SonicWall Admin account not allowed on LAN after config
When setting up a SonicWall TZ 105. I have come across issues after setup and assigning a differnet LAN address that the admin login will no longer work. Scenario is that I get a firewall, program and configure this. Then assign a different IP address for the LAN connection and send this to a remote location for install. The WAN interface does work as I allow https management on the WAN interface and this also has default rules applied to allow this config. I have also set the X1 inteface to allow http and https management on this interface. When installing the new Sonicwall at remote locations, I can no longer connect via the LAN interface through our VPN tunnel. I had to do the following.
Set a rule in VPN firewall setting to allow http and https management from the LAN interface
Firewall VPN rules >ADD
Action > Allow From Zone>VPN To Zone >LAN Service>HTTPS Management Source >Any ( this was set to VPN Lan setup earlier) Destination>All X0 Management IP Users Allowed>ALL Schedule>Always On
I did this for both the https and http management settings.
I then needed to VPN and edit the current policy I had setup earlier (local VPN configuration).
Edit this policy and go to the Advanced Tab, Management via this SA: HTTPS and User Login vi this SA:HTTPS
I had to do the second edit to the current VPN policy because after adding the rules in the firewall I could bring up the login page, but was getting an error when trying to login via Admin user, error was Admin was not allowed. After editing the VPN policy under Advanced Tab, Admin account was able to log back on.

0 Comments:
Post a Comment
<< Home