Replaced the “old” SonicWALL with the new one. I decided to do the setup manually to refamiliarize myself with the configuration, and all went well except for remote connectivity!
The Enhanced OS is complicated and powerful, but once you get it in place it just works. Now I’m back in that place, but not after a call to support.
My client would connect and even allow drive mappings and Outlook connectivity but very sporadically. I could ping and get a single reply, then nothing.
Outlook would connect and then drop.
First I logged an online support session. Then I called support. Turns out that the guy that called me on the online session was more competent than the direct phone support rep! Phone Guy had me pinging servers on my LAN from the Global VPN Client (remote) and he was watching the packets fly by on the SonicWALL. He concluded that there must be a switch on the network messing things up. “Au Contrare!” I said. “It worked fine with the old SonicWALL.” He maintained his stand, and I let him off the hook, knowing I would get another call.
Online Guy called me, and he had it figured out in 20 minutes. We did a number of things to clean it up, which I summarize below!
Under Network Objects:
Created a network group object that included our two LAN interfaces: (X0 Subnets & X3 Subnets,) Called it VPN Networks. When exporting the VPN config file, choose this network object as the connect to item.
Under VPN:
In the VPN Configuration
On the Client TAB:
Client Connections section; Virtual adapter settings are DHCP Lease, Allow Connections to: SPlit Tunnels.
The setting that I changed was the “Set Default Route as this Gateway,” by clearing the check box. Since we are not allowing Internet access through the LAN this is not configured.
On the Advanced TAB:
Cleared the check box: Require Authentication of VPN Clients via XAUTH
> DHCP over VPN, click configure, and unchecked the box “Use Internal DHCP Server (this means the one in the SonicWALL), Since we are passing the request to our internal (LAN network) DHCP server.
> Advanced, Cleared the checkbox “Ignore DF(Don’t Fragment) Bit”
Re-export the config file, being sure to choose the new object. Don’t forget to save your config!
TLC