Solved

Sonicwall TZ 105 allow Lan to pull file from DMZ

Posted on 2014-03-28
13
618 Views
Last Modified: 2014-03-29
Have a Sonicwall TZ105 and the client needs to be able to run a batch file on the LAN side that will pull a file from the DMZ side. This is done periodically based on a task on the LAN Side computer.

What is the best way to do this
0
Comment
Question by:911bob
  • 8
  • 5
13 Comments
 
LVL 11

Accepted Solution

by:
Miftaul earned 500 total points
ID: 39963236
Access from LAN to DMZ is allowed. So it should work just fine without any additional configuration.
0
 

Author Comment

by:911bob
ID: 39963830
Thats what I thought.. but its not..

Everything is open from LAN to DMZ and Everything is denied from DMZ to LAN

Is there any NAT setting that has to be applied?

Trying to browse to a computer on that side using \\192.168.11.14\
0
 

Author Comment

by:911bob
ID: 39963831
If I open the DMZ>Lan for all then the DMZ can browse to the lan side
0
 
LVL 11

Expert Comment

by:Miftaul
ID: 39963837
Do you mean you want to access a lan resource from dmz. We can limit the access by selectively allowing any ip for selective services.
0
 

Author Comment

by:911bob
ID: 39963842
NO, From the LAN Side I cannot open the DMZ side
0
 

Author Comment

by:911bob
ID: 39963850
lan is 192.168.68.X

DMZ is 192.168.11.X

Trying to open \\192.168.11.14\ from LAN TO dmz

Oddly if I open everything from DMZ to LAN, then I cna ping and can open \\192.168.68\14\ from the DMZ Side.
0
New! My Passport Wireless Pro Wi-Fi Mobile Storage

Portable wireless storage to offload, edit, and stream anywhere.

High-capacity, wireless mobile storage designed to accompany professional photographers and videographers in the field to easily offload, edit and stream captured photos and high-definition videos.

 

Author Comment

by:911bob
ID: 39963858
2 03/29/2014 10:47:11.832 Notice Network Access UDP packet dropped 192.168.11.14, 137, X4 192.168.68.224, 137, X0 UDP NetBios UDP    
3 03/29/2014 10:47:09.736 Notice Network Access TCP connection dropped 192.168.11.14, 49166, X4 192.168.68.224, 445, X0 TCP SMB    
4 03/29/2014 10:38:27.832 Notice Network Access TCP connection dropped 192.168.11.14, 49371, X4 192.168.68.224, 445, X0 TCP SMB    
5 03/29/2014 10:38:14.304 Notice Network Access ICMP packet dropped due to policy 192.168.11.14, 1, X4 192.168.68.224, 8, X0 ICMP Echo, Code: 0

From log file
0
 

Author Comment

by:911bob
ID: 39963862
Well.. now it decided to start working..

Go figure..

I added an ICMP rule on the DMZ to the LAN to allow, Did a ping, and it worked..
I then turned off the ALLOW all from DMZ to LAn and it still works..

I gues patience plays a part.
0
 

Author Closing Comment

by:911bob
ID: 39963864
Thanks for your help
0
 
LVL 11

Expert Comment

by:Miftaul
ID: 39963865
So the Firewall Access rule from LAN to DMZ is allowed but you can not initiatate a connection from lan to dmz, is that what you experiancing. Please allow the required type of services from lan to dmz if its not already there.

Return traffic from dmz to lan will be allowed.
0
 
LVL 11

Expert Comment

by:Miftaul
ID: 39963869
The log shows you are initiating the connection from dmz to lan, where it should've been the other way, init.
0
 
LVL 11

Expert Comment

by:Miftaul
ID: 39963900
Good that it works. Thanks.
0
 

Author Comment

by:911bob
ID: 39964020
I am fairly sure it was a windows firewall issue on the DMZ Side
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
Hello All, I have been training on Multicast for a while now and whenever I start the topic , I find out that my friends /  Colleagues mention that they do not know how to test Multicast Joins. As most of the multicast would be video traffic and …
I designed this idea while studying technology in the classroom.  This is a semester long project.  Students are asked to take photographs on a specific topic which they find meaningful, it can be a place or situation such as travel or homelessness.…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now