How to configure SonicWall SD-WAN

  Рет қаралды 19,668

Jean-Pier Talbot

Jean-Pier Talbot

Күн бұрын

Пікірлер: 52
@tebogosekgobela3974
@tebogosekgobela3974 3 жыл бұрын
Next time please draft network diagram for more clarify. (for newbies) Your content is 100% professional and educational
@randylane1568
@randylane1568 2 жыл бұрын
Another great one JP! All my questions answered! Would you happen to have a video on Sonicwall logs,? Understanding, configuring, and using to troubleshoot? I find them very confusing. I know there is an admin guide. Confusing as well. Thanks!
@timsexton
@timsexton 2 жыл бұрын
Jean-Pier, thanks for the tips.
@muzaffermir2421
@muzaffermir2421 2 жыл бұрын
Hii Jean ....I Loved your videoso so so so much i am working in sonicwall from few months and i have learnt 100 times more from this video than i had learnt in last couple of months ..I have a request ..please make more videos on SDWAN 2.0 features .....How to send and check FTP traffic ...Also please mention difference between numbered and unmumbered tunnels and whats the difference between two............. Thanks In Advance.....
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
Thanks! Yes I do plan on keep doing videos! Fun fact, I didn’t know the difference between numbered and unnumbered tunnel interface when I did the video. I only knew one way of doing them… Yes one day I’ll do a video on those 2 tunnel interface vpn
@pointclick3428
@pointclick3428 2 жыл бұрын
Thank you for the videos! How does SDWAN work with Load Balancing (or should they not be used together)? Is Failover/load balancing the default and sdwan takes over when rules are tripped? I am looking for best practices for WAN connections.
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
Hum, good one. What are you trying to achieve? I’m trying to find a use case fit it
@Stephen-wh7vl
@Stephen-wh7vl 9 ай бұрын
Should I abandon lb/fail over groups in favor of sd wan for my two wan connection ?
@bindupriya870
@bindupriya870 Жыл бұрын
Intresting. Thank you.
@hernam03
@hernam03 3 жыл бұрын
AT 10:49 of the video why are my links not coming up at this point?
@KT-hx2ul
@KT-hx2ul Жыл бұрын
Started with Failover for two WAN connections. Since adding SD-WAN between branches, should Failover be disabled and an SD-WAN profile and route be created instead for LAN to WAN internet access to switch to the secondary in case the primary fails? What happens to SD-WAN traffic when the primary WAN fails and the Sonciwall switches to the failover interface?
@JeanPierTalbot
@JeanPierTalbot Жыл бұрын
Hum. Good one. Are you using SDWAN for ALL traffic going to the wan? In the video I use it only for office 365 (or maybe just teams, I don’t recall) in that case, SDWAN only applied to office 365. So I would keep the failover setting for everything else.
@KT-hx2ul
@KT-hx2ul Жыл бұрын
@@JeanPierTalbot Thanks for the reply. Not using SDWAN for all LAN to WAN traffic, just one cloud app like your example. Question is, does Fail Over conflict with SDWAN? I am wondering if both should be used together or if SDWAN should replace Failover.
@JeanPierTalbot
@JeanPierTalbot Жыл бұрын
@@KT-hx2ul I dont see SDWAN replacing the global failover setting. SDWAN will kickin for the specific stuff you have set and everything else will fall under the basic failover.
@HerikSilva_tech
@HerikSilva_tech Жыл бұрын
Hi Jean! Whats the difference betwen Site to Site vpn and tunnel interface?
@JeanPierTalbot
@JeanPierTalbot Жыл бұрын
They are pretty much the same. Both are a site to site vpn using same encryption. Tunnel interface, as the name states, the vpn is an interface. Giving you more flexibility in regards of static/dynamic routing and SDWAN. Where standard vpn can’t participate in those.
@pipi_delina
@pipi_delina 2 жыл бұрын
Hello Jean.. Can you make a video on CLI operation
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
Yeah, I could. Eventually. Working on a few videos now: capture atp and wireless
@pipi_delina
@pipi_delina 2 жыл бұрын
@@JeanPierTalbot great
@LucasSilva-et1su
@LucasSilva-et1su 2 жыл бұрын
is it possible to create ipsec tunnel on sd-wan to fortigate on the other end ? I am facing a problem where the automatic prob goes up but gets 100% packet loss, outside the SD-WAN the tunnel is up
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
Never tried it. I usually remove the fortinet in my day to day job :-) Not sure it will work. You need to create 2 or more tunnel interface VPN. Not sure how/if you can do that on fortinet. If you can get the fortinet to build tunnel interface vpns, then you can get SDWAN to route traffic on those vpn interfaces.
@michaelperugini4199
@michaelperugini4199 3 жыл бұрын
can you have IPsec VPN (site to site) and tunnel route VPN at the same time? or will this cause issues and take down the IPsec site to site that is using the same IPs? or cause route loop issues?
@kenvivo
@kenvivo Жыл бұрын
Hi, learned a lot from this video! When I read about SDWAN, it always mentions simple deployment and centralized management. If you have 10 sites and you have to create all these policies on each site, how do you automate this so it's centrally managed? Is it possible to have one location to create policies and it gets pushed to all the other Sonicwalls?
@JeanPierTalbot
@JeanPierTalbot Жыл бұрын
Thanks Ken! Glad you learned a lot with my videos! Yes NSM has a SDWAN thing to do what you want. To be honest, I never tried it. It would require me multiple firewall each having multiple ISP. That would be a pretty big/cable messy lab :-)
@kenvivo
@kenvivo Жыл бұрын
@@JeanPierTalbot thank you for taking time to reply! I'll look into NSM!
@Defhinitely
@Defhinitely 2 жыл бұрын
Is it possible to create an SD-WAN with a public IP from site A and a router IP from site B?
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
I’m not fully sure what you are trying to achieve, but if you want SDWAN to check which internet line is the best to reach an external ip, it can be done. It will be similaire to the portion I did on teams.
@atultyagi888
@atultyagi888 2 жыл бұрын
Thanks for your content I want to ask that what is the process for configuring route based vpn for multiple sites (more than two ).
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
It’s the same process, a second time for a second site
@NuwanRanawaka
@NuwanRanawaka 3 жыл бұрын
Hi Jean How to connect two sites with overlapping networks , eg: Xo & x2 networks are same on both firewalls thx
@JeanPierTalbot
@JeanPierTalbot 3 жыл бұрын
Best would be to change subnet so they don’t overlap anymore. Otherwise you can do 1 to 1 NAT in your tunnel So if the subset is 192.168.1.0 on both side, you will kind of have a fake subnet in the VPN. So when you ping 10.10.10.123, it will be NATed to 192.168.1.123
@Rajsingh-xv8vj
@Rajsingh-xv8vj Жыл бұрын
Sir Can we configure the Split tunnel in sonicwall NSa4650. scenario is site to site vpn is confgured (with nat of lan subnet. Bcoz Lan subnet both side are same. like (site a x.x.0.0/16 and site x.x.0.0/16 ) so why we have nat these subnet. now when server need to internet, server is not able to access the internet. we have some server for patch or software updation needed.
@JeanPierTalbot
@JeanPierTalbot Жыл бұрын
Hi Raj! You definitely can do split tunnel on site to site vpn. If you edit you vpn, under network menu you will see what networks are connected. If I had to take a guess, I would bet the issue is your NAT and that it also takes traffic that destination is the WAN into your site to site vpn NAT rule. Ensure no objects contains 0.0.0.0. (That’s for tunnel all) That’s something you can call support about. They are amazing. Wait time is pretty much always less than 5 minutes.
@dansanchez1264
@dansanchez1264 3 жыл бұрын
Hi Sir Jean, Good Day. I just want to say thank you for all of your vides regarding SonicWall since a new guy here. May I also know if SonicWall has an ISO image where i can use it in virtual box or vmware for training purposes? Thank you so muchhhh Sir
@JeanPierTalbot
@JeanPierTalbot 3 жыл бұрын
Thanks for the feedback. Yes you can download a 30 days trial if the virtual firewall for hyper-V or ESXi
@theshark84724
@theshark84724 3 жыл бұрын
Man, I wish I had his hair. NOICE
@JeanPierTalbot
@JeanPierTalbot 3 жыл бұрын
LOL give me your address, I’ll ship you a few
@vishalG-q2v
@vishalG-q2v 10 ай бұрын
Can we do SDWan for the P2P links?
@JeanPierTalbot
@JeanPierTalbot 10 ай бұрын
Yes, that’s what I do in this vifeo
@cavj1111
@cavj1111 2 жыл бұрын
Do you have to use Route based VPN's for SD-WAN or can you use your existing IPSEC tunnels?
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
it's not something I have tested. but I believe SDWAN will not work with standard VPN. SDWAN needs 2 or more routes to get to the same destination. I believe you cannot do 2 standard VPN going to the same place. so that might require to switch to tunnel interface.
@cavj1111
@cavj1111 2 жыл бұрын
@@JeanPierTalbot okay. Thank you. I'll have to figure out what that change entails
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
@@cavj1111 backup the config on both firewall, delete the standard VPN and create a tunnel interface VPN. if that does not work and you are out of time, restore the configs you saved...
@laquil23
@laquil23 2 жыл бұрын
i like your videos, but i have a small problem maybe you can help, i have two sites with two sonicwall both connecting to the isp on x1 and i have a wireless link between the two sonic wall on x4 how can i make a failover of the internet when it is down passing the traffic over the wireless link to get the internet from the other site
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
You would need to create 2 vlans in your wireless link. One for each wan to bring isp1 to site 2 and isp2 to site one. Then create isp1 vlan as wan on firewall 2 and isp2 on vlan as a wan on firewall1
@michaelperugini4199
@michaelperugini4199 3 жыл бұрын
I also see that there is a limitation only 1 SDWAN can be created.. if you create one for ZOOM (using both intefaces) you cannot build another SD-WAN say for exchange, the Interfaces are no longer available as they are now only used by zoom. which we use very little so i will be removing zoom . Is there no way to build multiple SD-WANS? if not then this probably answers my question below, as a IPSEC replacement because do have multiple IPsec VPNs
@JeanPierTalbot
@JeanPierTalbot 3 жыл бұрын
You can have interfaces only in one SD-WAN group, yes. But you CAN create multiple SD-WAN policies using the same group of Sdwan interfaces.
@michaelperugini4199
@michaelperugini4199 3 жыл бұрын
@@JeanPierTalbot but trying to build a site to site networks sdwan will not replace ipsec site to site. When you need all 5 offices talking to one another
@johnoliverpenaflor4962
@johnoliverpenaflor4962 2 жыл бұрын
Hi Jean, can I configure route based VPN in SDWAN without having a static or public IP's. thanks and more power!
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
Yes you can do VPNs with dynamic ip. I have seen many setup where the remote location has a dynamic IP and the head office has a static. It works great if it’s the remote location users that needs to access ressources in the head office. So the firewall with the dynamic ip is the one initiating a vpn to the fix it. And yes you can add SDWAN on top
@lancesoller5088
@lancesoller5088 3 жыл бұрын
How can I contact you?
@JeanPierTalbot
@JeanPierTalbot 3 жыл бұрын
Email is visible on my monitor at the very beginning of the video.
How to configure SonicWall High Availability
1:02:56
Jean-Pier Talbot
Рет қаралды 23 М.
How to configure SonicWall Content Filtering Service (CFS)
1:07:35
Jean-Pier Talbot
Рет қаралды 32 М.
Every team from the Bracket Buster! Who ya got? 😏
0:53
FailArmy Shorts
Рет қаралды 13 МЛН
Andro, ELMAN, TONI, MONA - Зари (Official Music Video)
2:50
RAAVA MUSIC
Рет қаралды 2 МЛН
Маусымашар-2023 / Гала-концерт / АТУ қоштасу
1:27:35
Jaidarman OFFICIAL / JCI
Рет қаралды 390 М.
How to configure SonicWall Intrusion Prevention Service (IPS)
11:38
Jean-Pier Talbot
Рет қаралды 10 М.
SonicWall basic configuration step by step (part 1)
31:27
Jean-Pier Talbot
Рет қаралды 161 М.
SDWAN Failover and Bandwidth Aggregation Explained
15:58
Lawrence Systems
Рет қаралды 39 М.
Generate SIP Voice Packets in EVE-NG (and More) with Ostinato
14:15
FortiGate IPsec ADVPN with SDWAN and  Dual ISPs
25:49
Verifine Academy
Рет қаралды 35 М.
How to configure SonicWall DPI-SSL
25:10
Jean-Pier Talbot
Рет қаралды 17 М.
How to configure SD-WAN in FortiGate Firewall
15:48
IgoroTech Official
Рет қаралды 34 М.
How to configure Tunnel Interface VPN (Route-Based VPN)
32:26
Jean-Pier Talbot
Рет қаралды 18 М.
JP's 4 basic security tips and tricks for your firewall
13:07
Jean-Pier Talbot
Рет қаралды 12 М.
Every team from the Bracket Buster! Who ya got? 😏
0:53
FailArmy Shorts
Рет қаралды 13 МЛН