SonicWall Endpoint Security (SES) MDR : Frequently Asked Questions (FAQs)

Description

Frequently Asked Questions about our SonicWall Endpoint Security (SES) Fully Managed - MDR offering.

GENERAL

Is a Proof of Concept (PoC) available?

Yes, we offer a 21 day Proof of Concept for our new partners.

What is involved with a Proof of Concept?
Will my licensing automatically convert to production at the end of the PoC?
  • Yes, we will convert the SES MDR accounts and associated tenant licensing to SES MDR monthly services at the end of the 21 day POC to continue protection and begin billing in the next billing phase
  • You can opt out of moving to production prior to the end of your 21 day PoC
What are the responsibilities of the partner?
  • Management of the deployment process
    • Deployment of the SES Agents to all devices in the environment
  • Removal of any pre-existing AV software, timing coordinated with SonicSentry support/onboarding team
  • Alert SonicSentry support/onboarding team when a device is decommissioned/uninstalled
  • Alert SonicSentry support/onboarding team when you are ready to onboard an additional tenant/customer
  • Inform SonicSentry of any updates/changes to the Approved Software List(s)
  • Providing Tier 1 support to your users
  • Contacting SonicSentry for any Tier 2 or Tier 3 issues that you are unable to resolve
  • Further investigate alerts sent from the SonicSentry SOC
What are the Deliverables from SonicSentry Services?

  • Initial configuration of the service platform architecture, including provisioning of portals and access for the MDR service
  • Consultative guidance and support for onboarding and initial provisioning of endpoints within a multi-tenant architecture
  • Guidance for migration of existing endpoint security licenses and agents during onboarding, including transitioning deployed agents into the MDR service or a managed security console, where supported
  • Provisioning and pre-staging of recommended baseline policies to support service onboarding
  • Ongoing changes to policies including enabling/disabling protection, configuring exclusions and blocklists, creating and managing custom rules and configuring device control rules
  • Updating and maintaining Approved Software Lists(s) based on updates from partner
  • Configuration and provisioning of log ingestion into the XDR/SIEM platform, including API-based integrations and syslog forwarding where applicable
  • Provisioning of service-related training, support, and documentation
  • Security Operations Center (SOC) monitoring services, including detection and alerting of abnormal, suspicious, or potentially malicious activity, along with initial investigations, response actions and remediation guidance
  • Access to service-related management portals and dashboards, including the endpoint detection and response (EDR/XDR) platform, ticketing system, and associated SOC monitoring and reporting interfaces
  • The MDR service empowers the SOC to take response actions, including host quarantine and process termination, these actions are executed without seeking additional permission, and will be discussed during service enrollment

IMPLEMENTATION

What devices do I need to install the SonicWall Endpoint Security (SES) agent on?
  • The SES agent should be deployed on all supported devices in an environment
Is Multi-Tenancy supported?
  • Yes, all SonicWall Endpoint Security accounts are setup with a ‘Parent-Child’ architecture
    • Partners will be able to create their own tenants and onboard additional clients as desired
    • Partners should communicate with our support team when spinning up new tenants and onboarding additional clients

SUPPORT

How do I contact support?
  • To initiate a support request, visit https://msssupport.myportallogin.com
    • When prompted, select Endpoint Security, then choose SES Support
  • Schedule a Meeting:
  • Emergency Support:
    • Available 24/7 for our MDR Partners: Please call 703.565.2395
  • Standard Support Hours:
    • Monday - Friday, 3:00 AM - 8:00 PM EST
How do I access SonicWall Endpoint Security (SES) documentation?
Is training provided?
  • SonicSentry fully manages the policies and any needed exclusions
  • Training/Documentation is provided for installing the SES agent
 

MONITORING

How are SonicWall Endpoint Security (SES) logs retained?
  • The SES agent syslogs are sent from the central management console to our SIEM/SOAR for SOC services
    • These logs are maintained for 1 year
Do I get access to the SIEM?
  • MDR partners are granted access to our SIEM (by request) for visibility and reporting purposes
Is your SOC outsourced?
  • No. Our SOC is a 24x7x365 in-house Security Operations Center
    • NOAM partners work with our US based and full time employees
    • EMEA partners work with our EMEA based and full time employees
How will partners be contacted about alerts or incidents?
  • Each partner should provide designated contact information for the following:
    • SES General: General communications, updates, and release notes
    • SOC Alerts: Notification of detected threats or alerts from the SOC
    • SOC Emergency Contact: Emergency phone contact
  • More details are available here: Fully Managed EPP SOC Alert Processing Summary

BILLING and LICENSING

How is licensing handled?
  • For Monthly Billed Partners:
    • Every month on the 25th (+/- 2 days) a snapshot of current usage is taken and will be used to provide your next invoice
      • Please be sure to notify SonicSentry support/onboarding teams of any unwanted/duplicate devices etc.. by the 20th, at the latest, to avoid being billed for them
    • The invoice will then be provided by your distributor
    • The License Report is also available via MySonicWall on the 1st
  • For Yearly Committed Partners:
    • If your monthly usage is over your annual commit, you will be invoiced for the overage for that month
    • Every month on the 25th (+/- 2 days) a snapshot of current usage is taken and will be used to provide your next invoice
      • Please be sure to notify SonicSentry support/onboarding teams of any unwanted/duplicate devices etc.. by the 20th, at the latest, to avoid being billed for them
How do I get a breakdown of my devices per customer?
  • You can see current license usage when logged into MySonicWall under the Monthly Billing section
  • Additional information for using MySonicWall and viewing usage is available at the following link, specifically License Report starting on page 30
Will duplicate or retired devices be billed?
  • Yes. Please be sure to notify SonicSentry support/onboarding teams of any unwanted/duplicate devices etc.. to avoid being billed for them

Related Articles

  • SES MDR POC : Frequently Asked Questions (FAQs)
    Read More
  • MSS Managed Firewall Best Practice Configuration
    Read More
  • Cysurance - SonicWall Configuration Guide
    Read More
not finding your answers?