SSLVPN user after login can't reach destination when interface in Bridge Mode

Description

SSLVPN users can't reach destination network even if VPN routes are correctly set up following: How to configure SSL-VPN feature

In this scenario, the interface of the destination network (i.e. X0) is bridged to another interface (i.e. X2) assigned to a different zone.

Cause

When an interface is bridged to another one and they're assigned to two different zones, the access rules will be automatically placed by SonicOs (after configuring the SSL-VPN) from X0 zone (i.e. LAN) to SSLVPN and from SSLVPN to LAN.

If X0 is bridged to another interface assigned to a different zone (i.e. X2 - DMZ zone), an identical access rule as the one auto-added from SSLVPN to LAN and LAN to SSLVPN  must be placed from SSLVPN to DMZ and viceversa in order to allow traffic.

Resolution

Taking as example that:

  • X0 is assigned to the LAN zone and it's the destination network of SSLVPN
  • X0 is bridged to X2 which is assigned to DMZ zone

An auto-added access rule will be placed from LAN to SSLVPN and from SSLVPN to LAN. In order to make it working we need to create the same access rules from DMZ to SSLVPN and viceversa:

  1. Go to Firewall | Access Rules
  2. Select SSLVPN to DMZ
  3. Add a new access rule as following:
    1. Service: Any
    2. Source: SSLVPN Pool
    3. Destination: X0 Subnet
    4. Leave the other fields as they are.
  4. Add another access rule from DMZ to SSLVPN, inverting Source and Destination.

Related Articles

  • How to block ICMP (Ping ) using Application control
    Read More
  • SonicWall GEN8 TZ and NSa Firewalls FAQ
    Read More
  • How to configure Link Aggregation
    Read More
not finding your answers?