We outsource to this company in India. For the longest they were using our SSLVPN
In November they started having issues that they could not connect. All of my other users in the US have no issues connecting.
Last week I changed the name of the http management cert to something else and it allowed them to connect for the entire week. This morning they cannot connect. I changed the name of the cert again and nothing.
Any ideas?
@joan-sonicwall
3 Spice ups
dbeato
(dbeato)
2
What is their OS they are using? What client are they using? If they are using Windows 10 they should use the Sonicwall Mobile Connect App from the AppStore to connect.
They are using windows 7 32 bit. I’ve tried version 7 of the netextender and version 8. Both get the same result
Neally
(Neally)
4
Win 10 does not like NetExtender. Other than that you provided limited information really to go of.
Are there any log entries? Do they get any errors on their site? Can they telnet? ISP issues?
Does it work form other locations in india? Or other areas in general?
While they can’t connect, can others still connect?
1 Spice up
dbeato
(dbeato)
5
Did you test the same on a Windows 7 computer on your control?
Yes I have tested on multiple locations. I have users all over the US that connect fine.
dbeato
(dbeato)
7
What is different on their connections? Do you have their IP connections white listed on your Sonicwall?
Your issue maybe linked to the SSL cert you are using on the sonicwall for the sslvpn.
Is it the self signed default cert that you are using ??
Check if the cert is a SHA 1.
If it is then regenerate a new cert which should be sha2/256.
After all the tweeting. I changed the port the net extender used and it connected on the first try. I guess I will see if it continues to work
dbeato
(dbeato)
10
So probably they cannot access the previous external port of your Sonicwall Nextender through their firewall .
That’s my best guess. I do find it strange that it would work some times and not. I saw people connected at 3 am so I guess all is well
1 Spice up
epoch70
(epoch70)
12
Could they have a local firewall that does packet inspection? Maybe it’s garbling the packets.