Link to home
Start Free TrialLog in
Avatar of Digital_Skream
Digital_SkreamFlag for United States of America

asked on

Sonicwall Global VPN Client grabs all internet traffic

When configuring the GVC to connect to a Sonicwall NSA 2600, every time the GVC connects, the pc's internet traffic does one of two things:
Either it goes entirely through the remote Sonicwall, or it just stops altogether.
i have teh GVC configured on the NSA to run in Split Tunnels, but if i configure the Sonicwall Virutal adapter witha  default gateway, the vpn works and i can access the machines on the remote subnet just fine, as well as on my local subnet.  But all internet traffic goes through the vpn at that point.
If I delete the default gateway on the vpn adapter and connect, my local intranet traffic as well as internet traffic passes normally out of my local router... but I lose all contact with the machines on the remote network.
Please help!
Avatar of Greg Hejl
Greg Hejl
Flag of United States of America image

This looks to be the correct fix:

http://dleetor.blogspot.com/2013/02/solution-sonicwall-global-vpn-user.html

FIXED!: SonicWall Global VPN User cannot get out to internet but can access stuff on the company's LAN
I just spent quite some time doing research into this issue.  If you have a user who connects to the company SonicWall with Global VPN Client but cannot get out to the internet but can ping and access everything internal on the company's LAN, here are a couple things to check out.

1) Go into VPN > Settings > Click Configure for the WAN GroupVPN
2) Go to the Advanced tab and make sure default gateway is set to 0.0.0.0
3) Go to the Client tab and make sure you have it setup like this:
4) Go into Users > Local Users and hover your mouse cursor over the VPN Access column for all users
5) If you see that VPN DHCP Clients or WAN RemoteAccess Networks is in any of the bubbles, this is what's causing the issue!  These objects will turn a Split Tunnel setup into a Tunnel All GroupVPN setup and so it will attempt to tunnel all internet traffic through the SonicWall which defeats the purpose of having Split Tunnels setup (I'm assuming S.T. because it's the most common kind of setup)

6) If you find that you can't edit the config for the local user All LDAP Users, try this...
7) Go into Local Groups, hover your mouse cursor over everything under VPN Access and check for the same entries (VPN DHCP Clients or WAN RemoteAccess Networks).  In my case, it was the SSLVPN Services group
8) Go into Config > VPN Access and remove both VPN DHCP Clients and WAN RemoteAccess Networks and leave only LAN Subnets
Avatar of Digital_Skream

ASKER

I already had that configuration setup.
I am having an issue wherein I am not aquiring an IP... the gvc just sits there saying aquiring ip for as long as I let it.
Please review your DHCP configuration

Is your relay agent setup correctly?

https://support.software.dell.com/kb/sw11769
We are using the Sonicwall as the DHCP server.
ASKER CERTIFIED SOLUTION
Avatar of Greg Hejl
Greg Hejl
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Beautiful.

That's got it sorted.