HowTo Enable Bonjour protocol between interfaces on NSF Firewall

RobertoC Lv1Posted 2026-Jul-21 17:30

Hi all,
i need to Enable Bonjour protocol between VLAN interfaces  on NSF Firewall,

Muhammad Abid has solved this question and earned 20 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Sangfor Athena NGFW (NSF Firewall) and want to enable Bonjour (mDNS) communication between different VLANs, it's important to understand that Bonjour uses multicast DNS (mDNS) on UDP port 5353 to the multicast address 224.0.0.251. By default, mDNS traffic is limited to the local subnet and is not routed between VLANs.

Can Sangfor NSF Firewall enable Bonjour across VLANs?

Currently, Sangfor NGFW/NSF does not provide a native Bonjour Gateway or mDNS Reflector feature to forward Bonjour advertisements between VLANs.

Possible Solutions
Check for an mDNS Gateway feature
In newer firmware versions, verify whether an mDNS Gateway/Bonjour Gateway feature is available under Network or Advanced Services.
If available, enable it and specify the VLANs that should share Bonjour services.
Allow the Required Traffic
If routing between VLANs is already configured:
Create security policies allowing:
UDP 5353
Source: Client VLAN
Destination: Service VLAN
Ensure multicast traffic is not being blocked.
Deploy an mDNS Reflector/Repeater
If the firewall does not support Bonjour forwarding, deploy an mDNS reflector on a Linux host or compatible network device (e.g., using Avahi in reflector mode). This is the most common solution in enterprise networks.
Use Vendor-Specific Solutions
If your wireless infrastructure supports Bonjour forwarding (such as Aruba, Cisco, or Ruijie), you can enable the Bonjour Gateway feature on the WLAN controller or AP instead of the firewall.

Recommendation

If you're using the latest Sangfor NSF firmware and cannot find an mDNS Gateway/Bonjour Gateway option, it is likely not supported natively. In that case, using an mDNS reflector or a wireless controller with Bonjour Gateway functionality is the recommended approach.

If you can share:

Sangfor NSF/NGFW model
Firmware version (e.g., 8.0.x)
Which Bonjour service you want to use (AirPrint, AirPlay, Chromecast, etc.)
Source and destination VLAN IDs

I can suggest the most suitable configuration for your environment.
Is this answer helpful?
Korchai Lv1Posted 2026-Jul-23 15:42
  
Bonjour employs multicast DNS (UDP port 5353 to 224.0.0.251 / FF02::FB). By default, mDNS does not traverse Layer 3 or VLAN boundaries since it is link-local.

Choices:Verify whether NSF is compatible with Relay or mDNS/Bonjour Gateway. Bonjour ads can be forwarded between certain VLANs using a mDNS Gateway/Relay functionality offered by some firewall vendors.Permit mDNS traffic (if Relay is being used). Bonjour won't function if the firewall doesn't function as a mDNS relay and only permits UDP 5353 between VLANs.
Install a mDNS reflector or relay (like Linux's Avahi in reflector mode).
Utilise a Bonjour Gateway on your switching infrastructure that is compatible with Apple.
If the device is connected by Wi-Fi, use a wireless controller that is compatible with Bonjour Gateway.
To confirm if mDNS ads are being forwarded, use packet captures.
Newbie A4 Lv1Posted 2026-Jul-22 13:10
  
Unlike certain wireless controllers and enterprise firewalls, Athena NGFW/NSF does not offer a specific Bonjour (mDNS) gateway/reflector functionality.
Prosi Lv4Posted 2026-Jul-21 20:23
  
Hi,

Bonjour uses multicast DNS (UDP port 5353 to 224.0.0.251 / FF02::FB). Because mDNS is link-local, by default it does not cross VLANs or Layer 3 boundaries.

Options:
- Check if NSF supports mDNS/Bonjour Gateway or Relay. Some firewall vendors provide an mDNS Gateway/Relay feature that forwards Bonjour advertisements between selected VLANs.
- Allow mDNS Traffic (If Using Relay). Only allowing UDP 5353 between VLANs will not make Bonjour work unless the firewall acts as an mDNS relay.
- Implement an mDNS reflector/relay (such as Avahi in reflector mode on Linux).
- Use an Apple-compatible Bonjour Gateway on your switching infrastructure.
- Use a wireless controller that supports Bonjour Gateway if the device is connected via Wi-Fi.
- Use packet captures to verify whether mDNS advertisements are being forwarded.
Humayun Ahmed Lv4Posted 2026-Jul-21 18:22
  
Athena NGFW/NSF does not provide a dedicated Bonjour (mDNS) gateway/reflector feature like some wireless controllers and enterprise firewalls.

I Can Help:

Change

Moderator on This Board

1
156
3

Started Topics

Followers

Follow

1065
219
100

Started Topics

Followers

Follow

Board Leaders