Routing all Internet traffic through Sonicwall TZ170 Site-to-Site VPN

Posted on 2011-09-15
Last Modified: 2012-06-22
Hi All,

I'm running two Sonicwall TZ170 routes with the latest SonicOS Enhanced I have a site-to-site VPN established between our office in Canada and China and it works just fine.

In an effort to circumvent the great firewall of China (which is blocking some critical business related websites), I would like to route all internet traffic (as well as LAN traffic of course) through the VPN to our Canada office and onto the internet from there.

I've tried various configurations and a Sonicwall tutorial (SOS2e_Route_all_Internet_traffic_through_this_SA.pdf) with no luck.  Any available help on the internet appears to be for old version of SonicOS, which has differently (yet similarly) named options and configurations.

Can anyone help with the firewall rules, VPN config (beyond the basic which already works) and NAT?

Question by:encoad
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
LVL 33

Accepted Solution

digitap earned 500 total points
ID: 36547064
I've used that PDF specifically before with success. I'll review it again and see what the possible caveats are. In the mean time, please review the article below and see if it helps.

Expert Comment

ID: 36547232
Can I post your settings screen shots for review and if possible the Tech Support Report from each unit here.

Alan, SonicWALL CSSA

Author Comment

ID: 36547595
With digitap's link, I was able to route all the traffic, but I am still unable to route some of the traffic.  

If "Use this VPN Tunnel as default route for all Internet traffic", it works fine.  But if I select "Choose destination network from list", it will not route to my group of networks.  Is this by design?  It says "destination network", not "destination networks"  Is there a way to select several networks?
IoT Devices - Fast, Cheap or Secure…Pick Two

The IoT market is growing at a rapid pace and manufacturers are under pressure to quickly provide new products. Can you be sure that your devices do what they're supposed to do, while still being secure?


Author Comment

ID: 36547649
It seems that once I follow digitap's instructions, I can only select "Use this VPN Tunnel as default route for all Internet traffic".  If I select "Choose destination network from list" the VPN tunnel will not be established.

Expert Comment

ID: 36548627
Both sides have to match for tunnel to come up. If you are ponying a handful of networks grime one side the other has to.Be setup to accept only that group. If you want all traffic then not sides have to match accordingly. The only way to route all traffic is by setting the remote side as the default gateway via Von for all traffic.
LVL 33

Expert Comment

ID: 36549311
Ah, so the Local Networks would need to be configured as Any Address on the other end, right? So it would look like this:

ChinaSW - Remote Networks set to "Use this VPN Tunnel as default route for all Internet traffic" <> USSW - Local Networks set to Any address.

Does this look right or do i have it backwards?

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses
Course of the Month9 days, 21 hours left to enroll

624 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question