Getting Started With CSE

Description

Welcome to SonicWall Cloud Secure Edge (CSE). The articles in this section provide the steps to prepare your environment and deploy Cloud Secure Edge.

Prerequisites #

Before proceeding, ensure that you have the following:

  1. A private network or a private service that you’d like to be able to access remotely.

  2. A computer on this network that can make outbound HTTPS (port 443) connections and outbound UDP connections to the CSE Global Edge Network (ports in the range of 21000 - 59999).

  3. A back up of your Gen7 (or later version) firewall, if you have an existing firewall that you would like to use.

  4. Register CSE activation keys in MySonicWall.

Get started #

Step 1: Set up your user directory #

1.1 Do you have an existing identity provider for your end users?

If yes, then configure your IDP in Cloud Secure Edge:

If not, then use Cloud Secure Edge’s Local User Management to get started.

Step 2: Connect your network #

SonicWall Cloud Secure Edge offers two deployment models for access to your organization’s private resources: Self-hosted Private Edge and Global Edge. In most cases, your org will be provisioned so you can use one or both deployment models. Most of our customers will be using the Global Edge deployment model, and therefore deploying a Connector to connect their network.

2.1 Do you have a Gen 7 (or later version) firewall?

Step 3: What would you like to accomplish with Cloud Secure Edge? #

Below, we’ve outlined the most common use cases for Cloud Secure Edge.

3.1 Pick your path:

For a deeper understanding of Cloud Secure Edge licenses, see our licenses doc.

Guided Onboarding Set-up #

The Cloud Secure Edge admin console offers a one-time guided onboarding set-up for orgs that meet the following conditions:

  • Global Edge deployment (or Global Edge + Private Edge deployment)
  • An SPA license
  • A MySonicWall provisioned org (i.e., not a Managed Service Provider (MSP) org) accessed via admin SSO

If you want to set up a Service Tunnel (i.e., set up remote access) using CSE, this guided onboarding set up will help you accomplish that.

Note: If the admin directly exits the Guided Onboarding Set Up (i.e., clicks Exit at any given point), they will not be able to return to the Onboarding Set Up; if the admin indirectly exits the Guided Onboarding Set Up (i.e., closes their browser), the Onboarding Set Up will be available exactly where they left off.

Set Up Remote Access

Use Cloud Secure Edge to set up a remote access VPN for your organization

Step 1: Create a Service Tunnel Policy #

1.1 On the Publish a Service Tunnel doc, navigate from Steps to Publish a Service Tunnel > Step 1: Create a Tunnel Policy. Follow this step to create a Service Tunnel Policy in your org.

1.2 Is SCIM enabled in your org?

  • If yes, then directly assign your users to the Service Tunnel Policy.

  • If not, then instruct your end users to log into the CSE app and register their devices; Afterward, assign your end users to the Service Tunnel Policy.

Step 2: Add a Service Tunnel #

2.1 Create a Service Tunnel;

2.2 Apply the Tunnel Policy (created above in Step 1.1) to the tunnel, so that your end users can access the Service Tunnel.

 

Block Malicious Content

Use Cloud Secure Edge to block users in your org from encountering malicious internet content

Step 1: Create an Internet Threat Protection Policy #

1.1 Create an ITP policy.

1.2 Is SCIM enabled in your org?

  • If yes, then directly assign users to your ITP policy.

  • If not, then instruct end users to log into the CSE app and register their devices; Afterward, assign your end users to the policy.

Step 2: Exclude Users from the Policy #

2.1 On the Managing Internet Threat Protection Policies doc, navigate to the Exclude Users from ITP Policies section to learn how to exclude specific users in your org from the ITP policy.

 

Protect your SaaS Apps

Use Cloud Secure Edge provide protected access to your org's SaaS apps

Step 1: Create a Service Tunnel Policy #

1.1 On the Publish a Service Tunnel doc, navigate from Steps to Publish a Service Tunnel > Step 1: Create a Tunnel Policy to create an access policy. This access policy determines which of your end users can access your Service Tunnel.

1.2 Is SCIM enabled in your org?

  • If yes, then directly assign users to your Tunnel policy.

  • If not, then instruct end users to log into the CSE app and register their devices; Afterward, assign your end users to the Service Tunnel policy.

Step 2: Add a Service Tunnel #

2.1 Create a Service Tunnel.

2.2 Configure a SaaS app (via allowing IPs) in your Service Tunnel configuration: On the Publish a Service Tunnel doc (linked above in Step 2.1), navigate to Network Settings and see Step 2.4 for how to configure a SaaS app.

 

Set Up Zero Trust Network Access (ZTNA)

Use Cloud Secure Edge to provide users in your org with granular access to protected services

Step 1: Create an Access Policy #

1.1 On the Register a Hosted Website to Users doc, navigate to Steps to create a hosted website > Step 1: Create a policy for web access. Follow this step to create a web access policy.

1.2 Is SCIM enabled in your org?

  • If yes, then directly assign users to your access policy.

  • If not, then instruct end users to log into the CSE app and register their devices; Afterward, assign your end users to the policy.

Step 2: Configure a Hosted Website #

2.1 On the Register a Hosted Website to Users doc, complete Step 2 and 3.

 

 

Check Devices' Security Posture

Use Cloud Secure Edge to provide users in your org with granular access to protected services

Step 1: Learn about Trust Profiles #

1.1 Follow the steps outlined on the Trust Profile doc to learn about how Trust Profiles function.

Step 2: Create a Trust Profile for a Set of User Roles using a Trust Factor #

2.1 Use any implementation of a Trust Profile configuration (e.g., the Application Check Trust Factor) as a template for how to configure a Trust Profile to check your devices’ security posture.

Related Articles

  • Cloud Secure Edge (CSE) Global Edge Network
    Read More
  • Cloud Secure Edge (CSE) Cloud Command Center
    Read More
  • SonicWall CSE: Install Connector using Windows Executable
    Read More
not finding your answers?