Accessing remote site resources when connected to the main site via remote VPN client

Description

In many scenarios, VPN users who are connected to the main site via a remote VPN Client need to have access to the resources behind the remote site in addition to the resources on main site. This KB article shows how to configure SonicWall to meet this need.
Image


Resolution for SonicOS 7.X

This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.

  1. Login to the SonicWall management GUI
  2. Click Network tab.
  3. Navigate to IPsec VPN |  Rules and Settings.
  4. Click on the Configure option of the appropriate VPN policy intended for remote site.

    Image

  5. Navigate to Networks tab in the new window and make a note of the address object/group set in the Choose destination network from list drop down list. (This may vary depending upon the remote site resource access privilege of the VPN users).

    Image

     NOTE: Here we are considering the GVC network to be a part of same local network on Main site (NSA 2650). 

  6. Navigate to the Device| Users | Local Users & Groups page  on Main site (NSA 2650) and click  configure option for VPN user account.

    Image

  7. Navigate to VPN Access tab in the new window and enforce the respective Address Object/Group of the remote site from left to right by clicking on the appropriate option as shown below in the image 

    Image

     NOTE: If you are using a separate network subnet/range for the GVC, then on Main Site under "Choose a local network from list" select  an address group consisting of local network and GVC subnet. And on Remote Site under "Choose destination network from the list select an address object consisting of remote network (main site network) and GVC network. 


How to Test this Scenario

  • When using GVC
  1. Disconnect the Global VPN Client session, reconnect & try to access (ping) the remote site resource.
  2. The client will be able to access the resources without any issues.


  • When using NetExtender
  1. Please follow: How can I allow ssl vpn user to access the remote network across site to site vpn?





Resolution for SonicOS 6.5

This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.


  1. Login to the SonicWall management GUI.
  2. Click  Manage tab.
  3. Navigate to VPN |  Base Settings.
  4. Click on the Configure option of the appropriate VPN policy intended for remote site.
    Image
  5. Navigate to Networks tab in the new window and make a note of the address object/group set in the Choose destination network from list drop down list. (This may vary depending upon the remote site resource access privilege of the VPN users).
    Image
     NOTE:  Here we are considering the GVC network to be part of same local network on Main site(NSA 2650) 

  6. Navigate to the Users | Local Users & Groups page on Main site(NSA 2650) and click  configure option of the remote VPN user account.Image

  7. Navigate to VPN Access tab in the new window and enforce the respective Address Object/Group of the remote site from left to right by clicking on the appropriate option as shown below in the image.
    Image
     NOTE: If you are using a separate network subnet/range for the GVC, then on Main SIte under"Choose a local network from list" select and address group consisting of local network and GVC subnet. And on Remote Site under"Choose destination network from the list" Select an address consisting of remote network(main site network) and GVC subnet. 

How to Test this Scenario

  • When using GVC
  1. Disconnect the Global VPN Client session, reconnect & try to access (ping) the remote site resource.
  2. The client will be able to access the resources without any issues.

Related Articles

  • Using 31-Bit Prefixes on IPv4 Address Error: Index of the interface: Invalid IP Address
    Read More
  • How to block a website using CFS 4.0 CLI commands
    Read More
  • How to Configure Wire / Tap mode in SonicOS
    Read More
not finding your answers?
was this article helpful?