Comments
-
yep, url custom portal is deprecated long time ago. Virtual host is the only one left.
-
Did you check?
-
KB released:
-
This is an interesting topic. Just tested its not firmware issue. @blue DNS security license just apply to the first tab DNS Filtering(without license, it will prompt an alert) However, other tabs like DNS Sinkhole is still configurable and usable without DNS security license. Not sure its intended or bug. So your device…
-
"control what devices" why dont just check UUID on device?
-
AOV should be always on VPN, did you set anything about it?
-
it means used 1GB from 1TB. You still have 943GB for logs.
-
User level setting will override domain setting. You can create new group/user then follow step 2 from kb. Then those new users can use email or totp for otp. Or you can enable all the options on domain settings. It should work on any OTP method. Except mobile connect on IOS/android, it only use the "Prefer" otp.
-
If you are running sma 100 series and with firmware 10.2.X. You can put wireguard on top over sslvpn protocol. This is a workaround for IOS16.1. Only SSLVPN protocol was affected.
-
Did you check this? https://community.sonicwall.com/technology-and-support/discussion/4573/any-one-had-issues-with-kb5018410-win-10-and-kb5018427-win-11-breaks-vpn#latest
-
Did you connect to a sma 100? Try disable wireguard from SMA or drag it to bottom.
-
Generally, the requirement is not hard to achieve but we don't understand your network. Maybe you can try redirect all to check if it works. Also, try call sonicwall support and let me remote check the config on SMA with you. We can't check the configuration. Just theoretically achievable.
-
Then mobile connect is not sending DNS to internal. Quick test just try "Enable Use tunnel as primary network (Mobile Connect only)". Remember to re-login after apply change.
-
@Erdal Add the private IP as "host name or IP" if you just added as URL resource. Then add to ACL. And what client you are testing? window CT is totally different from mobile connect. For mobile connect, enable the "primary network" checkbox will work as well. You can see the different before and after connected mobile…
-
@Erdal It don't really need the domain suffix if you just got 1 website. Search suffix with split route mainly for wildcard hosts searching. From SMA POV, you have to make the FQDN resolve private IP in SMA DNS resolution. When SMA can get private IP & your ACL allow to the private IP, CT will deploy routes to window once…