Solved

TopicsNetworking Hardware Firewalls ,Miscellaneous Networking ,Networking

Posted on 2014-02-17
11
329 Views
Last Modified: 2014-03-02
any helps shred some light every appreciates
needsaccess from X2 to our X0 port and vice versa.  


SW HP--sonicwal---Internet

Sw = L3 /(2)vlans

sonicwall X1 = ip 192.168.101.254 connecting to SW port 1(vlan 100)
Zone = X2 = ip 192.168.102.254  connecting to SW port 17 ( vlan 200)

SW-HP

Vlan 100 = 192.168.101.150

Vlan 200 = 192.168.102.150


Sonicwal route policy
Any      X2 Subnet      Any      0.0.0.0        X2      20      5


from X0 network I can accessing to X2 network = yes
from X2 network I could n't  to X0 network = not able


HP2650# conf
HP2650(config)# sh run

Running configuration:

; J4899A Configuration Editor; Created on release #H.10.83

hostname "HP2650"
interface 1
   no lacp
exit
interface 2
   no lacp
exit
interface 49
   no lacp
exit
interface 50
   no lacp
exit
trunk 49-50 Trk1 LACP
sntp server 207.200.81.113
ip routing
ip timep dhcp
snmp-server community "public" Unrestricted
vlan 1
   name "DEFAULT_VLAN"
   no ip address
   no untagged 1-48,Trk1
   exit
vlan 100
   name "manage-vlan"
   untagged 1-16
   ip address 192.168.101.150 255.255.255.0
   tagged Trk1
   exit
vlan 200
   name "VLAN200"
   untagged 17-32
   ip address 192.168.102.150 255.255.255.0
   ip helper-address 192.168.101.254
   tagged Trk1
   exit
vlan 300
   name "VLAN300"
   untagged 33-48
   ip address 192.168.103.151 255.255.255.0
   ip helper-address 192.168.101.254
   tagged Trk1
   exit
ip route 0.0.0.0 0.0.0.0 192.168.101.254
no stack
spanning-tree
spanning-tree Trk1 priority 4
spanning-tree priority 0

1
0
Comment
Question by:VN-PC view
  • 7
  • 4
11 Comments
 
LVL 20

Expert Comment

by:carlmd
Comment Utility
Have you added a rule to permit all traffic from X0 to X2 and vice versa?
0
 

Author Comment

by:VN-PC view
Comment Utility
you meant Nat rule ? can you point me where how to .

many thanks
0
 
LVL 20

Accepted Solution

by:
carlmd earned 500 total points
Comment Utility
OK. X1 is the default WAN interface, so I assume you are using it that way. X0 is the default LAN interface. So is X2 defined as a LAN interface? Are you using any other interfaces on this Sonicwall? What model Sonicwall is this?

Given that X1 is the WAN, and X2 is a LAN interface, by default all traffic from X1 and X2 to X0 will be permitted by default. If you look (Firewall -> Access Rules) you should see an "any any" rule for for LAN -> WAN. Do you have this?

Can you post what you see from Network -> Interfaces. You can sanitize any public ip addresses.
0
 

Author Comment

by:VN-PC view
Comment Utility
hi,

x1 LAN
x2 LAN 2 ( they both same zone of (trust), so route policy  all good here and access rule ( firewall) all good > allow any both side interface, I think it is default when you set x2 s same zone as LAN , sonicwall create default trusted, but I can accessing from x0 to x2 but when x2 to x0 not able,  maybe NAT issue

both x0 , x2 all able accesses to internet fine,
policy-rule.PNG
0
 

Author Comment

by:VN-PC view
Comment Utility
Hi carlmd

forgot tell you model tz 150 firmware 5.8.xx
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 20

Expert Comment

by:carlmd
Comment Utility
Under Firewall->Access Rules do you have an any any (permit all) rule from LAN to LAN?

Does the log have any entries (blocking?) when you attempt access from X2->X0?
0
 

Author Comment

by:VN-PC view
Comment Utility
Under Firewall->Access Rules do you have an any any (permit all) rule from LAN to LAN?

YES= all

Does the log have any entries (blocking?) when you attempt access from X2->X0?

YES= blocking from x2 to LAN
firewall rule doesn't have interface X2 - LAN not exist?
I suppose it must have X2 showing in firewall rule, but it is not showing that is wrong
0
 
LVL 20

Expert Comment

by:carlmd
Comment Utility
Can you post your firewall LAN to LAN rules.
0
 

Author Comment

by:VN-PC view
Comment Utility
Hi Carlmd

here you goes
Capture.PNG
0
 

Author Comment

by:VN-PC view
Comment Utility
resolved ( wrong configured on windows side not on sonic wall)

Carlmd , you were gave me right direction
0
 

Author Closing Comment

by:VN-PC view
Comment Utility
good job
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
Hi All,  Recently I have installed and configured a Sonicwall NS220 in the network as a firewall and Internet access gateway. All was working fine until users started reporting that they cannot use the Cisco VPN client to connect to the customer'…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now