How to allow wireless traffic over a site to site VPN when the WLAN is bridged to the LAN
08/01/2022 810 People found this article helpful 478,953 Views
Description
How to allow wireless traffic over a site to site VPN when the WLAN is bridged to the LAN
Resolution
Resolution for SonicOS 7.X
This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.
Procedure:
When setting up a site to site VPN with the WLAN bridged, even though the WLAN is in the same subnet as the LAN, it will not be able to pass traffic over the site to site VPN. This is due to the zone based rules. By default rules are created for the LAN zone or the zone/subnet specified in the VPN. If X0 subnet, LAN subnets, or LAN primary subnet is selected as the local network in the VPN it will include the subnet of the WLAN network, but not the zone. If wireless traffic should be allowed to pass over the VPN, please go to the access rules and create two rules. The first rule should be from zone WLAN and to zone VPN where the source network is the W0 subnet or WLAN subnet and the destination network is the remote network that is reached through the VPN. The service on this rule by default should be set to Any. The second rule should be from zone VPN to zone WLAN. It should have the source network as the remote VPN network and the destination network should be the WLAN subnet, W0 subnet or the wireless subnet in question. Please see the screen shots below.
Login to Sonicwall Device.
- Click Policy in the top navigation menu
- Click on Rules and Policies | Access Rules
- Click on Add and Create the rule as below
See Also:
For more information on how to configure the WLAN to be bridged to the LAN please see KB 7081.
Resolution for SonicOS 6.5
This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
Procedure:
When setting up a site to site VPN with the WLAN bridged, even though the WLAN is in the same subnet as the LAN, it will not be able to pass traffic over the site to site VPN. This is due to the zone based rules. By default rules are created for the LAN zone or the zone/subnet specified in the VPN. If X0 subnet, LAN subnets, or LAN primary subnet is selected as the local network in the VPN it will include the subnet of the WLAN network, but not the zone. If wireless traffic should be allowed to pass over the VPN, please go to the access rules and create two rules. The first rule should be from zone WLAN and to zone VPN where the source network is the W0 subnet or WLAN subnet and the destination network is the remote network that is reached through the VPN. The service on this rule by default should be set to Any. The second rule should be from zone VPN to zone WLAN. It should have the source network as the remote VPN network and the destination network should be the WLAN subnet, W0 subnet or the wireless subnet in question. Please see the screen shots below.
Login to Sonicwall Device.
- Click Manage in the top navigation menu
- Click on Rules | Access Rules
- Click on Add and Create the rule as below
See Also:
For more information on how to configure the WLAN to be bridged to the LAN please see KB 7081.
Resolution for SonicOS 6.2 and Below
The below resolution is for customers using SonicOS 6.2 and earlier firmware. For firewalls that are generation 6 and newer we suggest to upgrade to the latest general release of SonicOS 6.5 firmware.
Procedure:
When setting up a site to site VPN with the WLAN bridged, even though the WLAN is in the same subnet as the LAN, it will not be able to pass traffic over the site to site VPN. This is due to the zone based rules. By default rules are created for the LAN zone or the zone/subnet specified in the VPN. If X0 subnet, LAN subnets, or LAN primary subnet is selected as the local network in the VPN it will include the subnet of the WLAN network, but not the zone. If wireless traffic should be allowed to pass over the VPN, please go to the access rules and create two rules. The first rule should be from zone WLAN and to zone VPN where the source network is the W0 subnet or WLAN subnet and the destination network is the remote network that is reached through the VPN. The service on this rule by default should be set to Any. The second rule should be from zone VPN to zone WLAN. It should have the source network as the remote VPN network and the destination network should be the WLAN subnet, W0 subnet or the wireless subnet in question. Please see the screen shots below.
See Also:
For more information on how to configure the WLAN to be bridged to the LAN please see KB 7081.
Related Articles
Categories