlan, I cannot view/browse the computers of the internal LAN, and vice versa. I can ping them and manually navigate to them by IP address, but they don't show up as being "broadcasted" in the windows Network. Any way to configure this (to allow employee vlan users to browse internal LAN computers through Network)?

Thanks!
 
You need to read up on WINS and Microsoft networking between subnets/networks.....

Andy
 
Thanks for the nudge. Got a WINS server going on my Samba box, configured the Fortigate to hand out its IP to employee vlan/subnet users through dhcp. Hit and miss if users can browse the entire workgroup, but at least they can resolve names.

Notable articles:

Thanks again!
 
Yep - Hit and miss is probably a good desription.... In a typical wired environment you are supposed to keep at least two machines that are 'Browse Master' capable switched on permanently per subnet/broadcast domain. Clients will use the Browse Master to create the network browse list. In a wireless environment where hosts are more transient this is obviously a bit more tricky...
Personally I have disabled NetBIOS on my network so nobody ever sees a 'browse list' anymore. I have AD-published shares and printers and use mapped drives instead.

Some stuff here:


Good luck

Andy
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top