SonicWall TZ 205 BWM settings for RD Gateway (SBS 2011)
We have a client using SBS 2011 with a separate Remote Desktop server on Server 2012 at the main office. Users from a branch office RDP through the SBS RD Gateway to use the Remote Desktop server. Every so often the branch office users complain about sluggish connectivity to the remote server. Can anyone recommend, in detail, the best settings on their main office TZ 205 firewall, in terms of bandwidth management, to optimize traffic for the RD Gateway while still leaving enough resources for normal web browsing, SMTP, and the branch office VPN?
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
So...
Under Firewall Settings > BWM, I can change the BWM type to WAN, Global, or None. Should I choose Global here?
Under Firewall > Access Rules, I have rules for HTTP, HTTPS, and an RWW specific rule for port 987. There is a tab called Ethernet BWM. When I set BWM type (above) to WAN, the settings I change in Ethernet BWM under Access Rules do not stick. So, I'm guessing I need to set that to Global. When I choose this, I get a daunting message about BWM settings being reset on all Access Rules. I don't figure this will be a problem though since I don't have any BWM settings for any of the Access Rules yet.
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
To answer your other question. There is GAV, Content Filtering, and IPS running on the SonicWall, but these problems have been going on since before those services were enabled. Ultimately, I think the issue is on the end of the branch office, but I wanted to eliminate possibilities.
Aaron Tomosky
I ask because the tz205 with all the security running will likely have problems with more than a 10mbit connection
Your help has saved me hundreds of hours of internet surfing.
fblack61
MISquared
ASKER
It's closer to 18. Do you know if it's possible to omit that traffic, by service or IP, from being scanned by those services? I'll poke around to see what I can find out.
Aaron Tomosky
so not only can gav, ids, and content filtering be enabled or disabled entirely, but they can be enabled per direction per interface. If you can find some off-business-hours time, run a speedtest with how it is now. Disable all security features and run a speedtest. Plug a laptop directly into the internet line, run a speedtest.
So...
Under Firewall Settings > BWM, I can change the BWM type to WAN, Global, or None. Should I choose Global here?
Under Firewall > Access Rules, I have rules for HTTP, HTTPS, and an RWW specific rule for port 987. There is a tab called Ethernet BWM. When I set BWM type (above) to WAN, the settings I change in Ethernet BWM under Access Rules do not stick. So, I'm guessing I need to set that to Global. When I choose this, I get a daunting message about BWM settings being reset on all Access Rules. I don't figure this will be a problem though since I don't have any BWM settings for any of the Access Rules yet.
Any thoughts on that?
Thanks!