Off-Network Printing

Last Updated: August 12, 2026

The Off-Network Cloud Print (ONCP) and Off-Network Print (ONP) features solve two printing challenges:

  • Managing print in a Zero Trust Architecture (ZTA).
  • Providing simple and secure access to users without a virtual private network (VPN) or web portal.

Organizations can create an isolated, secure printer network that is separate from the main network used by employees, contractors, or guests. This separation adds an extra layer of security and keeps the printers in a controlled network environment. ONCP and ONP bridge the gap between networks, allowing users on the main network to print without compromising the security of the printer network.

Key Points

Review the following key points:

  • These features require additional licensing. Contact your Vasion representative for details.
  • These features exclusively use RAW printing on the Windows platform. ONP also uses RAW printing on macOS platforms.
    • Line Printer Remote (LPR) is not currently supported.

ONCP

  • Supports Windows, macOS, and mobile devices (iOS and Android).
  • Provides two internal routing options: install the ONCP app on the printer, or use an Internal Routing Service (IRS)Agent for manufacturers that do not support the app.

ONP

  • Supports Windows, macOS, Linux, ChromeOS, and mobile devices (iOS and Android).
  • Supports customer-hosted and hybrid gateway configurations for additional redundancy.
  • You can use your own asymmetric key pair for additional print-job encryption. For more details refer to Asymmetric Key Pair Configuration.

How Off-Network Printing Works

Both features use two main components: an external gateway and an Internal Routing Service, with the ONCP app acting as the IRS. The external gateway receives incoming print jobs from remote devices and acts as the entry point to the secure printer network. The IRS monitors the external gateway, downloads print jobs into the secure network, and delivers each job to the destination printer.

ONCP

ONCP uses regional external gateways hosted in Amazon Web Services (AWS) and the Vasion ONCP app, which installs on the printer. This model reduces infrastructure costs and lets users on other networks print. When a user on another network sends a job to an ONCP-enabled printer, the encrypted job travels to the external gateway. The ONCP app monitors the gateway, immediately retrieves the job, and releases it at the printer.

Not all printer manufacturers support the ONCP app. For unsupported manufacturers, ONCP uses an IRS Service Agent instead. The Service Agent is a designated device on the printer network that monitors the external gateway, retrieves print jobs, and routes them to the correct printer.

Diagram showing network traffic flow for ONCP.

ONP

ONP provides more redundancy and more gateway options, but it does not use the ONCP app and requires more infrastructure. ONP supports Vasion-hosted AWS gateways, customer-hosted gateways, and hybrid environments that combine both.

Instead of an app, ONP relies on IRS Service Agents on the printer network to route jobs from the gateway to the printer. You can configure multiple external gateways and IRS Service Agents for failover in high-availability environments.

Diagram showing network traffic flow for ONP.

Compare ONCP and ONP

Use the following comparison to choose the model that fits your environment:

Comparison Chart

Capability

ONCP

ONP

Supported Platforms

Windows, macOS, and mobile devices (iOS and Android).

Windows, macOS, Linux, ChromeOS, and mobile devices (iOS and Android).

External Gateway Hosting

Vasion-hosted (AWS).

Vasion-hosted, customer-hosted, or hybrid.

Gateway Assignment

Automatic, based on the instance region.

Manual, at the root, folder, or printer-level.

Internal Routing

ONCP app installed on the printer, or an IRS Service Agent.

IRS Service Agents only.

Redundancy

IRS Service Agent redundancy.

Multiple external gateways and IRS Service Agents.

Off-Network Priority Options

Off-Network Only and Direct IP Primary.

Off-Network Only, Direct IP Primary, and Off-Network Primary.

Off-Network Priority

Off-Network Priority controls where the PrinterLogic Agent tries to send the job first, either directly to the printer or to the ONCP or ONP service.

Off-Network Only
The Agent sends the print job using only the ONCP or ONP service and does not try to send the job directly to the printer, which is direct IP printing.
Direct IP Primary
The Agent sends the print job directly to the printer, which is direct IP printing. If unsuccessful, the Agent sends the print job using the ONCP or ONP service.
Off-Network Primary
The Agent sends the print job using the ONP service. If unsuccessful, the Agent sends the print job directly to the printer, which is direct IP printing.

Note the following:

  • ONCP does not support the Off-Network Primary option.
  • The Off-Network Priority options apply to only computers, not to mobile devices.

Requirements

Review the following requirements.

IRS Service Agents

For configurations using an IRS Service Agent:

    For Windows Service Agents, ensure that Visual C++ Redistributable for Visual Studio 2015 or later is installed. You must install both the x86 and x64 redistributable packages. You can download these packages from the Windows Download Center.

  • All devices, including Service Agents and printers, must access the Domain Name System (DNS) server to resolve names.
  • For redundancy, you can add multiple Service Agents.
  • Routing from the IRS to the printer occurs over TCP port 9100 or port 631 for IPPS.

For more details refer to Service Agent Setup.

ONP Requirements

Review the following requirements:

  • Printers using ONP cannot have the SNMP Status option selected on the printer's Port tab. This option is different from SNMP Status Monitoring.
  • ONP printing occurs over TCP port 443 from the device to the external gateway and from the external gateway to the IRS.
  • Ensure that the following allow list URLs are open and adjusted for your region:
    • ofn.app.printercloud.com.
    • ofn-gw.app.printercloud.com.
  • Customer-hosted gateways require a Secure Sockets Layer (SSL) certificate and key from a trusted Certificate Authority (CA).
    • The certificate must be a Base64 Privacy Enhanced Mail (PEM) full chain unencrypted file.
    • The key must be in unencrypted Public Key Cryptography Standards (PKCS) #8 format, and it must correspond to the PEM certificate.
    • The certificate must match the external Domain Name System (DNS) or IP address of the external gateway.

Vasion-Hosted Gateways

Vasion external gateways are hosted in AWS and include the following:

  • PrinterLogic U.S.-NOW Gateway: printercloudnow.

    Note that the PrinterLogic U.S.-NOW Gateway is only for Vasion Now instances. U.S.-based Scheduled Release SaaS (SRS) customers must use the PrinterLogic U.S. Gateway.

  • PrinterLogic U.S. Gateway: printercloud.
  • PrinterLogic EMEA Gateway: printercloud5.
  • PrinterLogic ASIAPAC Gateway: printercloud10.
  • PrinterLogic SE-ASIAPAC Gateway (Singapore): printercloud20.
  • PrinterLogic CANADA Gateway: printercloud15.
  • Service Agent Name: Customer hosted.

ONCP Requirements

Review the following requirements:

  • For a list of supported devices, refer to Supported Printers for Printer Apps. Filter the results by selecting the Off-Network Cloud Printing option from the Feature dropdown menu.
  • You need a Service Agent running the Printer Apps service. The ONCP app installs using the Printer Apps service. You can turn off or delete the Service Agent after installing the app if it is not part of another configuration.
  • Ensure that the following allow list URLs are open and adjusted for your region:
    • Oncp-ofn.app.printercloud.com.
    • Oncp-pgw.app.printercloud.com.
  • A Kyocera MFP must have an SD card to install third-party apps, like the ONCP app. If the device does not have an SD card by default, then you must install one.
  • The HP ONCP app requires you to turn on the Workpath platform on the printer.
  • Contact your HP representative or your HP-certified reseller to add the Vasion HP ONCP app from the HP Command Center. The representative needs to do the following:
    • Claim and add printers to the HP Command Center.
    • Add the Vasion ONCP app as a solution.
    • Add the app to the customer's account.
    • Manage and deploy the ONCP app to the printers.

Manufacturer Support

The following manufacturers support ONCP. Manufacturers supporting the ONCP app also work with an IRS Service Agent.

ONCP App Installation

  • Fujifilm.
  • Fuji Xerox.
  • HP.
  • Kyocera.
  • Lexmark.
  • Ricoh Multifunction Printer (MFP) devices.

IRS Service Agent

  • Canon.
  • Epson.
  • Konica Minolta.
  • Sharp.
  • Toshiba.
  • Xerox.
ONCP App Manufacturer Ports & Requirements
 
ONCP App Manufacturer Ports & Requirements

Manufacturer

Ports & Requirements

Fujifilm

  • ONCP app installation and uninstallation occur from the Service Agent to the printer over TCP port 50200.
  • Printing with ONCP occurs over TCP port 443 or port 631 for IPPS.
  • You must turn on imbedded plug-ins.

Fuji Xerox

  • ONCP app installation and uninstallation occur from the Service Agent to the printer over TCP ports 443 and 50200.
  • Printing with ONCP occurs over TCP port 443 or port 631 for IPPS.
  • You must turn on imbedded plug-ins.
  • The Controller ROM firmware must be version 1.60.4 or later.

HP

  • ONCP app installation and uninstallation occur from the Service Agent to the printer over TCP port 443.
  • Printing with ONCP occurs over TCP port 443 or port 631 for IPPS.
  • You must turn on the HP Workpath platform on the printer to install the ONCP app. Follow the HP Required Steps section later in this topic.
  • An HP representative or an HP-certified reseller must claim the ONCP app in the HP Command Center and add it to your account. Follow the HP Required Steps section later in this topic.

Kyocera

  • ONCP app installation and uninstallation occur from the Service Agent to the printer over TCP ports 8083, 9091, and 9090.
  • Printing with ONCP occurs over TCP port 443 or port 631 for IPPS.
  • A Kyocera MFP must have an SD card to install third-party apps, like the ONCP app.
  • Turn on the following network settings on the MFP:
    • SSL/TLS.
    • Enhanced WSD.
    • Enhanced WSD over SSL.

Lexmark

  • ONCP app installation and uninstallation occur from the Service Agent to the printer over TCP ports 80 and 443.
  • Printing with ONCP occurs over TCP port 443 or port 631 for IPPS.

Ricoh

  • ONCP app installation and uninstallation occur from the Service Agent to the printer over TCP port 443.
  • Printing with ONCP occurs over TCP port 443 or port 631 for IPPS.

Next Steps