Arkwright Community Legend ✭✭✭✭✭
Reactions
Comments
-
Check your throughput stats, do you see these events coinciding with peaks in thoughput?
-
Check the logs.
-
You can override this in /diag.html but I assume there has to be a reason why it gets disabled by default. This is an interesting article [although much is implied rather than explicitly stated] - it suggests to enable PortShield before enabling HA and it will work.…
-
How can I work out if any given connection is inspected? I think I might have an answer but would be grateful if my peers could try to validate this one for me…. Connection Monitor. Change destination port to 80, Flow Type to HTTPS. Every firewall I've checked, this looks like DPI-SSL. Firewalls with DPI-SSL disabled have…
-
Did support give you any specific notes on the hotfix?
-
Can anyone suggest any tools to help me t/s this? What is the status of the probes in F&LB?
-
At this point I'm about to do a conversion/restore from the configuration tool and just fix the mess after validating connectivity. That would have been my starting point.
-
The TZ370 is an upgrade from a TZ300, and the configuration was imported from that (after converting it in the SonicWall online tool) OK, that's a plausible explanation. If you know you have flat network LAN-side then the default gateway setting on the LAN interface is unnecessary.
-
Has anyone out there found a way to convert something like this to the proper format without manually doing it How many firewalls are you making this change on? If it's more than a handful, I suggest you look at DEAOs. The "file format" for those is about as simple as it gets - one FQDN or IP address per line. It would be…
-
Paste the actual drop code. My guess is, ARP complaining that IP address in network that does not belong to this interface.
-
I think you need to open a ticket with Sonicwall about DPI-SSL performance regression with 7.1.2.
-
when I hover over the X1 interface (which is the LAN), there's a value for Default Gateway shown in the window that opens, which is the correct value for the current connection. I'm not sure how it got there, but it's there. Should I remove that? Like I said, it's not normal [by which I mean, necessary in a flat LAN…
-
Are the counters incrementing as expected on NAT and access rules? What is the status of the probes in F&LB?
-
Open a support case. Sounds obviously like a bug.
-
The content of the default gateway object is determined by the interface settings; that's why it's not directly editable. It's not normal to have a default gateway on a LAN interface, so what is it for?