No Internet access after connecting using GVC in "Route all traffic" with "WAN Load-Balancing"
04/15/2021 67 People found this article helpful 488,494 Views
Description
No Internet access after connecting using GVC in "Route all traffic" with "WAN Load-Balancing" configured on SonicWall.
Resolution
There are multiple WAN connections on SonicWall and you have configured them in "Round-Robin / Ratio-Based / Spill-over" Load Balancing method. You have also configured "Route All traffic" WANGroup VPN policy to route the GVC users Internet traffic through the SonicWall.
When the GVC users are connected they are able to access the local resources but they are not able to access Internet or the Internet connection is intermittent.
Misconfigured VPN: Refer this article and confirm that the Route All traffic- WAN GroupVPN configuration is correct.
How to configure a 'Route all Traffic' WAN GroupVPN Policy
Missing NAT policies:
- SonicOS Enhanced (6.2.x.x): Click Network | NAT policies.
- SonicOS Enhanced (6.5.x.x): Click Manage | Policies | Rules | NAT policies.
- SonicOS Enhanced (7.x.x.x):Navigate to Policy | Rules and Policies | NAT Rules.
You must add necessary NAT policies which translates the traffic coming from the remote GVC user, as it goes through the WAN of the firewall towards the Internet. This NAT policy will not affect any traffic except traffic heading towards the Internet from route all VPNs.
Consider the following scenario:
>There are 2 WAN interfaces configured on SonicWall X1 and X2.
>WAN Load balancing is set to Round-robin (or) Ratio-based (or) Spill-over.
In this scenario, 2 NAT policies should be configured for each WAN connections to route the GVC traffic properly.
Resolution for SonicOS 7.X
This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.
Outbound NAT for X1 WAN:
Outbound NAT for X2 WAN:
This NAT policy is needed when the SonicWall is routing the GVC traffic through X2 WAN.
Resolution for SonicOS 6.5
This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
Outbound NAT for X1 WAN:
This NAT policy is needed when the SonicWall is routing the GVC traffic through X1 WAN.
Outbound NAT for X2 WAN:
This NAT policy is needed when the SonicWall is routing the GVC traffic through X2 WAN.
Note: If there are more than 2 WAN connections on the SonicWall then you need to create necessary NAT policies.
How to Test:
GVC users should be able to access Internet and to verify whether the Internet traffic is routed through SonicWall they can go to site ipchicken.com or whatismyip.com, it should show any one of the WAN interface IP address configured on the SonicWall.
Related Articles
Categories
Was This Article Helpful?
YESNO