MitatOnge All-Knowing Sage ✭✭✭✭
Reactions
Comments
-
Hi @Het1920 if your network and end user home network ips are same. Mobile connect doesn't work. If it is possible to change your ssl vpn network ip segment. before change the ip segment please check the "Tunnel All Mode" disabled. if tunnel all mode is disabled and same ip network doesn't work again than chenge the…
-
@ChrisLakeErie Please check below steps. 1) wan interface Bandwith settings ( 1 digit could be missing during Gbit to Kbit convertion. ) 2) check wan interface cable and sfp modules. 3) check ISP router DUBLEX settings. 4) Sonicwall MTU size test via command line 5) network connection test via Diagnostic test tools. 6)…
-
@TBHOSC if i'm not mistaken. nutanix ping himself, packet won't go to network, it will replay own arp table and loopback interface. ( This procudure is same as another network devices.)
-
Could you enable sip options on the VPN zone access rules and check local address objects and peer address group on the VPN settings
-
Did you create the rules with wizard or manuel ?
-
You should add static arp for wan interface and after that you can use second ip block. You can find out below knowledge base https://www.sonicwall.com/support/knowledge-base/configuring-multiple-wan-subnets-using-static-arp-with-sonicos-enhanced/170503911164326/
-
- Set to geo ip filter for attacker countries - change wan access rules drop to discard option. - enable TCP flood options under the firewall settings.
-
you should enable Web management on the GVC rule settings. NSA 250 and other devices have same option under the GVC Rule settings.
-
did you try disable this signature under the GAV menu?
-
did you check below menu? Firewall / Chiper Control / SSH Chipers
-
If you configured SMA behind the Firewall and remote client wants to access to internet via SMA You should use same DPI-SSL / Server SSL and Client SSL same certificate. what is your topolgy? could you give details? especially DPI-SSL settings.
-
has the switch flood portection or something like on the ports? because of sonicwall creates a lots of log and send to syslog server. is there any security settings on the switch.
-
could you check connection port 49 on the client via telnet command? If you can access on client to tacacs server port 49 you should check tacacs server firewall settings for NSA E5600 IP.
-
I think, log server and firewall connection not stable. could you check network topology between 2 devices.
-
@Targeted maybe this will be usefull tip, If you configured schadule cloud backup. you can see last backup on the mysonicwall account and see last backup date.