background image

About This Document

NOTE:

A NOTE icon indicates supporting information.

IMPORTANT:

An IMPORTANT icon indicates supporting information.

TIP:

A TIP icon indicates helpful information.

CAUTION:

A CAUTION icon indicates potential damage to hardware or loss of data if

instructions are not followed.

WARNING:

A WARNING icon indicates a potential for property damage, personal injury, or

death.

Secure Mobile Access Deployment Guide for the SMA 100 Series
Updated - June 2021
Software Version - 10.2
232-005680-00 Rev A

Copyright © 2021 SonicWall Inc. All rights reserved.

The information in this document is provided in connection with SonicWall and/or its affiliates’ products. No license, express or

implied, by estoppel or otherwise, to any intellectual property right is granted by this document or in connection with the sale of

products. EXCEPT AS SET FORTH IN THE TERMS AND CONDITIONS AS SPECIFIED IN THE LICENSE AGREEMENT FOR

THIS PRODUCT, SONICWALL AND/OR ITS AFFILIATES ASSUME NO LIABILITY WHATSOEVER AND DISCLAIMS ANY

EXPRESS, IMPLIED OR STATUTORY WARRANTY RELATING TO ITS PRODUCTS INCLUDING, BUT NOT LIMITED TO,

THE IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT.

IN NO EVENT SHALL SONICWALL AND/OR ITS AFFILIATES BE LIABLE FOR ANY DIRECT, INDIRECT, CONSEQUENTIAL,

PUNITIVE, SPECIAL OR INCIDENTAL DAMAGES (INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF

PROFITS, BUSINESS INTERRUPTION OR LOSS OF INFORMATION) ARISING OUT OF THE USE OR INABILITY TO USE

THIS DOCUMENT, EVEN IF SONICWALL AND/OR ITS AFFILIATES HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH

DAMAGES. SonicWall and/or its affiliates make no representations or warranties with respect to the accuracy or completeness of

the contents of this document and reserves the right to make changes to specifications and product descriptions at any time without

notice. and/or its affiliates do not make any commitment to update the information contained in this document.

For more information, visit

https://www.sonicwall.com/legal

.

End User Product Agreement

To view the SonicWall End User Product Agreement, go to:

https://www.sonicwall.com/legal/end-user-product-agreements/

.

Open Source Code

SonicWall Inc. is able to provide a machine-readable copy of open source code with restrictive licenses such as GPL, LGPL, AGPL

when applicable per license requirements. To obtain a complete machine-readable copy, send your written requests, along with

certified check or money order in the amount of USD 25.00 payable to “SonicWall Inc.”, to:

General Public License Source Code Request
Attn: Jennifer Anderson
1033 McCarthy Blvd
Milpitas, CA 95035

SMA 10.2 Deployment Guide for the SMA 100 Series

SonicWall Support

25

Summary of Contents for SMA 100 Series

Page 1: ...Secure Mobile Access 10 2 Deployment Guide for the SMA 100 Series...

Page 2: ...SMA to the Gateway 9 Allowing WAN to DMZ Connection 9 Allowing DMZ to LAN Connection 10 Deploying SMA on the LAN 13 Connecting the SMA to the Gateway 13 Configuring SMA to LAN Connectivity 13 Addition...

Page 3: ...3600 This method of deployment offers additional layers of security control plus the ability to use SonicWall s security services including Gateway Anti Virus Anti Spyware Content Filtering Intrusion...

Page 4: ...None For a full list of the supported SonicWall firewall and firmware versions see https www sonicwall com support product lifecycle tables The following illustrations provide an overview of each depl...

Page 5: ...t on the front of your SonicWall Secure Mobile Access 210 410 The X0 Port LED lights up indicating an active connection 3 Configure the SMA X0 IP address Refer to Configuring the X0 IP Address Allowin...

Page 6: ...mation and then click Next Server Name Specify the name for the SMA appliance Server Private IP Address SMA appliance X0 IP address Server Comment Brief description of the server 6 On the Server Publi...

Page 7: ...SMA appliance Name Name of the SMA appliance Zone Assignment SMA Type Host IP Address SMA appliance X0 IP address default 192 168 200 1 4 Click Save to create the object Once done click Close 5 Click...

Page 8: ...dress group you just created Source Zone Interface SMA Source Destination LAN Source Port Any Service Any Source The address group you just created such as SMA and NetExtender Destination Any Users Al...

Page 9: ...t Refer to Configuring the X0 IP Address for more information Allowing WAN to DMZ Connection If you are already forwarding HTTP or HTTPS to an internal server and you only have a single public IP addr...

Page 10: ...lays all configuration actions that are performed Click Apply to create the configuration and allow access from the WAN to the SMA appliance on the DMZ Allowing DMZ to LAN Connection When users have c...

Page 11: ...range l Enter a name for the group l In the left column select the address objects you created and click the right arrow button l Click Save to create the group when both objects are in the right col...

Page 12: ...This completes Scenario B NOTE Some gateway appliances have a default zone named SSLVPN Do not select this zone when configuring for the SMA appliance The SSLVPN zone is intended for use with the mor...

Page 13: ...ress for more information Configuring SMA to LAN Connectivity NOTE Before continuing you must add a new SMA custom zone Refer to Adding a New SMA Custom Zone for more information For users to access l...

Page 14: ...added click Close 8 On the OBJECT Match Objects Addresses page click the Address Groups tab 9 Click Add 10 In the Add Address Groups dialog box create a group for the X0 interface IP address of your S...

Page 15: ...Fragmented Packets 15 Click OK to create the rule This completes Scenario C NOTE Some gateway appliances have a default zone named SSLVPN Do not select this zone when configuring for the SMA appliance...

Page 16: ...b browser TIP For additional information see the SMA 210 410 Quick Start Guide 2 Using SonicOS navigate to the NETWORK System Interfaces page 3 In the Interface Settings table click the Configure icon...

Page 17: ...SMA on the LAN The LAN interface IP address To configure a default route 1 Using Secure Mobile Access navigate to the Network Routes page 2 Enter the upstream gateway device s IPv4 address in the Defa...

Page 18: ...u would like to provide access with NetExtender in the Destination Network field For example if you are connecting to an existing DMZ on the 10 1 1 0 24 subnet and you want to provide access to your L...

Page 19: ...nder address range 1 Using Secure Mobile Access navigate to the Clients Settings page 2 Enter an address range in the Client Address Range Begin and Client Address Range End fields 3 Click Accept to a...

Page 20: ...our gateway appliance as an administrator and navigate to the NETWORK System Interfaces page 2 Click the Configure icon for the interface connected to your SMA such as X2 3 Select Create new zone in t...

Page 21: ...168 168 x 10 Enter your Subnet Mask 11 Optionally enter the Default Gateway which is the WAN address of the gateway appliance 12 If you want to allow management of the gateway appliance over this inte...

Page 22: ...et You can verify your connection using a remote client on the WAN To verify a User Connection from the Internet 1 From a WAN connection outside of your corporate network launch a Web browser and ente...

Page 23: ...A appliance If you do not manage your own public DNS servers contact your ISP for assistance Policy Access Rules Matrix View If the SMA zone does not appear in the POLICY Rules and Policies Access Rul...

Page 24: ...knowledge base articles and technical documentation l View and participate in the Community forum discussions at https community sonicwall com technology and support l View video tutorials l Access h...

Page 25: ...LIATES BE LIABLE FOR ANY DIRECT INDIRECT CONSEQUENTIAL PUNITIVE SPECIAL OR INCIDENTAL DAMAGES INCLUDING WITHOUT LIMITATION DAMAGES FOR LOSS OF PROFITS BUSINESS INTERRUPTION OR LOSS OF INFORMATION ARIS...

Reviews: