Results 1 to 7 of 7

Thread: weird cisco vpn problem!

  1. #1
    daft ideas inc. scottyman's Avatar
    Join Date
    Jul 2003
    Location
    Charming and Exotic Bracknell
    Posts
    1,576
    Thanks
    2
    Thanked
    3 times in 3 posts

    weird cisco vpn problem!

    My Dad has just got here from NZ, and his laptop is playing silly buggers -
    using a cisco vpn client to get access to his office in Canberra, where the their cisco vpn seems to be set to disable local net access.
    does anyone know of a way around without having to get the head of IT over there out of bed?
    I set him up with a network printer in his home office which works quite cheerfully there, and the local subnet addressing is exactly the same (hey, I like consistency!) his local IP is the same - and for some reason the vpn client is blocking access to my network printer!

  2. #2
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    I suspect thats a "feature" of the way the Cisco VPN is set up.

    with a regular PPTP type VPN you can just tell it not to use the default gsteway on the local network , but i have a feeling that the cisco client takes over your whole networking and will *only* allow traffic down the secure tunnel.

    You'd be better of connecting your printer locally ( if your dad has sufficient admin rights )
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  3. #3
    Senior Member RVF500's Avatar
    Join Date
    Apr 2004
    Location
    Back in Sunny UK...and it is sunny too :D...pleasant surprise.
    Posts
    1,063
    Thanks
    0
    Thanked
    0 times in 0 posts
    A client VPN should only tunnel from the NIC on the client device, in this case your dad's laptop, to the far end which I assume will be the firewall. If you are going from the NIC to a switch and then out it may be that the the VPN tunnel is passing packets through and heading straight off to the firewall and anything passing through the port for the printer is encrypted so the printer won't recognise it. Packets for the printer may be being routed this way too and not being allowed back to the printer.

    The easiest way to do things if you are having issues is to do as moby says and connect the printer locally unless you install a second NIC into the laptop and create a second network for the printer.
    "You want loyalty? ......get a dog!"

  4. #4
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    RVF , have you had a play with the Novel VPN client ? Last time I saw it , it would only route packets from the NIC down the tunnel , the client wouldn't access the local network at all ( I'm assuming it modifies the local routing table for this ? )

    From a security point of view , having VPN connected clients accessing the web from the client end of the tunnel isn't as secure as having all their traffic running down the tunnel and allowing web access via a server side proxy ( slow, but it means that all traffic in/out of the client is encrypted )

    It may be worth seeing if there is a proxy for scottymans dad to use on the NZ side and do any web surfing via that ( or just drop the tunnel when you want to browse ! )
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  5. #5
    daft ideas inc. scottyman's Avatar
    Join Date
    Jul 2003
    Location
    Charming and Exotic Bracknell
    Posts
    1,576
    Thanks
    2
    Thanked
    3 times in 3 posts
    yeah - it's a hassle as has to use it to get access to the notes client...
    will see if I can configure the printer wirelessly and will see if that helps - another option is to unbind (forget which one) one of the two ipsec policies that it applies - apparently the remote vpn settings can force application of two incompatible ipsec policies which can allow it to happen. very strange - will see what happens.
    annoyingly, without getting access to the rules, I can't tell which settings and netmask are allowed!

  6. #6
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber
    My dad had exactly this problem when he connected to the office from home, he spoke to me about it asking for advice but it seemed that indeed, all traffic was going through the VPN tunnel when it was established, so he could not print locally.

    This was the first time I'd heard of this, as my VPN (SecuRemote) only tunnels traffic for subnets defined in the VPN topology in the client - so long as your local subnet and remote subnet are different then it doesn't try to route local traffic.

    I can only guess it's maybe a security feature within the client (or possibly defined at the connecting end?) to prevent hijacking of data at the client end and sending elsewhere?

    I can only suggest a second NIC if the printer has to remain network connected, or connect it locally as others have suggested.


    (I used the Novell VPN client a couple of years ago, but it was over a dial-up connection - the laptop was LAN-connected at the same time, though so a multiple NIC setup should still resolve the issue.)
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  7. #7
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. DVI problem, pc won't start! help needed.
    By snowwolf in forum Graphics Cards
    Replies: 1
    Last Post: 09-04-2010, 04:11 PM
  2. Weird problem your thoughts please
    By Flash in forum PC Hardware and Components
    Replies: 14
    Last Post: 15-04-2004, 03:21 PM
  3. Authenticating to Server 2003 - weird problem
    By Richie in forum Software
    Replies: 8
    Last Post: 12-02-2004, 12:55 AM
  4. VPN features
    By comtree in forum Networking and Broadband
    Replies: 3
    Last Post: 07-01-2004, 04:35 PM
  5. Weird problem adding XP box to a LAN
    By Beer in forum Networking and Broadband
    Replies: 7
    Last Post: 10-10-2003, 05:47 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •