How to establish a secure SSLVPN connection from SonicWave to the SSLVPN Server?
04/07/2021 12 5981
This article describes the steps for SSL VPN Client configuration on SonicWave access points (managed via WCM) connecting to an SSLVPN server.
Traditionally SonicWall NetExtender Client or the Mobile Connect client is used to connect to an SSLVPN Server [Firewall or SMA 100 / SMA 1000]. When a SonicWave is managed via WCM, we can configure the access point to connect to the SSLVPN server which will provide wireless clients with secure access to network resources and servers.
NOTE: SonicWave access points only act as SSLVPN client, and not as an SSLVPN Server. SonicWall Firewall appliance or an SMA 100 / SMA 1000 device can be use as SSLVPN servers.
WCM- WiFi Cloud Manager
SSLVPN - Secure Socket Layer Virtual Private Network
SMA - Secure Mobile Access
CSC- Capture Security Center
Supported Access Points:
Step1: Make sure that an SSLVPN server is properly configured.
Step 2: Login into WiFi Cloud Manager:
- Log into CSC (cloud.sonicwall.com) using your MySonicwall username and password, click on the Wireless tile to access WCM.
CAUTION: This article's scope is to help setup SSL VPN client Profile and we assume that the SonicWave is being managed by WiFi Cloud Manger. If it is not please use this KB article: [[How do I register and deploy a SonicWave using Wireless Cloud Manager?|190317011046878]] to configure and manage SonicWaves on WiFi cloud Manager.
Step 3: Configure SSLVPN Client profile:
- Navigate to the Policies Tab | Policy Hierarchy | Select the Zone that the SonicWave belongs to [In Default settings the zone will be Default Policy]
- Navigate to the Right Pane of the screen and select SSL-VPN
- Enable the toggle switch for SSL-VPN
- Set the Server Address, Username,password and Domain for connecting to your already configured SSLVPN Server (From Step 1).
- Choose NX if you are connecting to a firewall or SMA 100 series appliance. Choose CT if you are connecting to a SMA 1000 series appliance.
NOTE: SonicWave supports tunnel-all and split-tunnel modes. Client route is determined by SSLVPN server "Client Routes" profile.
Step4: Allow SSL-VPN Security Tunnel Access on Specific SSID's:
CAUTION: If you do not Allow SSL-VPN Tunnel on any SSID you will not be able to access the resources that the SSL VPN Server has shared.
- Select the SSID that your Wireless Clients will connect to access resources via SSL Tunnel.
- Navigate to the Advanced tab on the right pane.
- Look for the option SSL-VPN secure tunnel access
- Enable the toggle switch.
Step5:Verify the SSL VPN Connection Status:
- Navigate to the network devices tab
- All the access points that share the zone for which we have enabled SSL VPN show display an Green Overlay on the SSLVPN Icon.
- If you hover on the icon it will display the Domain,Client IP,User,Server and the Remote Network and the DNS server IP acquired from the SSLVPN server.
Conclusion: We have successfully configured SSLVPN Client profile on the SonicWave via WiFi Cloud Manager.