Jump to content

Recommended Posts

Posted

Hi guys.

 

I've got PaperCut Web Print set up and working for domain joined devices, however devices not on our domain that are connected via our Guest Wi-Fi are not allowed to communicate with our print server, this means the Web Print does not work, kinda defeats the object of web print. Has anyone that uses Paper Cut come across this before and found a solution?

 

Thank you in advance!

Posted

The whole point of the web print is to allow non-domain based devices to connect and use it, so not sure what you mean in regards to not allowed to communicate with it?

 

As it's over an SSL webpage you have a few options, either allow the connection to the print server directly within the network, which could be restricted via ACL etc for the right ports.

 

Or publish the page, as it's designed for external usage too. People can print from home via the same method it doesn't need to be on the domain. Then the users on the guest wifi just connect to the external facing address.

 

 

If it's security wise in regards to you don't really want people hitting the physical server there are two real options, a) as above use the external address, b) use a sandbox papercut server.

 

The sandbox server is a separate server that hosts the web-print part and does the rendering/printing from that system, not direct to the print server.

 

Unless I've missed what you mean completely :p

 

Steve

Posted
Here only devices in AD can connect to our main school wireless network, external devices connect to a guest wi-fi network which has certain restrictions, one of them being it cannot communicate with other computers on the network, ie our print server (which is a requirement of web print for it to work) :(
Posted
Or publish the page, as it's designed for external usage too. People can print from home via the same method it doesn't need to be on the domain. Then the users on the guest wifi just connect to the external facing address.

 

 

If it's security wise in regards to you don't really want people hitting the physical server there are two real options, a) as above use the external address, b) use a sandbox papercut server.

 

The sandbox server is a separate server that hosts the web-print part and does the rendering/printing from that system, not direct to the print server.

 

Unless I've missed what you mean completely :p

 

Steve

 

I like the idea of publishing the page, I'll look into that one. Web print is in sandbox mode running on a different server to that of the print server, however the papercut login address is that of our print server... :S sorry!

Posted

Best way would be publishing the address externally then. People on the guest one effectively would just connect to that then.

 

"But" I would query the logic as that's no different to just allowing the single IP address of the Sandbox access to all VLANs via a port lockdown on the ACL.

 

e.g. Allow 443 to "Sandbox" from the guest VLAN, is no different (if not more secure) then allowing external access. If that makes sense?

 

Would be easier externally for sure, but depends if you'd ever require the external part if that makes sense :)

 

Steve

Posted
Best way would be publishing the address externally then. People on the guest one effectively would just connect to that then.

 

"But" I would query the logic as that's no different to just allowing the single IP address of the Sandbox access to all VLANs via a port lockdown on the ACL.

 

e.g. Allow 443 to "Sandbox" from the guest VLAN, is no different (if not more secure) then allowing external access. If that makes sense?

 

Would be easier externally for sure, but depends if you'd ever require the external part if that makes sense :)

 

Steve

 

Just found out we don't have any control over the guest VLAN, all head office controlled :( I've emailed PaperCut support about publishing the login address externally, or how would you recommend enabling that? Thank you for all your help.

Posted

Ah that'd be a problem then haha :p

 

Effectively same as any other website, you publish the way they normally connect so like in your situation say, Print.address.co.uk dns address externally, reverse proxied on firewall pointing to sandbox internally.

 

Then when browsing to the address it'd just load the login page and bam printable :)

 

Steve

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...