![]() |
|
Welcome to the HEXUS.community discussion forums forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and other features. By joining our free community you will have access to post topics, respond to polls and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! |
|
|||||||
Help - technical & advisory Got a problem and need help fast? Shout it here! For any technical based queries ![]() |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
daft ideas inc.
Join Date: Jul 2003
Location: Kiwi living in Upper Bucklebury
Posts: 1,500
Thanks: 1
Thanked 0 Times in 0 Posts
|
weird cisco vpn problem!
My Dad has just got here from NZ, and his laptop is playing silly buggers -
using a cisco vpn client to get access to his office in Canberra, where the their cisco vpn seems to be set to disable local net access. does anyone know of a way around without having to get the head of IT over there out of bed? I set him up with a network printer in his home office which works quite cheerfully there, and the local subnet addressing is exactly the same (hey, I like consistency!) his local IP is the same - and for some reason the vpn client is blocking access to my network printer! |
|
|
|
|
|
#2 (permalink) |
|
Administrator
Join Date: Jul 2003
Location: There's no place like 127.0.0.1
Posts: 8,402
Thanks: 5
Thanked 103 Times in 90 Posts
|
I suspect thats a "feature" of the way the Cisco VPN is set up.
with a regular PPTP type VPN you can just tell it not to use the default gsteway on the local network , but i have a feeling that the cisco client takes over your whole networking and will *only* allow traffic down the secure tunnel. You'd be better of connecting your printer locally ( if your dad has sufficient admin rights ) |
|
|
|
|
|
#3 (permalink) |
|
Senior Member
Join Date: Apr 2004
Location: Back in Sunny UK...and it is sunny too :D...pleasant surprise.
Posts: 1,063
Thanks: 0
Thanked 0 Times in 0 Posts
|
A client VPN should only tunnel from the NIC on the client device, in this case your dad's laptop, to the far end which I assume will be the firewall. If you are going from the NIC to a switch and then out it may be that the the VPN tunnel is passing packets through and heading straight off to the firewall and anything passing through the port for the printer is encrypted so the printer won't recognise it. Packets for the printer may be being routed this way too and not being allowed back to the printer.
The easiest way to do things if you are having issues is to do as moby says and connect the printer locally unless you install a second NIC into the laptop and create a second network for the printer.
|
|
|
|
|
|
#4 (permalink) |
|
Administrator
Join Date: Jul 2003
Location: There's no place like 127.0.0.1
Posts: 8,402
Thanks: 5
Thanked 103 Times in 90 Posts
|
RVF , have you had a play with the Novel VPN client ? Last time I saw it , it would only route packets from the NIC down the tunnel , the client wouldn't access the local network at all ( I'm assuming it modifies the local routing table for this ? )
From a security point of view , having VPN connected clients accessing the web from the client end of the tunnel isn't as secure as having all their traffic running down the tunnel and allowing web access via a server side proxy ( slow, but it means that all traffic in/out of the client is encrypted ) It may be worth seeing if there is a proxy for scottymans dad to use on the NZ side and do any web surfing via that ( or just drop the tunnel when you want to browse ! ) |
|
|
|
|
|
#5 (permalink) |
|
daft ideas inc.
Join Date: Jul 2003
Location: Kiwi living in Upper Bucklebury
Posts: 1,500
Thanks: 1
Thanked 0 Times in 0 Posts
|
yeah - it's a hassle as has to use it to get access to the notes client...
will see if I can configure the printer wirelessly and will see if that helps - another option is to unbind (forget which one) one of the two ipsec policies that it applies - apparently the remote vpn settings can force application of two incompatible ipsec policies which can allow it to happen. very strange - will see what happens. annoyingly, without getting access to the rules, I can't tell which settings and netmask are allowed! |
|
|
|
|
|
#6 (permalink) |
|
Drone #467234
Join Date: Jul 2003
Location: C:\Windows
Posts: 1,750
Thanks: 9
Thanked 38 Times in 30 Posts
|
My dad had exactly this problem when he connected to the office from home, he spoke to me about it asking for advice but it seemed that indeed, all traffic was going through the VPN tunnel when it was established, so he could not print locally.
This was the first time I'd heard of this, as my VPN (SecuRemote) only tunnels traffic for subnets defined in the VPN topology in the client - so long as your local subnet and remote subnet are different then it doesn't try to route local traffic. I can only guess it's maybe a security feature within the client (or possibly defined at the connecting end?) to prevent hijacking of data at the client end and sending elsewhere? I can only suggest a second NIC if the printer has to remain network connected, or connect it locally as others have suggested. (I used the Novell VPN client a couple of years ago, but it was over a dial-up connection - the laptop was LAN-connected at the same time, though so a multiple NIC setup should still resolve the issue.)
There is no IRL... only AFK
My Site This signature (c)2006 Copywrong Paul Adams. All rights wronged, all wrongs reversed. |
|
|
|
![]() |
| Breadcrumb | ||||||
|
||||||
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Weird problem your thoughts please | Flash | HEXUS.hardware | 14 | 15-04-2004 02:21 PM |
| Authenticating to Server 2003 - weird problem | Richie | Operating systems & applications | 8 | 11-02-2004 11:55 PM |
| DVI problem, pc won't start! help needed. | snowwolf | Graphics cards and Monitors | 0 | 27-01-2004 05:01 PM |
| VPN features | comtree | Networking and Broadband | 3 | 07-01-2004 03:35 PM |
| Weird problem adding XP box to a LAN | Beer | Networking and Broadband | 7 | 10-10-2003 04:47 PM |