Search This Blog

Showing posts with label sonicwall. Show all posts
Showing posts with label sonicwall. Show all posts

Sunday, May 9, 2010

building site-site vpn using sonicwall

across Tasman, site-site vpns worked for some time.

now there is a new TZ 200 in the main office, I need to rebuild the site-site link.

connection to Sydney works using the manually key.

But I got a big problem with Brisbane site. payload error, cookie broken, auth error etc. eventually I lowered the encription strength, then boom... VPN tunnell is up and running, ping is 66ms... bot that bad ...

Saturday, May 8, 2010

check wan ip address -- I just copy from sonicwall admin guide

To test the HTTP policy-based route, from a computer attached to the LAN interface, access


the public Web site http://www.whatismyip.com and http://whatismyip.everdot.org. Both sites

display the primary WAN interface’s IP address and not the secondary WAN interface.

To test the Telnet policy-based route, telnet to route-server.exodus.net and when logged in,

issue the who command. It displays the IP address (or resolved FQDN) of the WAN IP address

of the secondary WAN interface and not the primary WAN interface.

Friday, May 7, 2010

configure a Sonicwall TZ200 with a PPPOE connection

TZ 200 having problem contacting sonicwall license site because the default MTU 1500 is a problem.
Their tech guy changed MTU to 1492. He said he observed this problem with PPPOE connections

Sonicwall is using salesforce.com for their job-logging.

Sonicwall tech is using logmein123.com for remote access.
Overall, it is a very good support case.

Tuesday, March 23, 2010

configure TZ 200 sonicwall - use wizards to configure just like EBS/SBS of MS

TZ 170 is slow handling 25 users.

now TZ 200 is used instead.

well, the problem with it is not new. manually doing it is Not working for incoming connections.

the proper way to setup is to
1. add network objects
2. add services
3. group objects
4. run wizards    (especially the Public server wizards)

the most important thing is now RUN Wizards ... this way will auto-populate some NAT rules which are not present in manually configuring simply firewall rules like lan-wan, wan-lan
Public Server Configuration Summary








Please review the settings below and click "Apply" to create the new objects listed below.



Server Address Objects

1. Create 'SonicwallTZ200mgmt Private' assigned to LAN Zone for Host 192.168.1.1.

2. Reuse 'WAN Primary IP' address object assigned to WAN Zone for 2xx.xxx.xx.xx.



Server Service Group Object

1. Create 'SonicwallTZ200mgmt Services' with HTTPS Management Service.



Server NAT Policies

1. Create Inbound Server NAT Policy to rewrite packets to original destination 'WAN Primary IP' to translated destination 'SonicwallTZ200mgmt Private'.

2. Create Outbound Server NAT Policy to rewrite packets from 'SonicwallTZ200mgmt Private' to translated source 'WAN Primary IP'.

3. Create Loopback NAT Policy to allow access from all internal zones to the server at public IP address 2xx.xxx.xx.xx.



Server Access Rules

1. WAN > LAN - Allow 'Any' to 'WAN Primary IP' for Service Group 'SonicwallTZ200mgmt Services'.

Similar rules will be created from all lower security zones to the LAN zone.



To apply these settings, click Apply.

Thursday, March 11, 2010

sonciwall device and syslogs

a TZ 180 device with 2 syslog PCs linked, it seemed fine.

install Sonicwall 6.0 UTM viewpoint

when I installed version 4.1, I have to un-install it and re-install it after the PC ip address change.

this time, things may be different, but I un-installed anbd re-innstalled anyway.

Tuesday, March 9, 2010

PPTP jungle

when you do pptp in a private subnet, you can't connect to yourself.

interesting is that worked last week when I was working on a vista PC. the pptp server is a windows xp pro, surprisingly I can pptp back.

But at another location, pptp started verifying u/p, eventually fail. probably because there is a sonicwall at this site.

Tuesday, February 23, 2010

my nitemare continues with the sonicwall + linksys wAP combination

my nitemare continues with the sonicwall + linksys wAP combination ...

Michael is back in OZ, after a tour of NZ, but his notebook cannot connect to the main office.

The branch is setup as ADSL+Sonicwall+linksys WAP .... the notebook wireless get an IP address, but the notebook can't browse the internet...

connect a network cable to the notebook in question, checked it remotely everything seems fine. but just can't ping it, the DHCP server is enabled in the sonicwall, so use reserved IP address for that  mac wireless card, then things started look good.

I have this similar weird problem last year  at another site...

Monday, January 25, 2010

configure sonicwall TZ100

what a nitemare. yeah my first enhanced os config.

I manually configured the rules. well that didn't work. I am told to use wizards. that worked.

I have configured standard OS on sonicwall TZ 170/180 for years. this is really a shock.

the new TZ 100 hasn't got nodes limit, more features, of course enhanced OS.

Tuesday, December 29, 2009

ftp not working?

ftp not working. it was working before. after some test, it is working inside LAN. But not working over the internet.

buffered? as the firewall (sonicwall) is configured to forward ftp packets to the FTP server.

ISP filtering ftp packets? DSL local exchange port got a problem?

the DLINK DSL router DSL-504T got its own packet filtering. on one of its setup pages, untick " block ftp requests".