George <george@nospam.invalid> hath wroth:
>Thats my beef with Sonicwall. Does setting the gateway same as device IP
>work to prevent the Sonicwall from finding the device?
Yes. That works well with HP print servers. I haven't tried it with
others. The original SOHO firmware would only count IP addresses that
went through the router. Since about 2002, the firmware counts all IP
addresses that hit the firewall LAN interface. Very dumb.
My current way is to simply add the IP address of the print server to
the IP filter exclusion list. That also excludes it from the user
count in some (not all) firmware versions.
The newer SonicOS has a license exclusion list specifically for print
servers. However, the older boxes lack this feature.
Yet another way around the problem is to use subnets. I use 0-126 for
the routeable parts of the LAN, which includes desktops, DHCP range,
and laptops. 129-254 is for devices that shouldn't count as users,
such as print servers and SNMP management ports. The router has a
subnet mask of 255.255.255.128 so that it only sees the routeable
devices. The clients all have a subnet mask of 255.255.255.0 so that
they can see the printers and managed devices. That worked fine until
about 2004, when the firmware no longer allowed setting the subnet
mask independently via DHCP. So, I had to setup another box to play
DHCP server. It works, but I don't recommend this method any more.
Sonicwall has their own formula. Their goofy support query tool
cannot be bookmarked or even cut-n-paste. So, go unto:
http://www.sonicwall.com/knowledgeportal/
and inscribe:
"license count"
in the query box. Click "yes" to the obvious question. You should
get two methods of having a print server not count as a user. Although
you can't cut-n-paste or save the answer, you can print or email it to
yourself.
>Previously I
>tried not entering a gateway on printservers but the Sonicwall saw the
>device. I thought it was because the Sonicwall did discovery of some
>sort on its subnet but maybe the printserver did an autodiscovery of the
>gateway?
I don't know. I think that most Sonicwall devices support IRDP
(router discovery protocol RFC1256) but that won't return anything
from a print server as the print server is unlikely to be broadcasting
ICMP "I'm a router" packets.
I still use and buy Sonicwall products because they're very good, very
reliable, very versatile, but expensive. If I want something complex,
that works out of the box, I tend to use Sonicwall.
--
Jeff Liebermann
jeffl@comix.santa-cruz.ca.us
150 Felker St #D
http://www.LearnByDestroying.com
Santa Cruz CA 95060
http://802.11junk.com
Skype: JeffLiebermann AE6KS 831-336-2558