Under the copyright laws, this manual or the software described within, can not be copied, in whole or
part, without the written consent of the manufacturer, except in the normal use of the software to
make a backup copy. The same proprietary and copyright notices must be affixed to any permitted
copies as were affixed to the original. This exception does not allow copies to be made for others,
whether or not sold, but all of the material purchased (with all backup copies) can be sold, given, or
loaned to another person. Under the law, copying includes translating into another language or
format.
Preface
Chapter :
Chapter :
SonicWALL is a registered trademark of SonicWALL, Inc.
Other product and company names mentioned herein can be trademarks and/or registered
trademarks of their respective companies.
Specifications and descriptions subject to change without notice.
Limited Warranty
SonicWALL, Inc. warrants that commencing from the delivery date to Customer (but in any case
commencing not more than ninety (90) days after the original shipment by SonicWALL), and
continuing for a period of twelve (12) months, that the product will be free from defects in materials
and workmanship under normal use. This Limited Warranty is not transferable and applies only to the
original end user of the product. SonicWALL and its suppliers' entire liability and Customer's sole and
exclusive remedy under this limited warranty will be shipment of a replacement product. At
SonicWALL's discretion the replacement product may be of equal or greater functionality and may be
of either new or like-new quality. SonicWALL's obligations under this warranty are contingent upon
the return of the defective product according to the terms of SonicWALL's then-current Support
Services policies.
This warranty does not apply if the product has been subjected to abnormal electrical stress,
damaged by accident, abuse, misuse or misapplication, or has been modified without the written
permission of SonicWALL.
DISCLAIMER OF WARRANTY. EXCEPT AS SPECIFIED IN THIS WARRANTY, ALL EXPRESS OR
IMPLIED CONDITIONS, REPRESENTATIONS, AND WARRANTIES INCLUDING, WITHOUT
LIMITATION, ANY IMPLIED WARRANTY OR CONDITION OF MERCHANTABILITY, FITNESS FOR
A PARTICULAR PURPOSE, NONINFRINGEMENT, SATISFACTORY QUALITY OR ARISING
FROM A COURSE OF DEALING, LAW, USAGE, OR TRADE PRACTICE, ARE HEREBY
EXCLUDED TO THE MAXIMUM EXTENT ALLOWED BY APPLICABLE LAW. TO THE EXTENT AN
IMPLIED WARRANTY CANNOT BE EXCLUDED, SUCH WARRANTY IS LIMITED IN DURATION
TO THE WARRANTY PERIOD. BECAUSE SOME STATES OR JURISDICTIONS DO NOT ALLOW
LIMITATIONS ON HOW LONG AN IMPLIED WARRANTY LASTS, THE ABOVE LIMITATION MAY
NOT APPLY TO YOU. THIS WARRANTY GIVES YOU SPECIFIC LEGAL RIGHTS, AND YOU MAY
ALSO HAVE OTHER RIGHTS WHICH VARY FROM JURISDICTION TO JURISDICTION. This
disclaimer and exclusion shall apply even if the express warranty set forth above fails of its essential
purpose.
DISCLAIMER OF LIABILITY. SONICWALL'S SOLE LIABILITY IS THE SHIPMENT OF A
REPLACEMENT PRODUCT AS DESCRIBED IN THE ABOVE LIMITED WARRANTY. IN NO EVENT
SHALL SONICWALL OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER,
INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF PROFITS, BUSINESS
INTERRUPTION, LOSS OF INFORMATION, OR OTHER PECUNIARY LOSS ARISING OUT OF
THE USE OR INABILITY TO USE THE PRODUCT, OR FOR SPECIAL, INDIRECT,
CONSEQUENTIAL, INCIDENTAL, OR PUNITIVE DAMAGES HOWEVER CAUSED AND
REGARDLESS OF THE THEORY OF LIABILITY ARISING OUT OF THE USE OF OR INABILITY TO
USE HARDWARE OR SOFTWARE EVEN IF SONICWALL OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. In no event shall SonicWALL or its suppliers'
liability to Customer, whether in contract, tort (including negligence), or otherwise, exceed the price
paid by Customer. The foregoing limitations shall apply even if the above-stated warranty fails of its
essential purpose. BECAUSE SOME STATES OR JURISDICTIONS DO NOT ALLOW LIMITATION
OR EXCLUSION OF CONSEQUENTIAL OR INCIDENTAL DAMAGES, THE ABOVE LIMITATION
MAY NOT APPLY TO YOU.
SonicOS Enhanced is the most powerful SonicOS operating system designed for the latest
generation of SonicWALL security appliances. SonicOS Enhanced 2.5 is standard on the SonicWALL
PRO 4060 and PRO 5060 and available as an upgrade on the SonicWALL TZ170 Series, PRO 2040,
and PRO 3060.
SonicOS Enhanced 2.5
C
HAPTER
1
Chapter 1: Introduction
What’s New in SonicOS Enhanced 2.5
Built on the SonicOS architecture, this operating system features multiple network interfaces and
zones, WAN ISP failover and load balancing, policy-based NAT, object-based management, a multilevel administrator GUI, and enhanced VPN functionality. SonicOS Enhanced 2.5 builds on these
features with powerful new capabilities and industry-leading technologies.
•Updated Configuration Wizard: SonicOS Enhanced 2.5 includes an new configuration wizard
that includes three configuration wizards: Setup Wizard, Public Server Wizard, and VPN Policy
Wizard to provide you with a quick, easy, and comprehensive configuration of the SonicWALL
security appliance for common deployment scenarios.
•Enhanced VoIP Support: SonicOS Enhanced 2.5 adds comprehensive support for third-party
VoIP equipment, including products from Cisco, Mitel, Pingtel, Grandstream, Polycom, D-Link,
Pulver, Apple iChat, and softphones from Yahoo, Microsoft, Ubiquity, and OpenPhone. SonicOS
Enhanced 2.5 adds the ability to handle SIP, RTSP, H.323v1, H.323v2, H.323v3, H.323v4, H.323
gatekeepers, and LDAP ILS support. The internal DHCP Server capability in SonicOS Enhanced
2.5 allows Cisco CallManager addressing information into the DHCP scope information, so that
Cisco phones can receive addresses when they issue a DHVCP request on the network.
•Hardware Failover Enhancements: SonicOS Enhanced 2.5 includes a number of useful
enhancements to hardware failover, including the ability to automatically synchronize the firmware
between the Primary and Backup SonicWALL security appliances, and the ability to load new
firmware versions on to both devices simultaneously from the Primary SonicWALL security
appliance. You can also specify logical monitoring addresses for each interface.
•Flexible VPN Termination: SonicOS Enhanced 2.5 includes the ability to terminate incoming
site-to-site VPN connections on any interface. This feature is useful in situations where untrusted
transit networks terminate on internal interfaces; an example of this might be a router sitting on a
DMZ Zone/Interface with an untrusted Frame Relay network connecting the router to a business
partner. Using the flexible VPN termination feature, you are able to run a VPN connection across
the Frame Relay connection and know the Frame Relay provider cannot see the traffic.
•Multiple GroupVPN Policies: SonicOS Enhanced 2.5 allows you to create separate, customized
GroupVPN policies for each Zone, and SonicWALL Global VPN Client connections can terminate
on any interface.
•Wireless Extensions: SonicOS Enhanced 2.5 includes the ability to terminate wireless clients
using SonicWALL SonicPoint, and incorporating wireless features such as wireless guest services
(WGS), secure wireless roaming, using SonicWALL’s Global VPN Client, and rogue access point
detection. SonicOS Enhanced 2.5 allows you to manage SonicWALL SonicPoints for secure
wireless networking behind the firewall.
•Full Stateful IGMP Multicast Support: SonicOS Enhanced 2.5 includes the ability to track and
allow/deny multicast traffic, with support for IGMPv1, IGMPv2, and IGMPv3. Multicast can be
enabled or disabled on a per-interface and per-VPN policy basis.
•Inbound Bandwidth Management: SonicOS Enhanced 2.5 adds the ability to perform ingress
and egress bandwidth management for traffic passing in and out of the WAN interfaces on a
per-rule basis. Ingress bandwidth management uses rate-limiting via delayed ACKs for TCP traffic,
drops over-limit packets for connectionless UDP traffic. For both methods, you specify the
maximum upstream and downstream throughput for each WAN interface, and on a per-rule basis,
set the priority level of the traffic, the guaranteed percentage of bandwidth for that rule, and the
maximum (i.e. burstable) bandwidth for that rule.
•Transparent ModeSupport: SonicOS Enhanced 2.5 includes the ability to bridge WAN-side IP
addresses/subnets onto an internal interface, including the LAN Zone interface. This feature is
useful in network environments where it is not possible to renumber internal systems to a private
addressing scheme and perform NAT at the SonicWALL security appliance, or in “drop-in”
situations where the SonicWALL security appliance is used primarily as an IPS (Intrusion
Prevention Service) or CFS (Content Filtering Service) appliance.
•Expanded IP Protocol Support: SonicOS Enhanced 2.5 supports additional IP types (IGRE,
ESP, AH, EIGRP, OSPF, PIMSM, L2TP) as well as specify ICMP/IGMP subtypes when creating
customized service objects, across the firewall and through VPN connections.
•Policy Based Routing (PBR) - SonicOS Enhanced 2.5 allows you to create extended static
routes that match against source, service, and destination. This feature, for example, can be used
to steer traffic matching the route policies out a specific WAN. It also supports metrics, so highcost static route entries can be used in case dynamically received route entries fail.
•Expanded Logging: SonicOS Enhanced 2.5 includes additional logging capabilities to provide
expanded flexibility. You can export the log into plain text or CSV values. Logging categories are
dramatically expanded, the logs conform to Syslog severity levels so you can set the SonicWALL
security appliance to only log alerts and messages of specified levels, and you can independently
specify which categories are logged to the internal log. When directing logs to external Syslog
servers, you can rate-limit the messages based on events per second, or maximum bytes per
second, so that external Syslog servers do not get overwhelmed. The SonicWALL security
appliance also has the ability to do “POP before SMTP” in order to e-mail logs and alerts to SMTP
mail servers that require a successful POP3 authentication before e-mail is sent through them.
About this Guide
Welcome to the SonicWALL SonicOS Enhanced 2.5 Administrator’s Guide. This manual provides the
information you need to successfully activate, configure, and administer SonicOS Enhanced 2.5 for
the SonicWALL TZ170, PRO 2040, PRO 3060, PRO 4060, and PRO 5060 Internet Security
Appliances.
Note: Always check <http//:www.sonicwall.com/services/documentation.html> for the latest version of
this manual as well as other SonicWALL products and services documentation.
The SonicOS Enhanced 2.5 Administrator’s Guide organization is structured into the following parts
that follow the SonicWALL Web Management Interface structure. Within these parts, individual
chapters correspond to Management Interface layout.
Part 1 Introduction
This part provides an overview of new SonicWALL SonicOS Enhanced features, guide conventions,
and instructions for connecting a management station to the SonicWALL security appliance to access
the SonicWALL Management Interface.
Part 2 System
This part covers a variety SonicWALL security appliance controls for managing system status
information, registering the SonicWALL security appliance, activating and managing SonicWALL
Security Services licenses, configuring SonicWALL security appliance local and remote management
options, managing firmware versions and preferences, and using included diagnostics tools for
troubleshooting.
Part 3 Network
This part covers configuring the SonicWALL security appliance for your network environment. The
Network section of the SonicWALL Management Interface includes:
About this Guide
•Interfaces - configure logical interfaces for connectivity.
•WAN Failover and Load Balancing - configure one of the user-defined interfaces to act as a secondary WAN port for backup or load balancing.
•Zones - configure security zones on your network.
•DNS - set up DNS servers for name resolution.
•Address Objects - configure host, network, and address range objects.
•Routing - view the Route Table, ARP Cache and configure static and dynamic routing by interface.
•NAT Policies - create NAT policies including One-to-One NAT, Many-to-One NAT, Many-to-Many
NAT, or One-to-Many NAT.
•ARP - view the ARP settings and clear the ARP cache as well as configure ARP cache time.
•DHCPServer - configure the SonicWALL as a DHCP Server on your network to dynamically assign IP addresses to computers on your LAN or DMZ zones.
•IP Helper - configure the SonicWALL to forward DHCP requests originating from the interfaces on
the SonicWALL to a centralized server on behalf of the requesting client.
•Web Proxy - configure the SonicWALL to automatically forward all Web proxy requests to a network proxy server.
Part 4 Wireless
The part covers the configuration of the SonicWALL security appliance for provisioning and managing
SonicWALL SonicPoints as part of a SonicWALL Distributed Wireless Solution.
Cross Reference: For more information on SonicWALL’s Distributed Wireless Solution, go to
This part covers tools for managing how the SonicWALL security appliance handles traffic through the
the firewall, including Multicast and VoIP traffic.
This part covers how to create VPN policies on the SonicWALL security appliance to support
SonicWALL Global VPN Clients as well as creating site-to-site VPN policies for connecting offices
running SonicWALL security appliances.
Part 7 Users
This part covers how to configure the SonicWALL security appliance for user level authentication as
well as manage guest services for managed SonicPoints.
Part 8 Hardware Failover
This part provides configuration instructions for setting a SonicWALL high availability pair for
maintaining secure, mission-critical connectivity.
Part 9 Security Services
This part includes an overview of available SonicWALL Security Services as well as instructions for
activating the service, including FREE trials. These subscription-based services include SonicWALL
Content Filtering Service, SonicWALL Instrusion Prevention Service, SonicWALL Network Anti-Virus,
and well as other services.
Â
Cross Reference: For more information on SonicWALL Security Services, go to
<http//:www.sonicwall.com.
Part 10 Log
This part covers managing the SonicWALL security appliance’s enhanced logging, alerting, and
reporting features. The SonicWALL security appliance’s logging features provide a comprehensive
set of log categories for monitoring security and network activities.
Part 11 Wizards
This part walks you through using the SonicWALL Configuration Wizards for configuring the
SonicWALL security appliance for LAN to WAN (Internet) connectivity, settings up public servers for
Internet connectivity behind the firewall, and setting GroupVPN and site-to-site VPN policies for
establishing VPN connections for remote SonicWALL Global VPN Client users or remote offices with
a SonicWALL security appliance for LAN to LAN connections.
The SonicWALL Configuration Wizards in SonicOS Enhanced 2.5 or higher include:
•The Setup Wizard takes you step by step through network configuration for Internet connectivity.
There are four types of network connectivity available: Static IP, DHCP, PPPoE, and PPTP.
•The Public Server Wizard takes you step by step through adding a server to your network, such
as a mail server or a web server. The wizard automates much of the configuration you need to
establish security and access for the server.
•The VPN Policy Wizard steps you through the configuration of Group VPNs and site-to-site
VPNs.
For timely resolution of technical support questions, visit SonicWALL on the Internet at
<http://www.sonicwall.com/services/support.html>. Web-based resources are available to help you
resolve most technical issues or contact SonicWALL Technical Support.
To contact SonicWALL telephone support, see the telephone numbers listed below:
North America Telephone Support
U.S./Canada - 888.777.1476 or +1 408.752.7819
International Telephone Support
Australia - + 1800.35.1642
Austria - + 43(0)820.400.105
EMEA - +31(0)411.617.810
France - + 33(0)1.4933.7414
Germany - + 49(0)1805.0800.22
Hong Kong - + 1.800.93.0997
India - + 8026556828
Italy - +39.02.7541.9803
Japan - + 81(0)3.5460.5356
New Zealand - + 0800.446489
Singapore - + 800.110.1441
Spain - + 34(0)9137.53035
Switzerland - +41.1.308.3.977
UK - +44(0)1344.668.484
Note: Please visit <http://www.sonicwall.com/services/contact.html> for the latest technical support
telephone numbers.
SonicWALL Support Solutions
SonicWALL’s powerful security solutions give unprecedented protection from the risks of Internet
attacks. SonicWALL’s comprehensive support services protect your network security investment and
offer the support you need - when you need it.
Note: For complete information on SonicWALL Support Solutions, please visit <http://
www.sonicwall.com/services/support.html.
All SonicWALL customers have immediate, 24X7 access to our state-of-the-art electronic support
tools. Power searching technologies on our Web site allow customers to locate information quickly
and easily from our robust collection of technical information - including manuals, product
specifications, operating instructions, FAQs, Web pages, and known solutions to common customer
questions and challenges.
Internet Security Expertise
Technical Support is only as good as the people providing it to you. SonicWALL support professionals
are Certified Internet Security Administrators with years of experience in networking and Internet
security. They are also supported by the best in class tools and processes that ensure a quick and
accurate solution to your problem.
SonicWALL Support Programs
SonicWALL offers a variety of support programs designed to get the support you need when you
need it. For more information on SonicWALL Support Services, please visit
<http://www.sonicwall.com/products/supportservices.html.
Warranty Support - North America and International
SonicWALL products are recognized as extremely reliable as well as easy to configure, install, and
manage. SonicWALL Warranty Support enhances these features with
•1 year, factory replacement for defective hardware
•90 days of advisory support for installation and configuration assistance during local
business hours
•90 days of software and firmware updates
•Access to SonicWALL’s electronic support and Knowledge Base system.
More Information on SonicWALL Products
Contact SonicWALL, Inc. for information about SonicWALL products and services at:
Your SonicWALL security appliance is configured with the default IP address of 192.168.168.168.
This IP address is used to initially access the Management Interface of the SonicWALL security
appliance.
Cross Reference: For instructions on setting up your SonicWALL security appliance, see the
Â
SonicWALL Quick Start Guide.
C
HAPTER
2
To access the Management Interface for the first time, you must configure your computer with an IP
address in the same network range as the SonicWALL security appliance. Follow the instructions
below for your operating system:
Windows XP
•Right-click My Network Place and select Properties.
•Right-click on the Local Area Connection icon and select Properties.
•Open the Local Area Connection Properties window.
•Double-click Internet Protocol (TCP/IP) to open the Internet Protocol (TCP/IP) Properties
window.
•Select Use the following IP address and type 192.168.168.200 in the IP address field.
•Enter 255.255.255.0 in the Subnet Mask field.
•Enter the DNS IP address in the Preferred DNS Server field. If you have more than one address, type the second one in the Alternate DNS server field.
•Click OK for the settings to take effect on the computer.
Windows 2000
1
From your Windows task bar, click Start.
2
Then click Settings.
3
Click Network and Dial-up Connections.
4
Double-click the network icon to open the connection window.
5
Click Properties.
6
Highlight Internet Protocol (TCP/IP) and click Properties.
If you have a DNS Server IP address from your ISP, enter it in the Preferred DNS Server field.
11
Click OK.
Windows NT
1
From the Start list, highlight Settings and then select Control Panel.
2
Double-click the Network icon in the Control Panel window.
3
Double-click TCP/IP in the TCP/IP Properties window.
4
Select Specify an IP Address.
5
Enter 192.168.168.200 in the IP Address field.
6
Enter 255.255.255.0 in the Subnet Mask field.
7
Click DNS at the top of the window.
8
Type the DNS IP address in the Preferred DNS Server field. If you have more than one address,
enter the second one in the Alternate DNS server field.
9
Click OK, and then click OK again.
10
Restart the computer.
Windows 98
1
From the Start list, highlight Settings and then select Control Panel. Double-click the Network
icon in the Control Panel window.
2
Double-click TCP/IP in the TCP/IP Properties window.
3
Select Specify an IP Address.
4
Enter 192.168.168.200 in the IP Address field.
5
Enter 255.255.255.0 in the Subnet Mask field.
6
Click DNS Configuration.
7
Type the DNS IP address in the Preferred DNS Server field. If you have more than one address,
type the second one in the Alternate DNS server field.
8
Click OK, and then click OK again.
9
Restart the computer.
Accessing the Management Interface
To access the SonicWALL Management Interface, you need to configure the Management Station
TCP/IP settings in order to initially contact the SonicWALL. A computer used to manage the
SonicWALL is referred to as the “Management Station.” Any computer on the same network as the
SonicWALL can be used to access the management interface.
MD5 authentication is used to secure communications between your Management Station and the
SonicWALL Web Management Interface. MD5 Authentication prevents unauthorized users from
detecting and stealing the SonicWALL password as it is sent over your network.
The Web browser used to access the management interface must be Java-enabled and support
HTTP uploads in order to fully manage the SonicWALL. If your Web browser does not support these
functions, certain features such as uploading firmware and saved preferences files are not available.
S
10
Alert: Please allow enough time for the SonicWALL security appliance to power up completely before
attempting to log into the Management Interface. It takes approximately one minute for the
SonicWALL security appliance to cycle completely. When the Test light is no longer lit, the
SonicWALL security appliance is ready for configuration.
Alert: Because you are temporarily disconnected from the Internet, you may receive an error
message when your Web browser first opens. This does not affect your installation process. Continue
with the steps below.
To begin the configuration of your SonicWALL security appliance, you must log into the SonicWALL
security appliance using a Web browser and the SonicWALL security appliance default LAN IP
address, 192.168.168.168. Follow the instructions below:
1
Launch your Web browser.
2
Enter 192.168.168.168 in the Location or Address field.
3
The first time you log into the SonicWALL Management Interface, the Setup Wizard is
automatically displayed for configuring your WAN (Internet) and LAN setup.
Cross Reference: See Chapter 49 Configuring Internet Connecitivity using the Setup Wizard.
Â
Troubleshooting
If you cannot connect to the SonicWALL security appliance, check the following:
• Did you correctly enter the SonicWALL security appliance default LAN IP address in your browser
window?
• Is the SonicWALL security appliance connected to the same network as your computer?
• Have you changed the TCP/IP network settings on your computer?
•Try pinging the 192.168.168.168 LAN IP address of the SonicWALL security appliance from your
computer. It should reply, assuming that you are using the correct TCP/IP network settings and
have a good ethernet connection. If it does reply, try again with the web browser to
The SonicWALL’s Web Management Interface provides a easy-to-use graphical interface for
configuring your SonicWALL. SonicWALL management functions are performed through a Web
browser.
Tip: Microsoft Internet Explorer 5.0 or higher, or, Netscape Navigator 4.5 or higher are two
9
recommended Web browsers.
Navigating the Management Interface
Navigating the SonicWALL Management Interface includes a hierarchy of menu buttons on the
navigation bar (left side of window). The SonicOS Enhanced menu buttons on the navigation bar
include:
•System
•Network
•Wireless
•Firewall
•VPN
•Users
•Hardware Failover
•Security Services
•Log
•Wizards
•Help
•Logout
When you click a menu button, related management functions are displayed as submenu items in the
navigation bar. To navigate to a submenu page, click the link. When you click a menu button, the first
submenu item page is displayed.
Applying Changes
Click the Apply button at the top right corner of the SonicWALL Management Interface to save any
configuration changes you made on the page.
If the settings are contained in a secondary window within the Management Interface, when you click
OK, the settings are automatically applied to the SonicWALL.
Getting Help
Each SonicWALL includes Web-based online help available from the Management Interface. Clicking
the question mark ? button on the top right corner of every page accesses the
context-sensitive help for the page.
Alert: SonicWALL online help requires Internet connectivity.
S
Logging Out
The Logout button at the bottom of the menu bar terminates the Management Interface session and
displays the Login page.