Initial Setup Guide of SMA1000 for high security environments
11/22/2021 1 People found this article helpful 32,962 Views
This document details the best practices to follow in a Department of Defense Information Network Approved Products List Military Unique Deployment, including deploying appliances, setting policies. This is intended to assist site administrators in configuring and deploying a SonicWall Secure Mobile Access (SMA) device following best practices and FIPS 140-2 and UC_APL certification
- Power up the unit (or primary if there are others to be used in a redundant configuration through the Central Management System (CMS)).
- Enter the IP and gateway addresses through the LCD on the front panel.
- Continue the initial setup at http://[IP address of the new unit]:8443
a. Accept the license agreement.
b. Change the primary administrator password, select the appropriate Time Zone, and change the time if necessary.
c. Set the appliance name and configure the external interface (if applicable).
d. Select the appropriate Routing Mode and set the Gateway address(es).
e. Enter the Domain Name and set the DNS server address(es).
f. Set the User Access Method (e.g., Enable On-Demand Tunnel and set the NAT-IP if applicable); Choose the appropriate Access Policy.
g. Verify the settings reflected in the Summary screen and select Finish.
Authentication Server setup:
Create Authentication Servers (System Configuration/Authentication Servers/New).
b. Active Directory Server:
Check the Active Directory over SSL option to maintain FIPS compliance.
c. PKI Server:
Realms and Communities Setup:
Create realms in User Access/Realms. Realms are tied to a specific Authentication server. Realms serve as a means for tying together particular access methods, users, authentication servers, and resources.
Create communities within each realm (User Access/Realms/[appropriate realm]/Communities).
NOTE: There is no community for the PKI realm because anyone with a CAC card that contains the proper certificates can authenticate. An individual authenticated by the PKI server will then be passed to the Active Directory authentication server for further authentication and authorization as part of the PKI Realm’s chained authentication.
Add or create users. Options include mapping users and groups to SMA user and group accounts by browsing the Active Directory tree or creating users and group accounts locally. NOTE: You will not add or map users and groups to the PKI authentication server, as it will authenticate all CAC holders with the CA and DoD certs also contained within the SMA (see the PKI authentication server creation).
a. Mapped via Active Directory (Security Administration/Users and Groups):
b. Local (Security Administration/Local Accounts):
Assigning Admin Roles:
Add users to administrative roles System Configuration/General Settings/Administrators/Administrator Accounts.
A good practice is to create additional local users that are associated with an administrative role to ensure the organization can access and administer the SMA even when the Active Directory server (or other network-connected authentication servers) is unavailable.
Put the device into FIPS mode (System Configuration/General Settings/FIPS Security). Note: Turning on FIPS mode will cause a reboot and delete all existing certificates on the appliance.
Enter the following CEM extensions in System Configuration/Maintenance/Advanced.
Import the local CA and DOD certificates in SSL Settings/CA Certificates: Note: Certificate formats must be PKCS#7 or X509.
a. Import the local CA certificate
b. Import the DoD root certificate
c. Import DoD Intermediate certificates
The following references will help site administrators plan for and deploy the SMA, as well as assist in its administration:
Sonicwall SMA 12.1 Administration Guide - SMA 12.1 Administration Guide (sonicwall.com)
Sonicwall SMA 12.1 6210/7210 Quick Start Guide - Secure Mobile Access 6210/7210 Quick Start Guide (sonicwall.com)