Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
faisalvt
New Contributor

Persistent Canon Printer Disconnection Issue with UniFlow and Fortinet Firewall

I hope this post finds you well. I'm reaching out to the community for some expert advice on a persistent issue we've been facing for the past year. Despite multiple tickets with Fortinet support, we haven't been able to identify the root cause or find a lasting solution.

The Problem: Our Canon printers are experiencing frequent disconnections from Uniflow (Print Server). This issue seems to be particularly prevalent after power failures in our remote offices. Interestingly, the printers reconnect after a couple of days or when we change the printer's IP address.

Here's a bit about our network setup:

 

  • Branch Fortinet firewall is connected to the HQ Fortinet firewall via an IPsec VPN.
  • The print server is located in the HQ.
  • The Printers are in our remote offices
  • Branch firewall we are using Fortigate101F,81E,61F(Firmware 7.2.4)
  • HQ firewall  Fortigate601E(Firmware 7.2.4)
  • Branch and HQ firewall are connected over IPsec VPN
7 REPLIES 7
AEK
SuperUser
SuperUser

Have you found in traffic logs any blocked traffic from printer to print server or vice versa? Make sure the related policies have all traffic log enabled, and implicit deny policy as well.

On the other hand ha e you checked if one of the two devices was listed in quarantine monitor during the issue?

AEK
AEK
sveinol
New Contributor

Hi!

 

Did you find a solution to this?

I have a customer with the somwhat the same issue.

 

We also noticed that the UDP Traffic from the serve on port 53214 to the printer, is sendt out the server. but when doing a diag sniffer packet, we dont see it at all in the fortigte.

Even after the problem where resolved, and we see 2 waytraffic on the server(Wireshark), but we dont se the UDP traffic from  in the diag sniffer packet output.

We do however se other traffic on port 8443 and  8000 between server and printer.

 

AEK

Why do you send UDP to printer?

As per my knowledge printers use TCP for printing.

AEK
AEK
sveinol
New Contributor

I dont send UDP to the printer, the server do ;)

Its Uniflow managment traffic, if the server dont get a response, it thinks the printer is offline, and dont reply to userauth messages. Hens, print stops working.

AEK

If FG doesn't see UDP traffic from server to printer that means it is stopped somewhere before the FG, e.g.: could be at Windows' firewall level.

AEK
AEK
Micgate
New Contributor

Our network setup involves FortiGate firewalls at both ends connected via IPsec VPN, with the phone server located in the HQ. The phones in our remote offices frequently lose connection to the server after power outages, and they only reconnect after a couple of days or when we manually restart them. We've checked VPN stability, firewall configurations, and power failure handling. But no....

ede_pfau
SuperUser
SuperUser

If this only occurs after a tunnel failure (due to power outage), it might be that tunneled traffic is sent out of the WAN interface instead of the tunnel IF. Put in a blackhole route for the private address range you use. It will not harm during normal operation but will prevent a session out of the WAN interface which would prevent the correct VPN tunnel session.


Ede


"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors