All of this I have done as well, and it doesn't work. SonicWALL has been working on us hard to try to get a piece of our firewall sales and the reps have admitted they have a long way to go and have been paraphrased as saying "stick with us because it's going to get better." How about not having a freakin' CLI? Being stuck with a stupid a$$ web ui is not acceptable.
Congratulations on having CF working, I'm happy for you. Dumb.
And as for your comment on translating it back in as the LAN interface, how absolutely retarded is this? Thanks for translating that so that if I wanted to review logs or troubleshoot something I can't do it affectively because everything is translated to the LAN interface, freakin stupid. And yeah, I've read the stupid 'KB' article, and was even sent it from T3 engineers over there that we were working with. Still not impressed. Out of the box, I can do this with a NetScreen without ANY special configurations (ALG handles that for me as it should) and WITHOUT having to translate the address, that's just a function that should be inherent not prohibitive, which the entire SonicOS 'Enhanced' (pfft) is.
"As far as HSRP, since that's a proprietary Cisco thing, whaddya expect? If you want to run cisco propietary stuff, stick with Cisco."
This is just a stupid comment, how are you supposed to control what a colo runs for redundant protocols when deploying SonicWALL? Come on man, you gotta think out of the box. Same problem should be expected using VRRP.
"As far as HA goes, I didn't expect that it saved ANY state at all, up or downstream."
Then it's apparent that it's NEVER occured to you that other vendors can do this on some of the simplest as well as highest end devices, and it's also apparent that you have never considered maintaining session state for simple tasks ie...firewall maintenance without interfering with traffic, zero down time, not the case with SonicWALL.
Basically, everytime I get someone like you trying to get me to like SonicWALL, I can always tell that they never want to do anything interesting with their traffic and are not on a level of true engineering (which would require granular control over the entire box), and which requires more than the average freakin', and might I add horribly performing, WebUI can provide. And as well, the people that choose SonicWALL never do proper due diligence or a serious roundup between devices but rather say, "Oh look I can fill my rack with this crap and not be expected to do much because the crap I chose -can't- do much." Whatever, this crap is the same ol' rhetoric of lazy firewall administrators and retarded resellers who are not considering the proper solution but rather what they can pimp out and push boxes out the door.