Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Abel
New Contributor

Printer behind FortiClient not accessible

Hi,

We are having a printer installed on a local PC of one employee, the same employee is using FortiClient vpn to connect into a Visual Machine on the company LAN. The employee has to print from the Virtual Machine on the company LAN to the printer behind SSL VPN. When I add the printer on the VMware machine, I can see the name of the printer on the printer list but the connection is timing out. I cannot even PING the IP address of the printer in the LAN while connected to SSL VPN. I get message request timed out. We are using FortiGate firewall version 7.2.4 build 1396

 

What is the issue that makes the LAN not to see the printer while connected into the SSL VPN?

 

Thank you in advance.

Kind Regards,

Abel

6 REPLIES 6
nithincs
Staff
Staff

hi Abel,

Please make sure you have spit tunnel enable in the sslvpn so you that only remote subnet are pointing todards sslvpn adaptor in local pc.

Better to check routing-table in the pc before and after connecting to sslvpn. use "route print" if its a Windows pc. Also do traceroute and check the path

vsahu
Staff
Staff

Hello Abel,

 

There is a possibility that you're using "Tunnel all" and when connected to VPN all the traffic is routed towards Fortigate, you can follow the below guide and configure Split Exclude for SSL VPN.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Exclude-some-traffic-from-SSL-VPN-using-Tr...

If the "tunnel all" is not configured then we will have to verify the configuration and routing table of the end machine when connected with VPN.

Regards,
Vishal
sw2090
Honored Contributor

also the vm does have to have a route back to the vpn client (or the FGT as default gateway)

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Abel
New Contributor

Hi,

Thank you very much for the information. I have created the Split Exclude for SSL VPN in the Fortigate firewall but now I cannot RDP into the VMware computer where I should be adding the printer and testing.

 

It looks like the Split Exclude for SSL VPN which I created is blocking the RDP connection.

Kind Regards,

Abel

vsahu
Staff
Staff

Hello Abel,


Can you share the "route print" output from the test machine before and after VPN is connected & mention the VM IP also when connected with VPN you mentioned RDP not working but are you able to ping the VMware PC from the test machine?

Regards,
Vishal
Abel
New Contributor

Hi Vishal,

I would like to share the route prints but I am concerned about IP addresses been seen on public?

Kind Regards,

Abel

Labels
Top Kudoed Authors