How to restrict SSLVPN access to the SonicWall firewall based on Source WAN IP's?
07/15/2021
5 People found this article helpful
188,025 Views
Description
This KB article depicts instructions on how to restrict SSLVPN connection to the SonicWall firewall appliance so that the device allows only authorized users to connect via SSLVPN. The SSLVPN users are limited for connection based on source Public IP addresses.
Resolution
Step 1 - SonicWall diag page setting change for auto-added access rules edit
Step 2 - Creating Address Objects and Address Group(s)
Step 3 - Updating the default SSLVPN access rule with the address objects created
Step 1 - SonicWall diag page setting change for auto-added access rules edit
1. Login to the firewall and visit the diag page by replacing the keyword main in URL with diag (For ex: https://ipaddress/diag.html) and hit enter.
2. Click on Internal Settings and search for the section Firewall Settings.
3. Enable the checkbox Enable the ability to remove and fully edit auto-added access rules.

4. Click on Accept to save the configuration.
5. Click on CLOSE to visit SonicWall's conventional GUI.
NOTE: Unfortunately, Gen 5 and Gen 5.5 firewall models are not embedded with the diag page option "Enable the ability to remove and fully edit auto-added access rules" to tweak the default rules/policies. Hence, Gen 5 and 5.5 firewall models do not follow this KB article. The embedded feature is available only from Gen 6 firewalls.
Step 2 - Creating Address Objects and Address Group(s)
6. Navigate to MANAGE | Objects | Address Objects page in the GUI.
7. In the Address Objects tab, click Add.

8. In the Address Object creation pop-up window, specify the Name, Zone Assignment, Type and IP Address details. (The address objects are created for the WAN IP addresses of the SSLVPN users)
9. Click ADD.

10. Put the address objects together in an Address Group by navigating to Address Groups tab and click on Add.

11. In the Address Group creation pop-up window, specify the Name of the group, enforce the address objects from LHS to RHS and click OK.

Step 3 - Updating the default SSLVPN access rule with the address objects created
12. Navigate to Rules | Access Rules page and visit WAN to WAN rules section.
13. Click on the Configure option of the default SSLVPN access rule as shown below.

14. To modify the access rule, in the General tab, change the Source field to the address objects/group containing the preferred public IP addresses of SSLVPN users and click OK.

15. The Default SSLVPN WAN access rule looks as below with source being specific.

Related Articles
Categories