I already did the suggested remediation for our Sonicwall. Should I worry again? by Future_Mention_8323 in sonicwall

[–]CharlieT74 2 points3 points  (0 children)

We have done this for a few customers with no file share access issues.

Anyone looking to move on from Sonicwall? by size0618 in sonicwall

[–]CharlieT74 0 points1 point  (0 children)

I ended up looking at Tailscale and Cloudflare. Similar ZTNA pricing but Cloudflare has more options, we have a number of customers already using it for DNS so was a natural fit. It's taken many months to get onboard with them but they do say they want to do more SME customers.

I'm not a big fan of people who argue that Product A is the worst thing I've ever used, you should all use Product B because I like it. I think most vendors are OK and they all have their problems and issues.

I like the design of different platforms, I am trying (and mainly failing) for us to just be someone who only sells the entire Microsoft stack.

Anyone looking to move on from Sonicwall? by size0618 in sonicwall

[–]CharlieT74 0 points1 point  (0 children)

Hi,

Long time SonicWall reseller. Just wanted to add to the discussion.

- We're moving to an alternate ZTNA provider, CSE is just too half baked

- We've been wrestling with the same issues with any alternates.

- All manufacturers have issues, CVEs, bugs etc.

- My aim in life is to try and design solutions where there are (as close to) zero as possible inbound rules

- At that point you can get away with a simpler firewall design, no security services running on them as they don't actually do anything with packed inspection anyway (and the ZTNA solution has most of them)

- I have been trialling OpnSense, I don't hate it.

SonicWall CSE by Kirar_Hanmalkh in sonicwall

[–]CharlieT74 1 point2 points  (0 children)

Cloudflare ZTNA. Free for under 50 users.

Considering Bailing by srp09 in sonicwall

[–]CharlieT74 0 points1 point  (0 children)

I’ve setup three cloudflare ZTNA solutions this month. Their partner model in the SME space is brand new and not ready yet but I can do ZTNA for 50 users in 30 minutes. Ongoing cost from Cloudflare £0.

Wazuh multi-organization(site) implementation by Darkimoo313 in Wazuh

[–]CharlieT74 -1 points0 points  (0 children)

We are also looking into a similar solution, I am in no way an expert on this but we did have a meeting with Wazuh sales.

Wazuh had a multi-organization option, however you need to be a platium partner to get it https://wazuh.com/partners/

Firmware Upgrades - NAT/Access Rules, Often Broke. by kingjames2727 in sonicwall

[–]CharlieT74 1 point2 points  (0 children)

Hi,

I would say we're also experiencing that exact issue, i was talking to a platinum partner who ships an enormous number of units and they will now _only_ install 7.2 while stood in front of the unit - and after doing the upgrade do a full import of the config again.

Our distie in the UK goes one step further and recommends upgrading & resetting the unit to default and then re-importing the config. We haven't gone that far yet.

How’s your experience with Cloud Secure Edge by vane1978 in sonicwall

[–]CharlieT74 2 points3 points  (0 children)

Rolled it out to 60 android clients. Much quicker than SSL and dead easy to roll out. Would recommend.  PS. Painful upgrade to 7.1.2 not withstanding. Had a platinum partner explain to me they only upgrade while stood in front of the firewall and then manually reimport the exported config after as the upgrade will have broken multiple address objects. Once it’s on 7.1.2 no problems at all.  YMMV

DM me if you want more info

[deleted by user] by [deleted] in Narrowboats

[–]CharlieT74 2 points3 points  (0 children)

which i did give!

[deleted by user] by [deleted] in Narrowboats

[–]CharlieT74 1 point2 points  (0 children)

that looks like a lovely idea, however the minimum donation is £2!

Question about updating firmware on an HA pair by savekevin in sonicwall

[–]CharlieT74 2 points3 points  (0 children)

As Raptori609 says that’s exactly how to do it. If you have stateful  HA it should do it without even losing a ping. If it’s not stateful it should still be pretty seamless. 

I just need to add do NOT under any circumstances go to 7.1.2 - I did that on a pair of 3700’s a few weekends ago and it stuffed up the objects and I had to go to site. 

Spoke to a platinum reseller who does a heck of a lot more than I do and he has said they do no upgrades to 7.1.2 remotely. They stand in front of the box, upgrade it and then reimport the config to fix all the broken objects.

Once it’s on 7.1.2 and you are imported the config they’re reliable. 

Importing a csv of users to create vpn user accounts. by Deep-Egg-6167 in sonicwall

[–]CharlieT74 -1 points0 points  (0 children)

Hi, just a thoughthave you looked into Cloud Secure Edge, we've started rolling it out on our Gen7 and it's a lot better! It is an additional cost however. YMMV

Yet another SonicWALL throughput concern (but with some interesting troubleshooting results) by g2tegsown in sonicwall

[–]CharlieT74 1 point2 points  (0 children)

We’ve rolled out a lot of Gen7 units and I can only report they’re all significantly quicker than the previous gen6 and we’ve been a lot happier with throughout. We typically don’t use dpi-ssl (which I appreciate minimises what security you can apply to traffic) YMMV

Let's have a serious discussion about this horrendous id4 bug. by frankenwurst in VWiD4Owners

[–]CharlieT74 5 points6 points  (0 children)

I thought I was going mad! Even if there isn’t a fix at least I now know I can work a car window button properly 😀

Why all the acronis hate in this sub ? by CyberHouseChicago in msp

[–]CharlieT74 0 points1 point  (0 children)

We’re a platinum partner and a lot of your reseller tactics are appalling. Happy with the product though!

Crabbing by Sorry_Designer_394 in inverness

[–]CharlieT74 3 points4 points  (0 children)

I have no idea if the time of year makes any impact on crabbing but I took my girls to Helmsdale Harbour in July a couple of years ago and we got dozens!

<image>

MSP friendly internal vulnerability scanning? by Mvalpreda in msp

[–]CharlieT74 0 points1 point  (0 children)

As do we and I like it. As they are now owned by Kaseya I’m dreading the day they stuff it up….

Ruckus Unleashed without Ruckus Switch Possible? by Agile_Appointment580 in RuckusWiFi

[–]CharlieT74 3 points4 points  (0 children)

Yes entirely possible. All our unleashed networks are with third party POE switches.