- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Printer behind FortiClient not accessible
Hi,
We are having a printer installed on a local PC of one employee, the same employee is using FortiClient vpn to connect into a Visual Machine on the company LAN. The employee has to print from the Virtual Machine on the company LAN to the printer behind SSL VPN. When I add the printer on the VMware machine, I can see the name of the printer on the printer list but the connection is timing out. I cannot even PING the IP address of the printer in the LAN while connected to SSL VPN. I get message request timed out. We are using FortiGate firewall version 7.2.4 build 1396
What is the issue that makes the LAN not to see the printer while connected into the SSL VPN?
Thank you in advance.
Kind Regards,
Abel
- Labels:
-
FortiClient
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hi Abel,
Please make sure you have spit tunnel enable in the sslvpn so you that only remote subnet are pointing todards sslvpn adaptor in local pc.
Better to check routing-table in the pc before and after connecting to sslvpn. use "route print" if its a Windows pc. Also do traceroute and check the path
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Abel,
There is a possibility that you're using "Tunnel all" and when connected to VPN all the traffic is routed towards Fortigate, you can follow the below guide and configure Split Exclude for SSL VPN.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Exclude-some-traffic-from-SSL-VPN-using-Tr...
If the "tunnel all" is not configured then we will have to verify the configuration and routing table of the end machine when connected with VPN.
Vishal
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
also the vm does have to have a route back to the vpn client (or the FGT as default gateway)
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Thank you very much for the information. I have created the Split Exclude for SSL VPN in the Fortigate firewall but now I cannot RDP into the VMware computer where I should be adding the printer and testing.
It looks like the Split Exclude for SSL VPN which I created is blocking the RDP connection.
Kind Regards,
Abel
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Abel,
Can you share the "route print" output from the test machine before and after VPN is connected & mention the VM IP also when connected with VPN you mentioned RDP not working but are you able to ping the VMware PC from the test machine?
Vishal
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Vishal,
I would like to share the route prints but I am concerned about IP addresses been seen on public?
Kind Regards,
Abel
![](/skins/images/EC9FF2F7BE06D4243426EA19DD2C8052/responsive_peak/images/icon_anonymous_message.png)