The "Route All Traffic" option would prevent this communication, as would an overlap between their local network and the encryption domain.
The first step I would take would be to compare the routing tables when connected to the VPN or not to see if traffic to the local LAN is going to the same route or not.
You may need to add a route manually to force the traffic for the local printer through the LAN interface.
See also this thread: https://community.checkpoint.com/message/9685-route-vpn-client-remote-access-to-lan