|
#1
|
||||
|
||||
|
I've got an interesting issue I need some help with. I'm sure I am missing something simple. Here is the situation. I have a client with a Sonicwall TZ100. We've opened ports for their exchange server, rdp, etc. and those work just fine. Recently they got a new security camera system with a networked DVR. I went through the same procedure that I did for the other port forwards, but the ports still show as closed and you cannot access the system from the outside. Inside the network there are, of course, no issues.
Here is what I have done to troubleshoot:
I'm at a loss as to what it could be. All the other port forwards show as open and work just fine. Any ideas? |
|
#2
|
||||
|
||||
|
You say it's blocked outside the company, is it possible the ISP is blocking the ports you are trying to use?
|
|
#3
|
||||
|
||||
|
I checked with the ISP, and they say no. One thing that I will add is that there is nothing other than a couple of switches (unmanaged) between the computers and the Sonicwall.
|
|
#4
|
||||
|
||||
|
Are all the other ports going to your server?
Did you create a reflective rule? Do you more then 1 static IP? |
|
#5
|
|||
|
|
|||
|
try setting up another service on that port that goes back to another machine and see if it works. If you can get back through there's probably a problem with the device.
There's a few devices like that which only allows connections via the local subnet unless you subscribe to a service. Check the device out and see if there's a setting that controls what subnets can connect to the device.
__________________
"..You are not brought upon this world to get it!" ~ David Lo Pan |
|
#6
|
||||
|
||||
|
Thanks for the suggestions, guys. I'll have to create a rule to another device this weekend.
To answer krtech's questions: I've created a reflective rule, the other ports are going to three different servers on site and they are working, and the client only has the one static IP. |
|
#7
|
||||
|
||||
|
Make sure your wan to LAN firewall rule has your wan ip as your destination not the LAN address
|
|
#8
|
||||
|
||||
|
It sure does. I double checked, but it has that and looks to be the exact same as the other rules. According to the security DVR vendor, they checked their equipment and it is functioning.
|
|
#9
|
|||
|
|||
|
Are both TCP and UDP services configured? Not sure about the DVR vendor, but you normally have to specify either/or in the sonicwall, thus having to create both custom services if both are necessary. Even if they aren't necessary, its worth testing.
|
|
#10
|
|||
|
|||
|
Most Sonicwalls that I have worked on have a wizard for doing this under a wizards button. Does your have something similar?
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|