When a firewall is added manually to NSM (Network Security Manager) the firewall acquisition fails on NSM with ‘Network down or Unit cannot be reached’ error as WAN IP used by NSM back-end is not the same as the resolved NSM fully qualified domain name (FQDN).
There is a WAN |WAN rule created on the firewall which allows HTTPS management access to the firewall from NSM. In many cases customer may lock down the access rule to NSM IP only which may prevent firewall acquisition on NSM.
Allow access to following NSM FQDN / IPs based on the CSC location to resolve the firewall acquisition issue.
For Oregon AWS Colo:
FQDN: nsm-uswest-syslog.sonicwall.com (Use it in GMS settings under Administration Page)
Zero Touch FQDN: nsm-uswest-zt.sonicwall.com (Use it in ZeroTouch Settings under Diag page)
Added below IPs in WAN Management access from WAN>WAN access rule