BWC Cybersecurity Overlord ✭✭✭
Reactions
Comments
-
@network_r this Drop Code is "dropped" when a Sessions timed out and is very common and IMHO no cause of trouble. You might check with the Connection Monitor if the default Idle Timeout of 15 Minutes isn't long enough. You might modify the TCP timeout in an Access Rule or force the RDP client/server to do keep-alives to…
-
@CFBITSolutions I can't recall what the error message was when I had constant trouble getting updates for GeoIP and Botnet, but do you have USA on your blocklist? This causes a lot of trouble for me because iptables isn't don't proper internally. My battle is documented over here, but it does not seem identical to your…
-
@preston that's interessting, I'll keep this in mind. Trial and Retail has different names on MSW, the appliance just don't allow to assign a new serial number, even the trust is revoked and license information reset. In the meantime we redeployed the qcow2 (KVM) and assigned the Full license, but the curse is still…
-
@Thomas_Buergis on one hand I would love the idea to get LE certs easily on the Firewall but on the other hand I don't like the idea of having Ports 80 and 443 open to the public connecting directly to the Firewall. I stick to the rule to keep the attack surface as small as possible. With a single IP assigned to the WAN it…
-
I spend a good amount of time (again) with Customer and Technical Support, there was no way to reset the trust enough to make the Appliance believe it needs to be registered again and asking for the new Retail Serial number. Long story short, converting Trial to Full is still a mess and ends as often in repeploying the…
-
@Vincent_GPCU yes, that's how routing policies getting prioritized, not just by metric (per default). This can be confusing sometimes, but having the Route Policies sorted by Prio always gives you the full picture. Please check the following for further reference how to control the priority.…
-
@DavBer you might check the following first: does MobileConnect shows only a single route when connected pointing to your internal network? e.g. 192.168.1.0/24 is there an overlap between your current network where your phone is connected to and the network behind the SOHO? e.g. both sides using 192.168.1.0/24 --Michael@BWC
-
@johnaaa did you tried to upload a SMA 100 Series Firmware to a SMA 1000 Series appliance? Please check what Firmware and Platform you're on and upload the correct image. The virtual 1000 Series model is called 8200v but you could have a bare metal appliance. They are called both SMA which might caused the confusion.…
-
@preston did you tried this recently? It's the 2nd time it isn't working as expected to convert a trial to full. Reseting the license makes the Appliance unresponsive for a while, I deleted the Trial license on MSW. All on 10.2.1.10 but a while back it was the same situation on an older version. When the Appliance is…
-
@Alexander_Bertol welcome to the club. I did experienced the crash only when downloading is done through Virtual Office, but maybe I was just "lucky". --Michael@BWC
-
@johnaaa like always you can get it on MySonicWall. --Michael@BWC
-
@Simon_Weel I guess it's safe to say to NOT use it at this moment. There are plenty of problems reported and I guess you should stick with 7.0.1 for the time being. --Michael@BWC
-
@GoldTipu the Appliances do support IPFIX/Netflow but need a separate solution (external Netflow Collector) if the onboard AppFlow Report is not sufficient. There is no free (included) solution for that from SNWL their offerings are Analytics and/or NSM. I'am still looking for an Open Source solution but did not found the…
-
@GoldTipu latest Firmware for a TZ 350 is 6.5.4.13. I had a few cases where existing Access Rules stopped working until rebooting the appliance, but that got fixed around 6.5.4.10 IIRC. If you're on site you should reboot the appliance and check if this changes anything. Maybe starting a Packet Monitor to see if anything…
-
@GoldTipu do you have a Router in front of your TZ 350 which does some NAT forwarding traffic to the Firewall? Maybe that's the root cause not having any inbound NAT working anymore if the Router stops working the NAT. --Michael@BWC


























