MustafaA SonicWall Employee
Reactions
Comments
-
Have you reviewed your Network Security Group configuration on Azure side?
-
Nice and useful script. Thanks @Alberto
-
Have you uninstalled/re-installed NetExtender?
-
You are welcome @Here2Learn . Glad I was able to help.
-
You can edit each record in the URI list.
-
You are very welcome @yiu2k . I am glad you have a clear understanding now.
-
@yiu2k , configuring DHCP scope for each interface, depends on your topology and network design. If you want two different subnets on those two different interfaces, then yes.
-
Use Packet Monitor to see the flow of the traffic. https://www.sonicwall.com/support/knowledge-base/how-can-i-setup-and-utilize-the-packet-monitor-feature-for-troubleshooting/170513143911627/
-
Please review your DHCP Server settings on the firewall. The following is just a reference of a SonicWall Live Demo firewall.
-
You can test this with "Source NATing". Add the following NAT policy and see if that helps. Source: SSLVPN IP Pool Source Translation: X3 Interface IP Destination: 192.168.10.7 Destination Translation: Original
-
There is no such a feature on the firewall that provides that information. An SNMP Manager can possibly collect that data, but I've not experimented that.
-
It goes out (egress) on the correct interface X3, but looks like there is no response coming back from 192.168.10.7. There could be two reasons I can logically think of. 192.168.10.7 does not have a default gateway configured. 192.168.10.7 does have end point protection (eg. Windows Firewall) which blocks the communication…
-
Can you do packet capture based on the source IP (given from the SSLVPN IP Pool)? Check if the packets are forwarded egress on the correct interface which 192.168.10.7 is part of.
-
@bpohlman , please make sure you backup your configuration before firmware upgrades. It is always good to have plan-B for recovery.
-
As @BWC highlighted the requirement cannot be fulfilled as is, since the NAT policies are not based on SNIs (Server Name Indicator). You have two options; Use reverse proxy, or Give each URI a distinct port so that it can be translated to the internal IP-Port pair