Solved

Routing all Internet traffic through Sonicwall TZ170 Site-to-Site VPN

Posted on 2011-09-15
6
2,613 Views
Last Modified: 2012-06-22
Hi All,

I'm running two Sonicwall TZ170 routes with the latest SonicOS Enhanced 3.4.1.3-11e. I have a site-to-site VPN established between our office in Canada and China and it works just fine.

In an effort to circumvent the great firewall of China (which is blocking some critical business related websites), I would like to route all internet traffic (as well as LAN traffic of course) through the VPN to our Canada office and onto the internet from there.

I've tried various configurations and a Sonicwall tutorial (SOS2e_Route_all_Internet_traffic_through_this_SA.pdf) with no luck.  Any available help on the internet appears to be for old version of SonicOS, which has differently (yet similarly) named options and configurations.

Can anyone help with the firewall rules, VPN config (beyond the basic which already works) and NAT?

Thanks,
Nicholas
0
Comment
Question by:encoad
  • 2
  • 2
  • 2
6 Comments
 
LVL 33

Accepted Solution

by:
digitap earned 500 total points
ID: 36547064
I've used that PDF specifically before with success. I'll review it again and see what the possible caveats are. In the mean time, please review the article below and see if it helps.

https://www.fuzeqna.com/sonicwallkb/consumer/kbdetail.asp?kbid=5243
0
 
LVL 8

Expert Comment

by:amatson78
ID: 36547232
Can I post your settings screen shots for review and if possible the Tech Support Report from each unit here.

Alan, SonicWALL CSSA
0
 

Author Comment

by:encoad
ID: 36547595
With digitap's link, I was able to route all the traffic, but I am still unable to route some of the traffic.  

If "Use this VPN Tunnel as default route for all Internet traffic", it works fine.  But if I select "Choose destination network from list", it will not route to my group of networks.  Is this by design?  It says "destination network", not "destination networks"  Is there a way to select several networks?
0
Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 

Author Comment

by:encoad
ID: 36547649
It seems that once I follow digitap's instructions, I can only select "Use this VPN Tunnel as default route for all Internet traffic".  If I select "Choose destination network from list" the VPN tunnel will not be established.
0
 
LVL 8

Expert Comment

by:amatson78
ID: 36548627
Both sides have to match for tunnel to come up. If you are ponying a handful of networks grime one side the other has to.Be setup to accept only that group. If you want all traffic then not sides have to match accordingly. The only way to route all traffic is by setting the remote side as the default gateway via Von for all traffic.
0
 
LVL 33

Expert Comment

by:digitap
ID: 36549311
Ah, so the Local Networks would need to be configured as Any Address on the other end, right? So it would look like this:

ChinaSW - Remote Networks set to "Use this VPN Tunnel as default route for all Internet traffic" <> USSW - Local Networks set to Any address.


Does this look right or do i have it backwards?
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Some of you may have heard that SonicWALL has finally released an app for iOS devices giving us long awaited connectivity for our iPhone's, iPod's, and iPad's. This guide is just a quick rundown on how to get up and running quickly using the app. …
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now