cancel
Showing results for 
Search instead for 
Did you mean: 

Print to home network without Split-Tunnel enabled - options

JohnW_
New Contributor

Print to home network without Split-Tunnel enabled - options

We currently use Network Connect for our remote users, but do not provision split-tunneling. We are starting to get requests for users who are connected to their "home" network to be able to print to their local printer. Is there a way short of creating profiles for each home network range, allowing split tunneling for the printer-port, to handle this. Any options that you know of and care to share?

Thanks in advance,

JW

6 REPLIES 6
AndyC_
Occasional Contributor

Re: Print to home network without Split-Tunnel enabled - options

Hi,

Have you had a look at enabling local subnet access???

Allow access to local subnetÑThe IVE preserves the route on the client,

retaining access to local resources such as printers. If needed, you can add

entries to the clientÕs route table during the Network Connect session. The

IVE does not terminate the session. This is the default option.

This would give you partial split tunneling, so they could only get to their local network and not to the internet.

More info on this can be found in the administration manual under the network connect section.

Hope this helps.

Regards

Andy

JohnW_
New Contributor

Re: Print to home network without Split-Tunnel enabled - options

I considered that, but knowing that many home networks have "kids doing IM and music downloads" has me a bit concerned about opening up the local network. Is this option only to allow access "to" and not "from" the home network?
privatepile_
Contributor

Re: Print to home network without Split-Tunnel enabled - options

I think you're being overly cautious. Do you think the machine is any better when it doesn't run network connect and is on that subnet, then comes back on your LAN? Or gets on the net before with those same "IM and Music kiddies" and can now access your subnet via standard NC?
Another_Mike_
Occasional Contributor

Re: Print to home network without Split-Tunnel enabled - options

What about a compromise? Something like ... Have HC check for a software firewall on the target (protects from the kiddies // online or offline) and if so, map the user to a role that permits Split Tunneling to the local subnet so they can print (vs a fallback role that just gets the cruel punishment of zero split tunneling). Then when your users nag you for print capabilities you can tell em "sure thing - just enable that Windows firewall and you're all set". O'course, that's assuming all your folks are Windows types.

jspanitz_
Frequent Contributor

Re: Print to home network without Split-Tunnel enabled - options

Where has this option gone in the version 8 code?  I can't locate it anymore.

filbert_
Frequent Contributor

Re: Print to home network without Split-Tunnel enabled - options

It's under Route Precedence. "Tunnel Routes with local subnet access"