Question

SonicWALL PRO 2040 VPN issues

Asked by: 05fdml

Remote users can connect to the sonicwall via the GVPNC 4.086, but when they go to login to remote desktop on their machines at work, it times out. When they try and PING an internal address, it also times out.
This just started happening to everyone about 2 weeks ago. Nothing has changed on the sonicwall. Our support contract was up in February, but i can't imagine that would affect connectivity.

On the sonicwall we are using the default group vpn configuration
GroupVPN                               ESP 3DES HMAC SHA1 (IKE)

using preshared secret

propsals IKE
dh - group 1
encryption 3des
auth sha1
lifetime 28800

ipsec
protocol ESP
encyption 3DES
Auth sha1

advanced
vpn termination LAN/DMZ
client auth (yes)

client
cache auth (never)
virtual adpater (none)
second gateways (allow connections)


the odd thing is that if a user tries 8 times to connect to the vpn it will finally work (they will be able to login to their machine via remote desktop)

It is really quite frustrating

Can anyone assist?

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-03-19 at 08:57:13ID24246137
Tags

sonicwall pro 2040

,

vpn

,

connectivity

Topic

Networking Hardware Firewalls

Participating Experts
4
Points
500
Comments
33

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. SonicWall to Sonicwal VPN.....Blocked?
    This is kind of strange....At our main office we run a sonicwall Pro-VX. One of my users wanted a VPN connection setup at his house, so I took his laptop, his little Linksys router/switch, and his SonicWall Tele3 (Thisis a box to box VPN) to my house and configured everythin...
  2. forgot password on my sonicwal ssl vpn 200
    I have a sonicwall ssl vpn 200 and i for got the admin passoword. How can i login or reset the passoword with out loosing the setting on the vpn 200 please help Thanks, Peter
  3. IPSec VPN
    Trying to setup new ASA box for IPSec VPN. I receive this error message in ASDM when a VPN client tries to connect. Group = DefaultRAGroup, IP = x.x.x.x, Error: Unable to remove PeerTblEntry Group = DefaultRAGroup, IP = x.x.x.x, Removing peer from peer table failed, no ma...
  4. New to IPSec VPN Setup
    Hi Experts, I am able to establish VPN connection to Win2k3 server using windows client setup at a remote site. However, i have found a need to connect a second user and therefore want to set up a site to site vpn connection. I have a Linksys WRV200 and Netgear DG834G router ...
  5. Cisco ASA 5510 Problem to sonicwal pro1260
    Hello experts, hope you can help I have a cisco asa5510 with multiple lan to lan vpn's configured (terminating on a mixture of cisco 837, 877 and pix 501) I also have a single lan to lan vpn terminating on a sonicwall pro 1260, this vpn does not come up, it fails phase 1, lo...
  6. Sonicwal change IP
    Hello there - Office moved to another location. ATT saying we need to change the IP in Sonicwall to reflect the new gateway. I asked to bypass. They tried but no aval. Users cannot access Internet. So few questions: - Is there a way to access the sonicwall if no one kn...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: JusticatorPosted on 2009-03-19 at 09:00:28ID: 23930965

Have the users tried to uninstall/reinstall the client, and the latest version at that?

I had two similar issues recently, but one was due to the client's public IP changing, and one was due to the business'(on the sonicwall's side) public IP changing.  Make sure these aren't being the issue either.

 

by: 05fdmlPosted on 2009-03-19 at 09:06:14ID: 23931030

yes I have updated all to the latest that we have 4.0.0.830
the users are mostly on comcast and they all have dynamic IP addresses, so it follows that comcast will switch their Ip addresses, I imagine once every few months or whenever the leases expire on them.

 

by: JusticatorPosted on 2009-03-19 at 09:27:38ID: 23931286

When the users log on, you can see their connections on the sonicWall active VPN users section?  Using an AD server, or is the SonicWALL the one handing out the VPN IPs?

If they are connecting, and staying connected, but unable to connect to anything in network, and they show on the sonicWALL, it seems like they are getting an odd IP/subnet/dns/etc.  Have the users do an ipconfig /all and send to you, and compare the tunneling IPs to what your network looks like.

From there, you can check what your AD servers are leasing out / SonicWALL attempts to lease out, etc.

 

by: ccpjcPosted on 2009-03-19 at 09:44:04ID: 23931468

had an issue like this, the sonicwall dhcp client was assigning IP addresses that were already being used on the network
i had to assign machines with static ip's to have new ones

 

by: 05fdmlPosted on 2009-03-19 at 09:56:55ID: 23931619

answer to your first question: yes, you can see them as online under users in the sonicwall
answer to your second question: sometimes the ipconfig /all for the sonicwall adapter shows all 0.0.0.0

sometimes is shows the correct internal LAn address (they can connect during that time)

 

by: ccpjcPosted on 2009-03-19 at 09:59:22ID: 23931647

if it shows 0.0.0.0 then do a renew in the client properties of the VPN client

 

by: 05fdmlPosted on 2009-03-19 at 10:05:06ID: 23931718

checking the vpn client. Sorry I can;t seem to find how to "renew" in the client properties of the VPN client.

 

by: JusticatorPosted on 2009-03-19 at 10:05:50ID: 23931733

That means the underlying problem is whatever is handing out IPs to the VPN clients.  That's not handing it out correctly.
Is the SonicWALL or something else handing out the (i'm guessing) DCHP IPs?

and yes, ccpjc's answer will fix the problem for only that one instance.  But I'm pretty sure you don't want to sit there and reset people's IPs all day/night.

 

by: JusticatorPosted on 2009-03-19 at 10:06:38ID: 23931740

you can simply to do a "ipconfig /renew" in a command prompt when you are connected to the VPN for that.

 

by: 05fdmlPosted on 2009-03-19 at 10:07:25ID: 23931749

yes the sonicwall is handling all DHCP.

Our windows sbs 2003 server handles AD and DNS requests

 

by: ccpjcPosted on 2009-03-19 at 10:08:05ID: 23931754

Right click on the Icon in the taskbar beside the clock -> Open SonicWall VPN Client
double click on the current connection, then at the bottom of the status tab you will see 'Renew'

 

by: ccpjcPosted on 2009-03-19 at 10:09:42ID: 23931774

Justicator:
That means the underlying problem is whatever is handing out IPs to the VPN clients.  That's not handing it out correctly.
Is the SonicWALL or something else handing out the (i'm guessing) DCHP IPs?

and yes, ccpjc's answer will fix the problem for only that one instance.  But I'm pretty sure you don't want to sit there and reset people's IPs all day/night.

-- I already posted my experience with it, about the VPN client assigning IP's to computers with them already on the network, haven't heard anything back yet

another thing is to exclude those that are static assigned on the network from the SonicWall DHCP Server

 

by: JusticatorPosted on 2009-03-19 at 10:12:30ID: 23931804

Make sure that the SBS server isn't fighting the SonicWall for IP handing out rights.
I'm willing to bet that the clients that are logging in through VPN are asking the SBS server for an IP.  Then the SBS server goes "I dunno, don't ask me" so the clients are stuck with a 0.0.0.0.  Way to do it is have the SonicWall take all requests first.  Then in the sonicWALL, there is an option to specific DNS servers -- which you point at your AD server.  personally, I'd have the AD server handle everything, to avoid this kind of problem.

 

by: 05fdmlPosted on 2009-03-19 at 10:13:57ID: 23931818

ccpjc:
did as you stated. Connected to VPN -

In the windows Virtual IP Configuration
IPaddress N/A Subnet mask N/A
"Renew" button greyed out

 

by: JusticatorPosted on 2009-03-19 at 10:14:22ID: 23931819

ccpjc:  Huh?

 

by: 05fdmlPosted on 2009-03-19 at 10:17:42ID: 23931856

I forgot to post:

In advanced for the VPN

 Enable NAT Traversal:  (yes)
Keep Alive interval: 240  
Enable IKE Dead Peer Detection: (yes)
        Dead Peer Detection Interval: 60      
        Failure Trigger Level: 3      
VPN Single Armed mode (stand-alone VPN gateway) NO
  Clean up Active tunnels when Peer Gateway DNS name resolves to a different IP Address YES
 Preserve IKE Port for Pass Through Connections NO
 Send vpn tunnel traps only when tunnel status changes NO

 

by: ccpjcPosted on 2009-03-19 at 10:18:14ID: 23931868

ok i'll re-write this hopefully you can understand
about 2 weeks ago, I had a remote user who would connect via GVPNC and no matter what he did, he was experiencing errors or it just wouldn't connect, the SonicWall DHCP Server was assigning him the ip of 10.3.0.119 which was already statically set on a computer on the network

To resolve this, i just released the Static IP for that computer since it didn't need it and was only for testing purposes, but another option is to set a list of DHCP Server IP's the sonicwall is allowed to hand out

 

by: 05fdmlPosted on 2009-03-19 at 10:22:24ID: 23931912

ccpjc:
I was refering to this comment you made below.....
my reply to you comment was essentially the "renew" button was greyed out so I could not "renew" as you indicated

"Expert Comment      
Was this comment helpful?
Yes No
ccpjc:
Right click on the Icon in the taskbar beside the clock -> Open SonicWall VPN Client
double click on the current connection, then at the bottom of the status tab you will see 'Renew'"

 

by: JusticatorPosted on 2009-03-19 at 10:25:42ID: 23931952

One at a time!  hahah..  i'm so confused with which answers go where.

I'm going to have to dig around my SonicWALL a tad to find it when I have a chance.

 

by: ccpjcPosted on 2009-03-19 at 10:25:55ID: 23931954

Sorry that comment was posted for Justicator and you to try not in relation to the greyed out part

are you trying the VPN client from within your network, the new version won't allow this

 

by: 05fdmlPosted on 2009-03-19 at 10:28:52ID: 23931991

@ccpjc : no worries
I have a laptop connected to a third party wireless to conduct the current VPN excitment.

 

by: ccpjcPosted on 2009-03-19 at 10:37:49ID: 23932079

ok let's try doing this from the start

Delete your VPN settings from the GVPNC
Add a new connection, verify the IP is correct
Make sure you have the correct PreShared key, you can find it in the SonicWall GUI under VPN -> GroupVPN, it will either be called Shared Secret or PreShare Key depending on the version

Double click the vpn connection to start, it should show Connecting, then change to provisioning, then acquiring IP, then finally connected
Once connected, it should pop up a balloon to show you are connected and your VPN IP address
if not then try going back into the Status screen and doing a Renew

Post results

 

by: 05fdmlPosted on 2009-03-19 at 10:50:40ID: 23932195

Delete VPN settings check
add new connection to correct ip - check
preshared key known (sonicwall router open presahred key dispalyed

double click on vpn connection
prompted for preshared key -entered

enter username /password box
enter successfully twice

vpn status is "connected"

networking icons in systray appear with the little gold ball moving back and forth...

Below is the connection details from the VPN client log


2009/03/19 09:11:28:852      Information      67.95.*.*      Starting ISAKMP phase 1 negotiation.
2009/03/19 09:11:28:898      Information      67.95.*.*      Starting aggressive mode phase 1 exchange.
2009/03/19 09:11:28:898      Information      67.95.*.*      NAT Detected: Local host is behind a NAT device.
2009/03/19 09:11:28:898      Information      67.95.*.*      The SA lifetime for phase 1 is 28800 seconds.
2009/03/19 09:11:28:898      Information      67.95.*.*Phase 1 has completed.
2009/03/19 09:11:28:914      Information      67.95.*.*      Received XAuth request.
2009/03/19 09:11:28:914      Information      67.95.*.*      Sending XAuth reply.
2009/03/19 09:11:28:914      Information      67.95.*.*      Received XAuth status.
2009/03/19 09:11:28:914      Information      67.95.*.*      Sending XAuth acknowledgement.
2009/03/19 09:11:28:914      Information      67.95.*.*      User authentication has succeeded.
2009/03/19 09:11:28:930      Information      67.95.*.*      Received request for policy version.
2009/03/19 09:11:28:930      Information      67.95.*.*      Sending policy version reply.
2009/03/19 09:11:28:930      Information      67.95.*.*      Received policy change is not required.
2009/03/19 09:11:28:930      Information      67.95.*.*      Sending policy acknowledgement.
2009/03/19 09:11:28:930      Information      67.95.*.*      The configuration for the connection is up to date.
2009/03/19 09:11:28:992      Information      67.95.*.*      Starting ISAKMP phase 2 negotiation with 198.68.70.0/255.255.255.0:Any:Any:N/A.
2009/03/19 09:11:28:992      Information      67.95.*.*      Starting quick mode phase 2 exchange.
2009/03/19 09:11:29:008      Information      67.95.*.*      The SA lifetime for phase 2 is 28800 seconds.
2009/03/19 09:11:29:008      Information      67.95.*.*      Phase 2 with 198.68.70.0/255.255.255.0:Any:Any:N/A has completed.
2009/03/19 09:11:29:008      Information      67.95.*.*      NetWkstaUserGetInfo returned: user: bigmon, logon domain: snoops, logon server: disk

 

by: ccpjcPosted on 2009-03-19 at 10:53:48ID: 23932221

Ok so you are connected now right?

Can you access network resources?
If it says access is denied, go into the the AD and make sure your account hasn't been locked out from too many attempts

 

by: JusticatorPosted on 2009-03-19 at 11:00:02ID: 23932270

What are your current DCHP settings on the SonicWALL?
Good policy states that you should have a range setup especially for DCHP, but conflict detection should take care of that without a problem.

The problem still is where your users are getting no IP addresses assigned to them, which I still think is it trying to contact the AD server for a DHCP address.

You can go this way (which I prefer):
Set your AD server to hand out DCHP exactly like your sonicWALL is doing, and set up your sonicWALL to point towards your AD server in the DNS pic as below.

Or, make sure your route policy is setup correctly.  See pics also.

 

by: 05fdmlPosted on 2009-03-19 at 11:10:21ID: 23932369

@ccpj

attempting to login to LAN resources via Remote desktop: "this computer can't connect to the remote computer"

ipconfig /all reveal that the sonicwall is coming up 0.0.0.0

@justicator

The dhcp(which is on sonicwall) is setup from .50 to .254  All workstations on the LAN have manual ip addreses. they start at .100 and goto .175


 

by: ccpjcPosted on 2009-03-19 at 11:14:15ID: 23932409

and the renew button is still greyed out?

In the actual SW GUI, when you click on the VPN properties and goto Client, is the Virtual Adapter setting set to DHCP lease?
And if you goto Network -> DHCP server and see the scopes, are there any listed there?
if not add a dynamic

 

by: 05fdmlPosted on 2009-03-19 at 12:21:45ID: 23933031

@ccpjc

yes the renew button is still greyed out.

No the virtual adapter setting was set to "none"

yes the scope is from .50 to .254 on the LAN

 

by: ccpjcPosted on 2009-03-19 at 12:24:37ID: 23933059

change it from None to Lease and connect again
also change the score to something you know isn't static or dynamically assigned
like .100 - .150

 

by: ccpjcPosted on 2009-03-19 at 12:24:52ID: 23933065

scope *

 

by: 05fdmlPosted on 2009-03-19 at 13:13:09ID: 23933611

in SW gui - leased is set
in sw gui DHCP scope is set to .50 to .59 (no static IPs)

attempt VPN connection
username and password - ok

then status stays on "cennecting"

Sonicwall virtual adapter icon appears in task bar (gold ball bounces back and forth)

In the properties of the GVPNC the renew button is no longer greyed out.

Sonicwall hangs on finding IP address, so I click on "renew" button - no effect

 

by: apostle12Posted on 2009-06-29 at 16:16:15ID: 24741069

Ok it sounds like you are already using aggressive mode on your tunnel correct? On the sonic wall you are sitting at, it has a unique name usually the serial #, and whatever you are connecting to it has a unique name. name the tunnel whatever name of the device is your connecting to. make sure you are in aggressive mode, set the default gateway to 0.0.0.0 set the local IKE as your unique name and the remote IKE to the remote unique name.

 

by: kurajeshPosted on 2009-12-12 at 22:42:18ID: 26038017

Hi

Please check the attachment which has the sonicwall settings (DHCP, VPN and Access Rules)

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...