Routing all Internet traffic through Sonicwall TZ170 Site-to-Site VPN

Hi All,

I'm running two Sonicwall TZ170 routes with the latest SonicOS Enhanced 3.4.1.3-11e. I have a site-to-site VPN established between our office in Canada and China and it works just fine.

In an effort to circumvent the great firewall of China (which is blocking some critical business related websites), I would like to route all internet traffic (as well as LAN traffic of course) through the VPN to our Canada office and onto the internet from there.

I've tried various configurations and a Sonicwall tutorial (SOS2e_Route_all_Internet_traffic_through_this_SA.pdf) with no luck.  Any available help on the internet appears to be for old version of SonicOS, which has differently (yet similarly) named options and configurations.

Can anyone help with the firewall rules, VPN config (beyond the basic which already works) and NAT?

Thanks,
Nicholas
LVL 1
encoadAsked:
Who is Participating?
 
digitapCommented:
I've used that PDF specifically before with success. I'll review it again and see what the possible caveats are. In the mean time, please review the article below and see if it helps.

https://www.fuzeqna.com/sonicwallkb/consumer/kbdetail.asp?kbid=5243
0
 
amatson78Sr. Security EngineerCommented:
Can I post your settings screen shots for review and if possible the Tech Support Report from each unit here.

Alan, SonicWALL CSSA
0
 
encoadAuthor Commented:
With digitap's link, I was able to route all the traffic, but I am still unable to route some of the traffic.  

If "Use this VPN Tunnel as default route for all Internet traffic", it works fine.  But if I select "Choose destination network from list", it will not route to my group of networks.  Is this by design?  It says "destination network", not "destination networks"  Is there a way to select several networks?
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

 
encoadAuthor Commented:
It seems that once I follow digitap's instructions, I can only select "Use this VPN Tunnel as default route for all Internet traffic".  If I select "Choose destination network from list" the VPN tunnel will not be established.
0
 
amatson78Sr. Security EngineerCommented:
Both sides have to match for tunnel to come up. If you are ponying a handful of networks grime one side the other has to.Be setup to accept only that group. If you want all traffic then not sides have to match accordingly. The only way to route all traffic is by setting the remote side as the default gateway via Von for all traffic.
0
 
digitapCommented:
Ah, so the Local Networks would need to be configured as Any Address on the other end, right? So it would look like this:

ChinaSW - Remote Networks set to "Use this VPN Tunnel as default route for all Internet traffic" <> USSW - Local Networks set to Any address.


Does this look right or do i have it backwards?
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.