Sonicwall best practice ...

Hello, I've just installed a Sonicwall security device for our small business.

I am unable to connect to the LAN X0, if I am connecting over wifi (from the W0 (wlan) interface). I cannot ping computers on the X0.

X0 is on 192.168.0.xx and W0 is on 172.16.31.xx

May I know how to do it and what is the best practice ?

thanks. Clifford
CliffordNgAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

PerarduaadastraCommented:
It seems that these Sonicwall units block traffic from WLAN to LAN by default.

You need to go into the management interface and add LAN-WLAN and WLAN-LAN firewall rules that will allow traffic to flow between them.

You don't say which unit you have, but Sonicwall provide instructions here under KBID 5351, though the last update to the article was two years ago...
CliffordNgAuthor Commented:
thanks. it's a NSA 220.

If i understand well, having different subnets does not matter ... i will still be able to ping, right ?

Cheers
PerarduaadastraCommented:
The Sonicwall will take care of the routing between the subnets, so once you've added the rules you should be able to ping hosts successfully regardless of which subnet you're on.
Cloud as a Security Delivery Platform for MSSPs

Every Managed Security Service Provider (MSSP) needs a platform to deliver effective and efficient security-as-a-service to their customers. Scale, elasticity and profitability are a few of the many features that a Cloud platform offers. View our on-demand webinar to learn more!

Syed_M_UsmanSystem AdministratorCommented:
Dear,

please make sure you have enabled interface trust,,,,,
CliffordNgAuthor Commented:
hello syed, hmm, what is the interface trust ? Cannot find it on the Sonicwall mgmt
CliffordNgAuthor Commented:
@Perarduaadastra, good morning, I've set up as follows and I still cannot connect from WLAN to LAN, although I can connect to the internet via WAN.

Is there something I am missing ?

      LAN      >      WLAN      1      Any      Any      Any      Allow      All                           
      WLAN      >      LAN      1      Any      Any      Any      Allow      All                           

Please help - Clifford
PerarduaadastraCommented:
I'm struggling a bit here, as my Sonicwall is an elderly TZ170, and yours is rather newer!

I have discovered, though that the interface trust referred to by Syed_M_Usman is only available in the SonicOS Enhanced version, which I suspect you don't have...

The closest I can find on SonicWall's support pages is KBID 3558; if you substitute WLAN for OPT, the principle of allowing traffic between zones still holds.

Sorry I can't be more help.
CliffordNgAuthor Commented:
thanks Peraduaadastra.

I've seen and enabled the Interface Trust for WLAN, it is found in Zone. the interface trust for LAN was default activated. I've activated for WLAN, but in vain.

I'm pretty sure Syed knows about it more. Thanks for helping, Clifford
PerarduaadastraCommented:
Perhaps you have to reboot the appliance after making this change? It seems unlikely, but doesn't cost anything to try...
CliffordNgAuthor Commented:
rebooting did not help :(

Please see my config screenshot below.

sonicwall management screenshot
CliffordNgAuthor Commented:
problem sorted. all pcs on the lan should have gateway pointed to the sonic wall.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
CliffordNgAuthor Commented:
found answer
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Hardware Firewalls

From novice to tech pro — start learning today.