How to configure site to site VPN

แชร์
ฝัง
  • เผยแพร่เมื่อ 4 ธ.ค. 2022
  • In this first video of 3, we are configuring a site-to-site VPN between two SonicWall firewall where both firewalls have a fix IP. Then we briefly cover how to do access rules within your VPN, then cover troubleshooting and finally we change the remote site firewall to a dynamic WAN IP (DHCP) and explain how to build VPN with one site having a dynamic IP.
    If you have more complex needs in terms of VPN, I personally advice to go with tunnel interface VPN
    How to configure Tunnel Interface VPN (Route-Based VPN) • How to configure Tunne...
    Which allows to leverage SD-WAN over your VPNs
    SonicWall SD-WAN Overview and demo • SonicWall SD-WAN Overv...

ความคิดเห็น • 40

  • @RayPetit
    @RayPetit ปีที่แล้ว +2

    I love your videos. They have helped so much. Keep em coming!

  • @dpiccine
    @dpiccine 4 หลายเดือนก่อน

    This is amazing, thanks for sharing!

  • @garynichols1502
    @garynichols1502 3 หลายเดือนก่อน

    Great video, thank you!

  • @rockinron5113
    @rockinron5113 7 หลายเดือนก่อน

    Nice one. Thanks. ❤️

  • @tintiniloveyou8491
    @tintiniloveyou8491 ปีที่แล้ว

    thanks for the video, it is good lab for the new like me

  • @damyj
    @damyj ปีที่แล้ว

    Hey Jean, thanks for the video. Always great time watching you. my question is, do you have multiple ISPs in your home or multiple EXT IPs to configure on both firewalls since youwere able to configure 2 different ext ips for both firewalls

    • @JeanPierTalbot
      @JeanPierTalbot  ปีที่แล้ว +1

      Those 2 ISP are fake. My home firewall (tz670) have x6 and x7 configure as 142.39.18.1/24 and 142.39.19.1/24 and both are DHCP server for their subnets. That provides me 2 fake internet lines.
      So yeah. It’s all fake!!! :-) lol
      Glad you like the videos!

  • @sohosterable
    @sohosterable หลายเดือนก่อน

    Great video. Thank you! Which Sonicwall device would you recommend for a main office and 10 remote offices for site-to-site VPN connections? 80-100 users.

  • @MrMcNarley
    @MrMcNarley ปีที่แล้ว

    Thanks for the excellent video Jean-Pier! You mentioned creating Access Rules to lock down the site-to-site VPN to allow only required network traffic. Can you point me to a resource to show what services are needed for a site-to-site VPN between a remote office and home office where the Windows server provides Active Directory, DNS, DHCP, Group Policy, etc.? Or better yet, can you do a video on setting that up? Thanks!

    • @JeanPierTalbot
      @JeanPierTalbot  ปีที่แล้ว

      Hi Mitch!
      Thanks for your feedback on the videos!
      I don’t know all the ports on top of my head, but dns will be port 53 from the workstation to the DNS server. Simple Google should allow you to find the other ports needed

  • @ztech-consulting
    @ztech-consulting ปีที่แล้ว

    Hi Jean-Pier. Amazing video. Would you be willing to make a video for multi site 2 site VPN's? I mean a hub and spoke model.

    • @JeanPierTalbot
      @JeanPierTalbot  ปีที่แล้ว +2

      Hi Z Tech!
      I’m so willing to do it that’s it’s already done! :-)
      How to configure Inter-VPN and SSL VPN routing
      th-cam.com/video/2YB5WXKQaUI/w-d-xo.html

  • @gilbertfajardo4170
    @gilbertfajardo4170 9 หลายเดือนก่อน

    Hi Sir, thank you for your help. May I request for the video content on how to setup the sonicwall hub and spoke topology using tunneling interface?

    • @JeanPierTalbot
      @JeanPierTalbot  9 หลายเดือนก่อน

      There is already a video on tunnel interface vpn :-)

  • @ocbroadband
    @ocbroadband 10 หลายเดือนก่อน

    HI Jean, I got this working between a TZ370 and a Omada ER7206(TP-Link). Only 2 subnets I'm working with on each side just like your video. The VPN comes up just fine, and for now, I have it autogenerating the rules, but I can only connect to very specific things on the TZ370 side from the Omada side. Thus far, I can VNC into a device behind the TZ370, but I can't ping it and I can't access for example any web accessible devices. I'm not sure why its limiting that, but not vnc.. Thoughts?

    • @JeanPierTalbot
      @JeanPierTalbot  10 หลายเดือนก่อน

      Try turning logs on the auto generated policies and see if you see trafic from the tp-link. If you don’t, then you know what’s the issue :-)

  • @SterpDawg-cy7zf
    @SterpDawg-cy7zf 5 หลายเดือนก่อน +1

    My sonicwall isn't getting an IP address on the system -interfaces screen when you connect it to the Internet. Literally doing everything you're doing but it's not working. Can anyone help me?

  • @lowellabraham6966
    @lowellabraham6966 ปีที่แล้ว

    Hi Jean-Pier, would you be able to do a video on VPN to AWS?

    • @JeanPierTalbot
      @JeanPierTalbot  ปีที่แล้ว

      Hum. Good topic! I’ll add it to my list. Thanks.
      If you want an easy way to do it, deploy a sonicwall firewall in AWS. It’s called a NSv. Then do a vpn between the NSv in AWS and your sonicwall firewall at the office. UI of NSv and tz/NSa are pretty much identical

  • @farooqdidar5731
    @farooqdidar5731 ปีที่แล้ว

    Hi Sir
    Quick question: what are the differences among all the gen firewalls.
    For example:
    How gen 6 differ from gen 7.
    Thanks

    • @JeanPierTalbot
      @JeanPierTalbot  ปีที่แล้ว

      Here is a good list.
      blog.sonicwall.com/en-us/2022/10/10-reasons-to-upgrade-to-the-latest-sonicwall-gen-7-tz-firewall/

  • @networkrealm15
    @networkrealm15 6 หลายเดือนก่อน

    We are creating tunnel between sonicwall and azure. Tunnel is up and working fine but after sometime it get down automatically for like 40sec and come up. I have also enabled Windows Networking (NetBIOS) Broadcast along with keep alive. Please advise on this?

    • @JeanPierTalbot
      @JeanPierTalbot  6 หลายเดือนก่อน

      Rule of thumb, if a vpn goes up, it means your encryption, authentication and stuff is good.
      If it goes down after a period of time (like 8 hours) and you bring it back up and it stops again after 8 hours, it generally because you have some mismatch in timeouts/reKey/life time in your vpn. Like one side can have a life time of 8 hours and the other side a lifetime of 12 hours. So vpn drops after 8 hours.
      There are a couple spots in a vpn that includes time variables.
      Always easier to do it with a sonicwall virtual firewall in azure because you can put both firewall side by side and compare settings.
      Hope that helps!

    • @networkrealm15
      @networkrealm15 6 หลายเดือนก่อน

      @@JeanPierTalbot VPN is showing up but after every 15min I am not able to ping remote azure subnet for 40sec and after that started pinging. I hope enabling netbios is not a problem.

  • @peterknight93
    @peterknight93 ปีที่แล้ว

    Great Videos, Thanks. QQ How would I setup site to site if the networks overlap the same subnet? Apply NAT policy Examples would be great.

    • @JeanPierTalbot
      @JeanPierTalbot  ปีที่แล้ว +1

      Thanks Peter for your feedback.
      Solution is to change subnet on one end. :-)
      If that’s not an option, you will need to do 1 to 1 NAT in your vpn

  • @jerrymoletto7301
    @jerrymoletto7301 2 หลายเดือนก่อน

    Jean-Pier I have a question. I have a client that has older SOHO firewall running a firmware of 6.5. Can I connect a TZ270w at a remote site that runs firmware 7.0 and still make a site to site VPN. Or do they both have to have same firmware. Please let me know

    • @JeanPierTalbot
      @JeanPierTalbot  2 หลายเดือนก่อน

      You can. It will work

  • @raygaviria
    @raygaviria ปีที่แล้ว

    hi, i like this videio, can you tell somethings experiencies conecting vpn s2s with other utm´s company for example fortige, tks

    • @JeanPierTalbot
      @JeanPierTalbot  ปีที่แล้ว

      Currently editing a video where I did a vpn between sonicwall and Watchguard. Should be available in a week or 2

  • @justinrhode7448
    @justinrhode7448 11 หลายเดือนก่อน

    Hey Jean, Is there a way to have a vpn between two sites and both sites have the same LAN subnet?

    • @JeanPierTalbot
      @JeanPierTalbot  11 หลายเดือนก่อน

      Yes, but it brings its share of complexity that you will be dragging forever. You have to do NAT in your vpn creating 2 fake subnets. That might create challenges if you try to get 2 AD to talk. Or DNS might be a challenge as DNS should not resolve to the true IP of a device on the other site…
      My opinion: change subnet on one site.
      Otherwise here is how to do NAT in a vpn. It’s easy, but then you may face challenges with DNS and other stuff that won’t like the change of IP. Certificate comes into mind as a potential issue.
      www.sonicwall.com/support/knowledge-base/how-can-i-configure-nat-over-vpn-in-a-site-to-site-vpn/170515155805172/

    • @justinrhode7448
      @justinrhode7448 11 หลายเดือนก่อน

      @@JeanPierTalbot Thank you so much.

  • @davilajeremy
    @davilajeremy ปีที่แล้ว

    Is there a link to get the sonicwall tshirt?

    • @JeanPierTalbot
      @JeanPierTalbot  ปีที่แล้ว +1

      That’s an employee privilege:-)

    • @davilajeremy
      @davilajeremy ปีที่แล้ว

      @@JeanPierTalbot understand that. Thanks for the reply

  • @arvindshinde12345
    @arvindshinde12345 9 หลายเดือนก่อน

    Behind Sonicwall PC can't access from B Site VPN pc

    • @JeanPierTalbot
      @JeanPierTalbot  8 หลายเดือนก่อน

      Mostly a windows firewall issue :-)
      Try ping on a printer or a switch (encore they have the firewall as default gateway)