BWC

Cybersecurity Overlord ✭✭✭
Avatar

Join the Conversation

To sign in, use your existing MySonicWall account. To create a free MySonicWall account click "Register".

BWC Cybersecurity Overlord ✭✭✭

Badges (27)

5 Year Anniversary250 Answers4 Year Anniversary3 Year Anniversary250 Likes100 Answers100 Helpfuls2 Year Anniversary1,000 Comments50 Answers1 Year Anniversary500 Comments25 Answers100 Likes25 Helpfuls100 CommentsWork Out Loud5 Answers25 LikesFirst Answer10 Comments5 HelpfulsFirst Comment5 LikesPhotogenicName DropperEarly Adopter

Comments

  • Hi @CFT this shouldn't make difference if your Client Address Range is handled on the SMA itself, the Firewall (Gateway) should know where to find the address, just check the ARP table on the Default Gateway Device your SMA is pointing to, maybe it's a similar issue. --Michael@BWC
  • Hi @rhnac I'am seeing this a lot, the log of an updated SMA 400 just stopped after 15 logged events, appliance is running besides that fine though. Did not have to power cycle it, because of that troublesome on-board logging I suggest having a syslog server, this helped in the past. --Michael@BWC
  • Hi, the problem could be resolved by setting the SSL Encryption Security Level for Internal Systems to Legacy instead of Secure, it seems that the TerminalServers are not up to date. System Configuration -> SSL Settings -> SSL ENCRYPTION (bottom) -> Edit -> Advanced -> Use a different security level for connections to…
  • Hi guys, I'am a never GMS'er (that's a saying these days, right?) but did you saw on MSW that there was a new version 9.3.9316 released on Feb 8th? Maybe this will ease your pain. Good luck. --Michael@BWC
  • Hi @CFT hmmm this is interessting, what could cause MobileConnect not to work but NetExtender if they are both fired by DHCP assignments, interessting. This is what I mean about the route TZ (X4) 192.168.55.1 DHCP-Range 192.168.55.128 - 192.168.55.254 (provided by TZ, could be DC as well) SMA (X0) 192.168.55.16 On the TZ I…
  • Hi @Micah my personal focus would be on 100 Series. --Michael@BWC
  • Hi @stf looks like another attempt for SQL injection. But you can be assured SNWL would definitely comment on that urgent matter if our deployments would be on any risk whatsoever. Wasn't worth a comment last week for a similar sighting, so it's a nothing burger. This message may include spoors of sarcasm, be advised if…
  • Hi @Davide when you have the developer tools open and selected the Web Console and then clicked on the Settings page, is there any error? Maybe a restart could fix this, but hard to tell. Otherwise it would be a case for the support which is a dilemma in your case. --Michael@BWC
  • Hi @Davide that's tricky, while investigating a bug recently I tested all versions from 8.0 upto 10.2 and never had trouble with accessing, so maybe it's not browser related. Always working with the lateste Google Chrome. Does the browser developer tools throw any errors? Does your AV interfere in any way? --Michael@BWC
  • Hi @Davide did you tried to upgrade from 8.6.0.1 to 10.2.0.5 directly? This seems to be an unsported jump of versions: SonicWall recommends a stepped upgrade process that goes from one major version to the next. For example, a system running 8.0 is incrementally upgraded going from version 8.0 to 8.1, then 8.1 to 8.5, 8.5…
  • Hi @MPNS putting the im LAN/DMZ or whatever custom Zone is 100% fine, my thought putting them in the WLAN zone was to avoid any changes when the customer decides to go with the SonicWaves later on. All I need to take care of is to disable "Only allow traffic generated by a SonicPoint/SonicWave" in the zone settings. Never…
  • Hi @Didier that's interessting, will keep that in mind if I'am facing this. Thanks and stay safe. --Michael@BWC
    in Log Comment by BWC February 2021
  • Hi @tracer I can't see any fundamental difference between deploying behind X0 or let's say X2 (DMZ alike zone) from a technical perspective, securitywise is another story which you already know. I don't get your scenario, you're having multiple Firewalls (SNWL?) or is the 2nd just for testing? Either way, deploy your SMA…
  • Hi @tracer you mileage may vary, but I usually deploy the SMA in a DMZ-like zone, having it in the LAN zone is a bad idea. In that scenario you can assign IPs to your NetExtender/MobileConnect clients which can be controlled on the Firewall as well. But this general advice, whenever possible do not grant access from WAN to…
  • Hi @SonicAdmin80 DKIM problems are way harder to debug than SPF, but in general I would say it works (until it got broken again). Did checked my log and DKIM failures are rare. This week I had a case where some mails from remote mail gateways got marked with a DKIM failure which was working without a problem before and…