Link to home
Start Free TrialLog in
Avatar of Mark Bill
Mark BillFlag for Ireland

asked on

Sonicwall Global VPN Issue - Intermittent packet loss

Hey Guys,

Bit of a weird issue here.
I have a sonicwall TZ200, it is doing DHCP for the VPN users, it also does VPN for the LAN users.
This is a simple one subnet network and two interface firewall. 1 LAN and 1 WAN.

Strange thing is I have managed to get the VPN connecting for my test user, we are using global vpn client.
We are getting massive packet loss, I am pinging things on the lan and losing like 75% of packets.
Funny thing is some are going through, but all have big lag attached.

Unsure of what the issue is really yet.
My first thoughts are to do the below.
1) Use a manual IP on the virtual adapter
2) Change the version of sonicwall global vpn client

Am using a windows 10 laptop for my test user who is connecting.
Avatar of J Spoor
J Spoor
Flag of Netherlands image

suggest using a different IP scope for DHCP over VPN
1) create a new Scope (e.g.192.168.254.50 - 192.168.254.99 subnetmask 255.255.255.0 gateway 192.168.254.254) which is a unique IP subnet
2) on DHCP over VPN set the optional relay IP to an IP address in the same subnet but outside of the scope (e.g. 192.168.254.254)

this will overcome any IP conflicts and ARP issues.
Avatar of Mark Bill

ASKER

Cheers in bad need of some help here. That is all I can say I know you all feel me!

This is very odd looking issue. So I installed newest version of global VPN issue.
Still have roughly 7/10 packets dropping. But the response time has improved drastically.

Agreed J Spoor, exactly what im thinking right now, but that is not a nice fix for me :(. brutal.
No support on the sonicwall. Disaster. This looks like a bug to me.
Also not sure how I will use a different scope for DHCP over VPN as all of the users here are using DHCP from the sonicwall(lol), I know.
Getting active directory DHCP is another days work.

I guess I will just have to statically assign a new range by MAC to individual VPN users.
The users here have never had a VPN(lol again). So anything will really do.

Also seriously considering buying a Sonicwall SRA.
There's no known bugs regarding that.

It's usually environmental, or something inside the network triggering this.

In most cases there's ARP issues or IP Conflicts when using the X0 LAN also for remote VPN clients, hence the suggestion to use a unique subnet.

Other VPN issues could have to do with fragmentation, but simple pings should not be impacted with that.

Also check what your core0 is doing, Pings are processed by Core0, so if that's busy with something, pings will be impacted.
SOLUTION
Avatar of J Spoor
J Spoor
Flag of Netherlands image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Cheers J Spoor, my Sonicwall is a bit out of date. Why would it be an ARP issue if 10-20% of pings are succesful and very smooth.
It follows a pattern too, i.e. 3 succesfull 7 unsucessfull, 4 succesfull 7 unsucessfull etc.
Always a bunch of success followed by a bigger bunch of failures.

Very strange issue.
I am going to try your suggestion once I have a second.
SRA is a much better solution, so many reasons should not be doing VPN like this at FW level these days
Really could do with getting this working for this guy today though.
really really bizzare resolution. I was in the process of trying to get virtual ips and interfaces setup for DHCP static as discussed.

i didnt think it was an arp issue tbh with the intermittent pings so consistently.

dont know how this fixed it but it did, keep split tunneling enabled, and enabling the two boxes below fixed it for me, the culprit looks to have been apply vpn policy box. I also installed the GVPN from just before the final firmware release for this firewall, this is a discontinued TZ200 im working on.
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
resolved by poster