This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Remote VPN User issues

I have just set up a Sophos XG125 firewall and I`m having the following issue(s):

 

  1. My remote VPN users can connect to all local resources except the printer.

 

 

Thanks



This thread was automatically locked due to age.
Parents Reply
  • Luk,

    When remote VPN users connect to the LAN, they have access to a pool of IP address (10.0.0.x), the printer`s IP address (10.0.0.x), as such I believe the remote VPN users should be able to access the print and print.

     

    Please correct me if I`m wrong.

     

    Thanks

Children
  • If the printer does not have default gateway configured, traffic from vpn can reach the printer but the printer cannot respond. Check with tcpdump

  • In this case, what will be the default gateway in order for the remote VPN users to reach the printer and the printer will then respond?

     

    Thanks.

  • Hello Aaron,

    you have to define the default ON THE PRINTER AS WELL.

    So if in your setup you have vpn clients coming in with an IP from the 10.x.x.x network-pool, that doesn't matter to the printer at all.
    If you have an internal LAN, for example, with 192.168.1.x /24 and your Sophos has the 192.168.1.254 /24 in this network and your printer has the 192.168.1.120 /24 as its IP addresss, then you need to add 192.168.1.254 as the default gateway to the printer's network parameters.  The printer has to know the "way back to the clients", in this case the Sophos is the gateway that "knows" how to further reach the vpn clients. It's always a two-way communication for TCP/IP to work.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • Thanks for your input.

    I was prompt to reply but phone rang!

  • Haha!

    I was faster than you - impossible :-)

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.