background image

Getting Started Guide

Dell SonicWALL E-Class NSA Appliances

NETWORK SECURITY

NSA E5500

Summary of Contents for NSA E5500

Page 1: ...Getting Started Guide Dell SonicWALL E Class NSA Appliances NETWORK SECURITY NSA E5500 ...

Page 2: ...of Dell Inc Microsoft Windows Internet Explorer and Active Directory are trademarks or registered trademarks of Microsoft Corporation Other product and company names mentioned herein may be trademarks and or registered trademarks of their respective companies and are the sole property of their respective manufacturers 2013 03 P N 232 001052 55 Rev A NOTE A NOTE indicates important information that...

Page 3: ...re internet access Dell SonicWALL NSA E5500 Note Always observe proper safety and regulatory guidelines when removing administrator serviceable parts from the Dell SonicWALL NSA E5500 Proper guidelines can be found in the Product Safety and Regulatory Information on page 68 I o PML Front Back 1U rack mountable 17 x 16 75 x 1 75 in 43 18 x 42 54 x 4 44 cm 17 30 lbs 7 9 kg 17 30 lbs 7 9 kg E5500 Net...

Page 4: ... Bezel Configuration Example page 16 Chapter 2 Sections Include Registering the Appliance page 18 Before You Register page 19 Creating a MySonicWALL Account page 20 Registering and Licensing the Appliance on MySonicWALL page 20 Chapter 3 Sections Include Deployment Scenarios page 24 Selecting a Deployment Scenario page 25 Initial Setup page 29 Configuring a Stateful HA Pair page 37 Configuring L2 ...

Page 5: ... page 55 Chapter 5 Sections Include Support and Training Options page 56 Customer Support page 57 Knowledge Portal page 57 User Forums page 58 Training page 59 Related Documentation page 60 Dynamic Tooltips page 61 Dell SonicWALL Live Product Demos page 61 Chapter 6 Sections Include Rack Mounting Instructions page 62 Rack Mounting Instructions page 63 Chapter 7 Sections Include Product Safety and ...

Page 6: ...n information Review this section before setting up your Dell SonicWALL NSA E5500 Check Package Contents page 7 Obtain Configuration Information page 8 The Front Panel page 10 The Back Panel page 11 Front Bezel Control Features page 12 Front Bezel Configuration Example page 16 1 ...

Page 7: ... for use only in specific countries or regions Before using a power cord verify that it is rated and approved for use in your location The power cords are for AC mains installation only Missing Items If any items are missing from your package contact Dell SonicWALL Support Web http www sonicwall com us Support html Email customer_service sonicwall com 1 E5500 Network Security Appliance 3 4 2 5 7 6...

Page 8: ...nd on the bottom panel of your SonicWALL appliance LAN IP Address Select a static IP address for your SonicWALL appliance that is within the range of your local subnet If you are unsure you can use the default IP address 192 168 168 168 Subnet Mask Record the subnet mask for the local subnet where you are installing your SonicWALL appliance Ethernet WAN IP Address Select a static IP address for yo...

Page 9: ...r to the SonicOS Administrator s Guide http www sonicwall com us support html Admin Name Select an administrator account name default is admin Admin Password Select an administrator password default is password If you connect using Please record DHCP No information is usually required Some providers may require a Host name Static IP IP Address Subnet Mask Default Gateway Primary DNS DNS 2 optional...

Page 10: ...sion Reset Button Press and hold the button for a few seconds to manually reset the appliance LED from left to right Power LED Indicates the Dell SonicWALL NSA E5500 is powered on Test LED Flickering Indicates the appliance is initializing Steady blinking Indicates the appliance is in SafeMode Solid Indicates that the appliance is in test mode Alarm LED Indicates an alarm condition HD LED Future e...

Page 11: ...apply Please read the Safety Instructions before use See the Product Safety and Regulatory Information on page 68 Icon Feature Description Expansion Bay Future extension Fans 2 The Dell SonicWALL NSA E5500 includes two fans for system temperature control Power Supply The Dell SonicWALL NSA E5500 power supply I o PML A B C ...

Page 12: ...isting of four buttons Up Down Left Right The table below describes the functions of the buttons Icon Feature Description LCD Screen Displays the front panel bezel interface which can be used to display status information perform basic configurations restart the appliance or boot the appliance in SafeMode Control Buttons Up Down Left and Right buttons used to navigate the LCD menu system ETWORK 3E...

Page 13: ...atistical readings Current number of connections Interface X0 X1 network settings Interface X0 X1 data transfer statistics The X1 DNS1 3 entries will only be displayed if they have been set from the Configure menu If their value is still 0 0 0 0 default value they will not appear in the Status List Contains basic status values including system resources connections and port configuration values Al...

Page 14: ...liance enters Screen Saver Mode whether from the 6 second time out or from pressing the Left button from the Main Menu the PIN number must be re entered again to access the Configuration Menu After entering a new value for a setting in the configuration menu you are asked if you want to commit changes Using the 4 way D pad press the Right button for yes or the Left button for no If you choose yes ...

Page 15: ...t Y for yes and press the Right button to confirm The appliance will reboot SafeMode This option will set the appliance to SafeMode Once selected the LCD will display a confirmation prompt Select Y for yes and press the Right button to confirm The appliance will change to SafeMode Once SafeMode is enabled the NSA E5500 must be controlled from the Web management interface Screen Saver If no button ...

Page 16: ...he cursor displays 6 press Right 7 Press Up or Down until the cursor displays 6 press Right 8 Press Up or Down until the cursor displays 4 press Right 9 Press Up or Down until the cursor displays 2 press Right 10 Press Right 11 Press Down until X1 IP is selected four times 12 Press Right to configure X1 IP Edit X1 IP 13 Press Right ten times to select the tenth digit 14 Press UP or Down until the ...

Page 17: ......

Page 18: ...500 Before You Register page 19 Creating a MySonicWALL Account page 20 Registering and Licensing the Appliance on MySonicWALL page 20 Note Registration is an important part of the setup process and is necessary in order to receive the benefits of Dell SonicWALL security services firmware updates and technical support 2 ...

Page 19: ...r a High Availability configuration you must use MySonicWALL to associate a backup unit that can share the Security Services licenses with your primary Dell SonicWALL Note Your Dell SonicWALL NSA E5500 does not need to be powered on during account creation or during the MySonicWALL registration and licensing process Note After registering a new Dell SonicWALL appliance on MySonicWALL you must also...

Page 20: ...ns Product Registration page 20 Licensing Security Services and Software page 21 Registering a Second Appliance as a Backup page 22 Registration Next Steps page 23 Product Registration You must register your Dell SonicWALL security appliance on MySonicWALL to enable full functionality 6 Login to your MySonicWALL account 7 On the main page in the Register A Product field type the appliance serial n...

Page 21: ...pport Services Dynamic Support 24x7 Software and Firmware Updates Consulting Services Implementation Service GMS Preventive Maintenance Service To manage your licenses perform the following tasks 1 In the MySonicWALL Service Management Associated Products page check the Applicable Services table for services that your SonicWALL appliance is already licensed for Your initial purchase may have inclu...

Page 22: ...Backup To ensure that your network stays protected if your Dell SonicWALL appliance has an unexpected failure you can associate a second appliance with the first in a high availability HA pair You can associate the two appliances as part of the registration process on MySonicWALL The second appliance will automatically share the Security Services licenses of the primary appliance To register a sec...

Page 23: ... that you do not miss any reporting data in the event of a failover You must also purchase a seperate support license for the backup unit Under DESKTOP SERVER SOFTWARE click Buy Now for Analyzer Follow the instructions to complete the purchase 8 To return to the Service Management Associated Products page click the serial number link for this appliance Registration Next Steps Your Dell SonicWALL N...

Page 24: ...AT Route Mode Gateway page 26 Scenario B State Sync Pair in NAT Route Mode page 27 Scenario C L2 Bridge Mode page 28 Initial Setup page 29 Configuring a Stateful HA Pair page 37 Configuring L2 Bridge Mode page 43 Tip Before completing this section fill out the information in Obtain Configuration Information on page 8 and Obtain Internet Service Provider ISP Information on page 9 You will need to e...

Page 25: ...le SonicWALL NSA as a primary gateway A NAT Route Mode Gateway Pair of SonicWALL NSA appliances for high availability B NAT with State Sync Pair Existing Internet gateway appliance SonicWALL NSA as replacement for an existing gateway appliance A NAT Route Mode Gateway SonicWALL NSA in addition to an existing gateway appliance C L2 Bridge Mode Existing SonicWALL gateway appliance SonicWALL NSA in a...

Page 26: ...appliance for load balancing and failover purposes Because only a single SonicWALL appliance is deployed the added benefits of high availability with a stateful synchronized pair are not available To set up this scenario follow the steps covered in Initial Setup on page 29 If you have completed setup procedures in that section continue to Additional Deployment Configuration on page 46 to complete ...

Page 27: ...primary device loses connectivity Note Active Active pair functionality is also available for high availability deployments For more information on the benefits and setup instruction for Active Active pair see the SonicOS Active Active Feature Module at http www sonicwall com us support html To set up this scenario follow the steps covered in Initial Setup on page 29 and Configuring a Stateful HA ...

Page 28: ...curity appliance integration Using L2 Bridge Mode a SonicWALL security appliance can be non disruptively added to any Ethernet network to provide in line deep packet inspection for all traversing IPv4 TCP and UDP traffic L2 Bridge Mode can pass all traffic types including IEEE 802 1q VLANs Spanning Tree Protocol multicast broadcast and IPv6 To set up this scenario follow the steps covered in Initi...

Page 29: ...ection page 32 Activating Licenses in SonicOS page 33 Upgrading Firmware page 33 System Requirements Before you begin the setup process check to verify that you have An Internet connection A Web browser supporting Java Script and HTTP uploads Connecting the WAN Port 1 Connect one end of an Ethernet cable to your Internet connection 2 Connect the other end of the cable to the X1 WAN port on your NS...

Page 30: ...pliance performs a series of diagnostic tests When the Power LEDs are lit and the Test LED is no longer lit the Dell SonicWALL NSA E5500 is ready for configuration This typically occurs within a few minutes of applying power to the appliance Warning When disconnecting power be sure to remove both power cords from the unit Note If the Test or Alarm LEDs remain lit after the Dell SonicWALL NSA E5500...

Page 31: ...a Connection settings on your computer set to use DHCP or set to a static IP address on the 192 168 168 x 24 subnet Do you have the Ethernet cable connected to your computer and to the X0 LAN port on your security appliance Is the connector clip on your network cable properly seated in the port of the security appliance Some browsers may not launch the Setup Wizard automatically In this case Log i...

Page 32: ...zard the login page reappears Log back into the Management Interface and verify your IP and WAN connection 2 Ping a site outside of your local network such as http www sonicwall com 3 Open another Web browser and navigate to http www sonicwall com If you can view the Dell SonicWALL home page you have configured your Dell SonicWALL NSA E5500 correctly If you cannot view the Dell SonicWALL home page...

Page 33: ...al setup is already complete you can synchronize licenses from the System Licenses page Manual upgrade using the license keyset is useful when the appliance is not connected to the Internet The license keyset includes all license keys for services or software enabled on MySonicWALL It is available on MySonicWALL at the top of the Service Management page for the appliance To activate licenses in So...

Page 34: ...ell SonicWALL security appliance Perform the following procedures to save a backup of your configuration settings and export them to a file on your local management station 1 On the System Settings page click Create Backup Your configuration preferences are saved The System Backup entry is displayed in the Firmware Management table 2 To export your settings to a local file click Export Settings A ...

Page 35: ...ode to Upgrade Firmware If you are unable to connect to the Dell SonicWALL security appliance s management interface you can restart the appliance in SafeMode The SafeMode feature allows you to recover quickly from uncertain configuration states with a simplified management interface that includes the same settings available on the System Settings page To use SafeMode to upgrade firmware on the De...

Page 36: ...ed Firmware New Use this option to restart the appliance with your current configuration settings Uploaded Firmware with Factory Default Settings New Use this option to restart the appliance with default configuration settings 7 In the confirmation dialog box click OK to proceed 8 After successfully booting the firmware the login screen is displayed If you booted with factory default settings ente...

Page 37: ...urity appliance locate the serial number and write the number down You need to enter this number in the High Availability Settings page Verify that the primary and secondary Dell SonicWALL security appliances are registered running the same SonicOS versions Make sure the primary and secondary Dell SonicWALL security appliances LAN WAN and other interfaces are properly configured for failover Conne...

Page 38: ...nchronization A dialog box is displayed with recommended settings for the Heartbeat Interval and Probe Interval fields The settings it shows are minimum recommended values Lower values may cause unnecessary failovers especially when the appliance is under a heavy load You can use higher values if your SonicWALL handles a lot of network traffic Click OK 3 To cause the HA pair to change back to the ...

Page 39: ...ails over The Election Delay Time can be used to specify an amount of time the appliance will wait to consider an interface up and stable before one of them takes the primary role This is useful when dealing with switch ports that have a spanning tree delay set The Dynamic Route Hold Down Time setting is used when a failover occurs on a HA pair that is using either RIP or OSPF dynamic routing When...

Page 40: ...e 3 In the Secondary IP Address field enter the unique LAN or WAN management IP address of the Secondary appliance 4 Select the Allow Management on Primary Secondary IP Address checkbox 5 Optionally Enable Physical Link Monitoring by selecting the checkbox 6 Optionally enable Logical Probe IP Address by selecting the checkbox and providing the IP Address of the target host 7 Click OK You can repea...

Page 41: ...wait a few minutes then power off the Primary Dell SonicWALL device The secondary Dell SonicWALL security appliance should quickly take over From your management workstation test connectivity through the secondary Dell SonicWALL by accessing a site on the public Internet note that the secondary Dell SonicWALL when active assumes the complete identity of the primary including its IP addresses and E...

Page 42: ...n is used during HA so that the secondary appliance can maintain the same level of network protection provided before the failover To enable HA you can use the SonicOS UI to configure your two appliances as a HA pair in Active Idle mode MySonicWALL provides several methods of associating the two appliances You can start by registering a new appliance and then choosing an already registered unit to...

Page 43: ... you want to associate as the child secondary backup unit 7 Select the group from the Product Group drop down list The product group setting specifies the mysonicwall users who can upgrade or modify the appliance 8 Click Register Configuring L2 Bridge Mode This section provides instructions to configure the Dell SonicWALL NSA E5500 appliance in tandem with an existing Internet gateway device This ...

Page 44: ... Configuring the Secondary Bridge Interface Complete the following steps to configure the Dell SonicWALL appliance 1 Navigate to the Network Interfaces page from the navigation panel 2 Click the Configure icon in the right column of the X0 LAN interface 3 In the IP Assignment drop down select Layer 2 Bridged Mode 4 In the Bridged to drop down select the X1 interface 5 Configure management options ...

Page 45: ...at all packets entering the L2 Bridge remain on the L2 Bridge segments You may optionally enable the Block all non IPv4 traffic setting to prevent the L2 bridge from passing non IPv4 traffic If You Are Following Scenario Proceed to Section C L2 Bridge Mode Additional Deployment Configuration page 46 ...

Page 46: ...his section also contains several SonicOS diagnostic tools and a deployment configuration reference checklist An Introduction to Zones and Interfaces page 47 Creating a NAT Policy page 48 Enabling Security Services in SonicOS page 51 Applying Security Services to Zones page 52 Troubleshooting Diagnostic Tools page 52 Deployment Configuration Reference Checklist page 55 4 ...

Page 47: ... X1 or X2 on the Dell SonicWALL appliance The X1 and X0 interfaces are preconfigured as WAN and LAN respectively The remaining ports can be configured to meet the needs of your network either by using basic zone types WAN LAN WLAN DMZ VPN or configuring a custom zone type to fit your network requirements for example Gaming Console Zone Wireless Printer Zone Wireless Ticket Scanner Zone A zone is a...

Page 48: ... Address User Service and Schedule in SonicOS These Address Objects allow for entities to be defined one time and to be re used in multiple referential instances throughout the SonicOS interface For example take an internal Web server with an IP address of 67 115 118 80 Rather than repeatedly typing in the IP address when constructing Access Rules or NAT Policies Address Objects allow you to creat...

Page 49: ...SonicWALL security appliance To add an Address Object 1 Navigate to the Network Address Objects page 2 Below the Address Objects table click Add 3 In the Add Address Object dialog box enter a name for the Address Object in the Name field 4 Select the zone to assign to the Address Object from the Zone Assignment drop down list 5 Select Host Range Network MAC or FQDN from the Type menu If you select...

Page 50: ...the request as coming from the IP address of the Dell SonicWALL security appliance WAN port and not from the internal private IP address For other NAT configurations see the SonicOS Administrator s Guide An example configuration illustrates the use of the fields in the Add NAT Policy procedure To add a Many to One NAT policy that allows all systems on the X1 interface to initiate traffic using the...

Page 51: ...ally in the SonicOS user interface See the following procedures to enable and configure the following three basic security services Gateway Anti Virus Intrusion Prevention Anti Spyware For more information on configuring your security services refer to the SonicOS Administrator s Guide ...

Page 52: ...k zones 1 Navigate to the Network Zones page 2 In the Zone Settings table click the Configure icon for the zone where you want to apply security services 3 In the Edit Zone dialog box on the General tab select the checkboxes for the security services to enable on this zone 4 On the Edit Zone page select the checkboxes for the security services that you want to enable 5 Click OK 6 To enable securit...

Page 53: ...ections matching certain criteria You can filter by Source IP Destination IP Destination Port Protocol Src Interface and Dst Interface Enter your filter criteria in the Active Connections Monitor Settings table The fields you enter values into are combined into a search string with a logical AND Select the Group Filters box next to any two or more criteria to combine them with a logical OR Using L...

Page 54: ... click Start without any configuration the Dell SonicWALL appliance will capture all packets except those for internal communication and will stop when the buffer is full or when you click Stop The SonicOS user interface provides three windows to display different views of the captured packets Click the Configure button to customize the settings for the capture Settings are available in the five m...

Page 55: ...curity Services on Zones section Configuring Web filtering protection Configuring SonicWALL Content Filtering Service Changing administrator login Configuring Administration Settings Administrator Name Password section Setting administrator email Configuring Log Automation Email Log Automation section Disabling HTTP and ping access Configuring Interfaces Configuring Advanced Settings for the Inter...

Page 56: ...overviews of customer support and training options for the Dell SonicWALL NSA E5500 Customer Support page 57 Knowledge Portal page 57 User Forums page 58 Training page 59 Related Documentation page 60 Dynamic Tooltips page 61 Dell SonicWALL Live Product Demos page 61 5 ...

Page 57: ...services to meet your needs from our innovative implementation services to traditional statement of work based services For further information visit http www sonicwall com us support contact html Knowledge Portal The Knowledge Portal is a resource which allows users to search for Dell SonicWALL documents based on the following types of search tools Browse Search for keywords Full text search For ...

Page 58: ...urity Manager topics Continuous Data Protection topics Email Security related topics Firewall related topics Network Anti Virus related topics Security Services and Content Filtering topics GMS and Analyzer related topics SonicPoint and Wireless related topics SSL VPN related topics TZ 190 Wireless WAN 3G Capability VPN Client related topics VPN site to site and interoperability topics For further...

Page 59: ...need to enhance their knowledge and maximize their investment in Dell SonicWALL Products and Security Applications Dell SonicWALL Training provides the following resources for its customers E Training Instructor Led Training Custom Training Technical Certification Authorized Training Partners For further information visit http www sonicwall com us support training html ...

Page 60: ...ashboard HA License Sync Multiple Admin NAT Load Balancing Packet Capture RF Management Single Sign On SSL Control Virtual Access Points GVC Administrator s Guide Analyzer Administrator s Guide GAV Administrator s Guide IPS Administrator s Guide Anti Spyware Administrator s Guide CFS Administrator s Guide For further information visit http www sonicwall com us support 289 html ...

Page 61: ...LL Live Product Demos The Dell SonicWALL Live Demo Site provides free test drives of Dell SonicWALL security products and services through interactive live product installations Unified Threat Management Platform Secure Cellular Wireless Continuous Data Protection SSL VPN Secure Remote Access Content Filtering Secure Wireless Solutions Email Security GMS and Analyzer For further information visit ...

Page 62: ...Rack Mounting Instructions In this Section This section provides illustrated rack mounting instructions for the Dell SonicWALL NSA E5500 Rack Mounting Instructions page 63 6 ...

Page 63: ...Rack Mounting Instructions M4 SCREW 8 WASHERS 8 Fasten 4 screws to the rail Assemble the Slide Rail 1 1 A B A B ...

Page 64: ...M5 SCREW 8 M5 Nut 8 Assemble the Slide Rail Fasten two sided screws to the rail 2 C C ...

Page 65: ...Assemble Inner Rail to Chassis Fasten 6 screws to attach the inner channel onto the chassis M4 SCREW 6 3 D D ...

Page 66: ...Insert Chassis to Frame 4 Push hook down to separate Slide inner channel into rails ...

Page 67: ......

Page 68: ...d Regulatory Information In this Section This section provides regulatory along with trademark and copyright information Safety and Regulatory Information page 69 Warranty Information page 73 Copyright Notice page 73 7 ...

Page 69: ...de when purchasing materials or components Consideration must be given to the connection of the equipment to the supply circuit Appropriate consideration of equipment nameplate ratings must be used when addressing this concern Do not overload the circuit Reliable grounding of rack mounted equipment must be maintained Particular attention must be given to power supply connections other than direct ...

Page 70: ... Sie den Anschluss des Geräts an die Stromversorgung damit der Überstromschutz sowie die elektrische Leitung nicht von einer eventuellen Überlastung der Stromversorgung beeinflusst werden Prüfen Sie dabei sorgfältig die Angaben auf dem Aufkleber des Geräts Überlasten Sie nicht den Stromkreis Eine sichere Erdung der Geräte im Rack muss gewährleistet sein Insbesondere muss auf nicht direkte Anschlüs...

Page 71: ...險狀況 必須使用四顆與機架設計相容的安裝螺釘 並用手鎖緊螺釘 確定安裝牢固 選擇一個安裝位置 將四個裝載洞孔對齊 19 吋架設機櫃的安裝桿 應當提供一個合適額定值並且已被認可的分支電路斷路器作 為安裝該裝置的一部分 在購買材料或部件時 應遵循當地安 全代碼 必須留心裝置與電源電路的連接問題 電路過載對過電流保 護與電路電線的影響需降至最低 解決這個問題時 需正確考 慮裝置銘牌額定值 不要過載電路 必須維護可靠的機架裝載設備接地 必須特別留意電源供應 器連線 而不是直接連接到電源板之類的分支電路 從工廠運出時 這個戴爾 SonicWALL 產品包括為後備交流電 源和增加可靠性而附帶的兩個電源 要斷開交流電源 兩條電源線都必須被拔除 隨附的電源線僅限於特定的國家或地區使用 使用前 請確 認電源線的額定值且已被認可在你的地區上使用 這個型號出貨時附帶的交流電源 是標準三芯器具耦合器的 配置 切勿...

Page 72: ...his manual without the written consent of Dell Inc could void the user s authority to operate this equipment BMSI Statement 警告使用者 此為甲類資訊技術設備 於居住環境中使用時 可能會造成射 頻擾動 在此種情況下 使用者會被要求採取某些適當的對策 VCCI Statement この装置は クラスA情報技術装置です この装置を家庭環境 で使用すると電波妨害を引き起こすことがあります この場合 には使用者が適切な対策を講ずるよう要求 されることがあります VCCI A Canadian Radio Frequency Emissions Statement This Class A digital apparatus complies with Canadian ICES...

Page 73: ... 2013 Dell Inc All rights reserved Under the copyright laws this manual or the software described within cannot be copied in whole or part without the written consent of the manufacturer except in the normal use of the software to make a backup copy The same proprietary and copyright notices must be affixed to any permitted copies as were affixed to the original This exception does not allow copie...

Page 74: ......

Reviews: