This quick start configures Secure Internet Access (SIA) in its most basic form: one Internet Threat Protection (ITP) policy applied to one registered device. Completing it confirms that filtering is enforced on the endpoint and recorded in the console before the configuration is extended to the wider organization.
This quick start serves the Block internet content use case, and the Protect SaaS apps use case where device trust is enforced on SaaS sign-in. To configure access to private resources instead, see the Reach a Resource on Your Network quick start.
For the full organization-wide configuration, see Block Malicious Internet Content in Use Cases.
Two terms describe the same capability at different levels:
A license is purchased as SIA, and the policies are configured under ITP.
SIA is enforced on the endpoint. The following are therefore not required to complete this quick start:
An identity provider is also not required at this stage. A single local account is used for validation, and the directory integration is completed afterwards. See Next steps.
Register the activation key so that SonicWall provisions the organization. See Activate Cloud Secure Edge.
Provisioning takes several minutes to complete after Done is selected.
A user must exist in CSE before a policy can be applied to that user. For this quick start, create a single account using local user management rather than integrating a directory.
See Local User Management, and Invite Code and Device Enrollment to register the account on a device.
Install the CSE desktop app on the test device and register it against the organization. See Register the Desktop App.
Install the app manually for this validation. For an organization-wide rollout, use a device manager instead, as described in Roll Out with a Device Manager.
The Chrome extension is an alternative to the desktop app where filtering is required only within the Chrome browser. See Chrome Extension.
Configure a single policy that blocks one content category, so that the outcome of the validation in Step 5 is unambiguous. See Manage ITP Policies.
Assign the policy to the user account created in Step 2.
On the test device:
In the CSE console, confirm that the blocked request is recorded. See Visibility and Logging.
If the request is not blocked, see Internet Traffic troubleshooting.
Filtering is now validated on one device. Extend the configuration in the following order:
The following capabilities extend what SIA inspects: