Basically if packets arrive at an interface which do not come from its local subnet then it will drop them unless that particular subnet is added to the anti-spoofing settings so that it knows to accept those packets.
E.g. if your LAN interface is 10.1.1.1/24 and you have a subnet 172.16.16.0/24 joined to the LAN by another router then you need to enter 172.16.16.0/24 into the antispoofing config for your LAN interface.
From the docs:
In a standard setup, the SonicWall will only recognize the subnet of its LAN IP address as being valid. If there are additional subnets connected to the LAN, they must be configured by creating a route to them on the Network > Routing page in SonicOS Enhanced or Standard firmware or the Advanced/Routes page in older appliances running Firmware 6.x.
Do not use the Network > Intranet (SonicOS Standard) or Advanced/Intranet (Firmware 6.x) page to configure the SonicWall for additional LAN subnets. The address ranges defined in these pages impacts only the use of the LAN interface in transparent (standard) mode.
Hope this helps
Main Topics
Browse All Topics





by: nappy_dPosted on 2009-09-22 at 05:57:02ID: 25392231
You cannot unless the firewall has a LAN interface that is connected to that subnet.