Solved

unable to get to the internet behind tz 100

Posted on 2011-03-11
15
706 Views
Last Modified: 2013-11-16
unable to get out from behind the firewall TZ 100, can ping www.google.com for diagnostics, and site to site vpn works
0
Comment
Question by:dwaynem2345
  • 6
  • 3
  • 2
  • +2
15 Comments
 
LVL 2

Expert Comment

by:jimponder
Comment Utility
On your domain controller: ipconfig /flushdns.
Do you have a rule in place that allow lan to wan traffic?  Is it enabled?
0
 

Author Comment

by:dwaynem2345
Comment Utility
lan to wan any
0
 

Author Comment

by:dwaynem2345
Comment Utility
it is a small office home office and no domain controller
0
 
LVL 29

Expert Comment

by:Randy Downs
Comment Utility
Do you mean no access to the web? :80 ?
0
 

Author Comment

by:dwaynem2345
Comment Utility
correct...I can through diagnostics, just cant from any machine i hook up to it....I can even get into the firewall remotely, very odd.
0
 
LVL 9

Expert Comment

by:avilov
Comment Utility
*I am not familiar with that firewall*

in general you need two rules: incoming and outgoing. "lan to wan any" is one, what is the other?

something like "wan to lan ..."
0
 
LVL 2

Expert Comment

by:jimponder
Comment Utility
how about wan to lan any?  Put that in place and verify the firewall is the problem.  
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:dwaynem2345
Comment Utility
i did that...and still no go....but like i said, site to site vpn works just fine.
0
 
LVL 9

Expert Comment

by:avilov
Comment Utility
what is your routing table looks like on that firewall?

do you have a router in front of firewall? does it have correct default route?
0
 
LVL 29

Expert Comment

by:Randy Downs
Comment Utility
0
 
LVL 33

Expert Comment

by:digitap
Comment Utility
site to site vpn is going to use IP not DNS so we at least now that your internet is up. the fact that you can ping www.google.com says DNS is resolving properly.

go to system > diagnostics of your sonicwall and select Ping from the drop down. choose 4.2.2.2 first. if that pings properly, ping www.google.com. if it pings successfully, then ping www.ibm.com or whatever. if it pings successfully, then your sonicwall is resolving DNS properly.

if you aren't able to ping those devices properly from a workstation then you've got an internal DNS resolution issue. how are your internal hosts resolving DNS? is it from a central server? if you replace the DNS server IP of one of your workstations with 4.2.2.2, is it able to get to internet hosts by name?

also, when you added the WAN > LAN Any on your firewall, you opened up your firewall to the internet. you want to delete that firewall rule or change it immediately!
0
 

Author Comment

by:dwaynem2345
Comment Utility
i did disable that rule already, i can get to the internet from the firewall, just nothing that is directly hooked  up to it.
0
 
LVL 33

Expert Comment

by:digitap
Comment Utility
ok...change the DNS server IP of one of your workstations to use 4.2.2.2 and try to get to the internet. can you ping 4.2.2.2 from one of your workstations behind the tz100?
0
 

Author Comment

by:dwaynem2345
Comment Utility
i cannot ping that
0
 
LVL 33

Accepted Solution

by:
digitap earned 500 total points
Comment Utility
ok...it seems like a routing issue. compare the IP address of the LAN interface of your tz100 to the gateway IP of the workstation that is unable to ping 4.2.2.2? is there a difference? what's handling IP assignments, an internal Windows DHCP server or the sonicwall?
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Checkpoint books 3 67
firewall rules 2 68
document a firewall 2 46
Best firewall recommendation 12 153
If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now