This quick start configures Secure Private Access (SPA) in its most basic form: one user, on one device, reaching one resource inside a private network through CSE, with no inbound firewall rule.
The configuration uses a Service Tunnel, which is the most direct method of publishing private access and is included in SPA Basic. Access to individually named resources is configured later.
This quick start serves the Replace your legacy VPN use case, and is the starting point for Set up ZTNA, which additionally requires SPA Advanced. To configure filtering of public internet traffic instead, see the Filter Internet Content quick start.
For the full organization-wide configuration, see Replace Your Legacy VPN in Use Cases.
The following are not required to complete this quick start:
Register the activation key so that SonicWall provisions the organization. See Activate Cloud Secure Edge.
A deployment model is selected during provisioning. On the Global Edge model, the geographic Points of Presence (PoPs) in which the infrastructure runs are also selected at this stage. This quick start assumes Global Edge, in which SonicWall hosts the edge infrastructure. See edge deployment models for a comparison, and Points of Presence for the available locations.
Provisioning takes several minutes to complete after Done is selected.
Install a Connector on a host inside the private network. The Connector establishes an outbound connection to SonicWall's Edge Network, which is why no inbound firewall rule is required.
See the Connector install guides for the available installation methods.
On the Private Edge deployment model, in which the edge infrastructure is self-hosted, install an Access Tier in place of a Connector.
A Service Tunnel grants an assigned user access to a range of addresses on the private network. See Service Tunnel.
Define the smallest address range that includes the target resource, so that the outcome of the validation in Step 7 is unambiguous.
Create a single account using local user management rather than integrating a directory. See Local User Management, and Invite Code and Device Enrollment to register the account on a device.
Access in CSE is granted through a role and a policy rather than by naming individual users on a resource:
Install the CSE desktop app on the test device and register it. See Register the Desktop App.
Sign in as the test user, select the Service Tunnel in the app, and connect.
On the test device, with the tunnel connected:
In the CSE console, confirm that the connection is recorded. See Visibility and Logging.
If the resource is not reachable, see Service Tunnel troubleshooting.
The path is now validated for one user. Extend the configuration in the following order:
The following capabilities narrow what has been granted: