Printing issues to local network when AnyConnect VPN in use

I have situation where I have a user connecting to the corporate office from her home network using a Win7 laptop and AnyConnect VPN 3.1.01065. She has an IP HP printer on her local network. When she is connected via VPN, she cannot print to her printer, Win saying the printer is off-line. That said, we are allowing access to the remote local network with a "split-exlude" conifiguration on the ASA:
access-list LocalLANAccess standard permit host 0.0.0.0
group-policy DfltGrpPolicy attributes
vpn-tunnel-protocol ssl-client
split-tunnel-policy excludespecified
split-tunnel-network-list value LocalLANAccess
"Allow local (LAN) access when using VPN" in the AC preference tab is checked. And also, she can ping the local printer when connected via VPN. however, the printer appears off-line, from the laptop perspective, when the VPN is on, and will go back "on-line" when the VPN is disconnected.
Anyone have any thoughts on how to correct this?

Well, if you want a workaround to apply for all VPN Client then you need to go for split-tunnel-policy tunnelspecified instead of split-tunnel-policy excludespecified. Suppose if your corporate network is 10.0.1.0/24 and you want to give the access to this subnet for vpn users.then configuration will be as follows.
access-list CorporateLAN standard permit 10.0.1.0 255.255.255.0
group-policy DfltGrpPolicy attributes
vpn-tunnel-protocol ssl-client
no split-tunnel-policy excludespecified
split-tunnel-policy tunnelspecified
split-tunnel-network-list value CorporateLAN
This will solve the problem globally
With Regards,
Safwan

Similar Messages

  • Printing from iPad - Why do I need third party app to print to a local network printer??

    Why do I need to pay for a third party app to print to ALL local network printer?? I understand that only some printers are compatable with iPads, but yet application like "iCanPrint" allow me to print just fine to a printer connected to my network. Why can't Apple include this as one of its features? Technology is apparently there?

    For that, and the many other apps to work, you need to be running a pc or Mac on the network.  The answer is drivers.  Every printer in the world needs a driver.  There simply is not enough space on a pad to load every possible printer driver that might be in play.  in the pc world, the operating system comes preloaded with hundreds of common drivers, and when you buy and install a new printer, you download the new drivers for that new printer.
    That all just will not work on a pad or phone.  So apple flipped the issue upside down, and said...'here is the printer driver we will make standard for its devices.  We call it AirPrint.  Include this in your printer'.    A lot of manufacturers have, and more printers are enabled each month.   
    So your choice is pretty basic.  You can buy an AirPrint enabled printer and print directly to it, or buy a non AirPrint printer, or use the one you have, and rely on your pc to act as the translation device to manage the print job.

  • How Can I print Oracle Report 9i directly To Printer on the local network?

    Dear All;
    How Can I print Oracle Report 9i directly To Printer on the local network?
    or to any other computer ? or to my default printer without prevoiues know the printer name i mean found it in my connected printer?
    plear help me?
    Best Wishes

    1. Check documentation for DESNAME and DESTYPE
    2. See 1 as long as they are a shared resource
    3. Think you must know the name, but please check or documentation
    Regards,
    Martin
    PS. There's a Reports Forum here which would be a better option for posting this question

  • How to send a file to a certain printer at the local network?

    Hello,
    Is there any Java API (standard or free packages) that allows to send a certain file from the filesystem to a certain printer at the local network, not necessarily the default one that the machine the code is running on is using? In case there is one, a code example could be nice...

    Hi Roy,
    There is a library part of the standard java for printing and searching printers. Have a look at the package
    javax.print
    A google search with the package name will lead to tutorials and code samples I guess.
    HTH
    Peter

  • Machines avail on Bonjour but not Local Network - when on same subnet?

    I have a simple system running ARD 3.2 on a machine running OS X 10.5.2, controlling a small number of machines running 10.5.2 or 10.4.11, all on the same sub-net.
    Two of the computers - both 20" Intel iMacs (2.0GHz CoreDuo) with 10.5.2 installed have an odd problem - most (but not all) of the time they show up in the ARD computers list as being available for Screen Sharing Only - and so things like copying files to the machine fail. Their entries have the 'light blue' icon next to them which appears to indicate this state.
    When in this mode they initially fail to show up when I do a scan of the local network. They should - as they are running off the same Airport hub as the ARD controller. However, if I change the scan to look for Bonjour connected computers they show up. If I then go back to scanning the local network they show up there too. But still nothing more than the light blue icon and screen sharing only as an option.
    I've checked the settings of both machines - both have ARD enabled in sharing, both have the firewall set to allow all incoming connections. Other machines connected to the same sub-net show up and can be used without problem. All the machines are running ARD client 3.2.1
    Anyone got any ideas what might be going on?
    Grateful for any advice / suggestions.
    Message was edited by: Gavin Lawrie

    Almost same setting here, same troubles.
    If I restart them via Screen Sharing via the Restart Button on the Login Window, they sometimes show up correctly. But this is way too annoying.

  • Connecting to a shared printer on a local network

    I want to connect my iBook G4 to my Dell Windows computer to utilize a shared printer on the Dell. We currently use a local area network. What do I have to do to my iBook to use this printer. Should the printers we are trying to connect to appear on my computer? I want to connect over our wireless network to a computer connected to our Dell Windows computer.
    Thanks for your help.

    I was having difficulty logging in to the server via. Finder, this is what worked for me.
    Netgear Router - WNDR 4000
    Mac OSX 10.5.8
    After selecting "Connect to Server" in Finder I typed in "smb://readyshare" and I pushed the connect button.  I was prompted with a username and password and I typed in the username and password that I use to log in to the Netgear router. 
    I recently upgraded from a WNDR3700 and I did not have to do the above.  The readyshare server showed up in Finder a few minutes after I connected the USB drive.
    This worked for me, hope it works for you.

  • How do I connect my Epson XP-205 printer to my wifi network when using an Apple Time Capsule as a router?

    Printer is updated with latest firmware and I have downloaded the latest installation sw from Epson. Configuration is done from my Mac Book pro running Mountain Lion.
    The network is set up using WPA2/AES.
    I have tried configuration using WIFI as well as through USB.
    Is there a way to reset the printer to factory settings?
    Any help appreciated

    Is there a way to reset the printer to factory settings?
    It's always possible that another user on an Apple support site might know the answer to this Epson question.....and you can wait to see if someone will reply......but, since you have a question about an Epson product, you will likely receive a much faster and informed answer if you ask your question on an Epson support site. The link is below:
    Epson America, Inc. - Support: Contacts - EPSON

  • TCP/IP Printing Issues on PC Network

    I work in an office and am trying to connect to our networked printer. I am connected to the network via my personal AirPort Express (as are about 5 PCs), but I am the only Mac connected. The PC's connect to the printer via a TCP/IP PORT named RNP750855. I just set up a few PC's printing capabilities by creating a new Port (RNP750855) from within the PC's printer setup menu. Once the port was created, I was able to select the correct printer model (Lanier 5645 PCL 6) from a pull-down list. I can print to this printer from within Virtual PC, but I have not been able to connect directly from Mac Programs. Any advice on how to print via my Mac?

    I wonder if this would help if you could find the IP address of the printer.
    Printing to a network ethernet printer (which has an IP address) from a Mac running OS 10.3.x
    http://www.ifelix.co.uk/tech/3005.html

  • Canon printer cannot communicate over network when plugged into time capsule

    I have just bought a new canon ix6550 and it will print fine when connected to my macbook pro but when i try to print when it is plugged into the timecapsule it will not communicate and I keep getting the error "Unable to communicate with the printer at this time". I have tried re installing the driver and can see the printer fine in airport utility.
    Any help would be appreciated as I am getting seriuosly stressed out with it! Haha!
    Cheers Ben

    Are you connecting the Canon printer to the USB port on the Time Capsule?
    If yes, did you also install the printer again using System Preferences > Print and Fax at the Time Capsule location?
    If yes, are you selecting the correct Time Capsule location when you look at the print dialog to print?

  • How can I use Airport Express to create a standalone Wi-Fi network without Internet Access so I can browse web pages on the local network? I will be using MAMP as my server (Apache)

    I would like to create my own Wi-Fi standalone network at an upcoming tradeshow where there will be NO internet access.
    Currently, I run and develop sites on my iMac use MAMP to manage my sites locally. Using MAMP, I run my sites as though they are on the internet although everything is local.
    I purchased an Airport Express hoping I could create a standalone network so that the iMac would broadcast its website to whatever device connects to it such as my iPhone, iPad and MacBookPro.
    However, after setting up the network successfully (I have a green light on the Airport Express, and there is NO internet going through it), I  am  not able to go any further by logging into the iMac's websites from the other machines. Form my MacBookPro Finder, I can look at files and folders using afp://10.0.1.2, from the Find/Go/Connect to Server utility, but I can't browse the website that is running on the iMac via the Safari browser.
    Can anyone help me configure my MacBookPro (or iPad, or iPhone) to run the website on the iMac when they are all on the same network?
    Thanks so much!!

    1) connecting the TC using a ethernet cable from one of the two modem's LAN ports to the TC's WAN port
    2) create a new Wi-Fi network using the TC ?
    Does someone already create a new Wi-Fi network using its TC connected by Ethernet on a modem/router device ? How do you set up the DHCP (and NAT) ? Which range did you use ?
    This is easy enough to do..
    Plug the TC directly into a computer.. without other connections to do the setup.
    Using the newly installed 5.6 utility.
    Bridge the TC.
    Create a wireless network.
    This is an older screen shot and I would set security to WPA2 Personal only not WPA/WPA2 Personal as shown above.
    I do recommend you use wireless names that are short, no spaces, pure alphanumeric.
    Update the TC..
    Now plug it into the modem router.. it will be a part of the network without doing NAT and DHCP itself.. which you do not want.. that leads to double NAT issues.. but it is a WAP that provides access to devices on both 2.4ghz and 5ghz bands directly to the main router.

  • I cannot print from firefox. I can print from open office. It seems to have something to do with when frames open because in IE, I can print a whole page, but when I try to use a print button embeded in a page or frame it does not work.

    Cannot print from firefox at all.
    In Internet Explorer, I was able to print by pushing the print button, but when opening a frame, like in mapquest, the embedded print button brings up an options window that has print frames options in it, but when hit OK in this box, a second error box comes up with a yellow exclamation point and nothing prints. I have a feeling that it is the same problem with both browsers, but would prefer using firefox. Can you help with this?

      Yes, I tried that.   The files were ordered by their original numbers as imported from the camera, but I batched them through Phocoshop to downsize all of them into a more manageable file size.   I opened that destination folder from quick time  from where it said select image sequence.   I clicked on the first one and opened it.   The result was a large image with an arrow indicating a movie was ready to go.   When I pressed the arrow, though, I realized it had only imported that one frame so there was no movie.   The files are Jpgs and are about 450 KB each. 
        To your knowledge are there any links to iMovie tutorials or quick time tutorials that may address this situation?  Maybe there will be one I haven't looked at yet. 
        Thanks

  • Issues with file locking when reading a file using RollingFile Appender

    Hi,
    I am facing a file Rotation Issue with log4j. I want a way to read one file from two diff apps.
    Intro: App A is writing a file F using log4j rolling file appender and app B is reading the same file F using “new BufferedReader(new InputStreamReader(new FileInputStream(_file)))”.
    Issue: App A is not able to roll the file. Because it is having a handle on the same file F.
    Please let me know how can I handle this issue.

    If you have the file open for reading when log4j tries to rename it, the rename will fail. Solution: don't have the file open for reading.
    I want to read the feed of such rolling logs without closing any handle.I gave you a solution to that too.
    If I am closing the handle after every read then there will be no way to determine where I left.Nobody suggested that.
    Is there any possible solution for this?What part of the solution I have already posted didn't you understand?

  • I cannot print to my photosmart 7510 when connected to work with VPN

    When I try to print to my printer while connected to VPN, I get an error that the software could not communicate with my printer. The IT department where I work has configured the VPN so that traffic to my local LAN is allowed (does not go through the tunnel). I had no problem printing to my old printer when connected with VPN (old printer was a photosmart 2510 connected via wireless network).
    These symptoms lead me to believe that the printer software is attempting to connect to the internet when I send a print job to my local printer. Why is it doing that? What settings do I need to change to make it stop so that I can print while connected with VPN?

    But I don't understand why the internet connection that my printer has comes into play when I'm sending a print job from my PC to my printer over my local network. I am not using the web services at all for that particular function.
    At least I shouldn't be - I don't know what the HP print software installed on my PC is doing under the hood. The software shouldn't have to access the internet to send a print job locally. Nor should my printer have to access the internet in order to receive the print job from my PC.
    What exactly is the printer or the print software accessing the internet for when I send a print job from my PC to my printer over my local network? 

  • VPN Server with two router local network

    I just got a Mac Mini Server 2011 to set up as a home server. One of the main features I want to use is a VPN so I can access my files on my local network when I'm away from home. I live in Japan and I have a Japanese optical connection to the internet that runs through two boxes before I can use it in any form: some sort of modem, and a "gateway" which I literally just found out is also acting as a router and serving DHCP addresses. In addition, I have a 2TB Time Capsule that, until just recently, I had been using in the "Share a Public IP" mode because I didn't realize the gateway was also issuing DHCP addresses. I cannot simply plug my TC into the modem in place of the gateway - both are required to access the internet.
    Until today I had both routers using DHCP on the local networks they each created. Under that environment, I had finally configured Lion Server to file share (easy), manage network accounts (moderate), and serve Profile Manager (difficult). But despite my best efforts at mapping the ports on the Time Capsule, I just couldn't get the ports open using tools like canyouseeme.org, so the VPN was a no-go. That's when I realized the gateway could be a router too, so with some creative google searches, and extensive use of google translate, I was able to figure out how to open ports on the gateway. It does it pretty differently from the Time Capsule and other routers I've seen. It asks you define the host on the LAN (what i assume to be the target IP), the protocol (TCP vs. UDP), and then a range of ports for it to open. I plugged in the IP of the Time Capsule, opened all the UDP ports (since it was an option to just open all, and I figured 1) the TC would still protect my network and 2) it would just be a test), but I still couldn't see the ports as being open.
    So then I got desperate, and I switched the TC back to Bridge Mode, reconfigured the Server and my MBP (my client Mac) to the new IP addresses being served by the Japanese gateway, and tried again. I think I reconfigured the DNS settings in Server Admin properly to account for the change in IP, and then updated the services in Server.app, but now I can't even get to my server homepage (the apple placeholder page) using either its IP or its .private domain, and to make matters worse, I STILL can't seem to get the ports open (yes, I changed the port mapping to send it directly to the server IP as the target after the change).
    To add insult to injury, the wired ethernet connection I had been running from my TC to the MM Server is now reporting a cable unplugged (it's not), even when I plug it directly into the gateway, though I am able to connect wirelessly.
    Does anyone have any idea what's going on? Why can't I get these ports open? (By the way, I called my ISP and they said they aren't blocking any of the ones I'd want to use for VPN.)
    What is the *better* set up - using the TC as a second LAN, serving its own DHCP addresses, or using it in Bridge mode?
    Why did these changes sever my wired connection?
    I was getting even more problems (like loss of internet connectivity on all devices) using the TC in bridge mode, so I decided to go back to the dual network setup.

    Hello Eric,
    As I mentioned above.
    For external Internet access, I would create a Generation
    1 VM
    and use 2 Legacy Network Adapters for
    the Interfaces . Connect it to the External and Internal network, and then install VM Linux IPFire (How
    to install) and
    configure IPFire with RED and GREEN interface.
    You don't need router or any firewall.
    I have the same set-up that you are trying to do in your lab and it's working great.
    All my VMs / computers on the LAN have their gateway the Linux VM.
    Hope this help.
    Regards,
    Charbel Nemnom
    MCSA, MCSE, MCS, MCITP
    Blog: www.charbelnemnom.com
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • Asa 5505 Remote VPN Can't access with my local network

    Hello Guys ,, i have a problem with my asa 5505 Remote VPN Connection with local network access , the VPn is working fine and connected , but the problem is i can't reach my inside network connection of 192.168.30.x , here is my configuration , please can you help me
    ASA Version 8.2(1)
    interface Vlan1
    nameif inside
    security-level 100
    ip address 192.168.30.1 255.255.255.0
    interface Vlan2
    nameif outside
    security-level 0
    ip address 155.155.155.10 255.255.255.0
    interface Vlan5
    no nameif
    no security-level
    no ip address
    interface Ethernet0/0
    switchport access vlan 2
    interface Ethernet0/1
    interface Ethernet0/2
    interface Ethernet0/3
    interface Ethernet0/4
    interface Ethernet0/5
    interface Ethernet0/6
    interface Ethernet0/7
    ftp mode passive
    access-list inside_nat0_outbound extended permit ip any 192.168.100.0 255.255.255.240
    pager lines 24
    logging asdm informational
    mtu inside 1500
    mtu outside 1500
    ip local pool vpn-Pool 192.168.100.1-192.168.100.10 mask 255.255.255.0
    icmp unreachable rate-limit 1 burst-size 1
    no asdm history enable
    arp timeout 14400
    global (outside) 1 interface
    nat (inside) 0 access-list inside_nat0_outbound
    nat (inside) 1 0.0.0.0 0.0.0.0
    timeout xlate 3:00:00
    timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
    timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
    timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
    timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
    timeout tcp-proxy-reassembly 0:01:00
    dynamic-access-policy-record DfltAccessPolicy
    no snmp-server location
    no snmp-server contact
    snmp-server enable traps snmp authentication linkup linkdown coldstart
    crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
    crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac
    crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac
    crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac
    crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac
    crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
    crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac
    crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac
    crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac
    crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac
    crypto ipsec security-association lifetime seconds 28800
    crypto ipsec security-association lifetime kilobytes 4608000
    crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs group1
    crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5
    crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
    crypto map outside_map interface outside
    crypto isakmp enable outside
    crypto isakmp policy 10
    authentication pre-share
    encryption 3des
    hash sha
    group 2
    lifetime 86400
    telnet timeout 5
    ssh timeout 5
    console timeout 0
    dhcpd auto_config outside
    threat-detection basic-threat
    threat-detection statistics access-list
    no threat-detection statistics tcp-intercept
    webvpn
    group-policy mull internal
    group-policy mull attributes
    vpn-tunnel-protocol IPSec
    username xxx password eKJj9owsQwAIk6Cw encrypted privilege 0
    vpn-group-policy Mull
    tunnel-group mull type remote-access
    tunnel-group mull general-attributes
    address-pool vpn-Pool
    default-group-policy mull
    tunnel-group mull ipsec-attributes
    pre-shared-key *
    class-map inspection_default
    match default-inspection-traffic
    policy-map type inspect dns preset_dns_map
    parameters
      message-length maximum 512
    policy-map global_policy
    class inspection_default
      inspect dns preset_dns_map
      inspect ftp
      inspect h323 h225
      inspect h323 ras
      inspect rsh
      inspect rtsp
      inspect esmtp
      inspect sqlnet
      inspect skinny 
      inspect sunrpc
      inspect xdmcp
      inspect sip 
      inspect netbios
      inspect tftp
    service-policy global_policy global
    prompt hostname context

    Hey Jennifer i did every thing you mention it , but still i can't reach my inside network (LOCAL network)  iam using Shrew Soft VPN Access Manager for my vpn connection
    here is my cry ipsec sa
    interface: outside
        Crypto map tag: SYSTEM_DEFAULT_CRYPTO_MAP, seq num: 65535, local addr: 155.155.155.1
          local ident (addr/mask/prot/port): (0.0.0.0/0.0.0.0/0/0)
          remote ident (addr/mask/prot/port): (192.168.100.1/255.255.255.255/0/0)
          current_peer:155.155.155.1, username: Thomas
          dynamic allocated peer ip: 192.168.100.1
          #pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0
          #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0
          #pkts compressed: 0, #pkts decompressed: 0
          #pkts not compressed: 0, #pkts comp failed: 0, #pkts decomp failed: 0
          #pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0
          #PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0
          #send errors: 0, #recv errors: 0
          local crypto endpt.: 155.155.155.1/4500, remote crypto endpt.: 155.155.155.20/4500
          path mtu 1500, ipsec overhead 82, media mtu 1500
          current outbound spi: 73FFAB96
        inbound esp sas:
          spi: 0x1B5FFBF1 (459275249)
             transform: esp-aes esp-sha-hmac no compression
             in use settings ={RA, Tunnel,  NAT-T-Encaps, }
             slot: 0, conn_id: 12288, crypto-map: SYSTEM_DEFAULT_CRYPTO_MAP
             sa timing: remaining key lifetime (sec): 2894
             IV size: 16 bytes
             replay detection support: Y
             Anti replay bitmap:
              0x00000000 0x00000001
        outbound esp sas:
          spi: 0x73FFAB96 (1946135446)
             transform: esp-aes esp-sha-hmac no compression
             in use settings ={RA, Tunnel,  NAT-T-Encaps, }
             slot: 0, conn_id: 12288, crypto-map: SYSTEM_DEFAULT_CRYPTO_MAP
             sa timing: remaining key lifetime (sec): 2873
             IV size: 16 bytes
             replay detection support: Y
             Anti replay bitmap:
              0x00000000 0x00000001

Maybe you are looking for

  • Won't let me restore to Factory Settings

    The family has 2 identical 'Hewlett Packard (HP) Pavilion P6210UK / Athlon II X4 620 2.6GHz / 4GB / 1TB / LightScribe DVD-SM / Windows 7 Home Premium / Desktop PC (VG245AA)'  My machine has started to run very slow these past few months and after va

  • Looking for a way to share a single library among two computer

    Ok here is the issue... I have a MB and MBP and I like to take the pro with me to work and such... Right now my itunes library on the pro is located on my USB drive connected to my airport extreme. my gf's is connected to her own on her laptop. now I

  • Bit Locker with Crucial SED

    Here is a quick video and walkthrough showing how to enable hardware encryption on Crucial SSD drives using Bitlocker in Windows 8/8.1 on a system without a built in TPM chip.

  • Photo on full screen

    If I switch to full screen mode in iphoto, I always see on right side this menu: faces, assign a places, data images, data camera, ... I see toolbar menu on bottom see too I read after 4 seconds should have to disappear but I can see always all menu

  • Combo Type UDF

    I have created a UDF in AR Credit Memo which is type of combo in line level matrix. how can i clear that combo box? have any one solution ? when i am trying to remove items from combo box the error message occuring "Iem - The Item is not a user defin