How to configure site to site VPN

Поделиться
HTML-код
  • Опубликовано: 4 дек 2022
  • In this first video of 3, we are configuring a site-to-site VPN between two SonicWall firewall where both firewalls have a fix IP. Then we briefly cover how to do access rules within your VPN, then cover troubleshooting and finally we change the remote site firewall to a dynamic WAN IP (DHCP) and explain how to build VPN with one site having a dynamic IP.
    If you have more complex needs in terms of VPN, I personally advice to go with tunnel interface VPN
    How to configure Tunnel Interface VPN (Route-Based VPN) • How to configure Tunne...
    Which allows to leverage SD-WAN over your VPNs
    SonicWall SD-WAN Overview and demo • SonicWall SD-WAN Overv...

Комментарии • 41

  • @RayPetit
    @RayPetit Год назад +3

    I love your videos. They have helped so much. Keep em coming!

  • @dpiccine
    @dpiccine 5 месяцев назад

    This is amazing, thanks for sharing!

  • @garynichols1502
    @garynichols1502 4 месяца назад

    Great video, thank you!

  • @tintiniloveyou8491
    @tintiniloveyou8491 Год назад

    thanks for the video, it is good lab for the new like me

  • @rockinron5113
    @rockinron5113 8 месяцев назад

    Nice one. Thanks. ❤️

  • @damyj
    @damyj Год назад

    Hey Jean, thanks for the video. Always great time watching you. my question is, do you have multiple ISPs in your home or multiple EXT IPs to configure on both firewalls since youwere able to configure 2 different ext ips for both firewalls

    • @JeanPierTalbot
      @JeanPierTalbot  Год назад +1

      Those 2 ISP are fake. My home firewall (tz670) have x6 and x7 configure as 142.39.18.1/24 and 142.39.19.1/24 and both are DHCP server for their subnets. That provides me 2 fake internet lines.
      So yeah. It’s all fake!!! :-) lol
      Glad you like the videos!

  • @SterpDawg-cy7zf
    @SterpDawg-cy7zf 5 месяцев назад +1

    My sonicwall isn't getting an IP address on the system -interfaces screen when you connect it to the Internet. Literally doing everything you're doing but it's not working. Can anyone help me?

  • @sohosterable
    @sohosterable Месяц назад

    Great video. Thank you! Which Sonicwall device would you recommend for a main office and 10 remote offices for site-to-site VPN connections? 80-100 users.

  • @rajappu4678
    @rajappu4678 7 дней назад

    Hi JP.. Please do a video for site to site vpn between sonicwall and fortigate

  • @ztech-consulting
    @ztech-consulting Год назад

    Hi Jean-Pier. Amazing video. Would you be willing to make a video for multi site 2 site VPN's? I mean a hub and spoke model.

    • @JeanPierTalbot
      @JeanPierTalbot  Год назад +2

      Hi Z Tech!
      I’m so willing to do it that’s it’s already done! :-)
      How to configure Inter-VPN and SSL VPN routing
      ruclips.net/video/2YB5WXKQaUI/видео.html

  • @MrMcNarley
    @MrMcNarley Год назад

    Thanks for the excellent video Jean-Pier! You mentioned creating Access Rules to lock down the site-to-site VPN to allow only required network traffic. Can you point me to a resource to show what services are needed for a site-to-site VPN between a remote office and home office where the Windows server provides Active Directory, DNS, DHCP, Group Policy, etc.? Or better yet, can you do a video on setting that up? Thanks!

    • @JeanPierTalbot
      @JeanPierTalbot  Год назад

      Hi Mitch!
      Thanks for your feedback on the videos!
      I don’t know all the ports on top of my head, but dns will be port 53 from the workstation to the DNS server. Simple Google should allow you to find the other ports needed

  • @gilbertfajardo4170
    @gilbertfajardo4170 10 месяцев назад

    Hi Sir, thank you for your help. May I request for the video content on how to setup the sonicwall hub and spoke topology using tunneling interface?

    • @JeanPierTalbot
      @JeanPierTalbot  10 месяцев назад

      There is already a video on tunnel interface vpn :-)

  • @ocbroadband
    @ocbroadband 11 месяцев назад

    HI Jean, I got this working between a TZ370 and a Omada ER7206(TP-Link). Only 2 subnets I'm working with on each side just like your video. The VPN comes up just fine, and for now, I have it autogenerating the rules, but I can only connect to very specific things on the TZ370 side from the Omada side. Thus far, I can VNC into a device behind the TZ370, but I can't ping it and I can't access for example any web accessible devices. I'm not sure why its limiting that, but not vnc.. Thoughts?

    • @JeanPierTalbot
      @JeanPierTalbot  11 месяцев назад

      Try turning logs on the auto generated policies and see if you see trafic from the tp-link. If you don’t, then you know what’s the issue :-)

  • @networkrealm15
    @networkrealm15 7 месяцев назад

    We are creating tunnel between sonicwall and azure. Tunnel is up and working fine but after sometime it get down automatically for like 40sec and come up. I have also enabled Windows Networking (NetBIOS) Broadcast along with keep alive. Please advise on this?

    • @JeanPierTalbot
      @JeanPierTalbot  7 месяцев назад

      Rule of thumb, if a vpn goes up, it means your encryption, authentication and stuff is good.
      If it goes down after a period of time (like 8 hours) and you bring it back up and it stops again after 8 hours, it generally because you have some mismatch in timeouts/reKey/life time in your vpn. Like one side can have a life time of 8 hours and the other side a lifetime of 12 hours. So vpn drops after 8 hours.
      There are a couple spots in a vpn that includes time variables.
      Always easier to do it with a sonicwall virtual firewall in azure because you can put both firewall side by side and compare settings.
      Hope that helps!

    • @networkrealm15
      @networkrealm15 7 месяцев назад

      @@JeanPierTalbot VPN is showing up but after every 15min I am not able to ping remote azure subnet for 40sec and after that started pinging. I hope enabling netbios is not a problem.

  • @lowellabraham6966
    @lowellabraham6966 Год назад

    Hi Jean-Pier, would you be able to do a video on VPN to AWS?

    • @JeanPierTalbot
      @JeanPierTalbot  Год назад

      Hum. Good topic! I’ll add it to my list. Thanks.
      If you want an easy way to do it, deploy a sonicwall firewall in AWS. It’s called a NSv. Then do a vpn between the NSv in AWS and your sonicwall firewall at the office. UI of NSv and tz/NSa are pretty much identical

  • @jerrymoletto7301
    @jerrymoletto7301 3 месяца назад

    Jean-Pier I have a question. I have a client that has older SOHO firewall running a firmware of 6.5. Can I connect a TZ270w at a remote site that runs firmware 7.0 and still make a site to site VPN. Or do they both have to have same firmware. Please let me know

  • @farooqdidar5731
    @farooqdidar5731 Год назад

    Hi Sir
    Quick question: what are the differences among all the gen firewalls.
    For example:
    How gen 6 differ from gen 7.
    Thanks

    • @JeanPierTalbot
      @JeanPierTalbot  Год назад

      Here is a good list.
      blog.sonicwall.com/en-us/2022/10/10-reasons-to-upgrade-to-the-latest-sonicwall-gen-7-tz-firewall/

  • @raygaviria
    @raygaviria Год назад

    hi, i like this videio, can you tell somethings experiencies conecting vpn s2s with other utm´s company for example fortige, tks

    • @JeanPierTalbot
      @JeanPierTalbot  Год назад

      Currently editing a video where I did a vpn between sonicwall and Watchguard. Should be available in a week or 2

  • @peterknight93
    @peterknight93 Год назад

    Great Videos, Thanks. QQ How would I setup site to site if the networks overlap the same subnet? Apply NAT policy Examples would be great.

    • @JeanPierTalbot
      @JeanPierTalbot  Год назад +1

      Thanks Peter for your feedback.
      Solution is to change subnet on one end. :-)
      If that’s not an option, you will need to do 1 to 1 NAT in your vpn

  • @justinrhode7448
    @justinrhode7448 11 месяцев назад

    Hey Jean, Is there a way to have a vpn between two sites and both sites have the same LAN subnet?

    • @JeanPierTalbot
      @JeanPierTalbot  11 месяцев назад

      Yes, but it brings its share of complexity that you will be dragging forever. You have to do NAT in your vpn creating 2 fake subnets. That might create challenges if you try to get 2 AD to talk. Or DNS might be a challenge as DNS should not resolve to the true IP of a device on the other site…
      My opinion: change subnet on one site.
      Otherwise here is how to do NAT in a vpn. It’s easy, but then you may face challenges with DNS and other stuff that won’t like the change of IP. Certificate comes into mind as a potential issue.
      www.sonicwall.com/support/knowledge-base/how-can-i-configure-nat-over-vpn-in-a-site-to-site-vpn/170515155805172/

    • @justinrhode7448
      @justinrhode7448 11 месяцев назад

      @@JeanPierTalbot Thank you so much.

  • @davilajeremy
    @davilajeremy Год назад

    Is there a link to get the sonicwall tshirt?

    • @JeanPierTalbot
      @JeanPierTalbot  Год назад +1

      That’s an employee privilege:-)

    • @davilajeremy
      @davilajeremy Год назад

      @@JeanPierTalbot understand that. Thanks for the reply

  • @arvindshinde12345
    @arvindshinde12345 9 месяцев назад

    Behind Sonicwall PC can't access from B Site VPN pc

    • @JeanPierTalbot
      @JeanPierTalbot  9 месяцев назад

      Mostly a windows firewall issue :-)
      Try ping on a printer or a switch (encore they have the firewall as default gateway)