How to Configure Bonjour Forwarding for MX in Passthrough Mode
Overview
The Cisco Meraki MX Security Appliance forwards Bonjour mDNS traffic across VLANs, even while in Passthrough mode. For information on configuring Bonjour forwarding when the MX is in NAT mode, refer to this article.
This functionality helps when you deploy the MX below a Layer 3 switch or another appliance that defines VLANs but cannot forward Bonjour traffic across them. An MX in Passthrough intercepts the traffic and forwards it from service VLANs to client VLANs. This lets clients on one VLAN use Bonjour services such as AirPlay or wireless printing when the service sits in another broadcast domain.
This article explains the network design the functionality requires, and then provides instructions on how to enable Bonjour forwarding in dashboard.
How Bonjour forwarding works in Passthrough mode
The MX forwards Bonjour traffic in Passthrough mode by inspecting each packet that passes through the appliance for 802.1Q VLAN tags. If a packet carries a VLAN tag, the MX references the Bonjour forwarding rules. When it identifies a match, the MX forwards the packet to the other broadcast domain.
For Bonjour forwarding to work in Passthrough mode, traffic must carry a VLAN ID before it passes through the MX. Forwarding from the native VLAN is not possible in Passthrough mode, because no explicit 802.1Q VLAN tag exists for native VLAN traffic. You can tag traffic in several ways, either through SSID VLAN tagging or by configuring an access port on a Layer 2 switch.
If traffic is not explicitly tagged downstream of the MX, the MX does not identify it for forwarding. The traffic passes upstream to the Layer 3 switch or security appliance, which cannot forward Bonjour traffic.
Example topology
Step-by-step instructions
-
Configure the MX for use in Passthrough mode.
-
Go to Configure > Firewall > Bonjour forwarding.
-
Add rules to forward each VLAN across. For the example topology, add one rule for VLAN ID 20 > VLAN ID 30 and another for VLAN ID 30 > VLAN ID 20 (shown below, with VLAN names displayed).

This configuration forwards traffic for all Bonjour services from the Apple TV on VLAN 20 to the MacBook Pro connected to an SSID that tags traffic for VLAN 30.
Troubleshooting
If Bonjour forwarding for the same VLANs is also enabled on the MRs, this configuration can cause a forwarding loop. Check your MR configuration before you create the above rules on the MX.
Additional considerations:
-
Traffic must be explicitly tagged downstream of the MX. Untagged traffic on the native VLAN is not identified for forwarding and passes upstream unchanged.

