Dell SonicWALL Secure Mobile Access 8.5
Administration Guide
82
Figure 9. Sequence of Events in Initial Connection
For information about configuring the SMA/SRA appliance to work with third-party gateways, refer to
Configuring the SMA/SRA Appliance with a Third-Party Gateway
Two-armed Deployment
The SMA/SRA appliances also support two-armed deployment scenarios, using one external (DMZ or WAN side)
interface and one internal (LAN) interface. However, two-armed mode introduces routing issues that need to be
considered before deployment. The SMA/SRA appliance does not route packets across interfaces, as there are IP
tables rules preventing that, and therefore cannot be used as a router or default gateway. Any other machines
connected to an internal interface of the SMA/SRA appliance in two-armed mode would need to access the
Internet or other network resources (DNS, NTP) through a different gateway.
If you have an internal router as well as an Internet router, you can use a two-armed deployment to leverage
your internal router to access your internal resources.
Sample Scenario - Company A has resources and a number of subnets on their internal network, and they
already have a robust routing system in place. With two-armed deployment of the SMA/SRA appliance, client
requests destined for internal resources on the corporate network can be delivered to an internal router.
LAN
SSL VPN
DMZ
2
1
3
X0 interface connects to available segment on gateway. Encrypted session passes to SRA appliance.
The internal network resource returns content to the SRA appliance through the gateway.
SRA traffic traverses the gateway to reach internal network resource
Internet
Secure Remote Access
EX7000
SRA
1200
SRA
Secure Remote Access
X0
X1
CONSOLE
PWR TEST ALARM
Internal Network
Resource
SSL VPN Client
SRA Appliance
NSA Appliance
1
2
3