I have a TZ670 on the latest firmware (Which seems to have solved the CPU issue of the earlier 7.1.1 release), but something still isn’t right.
We have a total of 35 licenses for SSLVPN, but folks are reporting they they are getting error messaging trying to connect due to maximum license count being reached. When I look at the list of logged in SSLVPN users, I see 15 users logged in successfully, but then 10 listings for the same remote IP with the status “login pending”, and a further 12 listings for a different remote IP with that same status. So for some reason, users are taking up multiple licenses getting stuck somehow trying to connect. When you add that all up, 15+10+12 = 37, which is over 35, so the next person trying to log in gets the “maximum licenses reached” rejection.
Once you let some time pass, those “login pending” folks actually complete the login and the multiple “pending” listings go away, but in the interim, I’m getting continual reports of login failures.
What’s going on here, and how do I even troubleshoot this? Is there some setting somewhere to restrict the number of licenses that can be taken by a single remote IP? We shouldn’t have to buy 50 licenses to guarantee 25 people can login.
Update - Hotfix supplied by support appears to have NOT solved this issue.
Hotfix Filename is: sw_tz_670.7.1.1.7051-R3176-HF46826.bin.sig dated 3/23/24.
Note this is different than the latest maintenance release shown in MySonicwall, which is:
sw_tz_670_eng.7.1.1.7051-R5653.bin.sig which is dated 3/12/24.
I’m still seeing occasional multiple licenses taken by bad actors, and when I input those IPs into the Diagnostics page of the GEO-IP filter, it shows they are all in the US, so I’m adding them to the blocked list, but this is not a scalable solution.
I have gotten back to Sonicwall with these results, but not heard back yet regarding next steps.