Solved

Sonicwall TZ215 nat policy

Posted on 2014-03-21
8
800 Views
Last Modified: 2014-03-28
I put in a new sonicwall and the wan static ip is set and the lan ip is set and working.  We have several servers on the opt network.  We are able to get out to the internet on the opt network.  We are having trouble getting packets back in the opt network.

I can see in the logs that rdp, ping, and the software that tries to connect to the ip addresses on the opt network are being blocked.

Any suggestions on the policy I need to get the wan to talk to the opt network would be excellent.
0
Comment
Question by:cnesupport
  • 4
  • 3
8 Comments
 
LVL 13

Expert Comment

by:Greg Hejl
ID: 39947388
run the wizard on each server, this will open up the ports you need to each server IP.

the wizard is in the top right corner
0
 

Author Comment

by:cnesupport
ID: 39947390
Tried that but it isn't just simple port forwarding that needs to be done.
0
 
LVL 13

Expert Comment

by:Greg Hejl
ID: 39947433
create service objects for the ports you need opened and apply those to the service group used in the nat policies that was created when you ran the wizard.

you may also need to adjust your IDS policy for the opt network, it may be set to block low level threats (icmp, etc)

i would not expose rdp directly on a public ip - use a vpn connection instead
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 1

Expert Comment

by:ZTeck
ID: 39949282
Have you tried to convert the OPT port as a DMZ zone? The, tried again. It maybe simple but can be over looked.
0
 

Accepted Solution

by:
cnesupport earned 0 total points
ID: 39949292
Got the issue resolved. I had to create a bunch of custom nat policies and route statements.
0
 
LVL 13

Expert Comment

by:Greg Hejl
ID: 39951084
Did my answer not direct you to your solution?  an assist would have been appropriate....
0
 

Author Comment

by:cnesupport
ID: 39951106
I had the issue resolved before you posted that.  I just had not been back here to post about it.  Also I had to manually create everything the wizard did not create the policies I needed in this instance.
0
 

Author Closing Comment

by:cnesupport
ID: 39961066
Found solution on my own.
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco 3560 switches not seeing VTP V3 12 70
OSPF - Convergence & Downtime 9 37
How do I allow multiple VLANs internet access on a Cisco ASA 5505? 8 39
Router Question 12 56
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question