Getting Started with MPSS

Description

MPSS Getting Started Process Overview

Welcome to SonicWall's Managed Protection Security Services (MPSS). This guide walks you through requesting onboarding for a firewall so the SonicSentry team can begin managing it. The whole request is now self-service in Unified Management, so getting started takes only a few minutes.


Before you begin

Ensure that the firewall is powered on, connected to the internet, configured for your environment, and online in NSM.

NSv (virtual) firewalls in Policy Mode are not supported.
SonicOSX uses a different configuration model that the MPSS management tools aren't compatible with. Re-deploy an NSv in Classic Mode before onboarding.


The Onboarding Process at a Glance

Once the firewall is delivered, the partner or end customer will complete the following steps:

🔹 Register the firewall under your organization and the correct tenant.

🔹 Configure the firewall - power, internet, and the base configuration for your environment (interfaces, DHCP, routes, firewall rules, NAT). You set the base; MSS applies best practices.

Who Configures the Firewall?

  • You are responsible for basic firewall setup before we can begin management.
  • Configure environment-specific items such as; Network Interfaces, DHCP Settings, Static Routes, Firewall Rules, NAT Policies, etc.
  • For guidance on how to configure your firewall, refer to MSS - How to Configure a Firewall (START HERE)

Tip: You are welcome to configure security services (Gateway AV, IPS, etc.) if you would like, but MSS will enable and apply them according to best practices during onboarding.

Important: If you are activating MPSS on an existing firewall that is already protecting the network, this step can be skipped. At a minimum, the firewall must be configured and online in NSM to the point where it is actively connected and visible.

🔹 Begin Onboarding - Submit your MPSS onboarding request from the firewall's Product Details page (Process below). The SonicSentry team onboards the unit, completes the NSM configuration, scheduled reports, an initial Health Check, and best-practice configuration.

Onboarding Completed - and your Cyber Warranty is confirmed active by the MPSS support team.

 

How to Submit your MPSS onboarding request

Onboarding is requested directly in Unified Management - there's no form to email and nothing to fill in by hand.

This replaces the old email-based request for MPSS license activations after July 15th, 2026:

  • For MPSS licenses activated after the above date, you no longer click a link to send an email with the firewall name and serial. The request, your best-practices choice, and your contacts are all captured in Unified Management.

  • For MPSS licenses that were activated before the above date, you will need to send an onboarding request via email by using the below link and filling in the requested infomration:

 

  1. Sign in to https://platform.sonicwall.com and navigate to the firewall's Product Details page.
  2. In the To-Do List, click Complete MPSS Onboarding Request.
  3. Confirm the prerequisites are met - powered on, connected to the internet, configured, and online in NSM. If the firewall is offline, it isn't ready to onboard; bring it online first.
  4. Choose how you want MPSS best practices handled (see below).
  5. Add your Authorized Contacts and mark each as a Report and/or Alert recipient.
  6. Click Submit. You'll see a confirmation and receive a confirmation email.

Choosing how best practices are handled

The onboarding request asks how you want the SonicSentry team to handle best-practice configuration. Your choice decides whether we apply changes for you or review them with you first.

  • Pre-approved - the SonicSentry team is authorized to remediate insecure configurations without additional review. Best practices are applied promptly, and your Cyber Warranty activates once onboarding is complete.
  • Approval Required - the SonicSentry team reviews best practices and requests your explicit approval before applying each remediation. Best practices are applied only after you approve, and Cyber Warranty activation is delayed until then.

What happens after you submit

The SonicSentry team takes it from here:

  • Configures the unit in NSM and confirms it's visible and in sync.
  • Sets up your scheduled reports (Security Assessment, Health Check, and Unit Change) to the report contacts you provided.
  • Runs an initial Health Check that identifies the configuration changes needed for Cyber Warranty eligibility.
  • Applies best practices - immediately if you chose pre-approved, or after your approval if you chose Approval Required. Settings can be tuned to your environment as long as the Cyber-Warranty required items are not weakened.
  • Runs a final Health Check to confirm the unit is Cyber-Warranty eligible, then sends an onboarding-complete confirmation.

Cyber Warranty activates when onboarding is complete.

  • The Cysurance Cyber Warranty is only considered Active once the MPSS support team has confirmed via the onboarding ticket that it has been activated.
  • For details on what the warranty covers, see the Cysurance Partner FAQs.

Your responsibilities

Once you have submitted the onboarding request, a ticket will be created and you are responsible for timely response/communication and any actions that need authorization. These include but are not limited to:

  1. Review the report and reply to the SonicSentry team to authorize changes to remediate the failed checks.
  2. The Health Check report will only list configuration items that did not pass. To review the complete list of Best Practice Configuration items, see: MSS Managed Firewall Best Practice Configurations.
  3. Confirm none of these changes will conflict with your environment. If you have noted any items in your onboarding request, the SonicSentry team will hold those specific items until they can review them with you or schedule a testing window. Some settings can be adjusted while still maintaining Cyber Warranty compliance, allowing for fine-tuning.
  4. To ensure compliance and secure configuration of partner’s firewalls, the SonicSentry team will send up to 3 reminders over a 9-business day period awaiting your authorization – after the final reminder, if no response is received from you, it will be deemed that the changes are authorized, and all best practices will be implemented by the SonicSentry MPSS support team.

Once changes are applied, the SonicSentry team will run a final Health Check Report. If the firewall passes, you will receive confirmation of Cyber Warranty eligibility and onboarding completion.


Ongoing firewall management and configuration changes

  • MPSS includes 24/7 monitoring and proactive management by the MSS Network Security team.
  • To keep the unit compliant, submit all configuration changes through MSS Support. If a requested change would affect best practices or Cyber-Warranty compliance, the team will explain it and work with you on an appropriate solution.

For details on what is and is not included in ongoing management, see: Service Plan SonicWall Managed Protection Security Suite (MPSS)


Contacting MSS Support

For firewall support after onboarding, submit a service ticket to the MSS Network Security Support team:

  1. Sign in to the SonicWall MSS Ticket Portal.
  2. Click Submit New Ticket.
  3. Choose Category: Network Security.
  4. Choose Service: MPSS.

Related Articles

  • Cloud Threat Analytics: SaaS Alerts Onboarding
    Read More
  • MPSS Frequently Asked Questions (FAQs)
    Read More
  • MSS CAS Migrations: Frequently Asked Questions (FAQs)
    Read More
not finding your answers?