How can I allow NetBIOS traffic via SSLVPN?
07/21/2022 1,337 People found this article helpful 494,228 Views
Description
Allowing NetBIOS over SSLVPN will reduce the number of problems associated with Microsoft workgroup/domain networks, as the SonicWall security appliances will forward all NetBIOS-Over-IP packets sent to the local LAN subnet's broadcast address coming from the SSL tunnel. Microsoft networking, unless explicitly configured otherwise, is heavily dependent upon local LAN broadcast messages; normally, edge security appliances such as routers, firewalls, or VPN security appliances discard these broadcast messages.
NOTE: We do not have a specific option to enable to allow NetBIOS traffic over SSLVPN on SonicOS 5.9 firmwares. Follow these steps after configuring SSLVPN on SonicWall appliance running SonicOS 5.9 and above.
Resolution
Resolution for SonicOS 7.X
This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.
Configure address object for the broadcast address
Since NetBIOS is a broadcast traffic on UDP port 137, an address object needs to be configured for the broadcast IP address 255.255.255.255.
Testing:
From a host connected through Netextender client ping a host on the SonicWall network by it's NetBIOS name. Before testing make sure the host you are trying from and the host being accessed has NetBIOS enabled in their NIC.
If that did not work, please check if you are able to reach your Domain controller. Check the FQDN (hostname.domainName) of the computer you are trying to reach. If it works, then you only need to add the domain name on the SSLVPN Virtual adapter > IPv4 properties > Advanced > DNS
Resolution for SonicOS 6.5
This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
Configure address object for the broadcast address
Since NetBIOS is a broadcast traffic on UDP port 137, an address object needs to be configured for the broadcast IP address 255.255.255.255.
- Select Manage | Policies | Objects | Address Objects and Add a new address object.
- Name: NetBIOS
- Zone Assignment: LAN
- Type: Host
- IP Assignment: 255.255.255.255
Adding broadcast address to SSLVPN services group
- Under Manage | System Setup | Users | Local Users & Groups, ensure that the relevant user or user group is a member of the SSLVPN Services group.
VPN Access Tab:
On the VPN Access Tab allows users to access networks using a VPN tunnel, select one or more networks from the Networks list and click the arrow button to move them to the Access List. To remove the user's access to a network, select the network from the Access List, and click the left arrow button.
Testing:
From a host connected through Netextender client ping a host on the SonicWall network by it's NetBIOS name. Before testing make sure the host you are trying from and the host being accessed has NetBIOS enabled in their NIC.
If that did not work, please check if you are able to reach your Domain controller. Check the FQDN (hostname.domainName) of the computer you are trying to reach. If it works, then you only need to add the domain name on the SSLVPN Virtual adapter > IPv4 properties > Advanced > DNS
Resolution for SonicOS 6.2 and Below
The below resolution is for customers using SonicOS 6.2 and earlier firmware. For firewalls that are generation 6 and newer we suggest to upgrade to the latest general release of SonicOS 6.5 firmware.
Configure address object for the broadcast address
Since NetBIOS is a broadcast traffic on UDP port 137, an address object needs to be configured for the broadcast IP address 255.255.255.255.
- Select Network | Address Objects and add a new address object.
- Name: NetBIOS
- Zone Assignment: LAN
- Type: Host
- IP Assignment: 255.255.255.255
Adding broadcast address to SSLVPN services group
- Under Users | Local users, ensure that the relevant user or user group is a member of the SSLVPN Services group.
VPN Access Tab:
On the VPN access tab allows users to access networks using a VPN tunnel, select one or more networks from the networks list and click the arrow button to move them to the Access List. To remove the user's access to a network, select the network from the Access List, and click the left arrow button.
Testing:
From a host connected through Netextender client ping a host on the SonicWall network by it's NetBIOS name. Before testing make sure the host you are trying from and the host being accessed has NetBIOS enabled in their NIC.
If that did not work, please check if you are able to reach your Domain controller. Check the FQDN (hostname.domainName) of the computer you are trying to reach. If it works, then you only need to add the domain name on the SSLVPN Virtual adapter > IPv4 properties > Advanced > DNS
Related Articles
Categories