

Don’t use sonic walls, and also I don’t have any configured, so I can’t help you with any specifics other than other vendors.
Just guessing, they might be doing some kind of network level exploit detection along with the VPN. My network team has that setup on our firewall (multi-zone, including VPN), and I’ve been called in on more than a few security calls triggered by network EDR. If they have people you can use in that kind of a scenario, it would probably be worth it (my CISO is always trying to get customers to buy into the service BEFORE we have to get on a call rather than after).
Well, I have no intention of hitting CTO/CISO, so no goat farming for me