Choose your language

Choose your login

Support

User printing onsite — multi-subnet restricted network

This page applies to:

Last updated July 3, 2026

This page covers how PaperCut Hive and Pocket provide serverless cloud print management in complex multiple-subnet network environments when there are restrictions on communications between subnets. It also outlines the end-to-end technical workflows for job submission and release in two primary network architecture scenarios:

  • when communications are blocked between user subnets, but user computers are allowed direct access to printers
  • when communications are blocked between the user and printer subnets.

Examples of multi-subnet restricted networks

Computer security is an ongoing concern, and companies need to protect their intellectual property.

Many businesses set up their environments with multiple subnets and data communication restrictions to limit who can access sensitive data on the server infrastructure. These businesses often restrict access to their printer subnets to limit who can access printers over the network, forcing users to submit print jobs via a protected print server and preventing sensitive documents from being intercepted on the network as they are routed from the print server to the printer.

These restricted environments can operate at a single site or across multiple sites connected on a restricted WAN. Network boundaries control access and dictate allowed communication ports.

Typical customers with this setup include:

  • small legal firms
  • schools
  • libraries
  • universities
  • government agencies
  • healthcare providers.

Regardless of the industry, these organizations need to control the flow of access and information within their networks.

In complex environments, you can configure your network to restrict communications while still allowing printing. The following scenarios explain how to configure PaperCut Hive or Pocket based on the severity of the communication restrictions.

Method 1: Printing when there are restrictions between user subnets, but access is allowed to the printer subnet

In this scenario, any computer in the network can deliver print jobs directly to the printers; that is, no printer port restrictions exist. However, for security purposes, limited or no communication is allowed between specific different user subnets, such as a guest network and staff network, or a teacher network and student network.

When restrictions exist between user subnets, PaperCut Hive and Pocket use the most appropriate nearby edge nodes (Windows or macOS computers running the PaperCut Hive or Pocket client) within the user’s subnet.

For example, if a teacher submits a print job, the system uses edge nodes in the teacher’s subnet to replicate or retrieve the job. The system would not use edge nodes in the student subnet because the subnet or VLAN boundary prevents communication between the teacher and student subnets. However, any edge node in the originating (teacher’s) subnet can accept and release the print job to any printer, because every user subnet can communicate freely with the printer subnet on the allowed printing ports.

Method 2: Printing when there are restrictions between user and printer subnets

In this scenario, communication between user subnets and printer subnets is restricted, or direct communication between user machines and printers is prevented.

Schools and universities frequently use this setup so that students can access data only on the student subnet and submit print jobs via a print server. This prevents students from bypassing the print server to avoid print charges.

To use PaperCut Hive or Pocket in this scenario, you require either:

  • at least one edge node that can communicate with the printers and route print jobs to them
  • printers that support Pull Delivery, which retrieve and print stored jobs directly from the Cloud Node.

If your printers support Pull Delivery and integrate with the Full Embedded Printer App, configure Pull Delivery as the primary print delivery method and enable the Cloud Node. In that setup, the printer downloads a copy of a print job from the Cloud Node and prints it directly. This avoids routing jobs via an edge node when they are released. For more information, refer to Pull Delivery in PaperCut Hive.

Consider the following when using Pull Delivery:

  • The printer subnets might contain a mixture of printer types, with some not supporting Pull Delivery.
  • Some MFD brands require an edge node to communicate directly with the printer for Full Embedded Printer App tasks.
  • It’s a good idea to provide backup methods to route print jobs for release.

Because of these considerations, you might need at least one dedicated, always-available edge node to communicate with the printers and deliver jobs.

However, you also need a way to route jobs from the user devices to the dedicated edge node(s). You can route jobs from user devices to dedicated edge node(s) in two ways:

Create a separate subnet for dedicated edge nodes reachable by user devices

To configure this:

  1. Create a new subnet and install one or two dedicated edge node computers.
  2. (Optional) If you require iOS printing, promote these edge nodes to Super Nodes and assign them static IP addresses. This provides specific edge nodes for iOS devices to submit print jobs to.
  3. Open the required ports to allow all user devices to communicate with the dedicated edge node(s) in the new subnet over the required ports. For a list of required ports, refer to System requirements.
  4. Open the standard ports for SNMP, IPP, and RAW printing to allow the new subnet to communicate with the printer subnets over SNMP and standard printing ports.
  5. Create a Print Delivery Profile that’s configured with one of the following:
    • Configure the dedicated edge node(s) as Individual selected clients.
    • Configure the new subnet as the network location for Dynamically selected clients.
  6. Apply the Print Delivery Profile to all printers.

After setup, when a user submits a print job, it replicates to the dedicated edge nodes or other nearby edge nodes. When the user releases the job, a dedicated edge node in the new subnet will be holding a replicated copy or able to retrieve one from an edge node in the user subnet. The dedicated edge node then delivers the job to the printer.

Create a separate subnet for dedicated edge nodes and enable the Cloud Node

To configure this:

  1. Create a new subnet and install one or two dedicated edge node computers.

  2. Allow the new subnet to communicate with the printer subnets over SNMP and standard printing ports.

  3. Enable the Cloud Node.

  4. Create a Print Delivery Profile that’s configured with one of the following:

    • Configure the dedicated edge node(s) as Individual selected clients.
    • Configure the new subnet as the network location for Dynamically selected clients.
  5. Apply the Print Delivery Profile to all printers.

  6. For supported printers, configure Pull Delivery as the primary print delivery method.

After setup, the system securely replicates a copy of each print job to PaperCut Cloud Services. When a user releases a job, printers that support Pull Delivery download and print the job directly from the Cloud Node. For printers without Pull Delivery support, the dedicated edge nodes in the new subnet download the job from the Cloud Node and route it to the printer.

How printing with PaperCut Hive and Pocket works

For detailed information on print job submission and release in a multiple subnet restricted network environment, refer to Job submission process and Find-Me job release process below.

Pros and cons of PaperCut Hive and Pocket in multi-subnet restricted networks

ProsCons

Enabling the Cloud Node allows job traffic to route around subnet boundaries, negating the need to open ports between subnets or VLANs.

If computers in the user subnets cannot communicate directly with the printers and Pull Delivery is not configured, you require dedicated edge nodes with connectivity to the printer subnets.

Network administrators maintain full control of security between subnets.

If computers in the user subnets cannot communicate directly with the printers, Direct print queues provisioned with Print Queue Deployment do not function.

Network diagrams

Method 1: Printing when there are restrictions between user subnets, but access is allowed to the printer subnet

Line diagram show PaperCut Cloud connected to 3 Edge Meshes - one for staff, one for students and one for guests. The PaperCut Cloud and Edge Meshes are all also connected to Printers. The connections are labelled with HTTPS or Protocol details.

Method 2 — Option 1: Create a separate subnet for dedicated edge nodes reachable by user devices

Line diagram show PaperCut Cloud connected to 3 subnets - one for staff,  one for students and one new subenet that has 2 super nodes. The staff and student subnets are connected to the new subnet, and the new subnet is connected to the printers. The connections are labelled with HTTPS or Protocol details.

Method 2 — Option 2: Create a separate subnet for dedicated edge nodes and enable the Cloud Node

Line diagram show PaperCut Cloud connected to 3 subnets - one for staff,  one for students and one new subenet that has 2 super nodes. Only the new subnet and the PaperCut Cloud are connected to Printers. The connections are labelled with HTTPS or Protocol details.

Ports

If you run the Full Embedded Printer App, some MFD platforms need additional ports opened between edge nodes and the MFD to facilitate certain device tasks. For the complete list of ports, refer to System requirements.

Job submission process

The following sections explain the process when a user prints in a multiple subnet environment with restrictions on communications between subnets.

Process for Find-Me printing from Windows, macOS, ChromeOS, and Android

ActionComms

1. The user submits a print job from a computer (PaperCut client) or a mobile device.

N/A

2. The PaperCut client requests a list of available edge nodes from PaperCut Cloud Services to submit the print job to.

HTTPS/MQTT via port 443/8883

3. PaperCut Cloud Services returns a list. The client checks the list to find a suitable edge node (Windows or macOS computer) and sends the job. When printing from a Windows or macOS computer, the system usually selects the edge node running on the same device.

HTTP/S via port 9263 (ChromeOS) 9264 (Win, macOS, Android).

HTTP via port 9265 (localhost only - Win, macOS).

4. If an available edge node accepts the job, it contacts PaperCut Cloud Services to verify it was submitted by a valid source. It then requests a list of available edge nodes to replicate the job.

HTTPS/MQTT via port 443/8883

5. The edge node checks the list and delivers the job to additional edge nodes on the network.

By default, the system replicates jobs to two edge nodes, but you can reduce this to one or zero in the print job replication advanced configuration. If set to zero, the system submits jobs only to the initial edge node and the Cloud Node (if enabled).

HTTPS via port 9264 (Win, macOS)

6. If the Cloud Node is enabled, the edge node securely submits the encrypted print job to the Cloud Node over the public internet.

HTTPS via port 443

7. Between one and three edge nodes store the job, depending on configuration and availability. If enabled, the Cloud Node also stores the job. The system uses a multi-part encryption key to encrypt stored jobs.

N/A

Process for Find-Me printing from iOS

ActionComms

1. The user submits a print job from an iOS device connected to the organization’s WiFi network.

N/A

2. If the Cloud Node is enabled, the iOS device securely submits the encrypted print job to the Cloud Node over the public internet. The URL to submit print jobs to the Cloud Node is provided by an AirPrint profile installed by the Mobile App to the iOS device.

HTTPS via port 443

3. The AirPrint profile also provides URLs for configured Super Nodes. The iOS device securely submits the print job to a reachable Super Node over the organization’s network.

HTTPS via port 9264

4. The Super Node accepts the job and contacts PaperCut Cloud Services to verify it was submitted by a valid source. It then requests a list of available edge nodes to replicate the job.

HTTPS/MQTT via port 443/8883

5. The Super Node checks the list and delivers the job to additional edge nodes on the network.

By default, the system replicates jobs to two edge nodes, but you can change this to one or zero in the print job replication advanced configuration. If set to zero, the system submits jobs only to the initial Super Node and the Cloud Node (if enabled).

HTTPS via port 9264 (Win, macOS)

6. The Super Node stores the job. Depending on configuration and availability, up to two additional edge nodes also store the job. The Cloud Node stores the job if enabled. The system uses a multi-part encryption key to encrypt stored jobs.

N/A

Process for Direct printing from Windows and macOS

ActionComms

1. The user submits a print job to a Direct print queue from a Windows or macOS computer (client).

N/A

2. The PaperCut client sends the print job to the edge node running on the user’s computer.

HTTPS via port 9264 (Win, macOS).

HTTP via port 9265 (localhost only - Win, macOS).

3. The edge node contacts PaperCut Cloud Services to verify it was submitted by a valid source. It then requests the destination printer's known IP address.

HTTPS/MQTT via port 443/8883

4. PaperCut Cloud Services returns the printer IP address, and the edge node attempts to reach the destination printer. If the printer and printing port are available, the edge node sends the job to the printer.

SNMP via port 161/162.

RAW printing via port 9100.

Find-Me job release process

When a user releases a Find-Me print job, they can use two methods:

After the user releases their job, how you configure PaperCut Hive or Pocket determines the job’s route to the destination printer.

To have the printer retrieve and print jobs directly from PaperCut Cloud Services, configure Pull Delivery for a supported destination printer and enable the Cloud Node. The printer will retrieve and print jobs directly from the Cloud Node.

If Pull Delivery is not configured, at least one edge node on the network needs access to the printer to route and print the job. For more information, refer to Pull Delivery in PaperCut Hive.

When Pull Delivery cannot be used, PaperCut Hive or Pocket selects an edge node to relay the job to the destination printer. By default, the Autopilot algorithm attempts to select the most reliable client device to deliver the print job, which then relays the job.

In restricted network environments where user computers cannot communicate directly with the printers, apply Print Delivery Profiles to all printers. Grant dedicated, always-on edge nodes network access to the printers and configure them as the Individual selected clients for job release. This ensures that only the dedicated edge nodes are selected to route print jobs for release. For more information, refer to Autopilot - Overview and About Print Delivery Profiles.

Releasing jobs at the MFD

ActionComms

1. At the MFD, the end user logs in to PaperCut Hive using the touchscreen.

HTTPS via port 443, plus additional ports for certain brands

2. PaperCut Cloud Services returns a list of available jobs. The jobs appear on the touchscreen.

HTTPS via port 443

3. The user selects the print jobs they want to release, modifies the job settings if necessary (for example, double-sided), and selects Print.

HTTPS via port 443

4. If the Cloud Node is enabled and Pull Delivery is configured for the printer, the printer retrieves the jobs directly from the Cloud Node and prints them.

HTTPS via port 443

5. If Pull Delivery is not configured, PaperCut Cloud Services contacts edge nodes to issue the job release command.

If a Print Delivery Profile applies to the printer, PaperCut Cloud Services contacts the clients specified in the profile.

Otherwise, the Autopilot algorithm nominates edge nodes based on reliability. For print jobs submitted from a Windows or macOS computer, this is usually the edge node running on that device, provided it can reach the printer. In restricted networks where user computers cannot reach the printers, dedicated edge nodes would be nominated.

HTTPS/MQTT via port 443/8883

6. The selected edge node retrieves a copy of the job. The edge node retrieves the job from any edge node holding a replicated copy accessible on the main network.

The edge node can also retrieve the job from the Cloud Node (if enabled) if all other edge nodes are unreachable.

HTTPS via port 443 (Cloud Node retrieval).

HTTPS via port 9264 (edge node retrieval).

7. The edge node holding the job attempts to reach the specified printer. If available, the edge node sends the job to the printer using a configured print delivery protocol (for example, IPPS), and the job prints.

SNMP via port 161/162.

IPP/IPPS printing via port 80/443/631.

RAW printing via port 9100.

Releasing jobs from a mobile device

ActionComms

1. The user launches the PaperCut Mobile App on their mobile device (iOS or Android). The Mobile App contacts PaperCut Cloud Services to find the user's print jobs.

HTTPS via port 443

2. The Mobile App displays a list of print jobs ready for release.

HTTPS via port 443

3. The user selects the print jobs and modifies the job settings if necessary (for example, double-sided).

N/A

4. The user selects Print document, then selects the printer from the list. Depending on the mobile release options configuration, the user can also select the printer using a QR code, NFC tag, or printer Release Code. The Mobile App relays this release request to PaperCut Cloud Services.

HTTPS via port 443

5. If the Cloud Node is enabled and Pull Delivery is configured for the printer, the printer retrieves the jobs directly from the Cloud Node and prints them.

HTTPS via port 443

6. If Pull Delivery is not configured, PaperCut Cloud Services contacts edge nodes to issue the job release command.

If a Print Delivery Profile applies to the printer, PaperCut Cloud Services contacts the clients specified in the profile.

Otherwise, the Autopilot algorithm nominates edge nodes based on reliability. For print jobs submitted from a Windows or macOS computer, this is usually the edge node running on that device, provided it can reach the printer. In restricted networks where user computers cannot reach the printers, dedicated edge nodes would be nominated.

HTTPS/MQTT via port 443/8883

7. The selected edge node retrieves a copy of the job. The edge node retrieves the job from any edge node holding a replicated copy accessible on the main network.

The edge node can also retrieve the job from the Cloud Node (if enabled) if all other edge nodes are unreachable.

HTTPS via port 443 (Cloud Node retrieval).

HTTPS via port 9264 (edge node retrieval).

8. The edge node holding the job attempts to reach the specified printer. If available, the edge node sends the job to the printer using a configured print delivery protocol, and the job prints.

SNMP via port 161/162.

IPP/IPPS printing via port 80/443/631.

RAW printing via port 9100.

Releasing jobs from a mobile device using Print Offline

If the link to PaperCut Cloud Services is unavailable (for example, an Internet Service Provider outage), users can still release print jobs using their mobile device if:

  • the Print Offline feature is enabled
  • the mobile device is connected to Wi-Fi on the organization’s main network
  • the mobile device can communicate with nearby edge nodes
  • a nearby edge node stores a replicated copy of the job.

In restricted network environments where user computers can’t reach the printers, a dedicated edge node that the mobile device can reach is required to hold a replicated copy of the job. If no firewall ports are opened between user subnets and dedicated edge nodes (that is, the Cloud Node is exclusively relied on for routing jobs between subnets), Print Offline will not be available.

For more information, refer to About printing offline.

ActionComms

1. The user launches the PaperCut Mobile App. The Mobile App detects the internet connection is down and switches to looking for local edge nodes.

HTTPS via port 9266

2. The edge nodes return a list of available print jobs to the Mobile App.

HTTPS via port 9266

3. The user selects the print jobs and modifies the job settings if necessary (for example, double-sided).

N/A

4. The user selects Print document, then selects the printer from the list. Depending on the mobile release options configuration, the user can also select the printer using a QR code, NFC tag, or printer Release Code. The Mobile App relays the release request to nearby edge nodes.

HTTPS via port 9266

5. The edge nodes communicate to find the node holding the print job to issue the release command.

HTTPS via port 9264

6. The edge node holding the job attempts to reach the selected printer. If available, the edge node sends the job to the printer using a configured print delivery protocol, and the job prints.

SNMP via port 161/162.

IPP/IPPS printing via port 80/443/631.

RAW printing via port 9100.

​​​​​​

Comments