background image

49

   |   Creating a NAT Policy  

SonicOS provides a number of Default Address Objects that 
cannot be modified or deleted. You can use the Default Address 
Objects when creating a NAT policy, or you can create custom 
Address Objects to use. All Address Objects are available in the 
drop-down lists when creating a NAT policy.

Configuring Address Objects

The 

Network 

>

 Address Objects 

page allows you to create 

and manage your Address Objects. You can view Address 
Objects in the following ways using the 

View Style 

menu:

All Address Objects

—displays all configured Address 

Objects. 

Custom Address Objects

—displays Address Objects with 

custom properties. 

Default Address Objects

—displays Address Objects 

configured by default on the Dell SonicWALL appliance. 

To add an Address Object:

1.

Navigate to the 

Network

 > 

Address

 Objects page.

2.

Below the Address Objects table, click 

Add

.

3.

In the Add Address Object dialog box, enter a name for the 
Address Object in the 

Name 

field. 

4.

Select the zone to assign to the Address Object from the 

Zone Assignment 

drop-down list. 

5.

Select 

Host

Range

Network

MAC

, or 

FQDN 

from the 

Type 

menu. 

• If you selected 

Host

, enter the IP address in the 

IP 

Address 

field. 

• If you selected 

Range

, enter the starting and ending IP 

addresses in the 

Starting IP Address 

and 

Ending IP 

Address 

fields. 

• If you selected 

Network

, enter the network IP address 

and netmask in the 

Network 

and 

Netmask 

fields.

• If you selected 

MAC

, enter the MAC address and 

netmask in the 

Network 

and 

MAC Address 

field. 

• If you selected 

FQDN

, enter the domain name for the 

individual site or range of sites (with a wildcard) in the 

FQDN 

field.

6.

Click 

OK

.

Summary of Contents for NSA E8500

Page 1: ...Getting Started Guide Dell SonicWALL E Class NSA Appliances NETWORK SECURITY NSA E8500 ...

Page 2: ...soft Windows Internet Explorer and Active Directory are trademarks or registered trademarks of Microsoft Corporation Other product and company names mentioned herein may be trademarks and or registered trademarks of their respective companies and are the sole property of their respective manufacturers 2013 04 P N 232 001891 53 Rev A NOTE A NOTE indicates important information that helps you make b...

Page 3: ...in its class This Getting Started Guide provides instructions for basic installation and configuration of the Dell SonicWALL NSA E8500 Caution Always observe proper safety and regulatory guidelines when removing administrator serviceable parts from the Dell SonicWALL NSA E8500 Proper guidelines can be found in Product Safety and Regulatory Information on page 68 of this guide E8500 Network Securit...

Page 4: ... Control Features page 12 LAN IP Configuration Example page 16 Chapter 2 Sections Include Registering Your Appliance page 18 Before You Register page 19 Creating a MySonicWALL Account page 20 Registering and Licensing Your Appliance on MySonicWALL page 20 Chapter 3 Sections Include Deployment Scenarios page 24 Selecting a Deployment Scenario page 25 Initial Setup page 29 Configuring a Stateful HA ...

Page 5: ... page 54 Customer Support page 55 Knowledge Portal page 55 User Forums page 56 Training page 57 Related Documentation page 58 Dynamic Tooltips page 59 Dell SonicWALL Live Product Demos page 59 Dell SonicWALL Secure Wireless Network Integrated Solutions Guide page 60 Chapter 6 Sections Include Rack Mounting Instructions page 62 Rack Mounting Instructions page 63 Chapter 7 Sections Include Product S...

Page 6: ...tion information Review this section before setting up your Dell SonicWALL NSA E8500 Check Package Contents page 7 Obtain Configuration Information page 8 The Front Panel page 10 The Back Panel page 11 Front Bezel Control Features page 12 LAN IP Configuration Example page 16 1 ...

Page 7: ...ries or regions Before using a power cord verify that it is rated and approved for use in your location The power cords are for AC mains installation only Field conversion DC power cable is different see Safety and Regulatory Information for more information Missing Items If any items are missing from your package contact Dell SonicWALL Support Web http www sonicwall com us Support html Email cust...

Page 8: ...s Select a static IP address for your Dell SonicWALL appliance that is within the range of your local subnet If you are unsure you can use the default IP address 192 168 168 168 Subnet Mask Record the subnet mask for the local subnet where you are installing your Dell SonicWALL appliance Ethernet WAN IP Address Select a static IP address for your Ethernet WAN This setting only applies if you are a...

Page 9: ...e not using one of the network configurations above refer to the SonicOS Administrator s Guide www sonicwall com us support html If You connect using Please record DHCP No information is usually required Some providers may require a Host name Static IP IP Address Subnet Mask Default Gateway Primary DNS DNS 2 optional DNS 3 optional ...

Page 10: ... High speed Gigabit Ethernet ports Lit Indicates when fail to wire bypass mode is armed Power 2 Blue Indicates power supplies are operating correctly Yellow Indicates an unconnected power supply or failure Test Quick blinking Initializing Slow blinking SafeMode Navigate the LCD screen Interface to display status make configuration changes restart the appliance or boot into SafeMode Hot pluggable sm...

Page 11: ...e Product Safety and Regulatory Information on page 68 I o I o Expansion Bay Fans 2 Power Supplies 2 For SonicWall approved expansion modules Dual auto throttling fans for system temperature control Dual power supplies for redundant AC power and added reliability Field conversion is available to convert to DC mains DC power supplies use different input connector and power cables ...

Page 12: ... four buttons up down left right The table below describes the functions of the buttons Icon Feature Description LCD Screen Displays the front panel bezel interface which can be used to display status information perform basic configurations restart the appliance or boot the appliance in SafeMode Control Buttons Up Down Left and Right buttons used to navigate the LCD menu system ETWORK 3ECURITY PP...

Page 13: ...atistical readings Current number of connections Interface X0 X1 network settings Interface X0 X1 data transfer statistics The X1 DNS1 3 entries will only be displayed if they have been set from the Configure menu If their value is still 0 0 0 0 default value they will not appear in the Status List Contains basic status values including system resources connections and port configuration values Al...

Page 14: ...liance enters Screen Saver Mode whether from the 6 second time out or from pressing the Left button from the Main Menu the PIN number must be re entered again to access the Configuration Menu After entering a new value for a setting in the configuration menu you are asked if you want to commit changes Using the 4 way D pad press the Right button for yes or the Left button for no If you choose yes ...

Page 15: ... yes and press the Right button to confirm The appliance will reboot SafeMode This option will set the appliance to SafeMode Once selected the LCD will display a confirmation prompt Select Y for yes and press the Right button to confirm The appliance will change to SafeMode Once SafeMode is enabled the Dell SonicWALL NSA E8500 must be controlled from the Web management interface Screen Saver If no...

Page 16: ...ess Up or Down until the cursor displays 7 press Right 6 Continue this process until all of the numbers are entered 7 Press Right to commit changes 8 Press Down until X1 IP is selected four times 9 Press Right to configure X1 IP 10 Edit X1 IP 11 Press Right ten times to select the tenth digit 12 Press UP or Down until the cursor displays 0 13 Press Right once to select the next digit 14 Press UP o...

Page 17: ......

Page 18: ...SonicWALL Account page 20 Registering and Licensing Your Appliance on MySonicWALL page 20 Licensing Security Services and Software page 21 Registering a Secondary Appliance page 22 Note Registration is an important part of the setup process and is necessary in order to receive the benefits of Dell SonicWALL security services firmware updates and technical support 2 ...

Page 19: ... your deployment before making any changes to your existing network For a High Availability configuration you must use MySonicWALL to associate a secondary unit that can share the Security Services licenses with your primary Dell SonicWALL appliance Note Your Dell SonicWALL NSA E8500 does not need to be powered on during account creation or during the MySonicWALL registration and licensing process...

Page 20: ...e 20 Licensing Security Services and Software page 21 Registering a Secondary Appliance page 22 Registration Next Steps page 23 Product Registration You must register your Dell SonicWALL NSA E8500 on MySonicWALL to enable full functionality 1 Login to your MySonicWALL account If you do not have an account you can create one at www mysonicwall com 2 On the main page in the Register A Product field ...

Page 21: ...and Anti Spyware Global VPN Client Global VPN Client Enterprise VPN Policy Upgrade for site to site VPN SSL VPN Virtual Assist Global Management System Analyzer Support Services Dynamic Support 24x7 Software and Firmware Updates Consulting Services Implementation Service GMS Preventive Maintenance Service To manage your licenses perform the following tasks 1 In the MySonicWALL Service Management A...

Page 22: ...onicWALL server will generate a license key for the product The key is added to the license keyset You can use the license keyset to manually apply all active licenses to your Dell SonicWALL appliance Registering a Secondary Appliance To ensure that your network stays protected if your Dell SonicWALL appliance has an unexpected failure you can associate a second appliance with the first in a high ...

Page 23: ...it listed in the Parent Product section as well as a Status value of 0 in the Associated Products Child Product Type section To return to the Service Management Associated Products page click the serial number link for this appliance Registration Next Steps Your Dell SonicWALL NSA E8500 or E8500 HA Pair is now registered and licensed on MySonicWALL To complete the registration process in SonicOS a...

Page 24: ...ario page 25 Scenario A NAT Route Mode Gateway page 26 Scenario B State Sync Pair in NAT Route Mode page 27 Scenario C L2 Bridge Mode page 28 Initial Setup page 29 Configuring a Stateful HA Pair page 36 Configuring L2 Bridge Mode page 43 Note Before completing this section fill out the information in the Obtain Configuration Information section on page 8 You will need to enter this information dur...

Page 25: ...A appliance as a primary gateway A NAT Route Mode Gateway A Pair of NSA appliances for high availability B NAT with State Sync Pair Existing Internet gateway appliance An NSA appliance as replacement for an existing gateway appliance A NAT Route Mode Gateway An NSA appliance in addition to an existing gateway appliance C L2 Bridge Mode Existing Dell SonicWALL gateway appliance An NSA appliance in ...

Page 26: ...d balancing and failover purposes Because only a single Dell SonicWALL appliance is deployed the added benefits of high availability with a stateful synchronized pair are not available To set up this scenario follow the steps covered in Initial Setup page 29 Additional Deployment Configuration page 46 Note Be sure to follow the steps in the Initial Setup section on page 29 before completing Additi...

Page 27: ... device loses connectivity Note Active Active pair functionality is also available for high availability deployments For more information on the benefits and setup instruction for Active Active pair see the SonicOS Active Active Feature Module at www sonicwall com us support html To set up this scenario follow the steps covered in Initial Setup page 29 Configuring a Stateful HA Pair page 36 Additi...

Page 28: ...cannot be handled by many other methods of transparent security appliance integration Using L2 Bridge Mode a Dell SonicWALL security appliance can be non disruptively added to any Ethernet network to provide in line deep packet inspection for IPv4 TCP and UDP traffic To set up this scenario follow the steps covered in Initial Setup page 29 Configuring L2 Bridge Mode page 43 Additional Deployment C...

Page 29: ...on page 32 Activating Licenses in SonicOS page 33 Upgrading Firmware page 33 System Requirements Before you begin the setup process check to verify that you have An Internet connection A Web browser supporting Java Script and HTTP uploads Connecting the WAN Port 1 Connect one end of an Ethernet cable to your Internet connection 2 Connect the other end of the cable to the X1 WAN port on your NSA E8...

Page 30: ...ory Information section on page 69 of this document 2 Turn on both power switches on the rear of the appliance next to the power cords The Power LEDs on the front panel light up blue when you plug in the Dell SonicWALL NSA E8500 The Alarm LED may light up and the Test LED will light up and may blink while the appliance performs a series of diagnostic tests When the Power LEDs are lit and the Test ...

Page 31: ...8500 appliance may restart Using the Setup Wizard If you cannot connect to the Dell SonicWALL NSA E8500 or the Setup Wizard does not display verify the following configurations Did you correctly enter the Dell SonicWALL NSA E8500 management IP address in your Web browser Are the Local Area Connection settings on your computer set to use DHCP or set to a static IP address on the 192 168 168 x 24 su...

Page 32: ...ents Testing Your Connection 1 After you exit the Setup Wizard the login page reappears Log back into the Management Interface and verify your IP and WAN connection 2 Ping a site outside of your local network such as www sonicwall com 3 Open another Web browser and navigate to www sonicwall com If you can view the Dell SonicWALL home page you have configured your Dell SonicWALL NSA E8500 correctly...

Page 33: ...rade using the license keyset is useful when your appliance is not connected to the Internet The license keyset includes all license keys for services or software enabled on MySonicWALL It is available on MySonicWALL at the top of the Service Management page for your Dell SonicWALL appliance To activate licenses in SonicOS 1 Navigate to the System Licenses page 2 Under Manage Security Services Onl...

Page 34: ...Backup entry is displayed in the Firmware Management table 2 To export your settings to a local file click Export Settings A popup window displays the name of the saved file Upgrading the Firmware Perform the following steps to upload new firmware to your Dell SonicWALL NSA E8500 and use your current configuration settings upon startup Note The appliance must be properly registered before it can b...

Page 35: ...isplays a confirmation prompt Select Y and press the Right button to confirm The NSA E8500 appliance changes to SafeMode The Test light starts blinking when the NSA E8500 appliance has rebooted into SafeMode 3 Point the Web browser on your computer to 192 168 168 168 The SafeMode management interface displays 4 If you have made any configuration changes to the security appliance select the Create ...

Page 36: ...gh Availability page 37 Configuring Advanced HA Settings page 38 Configuring HA Monitoring Settings page 39 Synchronize Settings page 40 HA License Configuration Overview page 41 Associating Pre Registered Appliances page 42 If You Are Following Scenario Proceed to Section A NAT Route Mode Gateway Additional Deployment Configuration page 46 B NAT with State Sync Pair Configuring a Stateful HA Pair...

Page 37: ... hub switch is also valid Power up the primary Dell SonicWALL security appliance and then power up the secondary Dell SonicWALL security appliance Do not make any configuration changes to the primary s HA interface the High Availability configuration in an upcoming step takes care of this issue When done disconnect the workstation Configuring High Availability The first task in setting up HA after...

Page 38: ...value is 1000 milliseconds Using a longer interval will result in the appliance taking more time to detect when if failures have occurred Less than this may cause unnecessary failovers especially when the appliance is under a heavy load 7 Set the Probe Interval for the interval in seconds between communication with upstream or downstream systems This timer controls the path monitoring speed Path m...

Page 39: ...ces synchronize all certificates and keys 11 Click Synchronize Settings to synchronize the settings between the primary and secondary appliances 12 Click Synchronize Firmware if you previously uploaded new firmware to your Primary unit while the Secondary unit was offline and it is now online and ready to upgrade to the new firmware Synchronize Firmware is typically used after taking your Secondar...

Page 40: ...efault the Include Certificate Keys setting is enabled This specifies that Certificates CRLs and associated settings such as CRL auto import URLs and OCSP settings are synchronized between the primary and secondary units When Local Certificates are copied to the secondary unit the associated Private Keys are also copied Because the connection between the primary and secondary units is typically pr...

Page 41: ...re correct configuration HA License Configuration Overview You can configure HA license synchronization by associating two Dell SonicWALL security appliances as HA Primary and HF secondary on MySonicWALL Note that the secondary appliance of your HA pair is referred to as the HF Secondary unit on MySonicWALL Also note that the secondary appliance must be an identical model to the primary applicancy...

Page 42: ...cense server and share licenses with the associated appliance Associating Pre Registered Appliances To associate two already registered Dell SonicWALL security appliances so that they can use HA license synchronization perform the following steps 1 Login to MySonicWALL 2 In the left navigation bar click My Products 3 On the My Products page under Registered Products scroll down to find the applian...

Page 43: ...ALL NSA E8500 to the LAN port on your existing Internet gateway device Then connect the X0 port on your NSA E8500 to your LAN resources Configuring the Primary Bridge Interface The primary bridge interface is your existing Internet gateway device The only step involved in setting up your primary bridge interface is to ensure that the WAN interface is configured for a static IP address You will nee...

Page 44: ...idged Mode 4 In the Bridged to drop down select the X1 interface 5 Configure management options HTTP HTTPS Ping SNMP SSH User logins or HTTP redirects Note Do not enable Never route traffic on the bridge pair unless your network topology requires that all packets entering the L2 Bridge remain on the L2 Bridge segments You may optionally enable the Block all non IPv4 traffic setting to prevent the ...

Page 45: ......

Page 46: ...cies for your deployment This section also contains several SonicOS diagnostic tools and a deployment configuration reference checklist An Introduction to Zones and Interfaces page 47 Creating a NAT Policy page 48 Enabling Security Services in SonicOS page 51 Applying Security Services to Zones page 52 Troubleshooting Diagnostic Tools page 52 4 ...

Page 47: ... X1 or X2 on the Dell SonicWALL NSA E8500 The X1 and X0 interfaces are preconfigured as WAN and LAN respectively The remaining ports can be configured to meet the needs of your network either by using basic zone types WAN LAN WLAN DMZ VPN or configuring a custom zone type to fit your network requirements for example Gaming Console Zone Wireless Printer Zone Wireless Ticket Scanner Zone A Zone is a...

Page 48: ...ress User Service and Schedule in SonicOS These Address Objects allow for entities to be defined one time and to be re used in multiple referential instances throughout the SonicOS interface For example take an internal Web server with an IP address of 67 115 118 80 Rather than repeatedly typing in the IP address when constructing Access Rules or NAT Policies Address Objects allow you to create a ...

Page 49: ...Dell SonicWALL appliance To add an Address Object 1 Navigate to the Network Address Objects page 2 Below the Address Objects table click Add 3 In the Add Address Object dialog box enter a name for the Address Object in the Name field 4 Select the zone to assign to the Address Object from the Zone Assignment drop down list 5 Select Host Range Network MAC or FQDN from the Type menu If you selected H...

Page 50: ...urations see the SonicOS Administrator s Guide An example configuration illustrates the use of the fields in the Add NAT Policy procedure To add a One to One NAT policy that allows all Internet traffic to be routed through a public IP address two policies are needed one for the outbound traffic and one for the inbound traffic To add both parts of a One to One NAT policy perform the following steps...

Page 51: ...ally in the SonicOS user interface See the following procedures to enable and configure the following three basic security services Gateway Anti Virus Intrusion Prevention Anti Spyware For more information on configuring your security services refer to the SonicOS Administrator s Guide ...

Page 52: ...o apply services to network zones 1 Navigate to the Network Zones page 2 In the Zone Settings table click the Configure icon for the zone where you want to apply security services 3 In the Edit Zone dialog box on the General tab select the checkboxes for the security services to enable on this zone 4 On the Edit Zone page select the checkboxes for the security services that you want to enable 5 Cl...

Page 53: ...the ISP connection Using the Active Connections Monitor The Active Connections Monitor displays real time exportable plain text or CSV filterable views of all connections to and through the Dell SonicWALL appliance This tool is available on the Systems Diagnostics page You can filter the results to display only connections matching certain criteria You can filter by Source IP Destination IP Destin...

Page 54: ...ining options for the Dell SonicWALL NSA E8500 Customer Support page 55 Knowledge Portal page 55 User Forums page 56 Training page 57 Related Documentation page 58 Dynamic Tooltips page 59 Dell SonicWALL Live Product Demos page 59 Dell SonicWALL Secure Wireless Network Integrated Solutions Guide page 60 5 ...

Page 55: ... that includes phone email and Web based technical support software and firmware updates and upgrades and Advance Exchange hardware replacement Please Note Continuous support is required on all E Class products For further information visit http www sonicwall com us support html Knowledge Portal The Knowledge Portal is a resource which allows users to search for Dell SonicWALL documents based on t...

Page 56: ...urity Manager topics Continuous Data Protection topics Email Security related topics Firewall related topics Network Anti Virus related topics Security Services and Content Filtering topics GMS and Analyzer related topics SonicPoint and Wireless related topics SSL VPN related topics Wireless WAN 3G 4G related topics VPN Client related topics VPN site to site and interoperability topics For further...

Page 57: ...tners who need to enhance their knowledge and maximize their investment in Dell SonicWALL Products and Security Applications Dell SonicWALL Training provides the following resources for its customers E Training Instructor Led Training Custom Training Technical Certification Authorized Training Partners For further information visit http training sonicwall com ...

Page 58: ...AT Load Balancing Packet Capture RF Management Single Sign On SSL Control Virtual Access Points Dell SonicWALL GVC Administrator s Guide Dell SonicWALL GMS Administrator s Guide Dell SonicWALL GAV Administrator s Guide Dell SonicWALL IPS Administrator s Guide Dell SonicWALL Anti Spyware Administrator s Guide Dell SonicWALL CFS Administrator s Guide For further information visit http www sonicwall ...

Page 59: ...LL Live Product Demos The Dell SonicWALL Live Demo Site provides free test drives of Dell SonicWALL security products and services through interactive live product installations Unified Threat Management Platform Secure Cellular Wireless Continuous Data Protection SSL VPN Secure Remote Access Content Filtering Secure Wireless Solutions Email Security GMS and Analyzer For further information visit ...

Page 60: ... wireless network Check out the Dell SonicWALL Secure Wireless Network Integrated Solutions Guide This book is the official guide to Dell SonicWALL s market leading wireless networking and security devices This title is available in hardcopy at fine book retailers everywhere or by ordering directly from Elsevier Publishing at http www elsevier com ...

Page 61: ......

Page 62: ...ion This section provides illustrated rack mounting instructions for the Dell SonicWALL NSA E8500 Rack Mounting Instructions page 63 Note For more information on rack mounting requirements see the Safety and Regulatory Information page 69 6 ...

Page 63: ...Rack Mounting Instructions M4 SCREW 8 WASHERS 8 Fasten 4 screws to the rail Assemble the Slide Rail A B A B ...

Page 64: ...M5 SCREW 8 M5 Nut 8 Assemble the Slide Rail Fasten two sided screws to the rail C C ...

Page 65: ...Assemble Inner Rail to Chassis Fasten 6 screws to attach the inner channel onto the chassis M4 SCREW 6 D D ...

Page 66: ...Insert Chassis to Frame Push hook down to separate Slide inner channel into rails ...

Page 67: ......

Page 68: ...d Regulatory Information In this Section This section provides regulatory along with trademark and copyright information Safety and Regulatory Information page 69 Warranty Information page 73 Copyright Notice page 73 7 ...

Page 69: ...onsideration must be given to the connection of the equipment to the supply circuit Appropriate consideration of equipment nameplate ratings must be used when addressing this concern Do not overload the circuit Reliable grounding of rack mounted equipment must be maintained Particular attention must be given to power supply connections other than direct connections to the branch circuits such as p...

Page 70: ...festigungsschrauben und ziehen Sie diese mit der Hand an Wählen Sie einen Ort im 19 Zoll Rack wo alle vier Befestigungen der Montageschien verwendet werden Ein angemessen dimensionierter und geprüfte Sicherung sollte Bestandteil der Haus Installation sein Bitte folgen die den lokalen Richtlinien beim Einkauf von Material oder Komponenten Prüfen Sie den Anschluss des Geräts an die Stromversorgung d...

Page 71: ...Anschlüsse der Dell SonicWALL keine Kabel an die aus dem Gebäude in dem sich das Gerät befindet herausgeführt werden 安全說明 需要滿足以下條件以進行正確安裝 戴爾 SonicWALL 設備被設計成安裝在一個標準的 19 吋機架安 裝櫃 需要滿足以下條件以進行正確安裝 使用機架製造商推薦的裝載硬體 確認機架足夠裝置所需 請確認裝置內不會滲入水分或過多的濕氣 裝置週邊請保持通風 特別是裝置通風口側 建議裝置與牆 壁間至少要有 1 英吋 25 44 公釐 的淨空 纜線的路徑應遠離電源線 日光燈 以及會產生雜訊的來源 如無線電 發送器與寬頻放大器 本產品的設計目的不是安裝並使用於住家或一般大眾可接觸 到的公共區域 如果是安裝在學校 本設備只能安裝在受訓人 員能接觸到的安全位置 架設...

Page 72: ...to Part 15 of the FCC Rules These limits are designed to provide reasonable protection against harmful interference when the equipment is operated in a commercial environment This equipment generates uses and can radiate radio frequency energy And if not installed and used in accordance with the instruction manual the device may cause harmful interference to radio communications Operation of this ...

Page 73: ...made in Taiwan R O C All certificates held by Secuwide Corps Warranty Information All Dell SonicWALL appliances come with a 1 year Limited Hardware Warranty which provides delivery of critical replacement parts for defective parts under warranty Visit the Warranty Information page details on your product s warranty http www sonicwall com us en support Services html tab warranty Copyright Notice 20...

Page 74: ......

Reviews: