SonicWall Cloud Secure Edge (CSE) uses WireGuard to create fast, secure tunnels utilizing state-of-the-art cryptography. Service Tunnels provide encrypted network connectivity to network segments - VLANs, VPCs, subnets, etc. While the objective of Zero Trust security is often to migrate away from granting full network access to users and instead provisioning access to specific corporate resources, there are some scenarios where full network access is necessary.
You can publish Service Tunnels when you need to enable:
As with the other service types, security policies are continuously enforced, locking down access based on user and device attributes and trust levels.
The flow diagram below describes how CSE's zero-trust access control mechanism works for Service Tunnels. Review the Publish a Service Tunnel to Users guide to see how to create a Zero Trust policy for a service tunnel so a user can access the tunnel via the desktop app.
Read about how routing works in CSE to secure access to your networks.