{"id":1290,"date":"2014-01-23T14:22:31","date_gmt":"2014-01-23T22:22:31","guid":{"rendered":"https:\/\/thebeagle.itgroove.net\/?p=1290"},"modified":"2023-02-24T21:48:35","modified_gmt":"2023-02-24T21:48:35","slug":"sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall","status":"publish","type":"post","link":"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/","title":{"rendered":"Sonicwall Site-to-Site VPN Tunnel Counts\u2013Something to keep in mind when you are sizing the firewall"},"content":{"rendered":"<p>Sonicwall firewalls are all capable of supporting site-to-site VPN connections to other firewalls and each firewall model has a specified maximum number of tunnels that it can support.&nbsp; From 5 tunnels on a TZ105 through to 10,000 on the SuperMassive Series (ooooo, I want one of these for Christmas!!!!), they all work in the same fashion.&nbsp; For the rest of this discussion I\u2019ll focus on Sonicwall-to-Sonicwall VPN\u2019s but the gist holds true regardless. <\/p>\n<p>When you create a site-to-site VPN connection (VPN Policy) between Sonicwalls you define the subnets behind each Sonicwall that will be accessible over the VPN connection.&nbsp; Each Sonicwall needs to understand what subnets are available over the VPN connection from the other Sonicwall.&nbsp; This is pretty straightforward and it is configured as part of the VPN policy on the Network tab within the Policy itself.&nbsp; What may be a bit surprising is that the VPN link that is created *might* actually be displayed as more than one VPN tunnel on each Sonicwall.&nbsp; In essence, there is a &#8220;tunnel&#8221; created on each Sonicwall between each network on the local Sonicwal that is included in the VPN policy and each network on the remote Sonicwall that is included in the policy.&nbsp; This means that you might see a whole bunch of tunnels listed on a Sonicwall when you might only have one site-to-site VPN Policy in place between two Sonicwalls with multiple networks involved on each side of the VPN.&nbsp; This is important to keep in mind as it is the total number of <strong><em>tunnels <\/em><\/strong>that you need to track; it is this number that you have to line up against the <em>maximum<\/em> number of tunnels that a given Sonicwall model supports.&nbsp; You can end up with no where to go and your cap in hand having to beg for more money for a bigger firewall if you don\u2019t plan your capacity correctly. <\/p>\n<p>Case in point:&nbsp; I have a customer that has 4 locations;&nbsp; there are now four Sonicwalls in place; one in Victoria, one in Richmond, one in Nanaimo and one at the owner\u2019s house.&nbsp; From the point of view of Victoria (main office with a NSA 250MW) that means there are three VPN policies in place, one to each of the remote sites and that is indicated in the VPN Policies listing:  <\/p>\n<p><a href=\"https:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2014\/01\/image27.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-top: 0px;border-right: 0px;border-bottom: 0px;padding-top: 0px;padding-left: 0px;border-left: 0px;padding-right: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2014\/01\/image_thumb27.png\" width=\"822\" height=\"171\"><\/a> <\/p>\n<p>But, as you can see, two of those sites have multiple networks that are available across the VPN; Richmond has three and Nanaimo has two.&nbsp; Keep in mind that Victoria offers up two networks across the VPN back to all the other sites and you can do the math.&nbsp; There should be:  <\/p>\n<ul>\n<li>2 tunnels to Home &#8212; 2 [Victoria] x 1 (House]\n<li>6 tunnels to Richmond &#8212; 2 [Victoria] x 3 [Richmond]\n<li>4 tunnels to Nanaimo \u2013 2 [Victoria] x 2 [Nanaimo] <\/li>\n<\/ul>\n<p>And that adds up to 12 tunnels in all.&nbsp; Not surprisingly, that is what we see under the <strong>Active Tunnels<\/strong> list:  <\/p>\n<p><a href=\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2014\/01\/image28.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-top: 0px;border-right: 0px;border-bottom: 0px;padding-top: 0px;padding-left: 0px;border-left: 0px;padding-right: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2014\/01\/image_thumb28.png\" width=\"812\" height=\"291\"><\/a> <\/p>\n<p>Each tunnel lists the associated local and remote networks.&nbsp; There is a reverse-match on the appropriate remote Sonicwall.&nbsp; As this particular unit is an NSA250MW it supports 50 tunnels so I have used up 12 of those 50 tunnels. Lots of headroom left on this box.&nbsp; But keep in mind I used up 12 tunnels provisioning 3 site-to-site VPN <em><strong>policies<\/strong><\/em>. <\/p>\n<p>However, in Nanaimo I have a TZ105W which supports 5 tunnels and I have used 4 up already and I have only provisioned one site-to-site VPN policy!&nbsp; If the customer wanted me to plug in Richmond to this site and provision similar connections as between Richmond and Victoria I would be dead in the water as I simply would not have the headroom on the box to do it.&nbsp; Thankfully that is not an issue as that is not something my customer wants to do.<\/p>\n<p>I think you can see where this is going \u2026 you need to give consideration to what your overall connectivity plans are when you are spec\u2019ing your firewall choice.&nbsp; While you might have a small office with limited devices behind the firewall and, therefore, you lean towards a smaller box (say a TZ105), you should think about the bigger picture.&nbsp; In other words, don\u2019t just think of the firewall as a mere \u201csecurity endpoint\u201d, think about how it fits into your overall plans.&nbsp; It is cheaper and better to \u201cdo it once and do it right\u201d up front than to end up scrambling and have to replace a relatively new firewall because you didn\u2019t do your sizing calculations.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sonicwall firewalls are all capable of supporting site-to-site VPN connections to other firewalls and each firewall model has a specified maximum number of tunnels that it can support.&nbsp; From 5 tunnels on a TZ105 through to 10,000 on the SuperMassive Series (ooooo, I want one of these for Christmas!!!!), they all work in the same &hellip; <a href=\"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/\"><\/a><\/p>\n","protected":false},"author":10,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[266],"tags":[608,641],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Sonicwall Site-to-Site VPN Tunnel Counts\u2013Something to keep in mind when you are sizing the firewall - Archive<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Sonicwall Site-to-Site VPN Tunnel Counts\u2013Something to keep in mind when you are sizing the firewall - Archive\" \/>\n<meta property=\"og:description\" content=\"Sonicwall firewalls are all capable of supporting site-to-site VPN connections to other firewalls and each firewall model has a specified maximum number of tunnels that it can support.&nbsp; From 5 tunnels on a TZ105 through to 10,000 on the SuperMassive Series (ooooo, I want one of these for Christmas!!!!), they all work in the same &hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/\" \/>\n<meta property=\"og:site_name\" content=\"Archive\" \/>\n<meta property=\"article:published_time\" content=\"2014-01-23T22:22:31+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-02-24T21:48:35+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2014\/01\/image_thumb27.png\" \/>\n<meta name=\"author\" content=\"Sean Wallbridge\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sean Wallbridge\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/\",\"url\":\"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/\",\"name\":\"Sonicwall Site-to-Site VPN Tunnel Counts\u2013Something to keep in mind when you are sizing the firewall - Archive\",\"isPartOf\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/#primaryimage\"},\"thumbnailUrl\":\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2014\/01\/image_thumb27.png\",\"datePublished\":\"2014-01-23T22:22:31+00:00\",\"dateModified\":\"2023-02-24T21:48:35+00:00\",\"author\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\"},\"breadcrumb\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/#primaryimage\",\"url\":\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2014\/01\/image_thumb27.png\",\"contentUrl\":\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2014\/01\/image_thumb27.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog Archive\",\"item\":\"https:\/\/regroove.ca\/archive\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Sonicwall Site-to-Site VPN Tunnel Counts\u2013Something to keep in mind when you are sizing the firewall\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/regroove.ca\/archive\/#website\",\"url\":\"https:\/\/regroove.ca\/archive\/\",\"name\":\"Archive\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/regroove.ca\/archive\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\",\"name\":\"Sean Wallbridge\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"caption\":\"Sean Wallbridge\"},\"url\":\"https:\/\/regroove.ca\/archive\/author\/swallbridge\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Sonicwall Site-to-Site VPN Tunnel Counts\u2013Something to keep in mind when you are sizing the firewall - Archive","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/","og_locale":"en_US","og_type":"article","og_title":"Sonicwall Site-to-Site VPN Tunnel Counts\u2013Something to keep in mind when you are sizing the firewall - Archive","og_description":"Sonicwall firewalls are all capable of supporting site-to-site VPN connections to other firewalls and each firewall model has a specified maximum number of tunnels that it can support.&nbsp; From 5 tunnels on a TZ105 through to 10,000 on the SuperMassive Series (ooooo, I want one of these for Christmas!!!!), they all work in the same &hellip;","og_url":"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/","og_site_name":"Archive","article_published_time":"2014-01-23T22:22:31+00:00","article_modified_time":"2023-02-24T21:48:35+00:00","og_image":[{"url":"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2014\/01\/image_thumb27.png"}],"author":"Sean Wallbridge","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sean Wallbridge","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/","url":"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/","name":"Sonicwall Site-to-Site VPN Tunnel Counts\u2013Something to keep in mind when you are sizing the firewall - Archive","isPartOf":{"@id":"https:\/\/regroove.ca\/archive\/#website"},"primaryImageOfPage":{"@id":"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/#primaryimage"},"image":{"@id":"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/#primaryimage"},"thumbnailUrl":"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2014\/01\/image_thumb27.png","datePublished":"2014-01-23T22:22:31+00:00","dateModified":"2023-02-24T21:48:35+00:00","author":{"@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77"},"breadcrumb":{"@id":"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/#primaryimage","url":"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2014\/01\/image_thumb27.png","contentUrl":"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2014\/01\/image_thumb27.png"},{"@type":"BreadcrumbList","@id":"https:\/\/regroove.ca\/archive\/2014\/01\/23\/sonicwall-site-to-site-vpn-tunnel-countssomething-to-keep-in-mind-when-you-are-sizing-the-firewall\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog Archive","item":"https:\/\/regroove.ca\/archive\/"},{"@type":"ListItem","position":2,"name":"Sonicwall Site-to-Site VPN Tunnel Counts\u2013Something to keep in mind when you are sizing the firewall"}]},{"@type":"WebSite","@id":"https:\/\/regroove.ca\/archive\/#website","url":"https:\/\/regroove.ca\/archive\/","name":"Archive","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/regroove.ca\/archive\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77","name":"Sean Wallbridge","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","caption":"Sean Wallbridge"},"url":"https:\/\/regroove.ca\/archive\/author\/swallbridge\/"}]}},"_links":{"self":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/1290"}],"collection":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/comments?post=1290"}],"version-history":[{"count":1,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/1290\/revisions"}],"predecessor-version":[{"id":2962,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/1290\/revisions\/2962"}],"wp:attachment":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/media?parent=1290"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/categories?post=1290"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/tags?post=1290"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}