Endpoint Protection

 View Only
  • 1.  SEP client preventing DNS resolution with SonicWALL VPN client

    Posted Jan 18, 2011 09:04 PM

    I've been working on a Windows 7 (32-bit) image for our client that includes SEP and have been experiencing an issue when connecting back to the network with the SonicWALL VPN client.  When I establish the VPN tunnel all DNS resolution (both local and across the VPN tunnel) appears to cease for a few minutes, though other network traffic is unaffected (e.g. ping by IP).

    After these few minutes it starts working again, then stops again after several more minutes.  Eventually the VPN tunnel is dropped due to it being unable to contact the server, but the problem persists after this and normal DNS resolution is not restored until a reboot is performed on the system.

    I have narrowed the problem down to something with the Symantec Endpoint Protection or SonicWALL VPN client.  If I uninstall this the DNS resolution works fine at all times.  I have also tested with a standard Windows VPN tunnel and that does not have the same issue.

    I was running 11.0.6a on both the test client and server, but I saw mention in the release notes for 11.0.6 MP2 fixes for VPN-related issues, so I upgraded both machines to 11.0.6 MP2.  However, the problem persists with this as well.

    The issue does not appear to be confined to this particular SonicWALL router as the same thing happens if I establish a tunnel to another site.  I have other Windows 7 machines running the SonicWALL VPN client and other AV packages and do not have this same issue with these.  All systems are running the same version (latest) of the SonicWALL VPN client software.

    Anybody have any ideas about what's going on here?  I've put the client in a basic group that only has a single AV and Live Update policy applied to it.  We're not running Network Threat Protection, Application and Device Control or the Firewall components.

    Thanks for any assistance you can provide.



  • 2.  RE: SEP client preventing DNS resolution with SonicWALL VPN client

    Posted Jan 19, 2011 12:42 AM

    have you tried upgrading vpn client software to latest version..?



  • 3.  RE: SEP client preventing DNS resolution with SonicWALL VPN client

    Posted Jan 19, 2011 12:46 PM

    Yes, I am using the latest version available from SonicWALL.



  • 4.  RE: SEP client preventing DNS resolution with SonicWALL VPN client
    Best Answer

    Posted Jan 19, 2011 03:35 PM

    I had a similar problem, and disabling DNS offload on the NIC driver from Device Manager seemed to help.



  • 5.  RE: SEP client preventing DNS resolution with SonicWALL VPN client

    Posted Jan 19, 2011 06:05 PM

    Looks that like may have done the trick!  It wasn't the DNS offload, but after I disabled TCP/UDP Checksum Offload and Large Send Offload on the NIC (Broadcom 57xx) I haven't had the problem since.  The Checksum Offload seemed to be the main culprit, but I was still getting the issue intermittently with Large Send Offload enabled.  With both disabled I can't reproduce it.

    Thanks for your help!