pjhtech Tools
UniFi

UniFi mDNS: AirPrint or AirPlay Missing Across VLANs

Separate service discovery from the application connection, scope the mDNS proxy and diagnose IoT discovery without opening every inter-VLAN service.

If AirPrint or AirPlay works on the device’s VLAN but disappears on another VLAN, enable the UniFi Gateway mDNS proxy for those two networks and the advertised service. If discovery already works, allow the advertised service connection instead; mDNS alone does not permit it.

Select networks and services in the proxy

Example: Trusted clients in 10.42.10.0/24 need an IoT printer at 10.42.30.20. Open Settings → Networks → mDNS, select Custom, set VLAN Scope to Trusted and IoT, and select its advertised IPP/IPPS service. Apply. Where mDNS is configured per network, enable it on both participating networks.

Auto shares common discovery across VLANs; leave Guest out of Custom VLAN Scope when it should not discover these devices.

Match the advertised service identifier in the documented _service._protocol.local form. A service visible by name may still advertise an address from the wrong interface.

Check discovery on the device VLAN first

Confirm that the service advertises and works with a client on the same VLAN. If it fails there, inspect the device service, Wi-Fi client isolation and local multicast transport. The inter-VLAN proxy is downstream of that test.

Example: a trusted client in 10.42.10.0/24 needs a printer at 10.42.30.20 on IoT. On a Mac connected first to the printer VLAN, browse for its IPP service:

Read the advertised endpoint

Read-only discovery • macOS client
dns-sd -B _ipp._tcp local.

Read Instance Name from an Add result. Stop with Ctrl+C, then resolve that exact name; Office Printer below is a fictional example:

Read-only lookup • macOS client
dns-sd -L "Office Printer" _ipp._tcp local.

Read the target hostname and port from the lookup, then stop with Ctrl+C. No browse result sends you back to the printer’s Bonjour/IPP setting or local isolation. If your printer advertises IPPS instead, use _ipps._tcp in both commands. Repeat from Trusted after configuring the proxy.

For AirPlay, run dns-sd -B _airplay._tcp local., then resolve the returned Instance Name with dns-sd -L "Living Room TV" _airplay._tcp local., replacing the example name. Stop each command with Ctrl+C. For an audio receiver, repeat with _raop._tcp. Select the matching AirPlay services in the proxy’s Custom settings; some receivers also advertise _companion-link._tcp or _appletv-v2._tcp.

The printer appears, but the service connection fails

On a Windows client, run Test-NetConnection <advertised-hostname> -Port <advertised-port> with the values from the discovery lookup. Read RemoteAddress and compare it with 10.42.30.20. If the printer advertises a stale or wrong-interface address, correct its network/Bonjour configuration before editing the firewall.

For a resolved TCP endpoint, a Windows client can run Test-NetConnection 10.42.30.20 -Port 631 when 631 is the advertised port; TcpTestSucceeded distinguishes TCP reachability from discovery. In the zone policy procedure, substitute the trusted client, printer IP and advertised service port for the HTTPS example. Preserve established/related replies and other blocks. Switch ACLs or AP isolation can block the packet before the gateway.

Test the service and retained isolation

Print or complete the media session from the intended client. Check that an excluded network cannot discover/use the device and that IoT cannot initiate unrelated trusted-network sessions.

References