Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [SOLVED] Solution to SonicWall VPN Client Behind pfsense [Now Up To $200]

    Scheduled Pinned Locked Moved Completed Bounties
    26 Posts 5 Posters 85.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      Eugene
      last edited by

      I managed to fix my SonicWall client by doing the following.
      On my XP PC (where SonicWall client is installed) I went to Registry [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
      Interfaces[Adapter ID]] found the virtual adapter installed by SW installation, changed MTU from 1300 to 1500. Then you have to run SW install again, it "repairs" its own installation and only after this "repaie" segmentation disappears as disappears the problem. On pfSense you have to allow only UDP:500, leave 'scrub' off.

      Resume: although the problem at pfSense exists you can avoid it by adjusting MTU on client (as jimp fairly mentioned).

      http://ru.doc.pfsense.org

      1 Reply Last reply Reply Quote 0
      • M
        mayesjc
        last edited by

        Done!  Thank you to everyone for their patient help.  I just paid my $200 (Confirmation No. 3HS208994B4607915), and it was well worth it.

        What I did was to ensure that scrub was disabled (it was).  I also chose Manual Outbound NAT rule generation (Advanced Outbound NAT (AON)), setting up rules for ports 50, 500, and 4500, which I understand from other sources are used by the SonicWall client.  Of course, I still have the inbound and outbound firewall rules allowing traffic to and from the VPN server's ip address.  Even at that point, the client would not connect.  The final step, which allowed the connection, was to enter 1500 in the MTU field on the WAN interface. (It is a bit fuzzy, but I first set the MTU to 1300.  The software firewall on the XP client then asked me to approve the outbound connection of the SonicWall Client.  That had never happened before.  I clicked OK to allow the connection, but still had no connection.  It was not until I entered 1500 into the MTU that the connection succeeded.)

        I made no changes on the XP client, although NAT Traversal is Forced On.

        Thanks again.

        1 Reply Last reply Reply Quote 0
        • E
          eri--
          last edited by

          I didn't get any part of the money :P

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            @ermal:

            I didn't get any part of the money :P

            He must have just made a project donation, and not a payment to any one person.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • M
              mayesjc
              last edited by

              I paid the bounty as a project donation, which is what I though I was supposed to do.  Indeed, I was told specifically to do that on another bounty.  I am very sorry for the misunderstanding and will be sure to clarify that point next time.  It is a great project, and I was happy to help financially.

              As a practical matter, how else would it get paid when so many people contributed to the eventual solution?

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                @mayesjc:

                I paid the bounty as a project donation, which is what I though I was supposed to do.  Indeed, I was told specifically to do that on another bounty.  I am very sorry for the misunderstanding and will be sure to clarify that point next time.  It is a great project, and I was happy to help financially.

                As a practical matter, how else would it get paid when so many people contributed to the eventual solution?

                That is, as I understand it, how things have been done lately as an "escrow" sort of deal and then cmb or someone else with access to that can distribute it.

                As to who gets what, that is up to you, depending on however you see fit to allocate. :-)

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.