News
:
This forum is now permanently frozen.
m0n0wall Forum
>
m0n0wall Support (English)
>
VPN
Topic: PPTP VPN clients cannot acess TCP/IP print servers
Pages: [
1
]
2
Topic: PPTP VPN clients cannot acess TCP/IP print servers (Read 7553 times)
PPTP VPN clients cannot acess TCP/IP print servers
« on: November 20, 2008, 01:58:13 »
winedog
Posts: 28
OK....banging my head against the wall on this one and wondering if anyone has any thoughts or ideas about this.
I've been running m0n0wall for years now and using PPTP and the built-in client on Windows XP to connect to my network via M0n0 wall. The connection works flawlessly and I even access local clients in the network neighborhood for windows file sharing services as I have setup the mappings on in the lmhost file on the XP clients.
Here's the catch though....
I cannot print to a TCP/IP based Axis printer server when connecting via VPN / PPTP. No problem printing when I'm physically on the network, but no dice otherwise.
I've switched the m0n0 wall firewall rule to allow all protocols and no restrictions as best I can tell. I also tried allowing fragmented packets. All with no success.
Any ideas on this? Am I missing a client-side or m0n0wall configuration step to allow this type of traffic to flow? Or is this one of those things that just "won't work on PPTP"?
I haven't switched to IPSec yet because I need the NAT transversal to work since all of our PPTP clients connect from home NAT routers.
Re: PPTP VPN clients cannot acess TCP/IP print servers
« Reply #1 on: November 20, 2008, 20:23:17 »
ChainSaw
Guest
you did change your m0n0wall's LAN IP address from the default 192.168.1.1 to something less common (like 192.168.just about anything but 1.1) didn't you?
can you ping the print server's IP thru the PPTP tunnel ?
CS...
Re: PPTP VPN clients cannot acess TCP/IP print servers
« Reply #2 on: November 20, 2008, 20:47:20 »
winedog
Posts: 28
Well....actually, I still run the internal LAN IP on the .1.1 address space, but the VPN clients are all using different a different address space (i.e. 192.168.0.1) to avoid the NAT Traversal issues.
So I don't see that actually being a problem.
And yeah, I can ping the print server, I can access the print servers web interface. I just can't successfully send a print job to the print server....
Re: PPTP VPN clients cannot acess TCP/IP print servers
« Reply #3 on: November 20, 2008, 21:58:57 »
ChainSaw
Guest
does the printer config on your Windows machine specify an actual IP for your print server or does it have to resolve a name of some kind?
CS...
Re: PPTP VPN clients cannot acess TCP/IP print servers
« Reply #4 on: November 20, 2008, 22:41:29 »
winedog
Posts: 28
an actual IP address
Re: PPTP VPN clients cannot acess TCP/IP print servers
« Reply #5 on: November 20, 2008, 22:54:12 »
ChainSaw
Guest
can you post your LAN and PPTP rules ?
CS...
Re: PPTP VPN clients cannot acess TCP/IP print servers
« Reply #6 on: November 20, 2008, 23:10:31 »
winedog
Posts: 28
very simple rules as attached
lanrules.gif
(7.38 KB, 591x225 - viewed 386 times.)
pptprules_cr.gif
(7.37 KB, 587x235 - viewed 393 times.)
Re: PPTP VPN clients cannot acess TCP/IP print servers
« Reply #7 on: November 24, 2008, 16:22:07 »
markb
Posts: 331
Does the printer have a correct gateway address?
Re: PPTP VPN clients cannot acess TCP/IP print servers
« Reply #8 on: November 24, 2008, 20:40:43 »
winedog
Posts: 28
Yup....gateway on the print server is correct.
Any suggestions on a good way to trap the data flow between the client and the print server? Run a network sniffer?
Re: PPTP VPN clients cannot acess TCP/IP print servers
« Reply #9 on: November 25, 2008, 10:26:45 »
markb
Posts: 331
What model of Print server is it. I am starting to think along lines of maybe it's working using some kind of broadcast rather than direct IP which of course is not routable.
Re: PPTP VPN clients cannot acess TCP/IP print servers
« Reply #10 on: November 25, 2008, 11:42:09 »
winedog
Posts: 28
Axis 1610 print server for use with Canon printers.
I'm starting to think the same thing about it possibly being broadcast related.
It claims to use a direct IP and the print driver actually has IP of the print server specified in it...but hey...that doesn't always mean it's the whole story.
Gonna try and sniff out all the traffic via wireshark and see what I can see.
Re: PPTP VPN clients cannot acess TCP/IP print servers
« Reply #11 on: November 26, 2008, 06:05:24 »
knightmb
Posts: 341
You can ping, but can't connect via TCP, sounds like a MTU issue then. What MTU are the PPTP clients using?
I've never had any print problems via PPTP, I do all the time myself with HP and Brother IP printers.
Radius Service for m0n0wall Captive Portal -
http://amaranthinetech.com
Re: PPTP VPN clients cannot acess TCP/IP print servers
« Reply #12 on: November 26, 2008, 09:31:56 »
winedog
Posts: 28
Yeah, I checked that. Ran pings to find out where the fragmentation was happening and then dropped the MTU on the Windows XP clients well below that amount at 1300 (1370 is where it fragments). Still didn't change the problem...
Re: PPTP VPN clients cannot acess TCP/IP print servers
« Reply #13 on: November 26, 2008, 10:53:46 »
ChainSaw
Guest
Did you get around to trying 1.3b15 ?
CS...
Re: PPTP VPN clients cannot acess TCP/IP print servers
« Reply #14 on: November 26, 2008, 12:05:38 »
winedog
Posts: 28
Not yet.....hopefully can get that going tomorrow.
Pages: [
1
]
2