Solved

SonicWall Firewall rules don't seem to take affect until after i reboot the device

Posted on 2010-11-22
10
979 Views
Last Modified: 2012-05-10
We are running a SonicWall Pro 3060 with the Enhanced OS. When I create a firewall rule to block certain traffic, those connections still show as active in the connections monitor for quite a while before they drop off. It will be 30 minutes before they all disappear. Any way to make that happen without rebooting the device?
0
Comment
Question by:crdixon
10 Comments
 
LVL 33

Expert Comment

by:digitap
ID: 34193384
i've not heard of that before, but flushing the arp table would net the same as restarting the sonicwall.  i'm sure this has been adressed, but have you updated the firmware?
0
 
LVL 33

Expert Comment

by:digitap
ID: 34193417
question: what kind of swith are your computers connected to?  if you disconnect everything, connect your  computer directly to X0, make a change to the sonicwall...does the change happen immediately?
0
 
LVL 14

Expert Comment

by:DonConsolio
ID: 34193425

Try to flush the unwanted connections in Active Connections Monitor.
0
 
LVL 15

Accepted Solution

by:
getzjd earned 100 total points
ID: 34193480
Your firewall rules, are they still set at the default values of 15 minutes or did you change them to 30?  Not that should matter because SonicWall changes should take effect immediately.
0
 
LVL 14

Assisted Solution

by:DonConsolio
DonConsolio earned 200 total points
ID: 34193565
I am no Sonicewall expert, but usually (at least for the firewalls i know) new rules
only affect new connections, while existing ones remain untouched.

Terminate the already established connections (Connection Monitor) or
reboot the firewall (i.e. terminate all connections)
0
Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

 
LVL 33

Assisted Solution

by:digitap
digitap earned 200 total points
ID: 34193630
my experience with the sonicwall is the rules take afeect immediately.
0
 
LVL 14

Assisted Solution

by:DonConsolio
DonConsolio earned 200 total points
ID: 34193691
They immediately do affect new connections, but i doubt that existing ones are affected.
0
 
LVL 33

Assisted Solution

by:digitap
digitap earned 200 total points
ID: 34194131
Being uncertain myself, i loaded up a pro 3060 and ran a continuous ping to 74.125.227.50 (one of the www.google.com IPs).  i then setup a rule to deny LAN > WAN from Any Source and 74.125.227.50 as the destination.  as soon as i clicked OK to create the rule, my ping failed.
0
 

Author Comment

by:crdixon
ID: 34327177
I swapped this deviced out with an NSA240 with the secuity suite. The "Flush" option now appears on this box and the updated software subscrition seems to have fixed all my woes.
0
 
LVL 33

Expert Comment

by:digitap
ID: 34327247
great...glad things worked out.  thanks for the points!
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now