TKWITS Community Legend ✭✭✭✭✭
Reactions
Comments
-
Is there really a need to create or 'bind' VLANs for the mentioned 192.168.10.x subnet? If the device works as it's supposed to but occasionally throws some packets out that are getting ID'd as a spoof is it a big deal?
-
i can try to test a NAT policy over a tunnel interface, but have you considered using the Sonicwall AWS integration to create the VPN?
-
It doesn't seem likely. Pertinent sections (page 16-18) of the admin guide makes no mention of the ability to change the management VLAN.
-
Older versions did not support route-based VPNs to 3rd party devices but that text has since been removed from modern KB articles. It is safe to assume it is supported. You are correct, it does not say it is not supported. It simple states 'when advanced routing is not needed'. Which in my opinion means it's not…
-
It's either on or off, you cannot force login uniqueness for specific groups or users.
-
You still havent shown us the problem NAT policy...
-
So your saying you lose Access Rules allowing firewall management upon reboot? But these rules are specific to a Site to Site VPN tunnel with NAT. Provide more description on which side is performing the NAT, sanitized screenshots, etc. If it were me I'd just re-subnet one of the subnets and get rid of the overlap.
-
You haven't shown us anything or provided enough information for us to help.
-
What do you mean you "enter passive ftp"? Are you hosting the FTP service behind the firewall or just trying to access one? You haven't given much info. Have you read any KB articles? or
-
Open a support ticket as you may have discovered a bug.
-
You can change the global timeouts in the Flood Protection settings.
-
If I am reading correctly you want to NAT over a tunnel interface. Im not sure thats supported. Also according to the below article, using Advanced Routing over a tunnel interface is not supported. You might want to consider utilizing a different method for tunneling to AWS.
-
Are you passing the AD domain DNS server to the netextender connection and using the FQDNs of the servers? If not have fun.
-
There's a reason it's either Tunnel All or Split, not a mix of both. However yourself and others have managed to get some functionality working would be unsupported by Sonicwall... You need to Split and add the needed routes.