A Service Tunnel is a SonicWall Cloud Secure Edge (CSE) service that provides encrypted network connectivity to entire network segments, such as VLANs, VPCs, and subnets.
A Service Tunnel is a modern, cloud-first VPN as a Service (VPNaaS) intended to replace a legacy VPN. While the objective of Zero Trust security is often to migrate away from granting full network access to users and instead provision access to specific corporate resources, there are some scenarios where full network access is necessary.
You can publish Service Tunnels when you need to enable:
CSE uses WireGuard to create fast, secure tunnels utilizing state-of-the-art cryptography. When a user connects through the desktop app, CSE evaluates the applicable security policy and, if access is granted, establishes an encrypted tunnel to the target network segment. As with the other service types, security policies are continuously enforced, locking down access based on user and device attributes and trust levels.
The flow diagram below describes how CSE's zero-trust access control mechanism works for Service Tunnels. Review the Publish a Service Tunnel to Users guide to see how to create a Zero Trust policy for a service tunnel so a user can access the tunnel via the desktop app.
Use a Service Tunnel when users require access to an entire network segment or to applications that cannot be reached through resource-specific access. When users only need access to individual corporate resources, prefer a resource-specific service type instead.
Tip: To publish a Service Tunnel and grant users access, see Publish a Service Tunnel to Users. To understand how traffic is directed once a tunnel is established, see how routing works.
Read about how routing works in CSE to secure access to your networks.