[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Sonicwal SSL VPN connected, but can't access remote LAN

Posted on 2010-08-13
4
Medium Priority
?
17,703 Views
Last Modified: 2012-05-10
Hi guys.
i'm done... it's been 4 hours of research and testing and i'm just done being a typical man, and i'll ask for help :).

We're using Sonicwall TZ100 enhanced OS 5.6.
Downloaded the SSL VPN NetExtender and set it up like shown on
this video

i am able to connect, and am getting an IP address from the TZ100.

Even though i have an IP, i can't ping any IP address on the VPN LAN side.
I noticed that when i do IPCONFIG, the VPN tunnel doesn't have a gateway. not sure if that's normal or not...

the office LAN subnet (where the sonicwall is located) is 10.0.125.x
the remote home subnet (where the remote computer is located is 192.168.2.130
no conflicts there...

i tried creating some rules on the NAT and firewalls, and open / allows any to any... no dice...
i disabled the firewall (windows firewall) on remote PC- still no help...

BUT- when i enabled the "Tunnel All Mode" (see attached image) option on the SSLVPN menu on the appliance, i was able to ping the remote network devices, but then i couldn't connect to the internet from the home PC...

so i'm pretty sure it's a firewall or NAT or routing rule that i can't  think of.

what am i doing wrong ?!
thanks in advance !


sonic.JPG
0
Comment
Question by:beits
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 5

Expert Comment

by:sosinc3
ID: 33428168
I am pretty savy with SonicWall VPNs but really to help you better I would need to see more of your setup. If you are able to attach screen shots from your vpn and network screens as well local users screens that would be helpful. If you want to protect things a little, you can wipe out the IP address/keys, etc. from your screens and replace them with some phony ones before you take the screen shots (just don't save them and you won't hurt your setup that way).
0
 
LVL 17

Accepted Solution

by:
Steve earned 2000 total points
ID: 33428222
Have you checked your DNS settings on the server and the sonicwall as well as any rules on firewalls to permit traffic on sonicwall ip range to your internal network.

We moved our sonicwall on a DMZ which makes config easier
0
 
LVL 33

Expert Comment

by:digitap
ID: 33430027
It's not NAT.  When you enable the SSL-VPN on the TZ series, then you fall undert the SSL-VPN zone.  You don't have a gateway because you only want to route traffic that the sonicwall owns.  You want to route anything else out of the local gateway from where you have the SSL-VPN configured.  Tunnel All means just that.  You tunnel all traffic through the ssl-vpn connection...period.  It sounds then, like you haven't a route or something like that configured improperly.
0
 

Author Comment

by:beits
ID: 33441706
hi guys.
thanks so much for the replies.
your answers made me dig deeper, and i found that it was a firewall rule that was not created correctly on the sonicwall.
i recreated the rule to allow SSL VPN all traffic to LAN, and i was able to ping the LAN PC again.
after disabling the LAN PC firewall, i was able to access the shares... woo hoo !

thanks again !

Beits
0

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …
Suggested Courses

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question