Avatar of Mark Bill
Mark Bill
Flag for Ireland asked on

Sonicwall Global VPN Issue - Intermittent packet loss

Hey Guys,

Bit of a weird issue here.
I have a sonicwall TZ200, it is doing DHCP for the VPN users, it also does VPN for the LAN users.
This is a simple one subnet network and two interface firewall. 1 LAN and 1 WAN.

Strange thing is I have managed to get the VPN connecting for my test user, we are using global vpn client.
We are getting massive packet loss, I am pinging things on the lan and losing like 75% of packets.
Funny thing is some are going through, but all have big lag attached.

Unsure of what the issue is really yet.
My first thoughts are to do the below.
1) Use a manual IP on the virtual adapter
2) Change the version of sonicwall global vpn client

Am using a windows 10 laptop for my test user who is connecting.
DHCPNetworkingVPNHardware FirewallsInternet Protocol Security

Avatar of undefined
Last Comment
Mark Bill

8/22/2022 - Mon
J Spoor

suggest using a different IP scope for DHCP over VPN
1) create a new Scope (e.g.192.168.254.50 - 192.168.254.99 subnetmask 255.255.255.0 gateway 192.168.254.254) which is a unique IP subnet
2) on DHCP over VPN set the optional relay IP to an IP address in the same subnet but outside of the scope (e.g. 192.168.254.254)

this will overcome any IP conflicts and ARP issues.
Mark Bill

ASKER
Cheers in bad need of some help here. That is all I can say I know you all feel me!

This is very odd looking issue. So I installed newest version of global VPN issue.
Still have roughly 7/10 packets dropping. But the response time has improved drastically.

Agreed J Spoor, exactly what im thinking right now, but that is not a nice fix for me :(. brutal.
No support on the sonicwall. Disaster. This looks like a bug to me.
Mark Bill

ASKER
Also not sure how I will use a different scope for DHCP over VPN as all of the users here are using DHCP from the sonicwall(lol), I know.
Getting active directory DHCP is another days work.

I guess I will just have to statically assign a new range by MAC to individual VPN users.
The users here have never had a VPN(lol again). So anything will really do.

Also seriously considering buying a Sonicwall SRA.
Your help has saved me hundreds of hours of internet surfing.
fblack61
J Spoor

There's no known bugs regarding that.

It's usually environmental, or something inside the network triggering this.

In most cases there's ARP issues or IP Conflicts when using the X0 LAN also for remote VPN clients, hence the suggestion to use a unique subnet.

Other VPN issues could have to do with fragmentation, but simple pings should not be impacted with that.

Also check what your core0 is doing, Pings are processed by Core0, so if that's busy with something, pings will be impacted.
SOLUTION
J Spoor

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Mark Bill

ASKER
Cheers J Spoor, my Sonicwall is a bit out of date. Why would it be an ARP issue if 10-20% of pings are succesful and very smooth.
It follows a pattern too, i.e. 3 succesfull 7 unsucessfull, 4 succesfull 7 unsucessfull etc.
Always a bunch of success followed by a bigger bunch of failures.

Very strange issue.
I am going to try your suggestion once I have a second.
Mark Bill

ASKER
SRA is a much better solution, so many reasons should not be doing VPN like this at FW level these days
Really could do with getting this working for this guy today though.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Mark Bill

ASKER
really really bizzare resolution. I was in the process of trying to get virtual ips and interfaces setup for DHCP static as discussed.

i didnt think it was an arp issue tbh with the intermittent pings so consistently.

dont know how this fixed it but it did, keep split tunneling enabled, and enabling the two boxes below fixed it for me, the culprit looks to have been apply vpn policy box. I also installed the GVPN from just before the final firmware release for this firewall, this is a discontinued TZ200 im working on.
ASKER CERTIFIED SOLUTION
Mark Bill

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Mark Bill

ASKER
resolved by poster