We help IT Professionals succeed at work.

SonicWall Site to site keep alive??

Sujada
Sujada asked
on
7,240 Views
Last Modified: 2013-12-31
Having a weird issue with a SonicWall TZ170. I know! It should be replaced, but.....

Anyway,, we have several of the small TZ series that we use for offsite clinics to connect back to our Hospital network. This particular 170 just came back from a clinic that we physically moved and assigned to another subnet so that we could test the networking prior to moving hardware and people. It didn't have any of these problems in it's original location.

I updated the firmware SonicOS Standard 3.1.6.6-9s on this when I got it back and booted to default settings, so the configuration is fresh and doesn't have any leftover configurations to cause problems.
After the firmware update, I built a new site to site tunnel with the appropriate vlans to our NSA E5500 HA main firewall utilizing a new subnet for the TZ170 Lan network. It assosciated and everything was working fine. Tested internet, corporate email, file shares, etc. and no problems. I have keep alive and bring up all possible tunnels checked on the TZ 170. I was using my laptop for this testing.

Once the laptop is allowed to go to power saving mode, the tunnel is disconnected within a few minutes and I loose the ability to manage the firewall from our central location. If I do a persistant ping from my desktop at the hospital, I am able to keep the connection alive, but that shouldn't be necessary. The location this is to be deployed will be an Ambulance station in another city, so often there is no one there using a connection if management of the firewall is necessary.

This is the first time I've seen this behavior from these firewalls. I don't see the tunnels dropped on our 5500 and when I power back up the laptop, I see all 4 tunnels still established. Seems like it must be a setting on the TZ 170 somewhere? Disabling the dead peer detection doesn't seem to have any effect on this.
Comment
Watch Question

Miftaul HICT consultant
CERTIFIED EXPERT

Commented:
Please edit the WAN GroupVPN and on the advanced tab,  ensure that "Enable Keep Alive" is checked.

This should work.

Author

Commented:
Miftaul,
The group VPN is not active VPN Screenshot
Under Edit>Advanced there is no keep alive on the group VPN. Keep alive and bring up all possible tunnels are both checked on the active VPN.
This one is on us!
(Get your first solution completely free - no credit card required)
UNLOCK SOLUTION
Miftaul HICT consultant
CERTIFIED EXPERT
Commented:
This one is on us!
(Get your first solution completely free - no credit card required)
UNLOCK SOLUTION

Author

Commented:
Thanks to both Miftaul and convergint for their suggestions. I took the firewall access rules a step farther and created a rule to allow http managment with a timeout value of 600 minutes from my local site Lan and then from the public IP of my local firewall. Neither allowed me to access the management interface of the remote firewall from my local Lan UNLESS there was an active device behind the remote firewall, in this case for testing, my laptop turned on.

What I suspect is that there must be some type of interesting traffic over the VPN or the remote firewall does not respond to management requests althouigh I can't find this documented anywhere. Even a network printer will generate enough traffic to keep this active and that will be the case once it is deployed.

Gain unlimited access to on-demand training courses with an Experts Exchange subscription.

Get Access
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Empower Your Career
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE

Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Unlock the solution to this question.
Join our community and discover your potential

Experts Exchange is the only place where you can interact directly with leading experts in the technology field. Become a member today and access the collective knowledge of thousands of technology experts.

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.