Solved

Sonicwall TZ170/180 Access Rules Question

Posted on 2009-05-15
2
402 Views
Last Modified: 2013-11-16
How do I write the access rules to force all http/https traffic thru a VPN tunnel on a TZ170 or TZ180?

We have remote locations that use TZ170/180's to connect to our Corporate office with a point to point VPN tunnel for data access.  What I'd like to do is force them to also route thru the VPN tunnel for Internet traffic so that we can monitor where they go on the Internet with our Websense box.  Currently I can deny LAN to WAN traffic for the Web but I can't turn around and enable a LAN to VPN rule for Web traffic because there is no VPN destination choice on the TZ 170/180 like there is on my Pro2040.  Is there another way to accomplish this task?
0
Comment
Question by:keithmendez
  • 2
2 Comments
 
LVL 16

Expert Comment

by:ccomley
ID: 24450610
Do you have Enchanced OS?

If so, you can achieve what you want, I'm pretty sure, using Policy Route. Make the target gateway for teh rule the Internet gate way at the FAR END of the VPN.

I don't think you can do it with Standard OS.

0
 
LVL 16

Accepted Solution

by:
ccomley earned 500 total points
ID: 24450642
Unless you want ALL internet traffic diverted through the tunnel so only VPN traffic goes to the router.

Edit the VPN config on the "remote" end
Go into the "Network" tab
In the Destination networks section, select "Use This Tunnel as Default for All Internet Traffic"

0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Site to Site VPN - Cisco ASA - Multiple Subnets at Main Location 6 79
Cisco ASA two factor VPN 3 51
VPN doubts 4 58
SSH over http/https 8 110
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now