Comments
-
@SEBASTIAN, Is the remote end also a SonicWall? Also, you have included both 192.168.1.0/24 and 192.168.50.0/24 as the remote network on VPN policy on the remote end right? The NAT policy is not checked while forming the SA for the VPN. That takes place only when the data needs to be sent across. If the phase 2 is not up,…
-
Hello @SEBASTIAN, For test case 1, I would suggest having both 192.168.1.0/24 and 192.168.50.0/24 in the local networks field on the VPN and then not applying the NAT on the VPN policy itself. After this you can add the NAT separately that translates 192.168.1.0/24 to 192.168.50.0/24 only if the destination is…
-
Hello @Ninad94, I verified internally and the max entries per list is 5000 for the all models. Thanks!
-
Hello @Ninad94, The number of URI list objects is 256 on the latest firmware version and is the same for both the models as I have verified that from the TSR. I could not find the number of entries per list in the TSR. I will search some more on that and let you know. But, based on the feature guide, it looks like it…
-
Hello @Revup67, Welcome to SonicWall community. It looks like you have already performed all the troubleshooting steps. But, I think this could be a hardware limitation. The full DPI throughput on this model is 100 Mbps. Even with all the security services turned OFF and it set to performance optimized, it still has the…
-
Hello @sbrantl, That number is actually pretty huge. You can use the connection monitor on the firewall to see if any device on LAN is generating unnecessary traffic to/through the firewall. Also, please make sure that the device is on the latest firmware version and since it is a Gen 5 device which is already EoL, I would…
-
Hello @PeteB_S4, Welcome to SonicWall community. We would need to check if any of the firewall security checks or SIP transformation is causing such a problem/delay. It would be ideal to perform packet capture in real-time while the transfer is made to see what is exactly happening. The best way to figure that out would be…
-
Hello @Disconnected, I agree with @Nat. If you are testing from an Android device and using 6.5.4.6-79n firmware on the firewall, please reach out to our support team for the HF firmware so that this issue can be fixed. The KB provided above lists exactly what has caused this problem. Thanks!
-
Hello @sbrantl, Welcome to SonicWall community. All the interfaces on the firewall are set to auto-negotiate and they set the speed based on the connection on the other end. If you have any other interface at 1 Gbps at the moment, can you plug that in to the firewall's X0 interface and verify the speed? 1 Gbps speed on X0…
-
Hello @Ninad94, I found an old document when we had moved from CFS 3.0 to CFS 4.0. I see that 128 CFS URI List Objects can be added and the maximum entries per URI list is 5000. So, if these devices are on firmware 6.2.6.0 and above, that should be the number. Please take a look at page 8 on the attached document. Thanks!
-
@kbrianbond, We would need to perform packet capture to see what feature could be blocking access to those websites. You can filter for dropped packets and check the drop code. You can reach out to our support team for real-time assistance. Thanks!
-
Hello @Corbak, Welcome to SonicWall community. Port mirroring is available for NSa models with Switching module, but you can set up packet mirroring to help you save those packets. Please take a look at the KB below. Also, we have an option to send the packet capture to an FTP server for storage. I hope that helps! Thanks!
-
Hello @kbrianbond, Welcome to SonicWall community. Please take a look at the KB articles below and let us know what you find: Thanks!
-
Hello @SEBASTIAN, Yes, it can certainly be done. If you do not wish to apply the NAT policy directly on the VPN policy's advanced settings, you would need to choose the translated address directly as the local network and create the NAT policies independently. Thanks!
-
Hello @Chris_has_questions, Welcome to SonicWall community. Even on 6.2.7.1, the Save credentials option should be under the client settings tab of the Default Device Profile tab. Could you please let us know what you see when you click on the edit button for the same and go to Client Settings tab? If you could attach a…





















