Explanation of Management modes in GMS
Management Modes:
Explanation of each management mode and when to use them
1. Existing Tunnel/LAN:
With this management method all of the syslog files are transmitted in clear text between the firewall and the GMS server. If syslog is destined for a GMS server across a VPN, the VPN will provide encryption (of clear text syslog) while traffic is traversing the Internet. This is a very good mode for troubleshooting and simple setups, or setups with already configured S2S VPNs.
Over VPN:

2. HTTPS/SSL:
The logic is the same as with existing tunnel/LAN mode. However, syslog are encrypted. The encryption is based on the password of the admin account. This means you must use the admin account (of the SonicWall) when adding the SonicWall to GMS. This management method is good for any network topology that requires end to end encryption for syslogs messages.

The recommended management method is HTTPS/SSL.