cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2162
Views
10
Helpful
18
Replies
ChrisLuberto
Beginner

Cisco C3650 OSPF with Sonicwall Firewall

I'm in the process of replacing a Sonicwall 2400 with a Sonicwall 2650.  The configuration easily copies over however, when I plug the LAN port (192.168.50.1) of the Sonicwall into the same Cisco interface that the old firewall plugged into,  traffic is not routed to Sonicwalll.  

 

OSPF populates the routes on the new fire wall, I've cleared the ARP table on the layer 3 switch (the MAC address for the new firewall is correct), and 'show ip ospf neighbor' shows the new firewall as a neighbor.  The 'Gateway of last resort' changes to a secondary internet connection when it should remain the same.

 

When I plug the old firewall back in, the 'gateway of last resort' changes back to the primary (192.168.50.1) and traffic routes through the firewall as it should.  The configuration on the firewalls are identical.  Sonicwall tech support was not able to provide a solution.  What am I missing on the Cisco switch side? 

18 REPLIES 18

Great point.  I am using the FWs default WAN interface, X1.  The zone is also applied correctly.  I'm contacting Sonicwall via an existing ticket to see if they can shed light on way the WAN interface is showing as DOWN when it is actually UP.

 

I'll update you when I have more information.

Chris

 

Please do update us as you make progress with this issue.

 

HTH

 

Rick

HTH

Rick

Solution:  The Sonicwall NSA 2650 is configured for OSPF on X0.  The settings for OSPF (Network > Routing> *Gear Icon*) was set to "When WAN is up" under 'Originate Default Route'.  The NSA 2650 has a known issue that X0 was not broadcasting to OSPF to the router because it never saw the WAN as "up".  Sonicwall provided a hotfix and it is now working correctly.

 

Workaround before hotfix: I set 'Originate Default Route' to "Always"

Chris

 

This has been a long and interesting discussion. Thanks for updating us and letting us know that it is now solved and that the issue was something on the Sonicwall. Glad that you now do have things operating as expected.

 

HTH

 

Rick

HTH

Rick