Dell SonicWALL Global VPN Client 4.9.4

Similar documents
Release Notes. Contents. Release Purpose. Pre-Installation Recommendations. Platform Compatibility. Dell SonicWALL Global VPN Client 4.

Release Notes. Pre-Installation Recommendations... 1 Platform Compatibility... 1 Known Issues... 2 Resolved Issues... 2 Troubleshooting...

Contents. Pre-Installation Recommendations. Platform Compatibility. G lobal VPN Client SonicWALL Global VPN Client for 64-Bit Clients

SonicWALL strongly recommends you follow these steps before installing Global VPN Client (GVC) 4.0.0:

Dell Statistica Statistica Enterprise Installation Instructions

Dell Spotlight on Active Directory Server Health Wizard Configuration Guide

Dell Statistica Document Management System (SDMS) Installation Instructions

Spotlight Management Pack for SCOM

Spotlight Management Pack for SCOM

Dell Recovery Manager for Active Directory 8.6. Quick Start Guide

formerly Help Desk Authority Upgrade Guide

Dell InTrust Preparing for Auditing Cisco PIX Firewall

Dell Statistica. Statistica Document Management System (SDMS) Requirements

Security Analytics Engine 1.0. Help Desk User Guide

Dell One Identity Cloud Access Manager How To Deploy Cloud Access Manager in a Virtual Private Cloud

Dell One Identity Cloud Access Manager How to Configure vworkspace Integration

Dell Unified Communications Command Suite - Diagnostics 8.0. Data Recorder User Guide

Dell One Identity Cloud Access Manager Installation Guide

Dell One Identity Cloud Access Manager How to Configure for SSO to SAP NetWeaver using SAML 2.0

New Features and Enhancements

Dell One Identity Cloud Access Manager How to Configure for High Availability

About Recovery Manager for Active

Dell InTrust Preparing for Auditing and Monitoring Microsoft IIS

Configuring SonicOS for Microsoft Azure

Dell InTrust Preparing for Auditing Microsoft SQL Server

Dell One Identity Cloud Access Manager How to Configure Microsoft Office 365

Global VPN Client Getting Started Guide

Dell NetVault Backup Plug-in for SQL Server 6.1

About Dell SonicWALL Analyzer 8.1

Security Explorer 9.5. About Security Explorer 9.5. New features. June 2014

Dell NetVault Backup Plug-in for SQL Server

Dell InTrust Preparing for Auditing CheckPoint Firewall

Dell NetVault Backup Plug-in for Advanced Encryption 2.2. User s Guide

Dell Spotlight on Active Directory Deployment Guide

Dell Migration Manager for Enterprise Social What Can and Cannot Be Migrated

Dell One Identity Cloud Access Manager SonicWALL Integration Overview

formerly Help Desk Authority HDAccess Administrator Guide

Dell Recovery Manager for Active Directory 8.6.0

Security Explorer 9.5. User Guide

Dell Enterprise Reporter 2.5. Configuration Manager User Guide

Dell One Identity Manager 7.0. Help Desk Module Administration Guide

Dell SonicWALL Directory Services Connector

Dell InTrust 11.0 Best Practices Report Pack

formerly Help Desk Authority Quest Free Network Tools User Manual

Enterprise Reporter Report Library

Introduction to Version Control in

Dell Recovery Manager for Active Directory 8.6.3

Dell Client Profile Updating Utility 5.5.6

FOR WINDOWS FILE SERVERS

ChangeAuditor 5.6. For Windows File Servers Event Reference Guide

Dell SonicWALL Aventail Connect Tunnel User Guide

4.0. Offline Folder Wizard. User Guide

Foglight Cartridge for Active Directory Installation Guide

Global VPN Client Getting Started Guide

Dell One Identity Quick Connect for Cloud Services 3.6.1

Quest ChangeAuditor 5.1 FOR ACTIVE DIRECTORY. User Guide

Spotlight on Messaging. Evaluator s Guide

ChangeAuditor 6.0 For Windows File Servers. Event Reference Guide

Troubleshooting Guide 5.1. Quest Workspace ChangeBASE

Dell NetVault Backup Plug-in for SharePoint 1.3. User s Guide

Dell One Identity Quick Connect for Cloud Services 3.6.0

Defender 5.7. Remote Access User Guide

Using Self Certified SSL Certificates. Paul Fisher. Quest Software. Systems Consultant. Desktop Virtualisation Group

TechNote. Configuring SonicOS for MS Windows Azure

Dell Migration Manager for Exchange Product Overview

Quest SQL Optimizer 6.5. for SQL Server. Installation Guide

Dell Directory Analyzer Installation Guide

About Dell Statistica

Dell Recovery Manager for Active Directory 8.6. Deployment Guide

VPN Configuration Guide SonicWALL with SonicWALL Simple Client Provisioning

How to Deploy Models using Statistica SVB Nodes

New features. June Complete Product Name with Trademarks Version

CA VPN Client. User Guide for Windows

Defender Delegated Administration. User Guide

Dell MessageStats for Lync and the MessageStats Report Pack for Lync & OCS 7.3. User Guide

Object Level Authentication

Global VPN Client Getting Started Guide

Dell One Identity Cloud Access Manager How to Develop OpenID Connect Apps

Web Portal Installation Guide 5.0

Dell NetVault Backup Plug-in for Hyper-V User s Guide

Intel Unite Solution. Standalone User Guide

Quick Connect Express for Active Directory

Quest ChangeAuditor 4.8

How To Use The Dll Sonicwall Global Vpn Client On A Pc Or Mac Or Ipsec Vpn On A Network With A Network Connection (Vpn) On A Laptop Or Ipse On A Ipsec Ipsec 2.5V

Dell Security Explorer 9.6

formerly Help Desk Authority HDAccess User Manual

VPN Configuration Guide SonicWALL with SonicWALL Simple Client Provisioning

Foglight Managing Microsoft Active Directory Installation Guide

Creating a Gateway to Client VPN between Sidewinder G2 and a Mac OS X Client

2.0. Quick Start Guide

Intel Active Management Technology with System Defense Feature Quick Start Guide

Dell InTrust Auditing and Monitoring Microsoft Windows

Global VPN Client 4.1 Administrator's Guide

Getting Started Guide

8.7. Resource Kit User Guide

Foglight. Dashboard Support Guide

Foglight. Foglight for Virtualization, Free Edition Installation and Configuration Guide

Quest vworkspace Virtual Desktop Extensions for Linux

Foglight Experience Monitor and Foglight Experience Viewer

Transcription:

Complete Product Name with Trademarks Version Dell SonicWALL Global VPN Client 4.9.4 Release notes August 2015 These release notes provide information about the Dell SonicWALL release. About Pre-installation recommendations Platform compatibility Known issues Troubleshooting Technical support resources About Dell About Dell SonicWALL supports 5 languages: English Simplified Chinese Japanese Korean Brazilian Portuguese Global VPN Client determines the default language based on the language setting in the client computer. Pre-installation recommendations Dell SonicWALL strongly recommends you follow these steps before installing the Global VPN Client (GVC) 4.9.4 client: If you have Dell SonicWALL Global VPN Client version 4.8.6 or earlier installed, you must uninstall that version before installing version 4.9.4. Upgrading to GVC 4.9.4 is supported from version 4.9.0. Dell SonicWALL GVC encounters run time conflicts when it co-exists with any 3 rd party IPsec VPN clients. Uninstall all IPsec VPN clients prior to installing Dell SonicWALL GVC. 1

For Vista systems, it is required that you update device drivers for each Network Adapter card to the latest available versions. You can check the NIC vendor Web site for these updates. NOTE: The Global VPN Client is launched as soon as the installation completes. The Start SonicWALL Global VPN client every time I login option can no longer be set during installation, but this option is available on the General tab in the View > Options page of the client. Platform compatibility Dell SonicWALL GVC 4.9.4 supports both 32-bit and 64-bit client machines. Supported Windows clients The following versions of Microsoft Windows are supported by Dell SonicWALL GVC 4.9.4: Windows 10 Windows 8.1 Windows 8.0 Windows 7 Windows Vista NOTE: The following operating systems and platforms are not supported: ARM based devices, including the ARM based Surface tablet The Preview version of the Windows 8.1 Tablet OS Windows XP, Windows 2000, Windows NT 4.0, Windows ME, Windows 98, or Windows 95 Supported SonicOS firmware The Dell SonicWALL GVC 4.9.4 release is compatible with the following firmware releases: SonicOS Enhanced 2.0.0.2 and above SonicOS Standard 2.0.0.2 and above Supported SonicOS appliances The Dell SonicWALL GVC 4.9.4 release supports the following Dell SonicWALL appliance platforms: SuperMassive 9000 series SuperMassive E10000 series NSA E-Class series NSA series TZ series 2

Known issues The following is a known issue in the Dell SonicWALL GVC 4.9.4 release. Known issue The SHA256 and AES-XCBC authentication modes are not supported by Global VPN Client. Occurs when SHA256 or AES-XCBC is selected on the Dell SonicWALL appliance as the authentication mode. Issue ID 125750 3

Troubleshooting This section describes troubleshooting procedures for Global VPN Client. Trouble shooting process for GVC Numbers in the boxes refer to the applicable process. For example, the box numbered 1 refers to Process 1. 4

NOTE: If you need to debug run time problems after a successful Dell SonicWALL GVC install, refer to the GVC logs to detect the error condition(s). Some problems may also require information from the firewall logs. Reporting GVC run time problems to technical support requires that you submit GVC and/or Firewall logs for analysis. Detailed troubleshooting processes are explained for the following issues: Process 1: Debug install issue Process 2: Post-install errors Process 3: TCP applications on Vista are slow Process 4: Cannot access certain destination networks Process 5: Cannot browse the Internet after GVC connection is enabled and connected Process 6: Peer is not responding to ISAKMP requests from GVC; Check GVC logs to verify Process 7: Stuck on authenticating when GVC connection is enabled Process 8: Failed to obtain DHCP lease for the Virtual Adapter Process 9: Not getting a prompt to enter a PreShared Key (PSK) Process 10: Not getting a prompt to enter XAUTH Credentials Process 1: Debug install issue NOTE: If Dell SonicWALL GVC was an upgrade install, then first uninstall GVC, reboot your computer and then run setup again. If you encounter an error, follow the troubleshooting instructions: 1 Blue Screen during Install Process If you get a blue screen after the upgrade to GVC 4.9.4, provide the following file %SystemRoot%\Minidump.dmp (%SystemRoot% is usually C:\Windows) to Tech support to troubleshoot further. For someone who can reproduce the symptom, choosing 'Kernel memory dump' could be of even more help as it should have more information. To get detailed memory dump need to set the following; a b Start > Computer, right-click on Computer and select Properties. Choose Advanced System Settings and then choose Settings under Startup and Recovery. The settings are under the System Failure section. The dump file by default is written to the %SystemRoot%\MEMORY.DMP file. 2 Global VPN Client install fails due to the following error This error could happen in the following cases: Installing Dell SonicWALL GVC without a reboot after GVC uninstall. Hard reset during the install operation. Dell SonicWALL GVC install is an upgrade from an earlier GVC Beta version. 5

Reboot your computer and then run setup again. If it still results in the same error, then do the following: a b c d Right-click on the Command Prompt icon and select Run as Administrator. Change directory to %SystemRoot%\system32\drivers (%SystemRoot% is C:\Windows). Type net stop SWIPsec.sys. You may see either success or failure returned. Rename SWIPsec.sys to SWIPsec.sys.bak (if SWIPsec.sys exists in this directory). Now run setup again and install Dell SonicWALL GVC. 3 GVC Install is stuck while installing the SonicWALL Virtual Adapter You may have to do a hard reset if the installation is stuck during the install of the Virtual Adapter. After power up, uninstall Dell SonicWALL GVC and reboot your computer. Now verify that SonicWALL Virtual Adapter does not exist. Go to Start > Control Panel > Network and Internet > Network and Sharing Center > Manage Network Connections page. If it still exists after the Dell SonicWALL GVC uninstall, it is most likely due to registry corruption during the hard reset. Manually uninstall SonicWALL Virtual Adapter as follows: a b c d e f g Go to Start > Computer, right-click on Computer and select Properties. Choose Device Manager and then choose Network adapters. Right-click SonicWALL VPN Adapter and uninstall this adapter. Select the Delete the driver software for this device checkbox. Change to the %SYSTEMROOT%\System32\Drivers directory and delete SWVNIC.SYS. Reboot your machine. After power up, install Dell SonicWALL GVC again. 4 Dell SonicWALL GVC Install fails due to following error SWGVCSVC Module has Stopped Working This error indicates that the installer failed to install Dell SonicWALL services. Run Dell SonicWALL GVC installer for the second time. Process 2: Post-install errors These problems are seen after the successful install: Blue Screen Failed to run SonicWALL Service Blue Screen Network Adapter Card drivers: Check if you are using the latest driver for each Network Adapter card installed on your computer. If it is not, then you have to first upgrade to this latest version of the driver and then run Dell SonicWALL GVC again. Trend Micro firewall: If you have installed this client based firewall, then check to make sure it is the latest version from the Vendor Website. If it is and you are still getting Blue screen, then disable the Trend Micro Common firewall driver binding from the properties of the Virtual adapter. On Vista, go to Start > Control Panel > Network and Internet > View network status and tasks > Manage network connections. Select SonicWALL Virtual adapter and right-click to select properties and then disable Trend Micro Common firewall driver binding. 6

If the blue screen still persists, then you need to provide the following to tech support for further investigation: After the upgrade to GVC 4.9.4, if you get a blue screen, provide the following file %SystemRoot%\Minidump (%SystemRoot% is usually C:\Windows) to Tech support in order to troubleshoot further. For someone who can reproduce the symptom, choosing 'Kernel memory dump' could be of even more help as it should have more information. To get detailed memory dump need to set the following: 1 Start > Computer, right-click on Computer and select Properties. 2 Choose Advanced system settings and then choose Settings under Startup and Recovery. The settings are under the System failure section. The dump file by default is written to the %SystemRoot%\MEMORY.DMP file. Failed to run SonicWALL Service Open a DOS command prompt window by right-clicking on the icon and select Run as administrator. Change directory to Dell SonicWALL GVC install directory, (Usually \Program Files\SonicWALL\SonicWALL Global VPN Client) and type the following commands. Net stop SWGVCSVC Net start SWGVCSVC Process 3: TCP applications on Vista are slow The issue is caused by Windows Scaling being handled incorrectly by the firewall device. To manually disable windows scaling, run the following command from the command prompt: netsh interface tcp set global autotuning=disabled Refer to the following URL for more information on this problem: http://support.microsoft.com/kb/934430 Process 4: Cannot access certain destination networks 1 From Dell SonicWALL GVC menu select, File > Properties > Status tab. In the connection section, select the Details button. Verify the destination network you are trying to reach, exists in the Destination Proxy IDs list. The information is user specific and can be controlled in the Group VPN Policy on the firewall. This verification can also be done from a Dell SonicWALL GVC report and can be found under the following heading: i. Destination Networks ii. -------------------- iii. iv. 192.168.0.0/255.255.255.0/BOOTPS: Phase 2 Complete 192.168.0.0/255.255.255.0/Any: Idle This destination proxy ID list is generated on a per user basis so it is possible the user access list is missing the required destination networks. 2 If Step 1 is verified but it still fails, then verify the route to and from the destination network is correct on the firewall side. This may require a packet capture either on the Dell SonicWALL appliance or an external packet capture on the host you are trying to reach. 7

Process 5: Cannot browse the Internet after GVC connection is enabled and connected Generate Dell SonicWALL GVC report (Help->Generate Report menu) and verify if the policy is a tunnel all policy. Check that the default route points to the correct interface. If the policy is tunnel all, then a packet capture on the Dell SonicWALL appliance should provide information if the packet is dropped at the firewall due to an incorrectly configured or unavailable rule to route the Internet packets. In order to help trace this, start a continuous ping from SonicWALL GVC client to 4.2.2.2 and use the packet capture utility on the firewall to trace the packet destination. Process 6: Peer is not responding to ISAKMP requests from GVC; Check GVC logs to verify 1 Verify host running Dell SonicWALL GVC application has Internet connectivity and can browse the Internet. If not, then fix this problem and then go to Step 2. 2 Verify the Peer gateway is running and the <zone> Group VPN policy is enabled. If you have other Dell SonicWALL GVC clients connecting to the same firewall on the same interface of the firewall, then this is not a problem. Go to Step 3. 3 Dell SonicWALL GVC works from certain locations and this error message only shows up when you are behind certain NAT device. There are two possible scenarios. NAT device is blocking IKE traffic from Dell SonicWALL GVC (Vista OS) since it is not using defined UDP source port (500) for IKE. This is currently only a problem with GVC running on Vista. In order for Dell SonicWALL GVC to use the defined IKE source port, start GVC by right-clicking on the icon and then select Run as administrator. If GVC still cannot connect, then go to Step 4. 4 It is possible that this NAT device is blocking IKE traffic and so requires a rule (policy) to allow IKE packets from GVC. To verify if the IKE traffic from SonicWALL GVC is reaching the Peer gateway, use the event logs (Network Debug Category enabled) or packet capture on the Dell SonicWALL appliance. If the Peer gateway does not get the IKE packets, then it is the NAT device in the middle or ISP that is dropping the IKE packets. Consult the NAT device manual or ISP to troubleshoot this problem. Process 7: Stuck on authenticating when GVC connection is enabled NOTE: Check GVC logs to get the state of the connection progress. Most likely causes are listed below. Group VPN Configuration error on the Firewall. Check if the user has VPN access list assigned. (With or Without XAUTH this is required). Dell SonicWALL GVC logs show Phase 2 error. This should never happen with Dell SonicWALL GVC. Delete the connection and create a new one and then try to connect again. The user has to enter the preshared key if the firewall GroupVPN setting Use Default Key for Simple Client Provisioning is not enabled. They will also enter their XAUTH credentials as they normally do on new connections, if the firewall XAUTH checkbox is on for GroupVPN. Dell SonicWALL GVC logs shows Phase 2 error. This should never happen with GVC. Delete the connection and create a new one and then try to connect again. The user has to enter their XAUTH credentials and the preshared key if default provisioning key is not enabled. Check if the firewall has license for Dell SonicWALL GVC connection. If it has, then check if the number of concurrent GVC connections does not exceed the licensed number. 8

Process 8: Failed to obtain DHCP lease for the Virtual Adapter NOTE: Try a reboot first. If that does not help follow the steps below. 1 Verify that no 3 rd party IPsec VPN clients are installed on your computer. Uninstall any existing IPsec VPN clients (including Dell SonicWALL GVC), reboot, and then install GVC again. 2 Dell Wireless WLAN 4.10+ wireless network driver includes VLAN Priority Support which conflicts with getting a DHCP lease for the SonicWALL Virtual Adapter. Check if VLAN Priority Support is enabled. If it is, disable it by performing the following steps: a b c d e f g h i Right-click My Computer on the desktop and click Properties. NOTE: If there is no My Computer icon on the desktop, click Start and right-click My Computer on the right column of the Start menu. When the System Properties window appears, click the Hardware tab and click Device Manager. When the Device Manager window appears, click the <+> next to Network Adapters. Double-click Dell Wireless WLAN Adapter. When the Dell Wireless WLAN Adapter Properties window appears, click the Advanced tab. Scroll down to VLAN Priority Support and click to highlight. Select Disable from the drop-down menu under the Value: field. Click OK to close the Dell Wireless WLAN Adapter Properties window. Click the X button in the upper right-hand corner of the Device Manager window to close it. 3 Verify DNE binding is enabled for the SonicWALL Virtual Adapter. a b c d Go to Start > Control Panel > Network and Internet > Network and Sharing Center > Manage network connections page. Select SonicWALL Virtual Adapter. Right-click on properties. On the properties page verify Deterministic Network Enhancer binding is enabled. 4 If this is a new setup, verify configuration on the firewall. Enable Network Debug category logs to show the DHCP transaction messages. Based on the logs you can determine if the DHCP request is received from the client and if the DHCP server responded to this request. If it is an already working setup, and only GVC on Vista is having this problem, then go to Step 5. 5 If you are running a client-based software firewall on the Vista machine, check if the version is Vista compatible. If it is not, then upgrade to the latest version. If it does not work after the upgrade, then add a rule to allow TCP/UDP port 67/68. If this does not fix the problem, then go to Step 6. NOTE: There were numerous problems reported with Norton Internet Security Suite. If you have this software installed, then the final try is to uninstall Norton and reboot your computer and then try again. 6 Disable the software firewall completely and then try again. If this does not work, then go to Step 7. 7 Change the default setting for this connection for NAT Traversal from Automatic to Disabled. To select the connection, go to File > Properties > Peer > Edit tab to change this setting. 9

Process 9: Not getting a prompt to enter a PreShared Key (PSK) This could happen due to process 6 error condition above. If that is not the case, then PSK prompt is only available if the Simple provisioning key is not enabled on the <zone> Group VPN Policy. After the PSK is entered for the first time, it is saved in the encrypted configuration file. Unless the PSK in Group VPN policy is changed the PSK is never prompted again. Process 10: Not getting a prompt to enter XAUTH Credentials This could happen due to process 6 error condition above. If that is not the case, then XAUTH prompt is only available if it is enabled on the <zone> GroupVPN Policy. XAUTH credentials are allowed to be cached in the encrypted configuration file only it is allowed on the <zone> Group VPN policy. Technical support resources Technical support is available to customers who have purchased Dell software with a valid maintenance contract and to customers who have trial versions. The Support Portal provides self-help tools you can use to solve problems quickly and independently, 24 hours a day, 365 days a year. In addition, the portal provides direct access to product support engineers through an online Service Request system. To access the Support Portal, go to http://software.dell.com/support. The site enables you to: Create, update, and manage Service Requests (cases) View Knowledge Base articles Obtain product notifications Download software. For trial software, go to Trial Downloads. View how-to videos Engage in community discussions Chat with a support engineer About Dell Dell listens to customers and delivers worldwide innovative technology, business solutions and services they trust and value. For more information, visit www.software.dell.com. 10

Contacting Dell Technical support: Online support Product questions and sales: (800) 306-9329 Email: info@software.dell.com 2015 Dell Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a software license or nondisclosure agreement. This software may be used or copied only in accordance with the terms of the applicable agreement. No part of this guide may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying and recording for any purpose other than the purchaser s personal use without the written permission of Dell Inc. The information in this document is provided in connection with Dell products. No license, express or implied, by estoppel or otherwise, to any intellectual property right is granted by this document or in connection with the sale of Dell products. EXCEPT AS SET FORTH IN THE TERMS AND CONDITIONS AS SPECIFIED IN THE LICENSE AGREEMENT FOR THIS PRODUCT, DELL ASSUMES NO LIABILITY WHATSOEVER AND DISCLAIMS ANY EXPRESS, IMPLIED OR STATUTORY WARRANTY RELATING TO ITS PRODUCTS INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. IN NO EVENT SHALL DELL BE LIABLE FOR ANY DIRECT, INDIRECT, CONSEQUENTIAL, PUNITIVE, SPECIAL OR INCIDENTAL DAMAGES (INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF PROFITS, BUSINESS INTERRUPTION OR LOSS OF INFORMATION) ARISING OUT OF THE USE OR INABILITY TO USE THIS DOCUMENT, EVEN IF DELL HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. Dell makes no representations or warranties with respect to the accuracy or completeness of the contents of this document and reserves the right to make changes to specifications and product descriptions at any time without notice. Dell does not make any commitment to update the information contained in this document. If you have any questions regarding your potential use of this material, contact: Dell Inc. Attn: LEGAL Dept. 5 Polaris Way Aliso Viejo, CA 92656 Refer to our web site (software.dell.com) for regional and international office information. Patents For more information about applicable patents, refer to http://software.dell.com/legal/patents.aspx. Trademarks Dell, the Dell logo, and SonicWALL are trademarks of Dell Inc. Other trademarks and trade names may be used in this document to refer to either the entities claiming the marks and names or their products. Dell disclaims any proprietary interest in the marks and names of others. Legend CAUTION: A CAUTION icon indicates potential damage to hardware or loss of data if instructions are not followed. WARNING: A WARNING icon indicates a potential for property damage, personal injury, or death. IMPORTANT NOTE, NOTE, TIP, MOBILE, or VIDEO: An information icon indicates supporting information. Last updated: 8/17/2015 232-002619-00 Rev B 11