Link to home
Create AccountLog in
Avatar of Bert517
Bert517

asked on

TZ-210 Removing Address objects

I have just cleaned up the Access rules, Address Objects, Nat Policies, and groups etc. on a new install. I am left with some Address Objects that error when trying to remove them stating that they are in use in an Access Rules when they are not. It acts like "leftovers" and they are still stuck in memory. One object states it ir referenced 24 times while another one states 3 time.

With the exception of restoring the device to factory settings and reloading the settings from an external file, any other thing I could try?

SonicOS Enhanced 5.6.0.10-52o
SOLUTION
Avatar of digitap
digitap
Flag of United States of America image

Link to home
membership
Create an account to see this answer
Signing up is free. No credit card required.
Create Account
Avatar of Bert517
Bert517

ASKER

Look for an entry named removeme TSI.txt
i analyzed your TSR.  i attached the results with several rules still accessing the removeme address object.  i deleted anything that didn't reference "removeme".  was your original TSR the result AFTER your changes?
Analyzed-TSR.txt
Avatar of Bert517

ASKER

I see where the removeme is accessing the wlan but where do I go to remove it from the sonicwall? Yes the TSR was after my changes.
ASKER CERTIFIED SOLUTION
Link to home
membership
Create an account to see this answer
Signing up is free. No credit card required.
Create Account
Avatar of Bert517

ASKER

Problem is, I don't see WLAN in the fireall access rules
looking at your TSR, i see you have the enhanced OS on the TZ-210.  you should see, under the matrix view, what i've shown in the screen shot within this message.  do you not see WLAN?
greenshot-2010-12-27-12-28-01.jpg
Avatar of Bert517

ASKER

No it is not there:

accessrules.JPG
go to network interfaces and tell me if wlan is enabled.
Avatar of Bert517

ASKER

LOL...I am stricking out here:

netiface.JPG
i think you'll need to remove one of the interfaces from the lan portshield.  assign the interface the wlan zone.  you'll be able to delete the rules then.
Avatar of Bert517

ASKER

Well that helped some. I got the reference for removeme down from 24 to 16. I still need to fine the other references.
Avatar of Bert517

ASKER

Updated TSR after the port shield change TSR1227.txt
Avatar of Bert517

ASKER

Afrter tweaking the settings a little bit. I was able to remove all the rules except for MULTITASK -> Lan. Once I figure that out I tyhink I am done. Thank you for all your help as you  did tach me some things I did not know.
sure, no problem.  glad we're making progress.  regarding multitask, i've never see a default multitask zone.  is that something you created?  i'd work this like the wlan zone above.
Avatar of Bert517

ASKER

I tried to set it up like that but there is no multitask option to assign the interface to. Still playing with it though.
you might have to create the multicast zone if it does not exist.
Avatar of Bert517

ASKER

I am not sure on how to do this. I tried but not good enough
SOLUTION
Link to home
membership
Create an account to see this answer
Signing up is free. No credit card required.
Create Account
Avatar of Bert517

ASKER

Thank you. I set up a Multitask zone as you said and I couldn't assign the adapter to Multitask but from my palying around I was able to remove some of the objests. I rebooted the device and i removed the last. Saved the current config to an external file so we are good to go!

Thank you for all your help.
thanks, glad i could help and thanks for the points!