A Service Tunnel is SonicWall Cloud Secure Edge (CSE)'s modern, cloud-first VPN as a Service (VPNaaS), built to replace a legacy VPN. It provides encrypted network connectivity to entire network segments, such as VLANs, VPCs, and subnets.
While Zero Trust security generally aims to replace full network access with access to specific corporate resources, some scenarios still require full network access.
You can publish Service Tunnels when you need to enable:
CSE uses WireGuard to create fast, secure tunnels utilizing state-of-the-art cryptography. When a user connects through the desktop app, CSE evaluates the applicable security policy and, if access is granted, establishes an encrypted tunnel to the target network segment. As with the other service types, security policies are continuously enforced, locking down access based on user and device attributes and trust levels.
The flow diagram below describes how CSE's zero-trust access control mechanism works for Service Tunnels. Review the Publish a Service Tunnel to Users guide to see how to create a Zero Trust policy for a service tunnel so a user can access the tunnel via the desktop app.
Use a Service Tunnel when users require access to an entire network segment or to applications that cannot be reached through resource-specific access. When users only need access to individual corporate resources, prefer a resource-specific service type instead.
Tip: To publish a Service Tunnel and grant users access, see Publish a Service Tunnel to Users. To understand how traffic is directed once a tunnel is established, see how routing works.
Read about how routing works in CSE to secure access to your networks.