Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Sonicwall 3060 Firewall Access Rule

Posted on 2013-05-15
7
384 Views
Last Modified: 2013-06-09
Hi,

I have the standard sonic OS  on my SonicWall 3060 and need to write a rule that says to allow all traffic from an external ip range to an internal destination ip range.  I don't want to reference any services but just ip addresses.

Thanks
0
Comment
Question by:wpmcj
  • 3
  • 2
7 Comments
 
LVL 9

Accepted Solution

by:
BigPapaGotti earned 350 total points
ID: 39168831
On the left hand side click on Network
Click on Address Objects
Scroll down to Address Objects and click on the "Add..." button
In the popup window give an appropriate name
Assign the Zone to the appropriate name
In the Type drop down select "Range"
Fill Out the Starting IP & Ending IP
Click Add
Repeat the above steps for the other range either internal or external based on what you did the first time.

Click on Firewall
Click on Access Rules
Select the Drop-down Boxes view style
Select WAN for the "From Zone:" and LAN for the "To Zone"
Click OK
Click on the Add button
Select "Any" Service
For Source select the External group you created above
for Destination select the Internal group you create above
Click on "Add"

Now test to ensure it works.

You may need to create a NAT policy to properly forward the ports in question to your internal computers.

Let me know if this worked for you.
0
 

Author Comment

by:wpmcj
ID: 39168919
Unfortunately, Address Objects is not available in the standard version of SonicOS.  I could update but looks like I'd have to start from scratch with the Enhanced version.
0
 
LVL 9

Expert Comment

by:BigPapaGotti
ID: 39168986
I see. What happens when you go to the next part of the Firewall Access Rule does it allow you to specify the access rule or is it useless without the Address Objects?

How much configuration would be involved with moving to the enhanced version. Although it is not supported you should be able to upload the Enhanced OS boot off of it and then import the configuration from your Standard OS. You may run into issues or you may be lucky and not having any. You can always revert back to the Standard OS if necessary. I'm not sure what your maintenance window looks like
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:wpmcj
ID: 39169071
Basically, I have to specify a service or use "any"  but tried and didn't work for my purpose.  Others maintain it would work if I had a rule based in IPs and not services.

Looking for more info on the upgrade to Enhanced but I think you're correct in that it may or not import the old settings.  Our maintenance time would probably be a weekend.
0
 
LVL 9

Expert Comment

by:BigPapaGotti
ID: 39169446
I think it would be worth your while about going from a Standard to Enhanced firmware and then trying to import the same configuration. I've completed once successfully in the past without any issues.

Let me know how it goes should you attempt this on the weekend or after hours one night
0
 
LVL 69

Expert Comment

by:Qlemo
ID: 39232897
I've requested that this question be closed as follows:

Accepted answer: 350 points for BigPapaGotti's comment #a39168831
Assisted answer: 0 points for wpmcj's comment #a39169071

for the following reason:

This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question