Solved

Printing between remote IPSEC networks

Posted on 2007-03-31
7
397 Views
Last Modified: 2013-11-21
I have 2 networks physically located in 2 cities, they are connected together with IPSEC devices that have been configured to allow unfettered access between the 2 networks.  Each network has an Win2003 SBS.  One network use 172.16.6.x the other 10.0.0.x.  Currently we are using RDP to allow access to machines between the networks.  IE from the 172 network, logged into the winXP machine named "Test" at 172.16.6.101, I connect to the "Test2" machine at 10.0.0.108.  Running MSWord on the "Test2" machine I attempt to print to the "Test" machine an am unable to.

I have turned on the the printer flag within the RDP configuration without success.  I have created entries in the HOSTS file without success, I have attempted to add another zone in the DNS server with a host record created for the remote machine again without success.

Any help would be appreciated. Thanks
0
Comment
Question by:FIFBA
  • 3
  • 2
  • 2
7 Comments
 
LVL 77

Expert Comment

by:Rob Williams
Comment Utility
To set up printing with remote desktop:
-On the users workstation when they start the remote desktop connection client, click the options button, and then go to the local resources tab. Check the box for printers and save.
-the drivers for the printer have to be installed on the computer to which you are connecting, assuming they are not native to the operating system. Do not install the printer on the computer to which you are connecting but rather; on the "server" computer, open printers and faxes, on the menu bar go to file, server properties, add, and point to the diver .inf file. You will have to download the drivers first to a temporary folder. If you do this remotely, you should log off and back on before trying to print
-if still having problems, again on the computer to which you are connecting, go to printers and faxes, on the menu bar go to file, server properties, ports. Look at the port type. If it is a Dot4, you will need to use the following Microsoft fix: http://support.microsoft.com/default.aspx?scid=kb;en-us;q302361
-if it is an option, often connecting the printer to another local computer and sharing it, then connecting to the share rather than having it attached locally, often resolves the problem. If you are using a VPN client this is not always possible, due to routing issues.
-if you are using a USB printer, though it usually works (some multi-function units do not), Microsoft does not officially support USB printing through remote desktop sessions. Vista is supposed to resolve this, though it doesn't help you now.
-avoid PCL6 drivers with terminal services
-Microsoft has released an updated version of the Remote desktop Connection (ver 6) which should be more compatible with USB printers. Certainly offers more USB options, assuming these are compatible with existing O/S's.
http://www.microsoft.com/downloads/details.aspx?familyid=26F11F0C-0D18-4306-ABCF-D4F18C8F5DF9&displaylang=en
0
 
LVL 6

Expert Comment

by:manicsquirrel
Comment Utility
If you want to go another router you can port tunnel to your printer on TCP 9100 and print directly to it across the internet.  You can also do the same with IPP (internet printing protocol) on TCP 631.

The client machine running the Remote Desktop Client can have those remote printers installed as local printers but the ports are remote ports.

Now the above would only be possible if the target printers are networked printers - meaning they have a network interface.

However, seeing that you have a 2003 SBS, you can use the print server function on the server and it will host LPR or IPP for the printers for you.
0
 

Author Comment

by:FIFBA
Comment Utility
Virtually all of the remote desktop methods have failed.  between the combination of printers that are being used (multipurpose) and porte being used (USB).  I wen thtrough each of the stes detailed in the first recommended solutions and followed the Microsoft rocesess to their ends without success.

Can I get some more information on the TCP 9100 solution?  is this secure when postng files to the printer?

Regards,
Kevin Gibson
kgibson@nksag.com
0
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 
LVL 6

Expert Comment

by:manicsquirrel
Comment Utility
"Can I get some more information on the TCP 9100 solution?  is this secure when postng files to the printer?"

It is possible that some random individual could discover TCP 9100 open and print garbage to your printer.  Other than that, I cannot think of anything.

On your SBS network, make sure that TCP 9100 is forwarded to your laser printer.  At the remote site, add the printer as if it were local, except you are going to create a new TCP/IP Printer Port.  When prompted for the address of the printer port, input the external ip of your SBS network.

If you would like step-by-step details I will provide them.
0
 
LVL 77

Expert Comment

by:Rob Williams
Comment Utility
As a first step troubleshooting, directly after starting a remote desktop session, go to the event viewer and look for errors with source of Print and Event ID 1111. This will tell you if the printer is even being recognized.

Must say multi-function USB printers are likely the worst ones to get to work with Remote Desktop.
0
 

Author Comment

by:FIFBA
Comment Utility
I have 2 networks (10.0.0.0) and (172.16.6.0)  There is an IPSec tunnel that exists between the 2 there is no restriction with respect to port traffic between the 2.  shouldn't I be able to send the 9100 traffic between the 2 without going to the internet?

i guess I'm a little slow, is there an instruction that I can step through.

thanks for all your help.

Kevin Gibson
kgibson@nksag.com
0
 
LVL 6

Accepted Solution

by:
manicsquirrel earned 500 total points
Comment Utility
Try this:

1. If you are in the 10.x network you can open the Printers and Faxes control panel.
2. From the File menu, select Server Properties
3. When the dialog box appears, click on the Ports tab, and then click Add Port
4. From the Printer Ports dialog box that appears, select Standard TCP/IP Port
5. Click New Port
6. When advancing through the wizard, when prompted for the ip address of the port, assuming the printer is on the 172.x network, you would type in the 172.x.x.x address of the printer.

Now that the port is added, try adding the printer as you would add an other printer, but do not have the printer auto-detect.  Select a Local Port, and when you are prompted to pick the port, change it from LPT1 to the port you had just created.

Of course, I don't know which network is your origin and which is your destination, but I should think that this would be enough info to print directly to the printer from where you are.
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

A quick step-by-step overview of installing and configuring Carbonite Server Backup.
This is an article about my experiences with remote access to my clients (so that I may serve them) and eventually to my home office system via Radmin Remote Control. I have been using remote access for over 10 years and have been improving my metho…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now