Skip to main content

SonicWALL Enhanced OS

Holy Moly!  I went to configure a simple port-forwarding rule on a customer’s SonicWALL TZ200 today and entered into a whole world of hurt!

All I wanted to do was allow HTTP traffic into an internal web server – exceedingly straightforward on any device I’ve ever worked on before… not so under SonicOS Enhanced!

After about an hour of bizarrely confusing options I realised that one needs to create an address object for the internal server, create a NAT policy to allow access, and then create a firewall access rule.  This doesn’t sound too bad except it wasn’t that simple in fact.  To add to the confusion, I managed to create a NAT loop which killed the network!  That was purely down to my own stupidity though!

So how did I get it to work?  I gave in and used one of the wizards after looking at the following excellent post online: http://www.fuzeqna.com/sonicwallkb/consumer/kbdetail.asp?kbid=7027

Turns out the device needs THREE NAT policies (inbound, outbound, and loopback) plus address object, plus firewall access rule!  What?!!

My advice: take your time with this OS and use the wizards unless you’ve got loads of experience with these devices.

Comments

Popular posts from this blog

Resolve WSUS Server issue that gives "Cannot save configuration because the server is still processing"

This is a pretty infuriating error and can sometimes crop up as a result of running a "wsusutil reset" command. First of all, give the server some time, and then a bit more...  but you've probably already done this. These steps may help to resolve the situation: - Install Microsoft SQL Management Studio (free download) - Run SQL Management Studio and start to connect to the WSUS database - Enter this in the "Server Name" box:  \\.\pipe\MICROSOFT##WID\tsql\query - Expand the "Databases" tree - Right-click on "SUSDB" and choose "New Query" - Paste this query in:     UPDATE tbSingletonData     SET ResetStateMachineNeeded = 0 - You should see a message like "1 row affected", which is good - Quit SQL Management Studio - Open "Services" and restart the "WSUS Service" - Now, open WSUS

Evolution MK-249C MIDI Keyboard Mac OS X Problem

Mac OS X generally seems capable of dealing with just about anything you can throw at it. However upon connecting my trusty Evolution MK-249C MIDI keyboard up to my 2nd generation MacBook it steadfastly refused to play ball. This keyboard has always been instantly recognised by Windows XP and so it was surprising to encounter this. The M-Audio website (M-Audio took over Evolution it appears) offered no real assistance. There was no driver available for Mac OS X 10.4.9 as the keyboard is supposed to be "Class Compliant" which apparently means it doesn't need one... strange. Eventually after consulting some forums I found the fix. The problem seems to be related to Mac OS on the Intel MacBooks. There is a patch on the M-Audio site but only for MacOS 10.1.5. This must be downloaded and installed. Here is the link: http://www.m-audio.com/index.php?do=support.drivers&f=596 Upon restarting the OS the keyboard was recognised by Mac OS and GarageBand had no trouble tal...

Jamf Pro DEP Enrollment Sync failed: Communication error. Awaiting next sync

 This error catches me out every so often when a customer of mine gets new iPads and I have to enrol them.  It's often been some time since I've last done this job and sometimes the MDM Server token needs to be refreshed (for want of a better term) before sync can re-commence between Apple School Manager and the customer's MDM (in this case Jamf Pro). Here are the list of steps to take: Log in to Apple School Manager (ASM) in one browser tab, and your MDM in another tab. In ASM, click your account name on the bottom left, and click "Preferences". Under "Device Management Services" click on your MDM service (Jamf Pro in my case). Click "Download Token" and allow the p7m file to download. In your MDM service, you'll need to upload the p7m file into its "Server token file" area. In Jamf Pro, click into "Settings" and then go into "Automated device enrollment", which is in the "Global Management" area. Cl...