SonicWALL SMA 6200 Quick start guide

Type
Quick start guide

This manual is also suitable for

SonicWall™SecureMobileAccess6200/7200
GettingStartedGuide
RegulatoryModelNumbers:
1RK310B0SMA6200
1RK300AFSMA7200
Copyright©2017SonicWallInc.Allrightsreserved.
SonicWallisatrademarkorregisteredtrademarkofSoni cWallInc.and/oritsaffiliatesintheU.S.A.and/orothercountries.Allothertrademarksandregistered
trademarksarepropertyoftheirrespectiveowners
TheinformationinthisdocumentisprovidedinconnectionwithSonicWallInc.and/oritsaffiliates’products .Nolicense,expressor
implied,byesto ppelor
otherwise,toanyintellectualpropertyrightisgrantedbythisdocumentorinconnectionwiththesaleofSonicWallproducts.EXCEPTASSETFORTHINTHETERMS
ANDCONDITIONSASSPECIFIEDINTHELICENSEAGREEMENTFORTHISPRO DUCT,SONICWALLAND/ORITSAFFILIATESASSUMENOLIABILITYWHATSOEVERAND
DISCL AIMSANYEXPRESS,IMPLIEDORSTATUTORYWARRANTYREL ATINGTOITSPRODUCTSINCLUDIN G,BUTNOTLIMITEDTO,THEIMPLIEDWARRANT YOF
MERCHANTABILIT Y,FITNESSFORAPART ICU L AR PU RPOSE,ORNON‐INFRINGEMENT.INNOEVENTSHALLSONICWALLAND/ORITSAFFILIATESBELIABLEFORANY
DIRECT,INDIRECT,CONSEQUENTIAL,PUNITIVE,23200343152RevAf
thisdocumentandreservestherighttomakechangestospecificationsandproduct
descriptionsatanytimewithoutnotice.SonicWallInc.and/oritsaffiliatesdonotmakeanycommitmenttoupdatetheinformationcontainedinthisdocument.
Formoreinformation,visithttps://www.sonicwall.com/legal/.
SMA6200/7200GettingStartedGuide
Updated‐June2017
232003431
52RevA
Legend
WARNING:AWARNINGiconindicatesapotentialforpropertydamage,personalinjury,ordeath.
CAUTION:ACAUTIONiconindicatespotentialdamagetohardwareorlossofdataifinstructionsarenotfollowed.
IMPORTANT,NOTE,TIP,MOBILE,orVIDEO:Aninformationiconindicatessupportinginformation.
SonicWallSecureMobileAccess6200/7200GettingStartedGuide
3
1
InthisGuide
ThisGettingStartedGuideprovidesinstructionsforbasicinstallationandconfigurationoftheSonicWall™SecureMobileAccess
6200/7200appliances.
ForQuickPolicySetupCharts,refertoQuickPolicySetuponpage57.
Contents
Chapter1Sectionsincluded:
InthisGuideonpage3Contentsonpage3
Chapter2Sectionsincluded:
IntroductiontotheSMA6200/7200onpage7SMA6200/7200PackageContentsonpage8
SMA6200/7200FrontPanelsonpage10
SMA6200/7200BackPanelsonpage11
4
SonicWallSecur eMobileAccess6200/7200GettingStartedGuide
Chapter3Sectionsincluded:
PreparingtoDeploytheSMA6200/7200onpage13 NetworkArchitectureonpage14
PreparingfortheInstallationonpage16
AboutInstallationandDeploymentonpage19
Chapter4Sectionsincluded:
InstallationandConfigurationonpage21 ConnectingtheApplianceonpage22
StartingtheApplianceonpage22
EnteringNetworkSettingsUsing
theLCDonpage23
RunningtheSetupWizardonpage23
ConnectingtoAMConpage25
ConfiguringBasicWorkPlacePortalAccessonpage26
Chapter5Sectionsincluded:
RegisteringandObtainingaLicenseonpage31 UsingMySonicWallonpage32
CreatingaMySonicWallaccountonpage32
RegisteringyourApplianceonpage33
Downloading
yourLicenseFileonpage33
ImportingyourLicensesonpage34
SonicWallSecureMobileAccess6200/7200GettingStartedGuide
5
Forgeneralsupportinformation,seeSonicWallSupportonpage55.
Chapter6Sectionsincluded:
RackMountingtheApplianceonpage37 AttachingInnerRailstotheApplianceonpage40
InstallingtheOuterRailsonpage40
InstallingtheApplianceintheRackonpage42
RemovingtheAppli ancefromtheRackonpage42
Chapter7Sectionsincluded:
SafetyandRegulatoryInformationonpage45 SafetyInstructionsonpage46
Sicherheitsanweisungenonpage48
安全說明onpage51
DeclarationofConformityonpage53
WarrantyInformationonpage53
台灣 RoHS/ 限用物質含有情況標示資訊onpage54
6
SonicWallSecureMobileAccess6200/7200GettingStartedGuide
SonicWallSecureMobileAccess6200/7200GettingStartedGuide
7
2
IntroductiontotheSMA6200/7200
Thissectiondescri bestheitemsshippedwiththeSonicWallSecureMobileAccess6200/7200appliancesandprovidesfrontand
rearillustrationsoftheappliances.
SMA6200/7200PackageContentsonpage8
SMA6200/7200FrontPanelsonpage10
SMA6200/7200BackPanelsonpage11
8
SonicWallSecur eMobileAccess6200/7200GettingStartedGuide
SMA6200/7200PackageContents
Beforeyoubeginthesetupprocess,verifythatyourpackagecontainsthefollowingitems:
1OneSMA6200orSMA7200appliance
2Onerackmountingkit
3OneRJ45toDB9consolecable
4OneEthernetcable
5OnepowercordforSMA6200ortwopowercordsforSMA7200*
6OneSonicWallSecureMobileAccess6200/7200Getting
StartedGuide
*Theincludedpowercord(s)areapprovedforuseonlyinspecificcountriesorregions.Beforeusingapowercord,verifythatitis
ratedandapprovedforuseinyourlocation.ThepowercordsareforACmainsinstallationonly.SeeSafetyandRegulatory
Informationonpage45for
minimumpowercordratingandadditionalsafetyinformation.
添付の電源 に関
電気安全確保 弊社製品に使用い 電源 は必ず製品同梱の電源 使用 い。
の電源 は他の製品は使用 せん
SonicWallSecureMobileAccess6200/7200GettingStartedGuide
9
Packagecontents
Ifanyitemsaremissingfromyourpackage,contactSupportathttps://support.sonicwall.com.
1
4
5
6
3
2
SonicWall™ Secure Mobile Access 6200/7200
Geƫng Started Guide
Regulatory Model Numbers:
1RK31-0B0 – SMA 6200
1RK30-0AF – SMA 7200
10
SonicWallSecur eMobileAccess6200/7200GettingStartedGuide
SMA6200/7200FrontPanels
LCD controls
Console port
DisplayPort
USB ports
LED Indicators
(top to bottom)
Hard disk drive activity
Alarm condition
Test - Quick blinking: Initializing;
Solid: Test mode
Power 1/2 - Blue: operating correctly;
Yellow: Unconnected power supply or failure
X1 / X0
X3 / X2
X5 / X4
SFP+ ports
(10 Gb)
Diagnostics port
(for future use)
(Disabled)
(1 Gb)
(1 Gb)
Digital audio/video
SonicWallSecureMobileAccess6200/7200GettingStartedGuide
11
SMA6200/7200BackPanels
SMA6200:
Hard drives (2) Power supply
Fans (3)
12
SonicWallSecur eMobileAccess6200/7200GettingStartedGuide
SMA7200:
Hard drives (2) Power supplies (2)
Fans (3)
SonicWallSecureMobileAccess6200/7200GettingStartedGuide
13
3
PreparingtoDeploytheSMA6200/7200
Thissectionprovidesanoverviewofsinglehomedanddualhomednetworkarchitectureanddiscussesfirewallsettingsandother
informationyouneedaboutcomponentsofyournetworktosuccessfullydeploytheSMA6200/7200.
NetworkArchitectureonpage14
PreparingfortheInstallationonpage16
AboutInstallationandDeploymentonpage
19
14
SonicWallSecureMobileAccess6200/7200GettingStartedGuide
NetworkArchitecture
AllSMA6200/7200appliancescanbesetupineitheradual
interfaceorsingleinterfaceconfiguration,alsoknownasdual
homedandsinglehomed.
Ineitherconfiguration,appliancemanagementwithAMCis
accomplishedbyaccessingtheinternal(X0)interface.
Thisguidestepsyouthroughabasicsinglehomedinterface
configuration.For
thehighestlevelofsecurityand
performance,SonicWallrecommendsadualhomed
configuration.Ref ertotheDeploymentPlanningGuideand
SMAAdministrationGuide forfurtherinformation.
DualHomedConfiguration(Internal
andExternalInterfaces)
Onenetworkinterfaceisusedforexternaltraffic(thatis,to
andfromtheInternet),andtheotherinterfaceisusedfor
internaltraffic(toandfromyourcorporatenetwork).
SingleHomedInterfaceConfiguration
(InternalInterface)
Asinglenetworkinterfaceisusedforbothinternaland
externaltraffic.Inthisconfiguration,theapplianceisusually
installedinthedemilitarizedzone(orDMZ,alsoknownasa
perimeternetwork).
SMA appliance
Firewall
Corporate network
Internet
File
Server
Application
Server
Web
Server
Firewall
DMZ
Internal interface
SMA appliance
SonicWallSecureMobileAccess6200/7200GettingStartedGuide
15
Inbothconfigurations,incomingrequeststotheSMA6200/
7200services—includingHTTP/StrafficfortheWebproxy
service—aresentoverport80(HTTP)andport443(HTTPS).
TrafficfromtheOnDemandagentisalwayssentoverport443.
Becausemostnetworksareconfiguredtoenabletrafficover
theseports,youshould
notneedtoreconfigurefirewallson
yournetwork.
Youshouldinstalltheapplianceinalocationwhereitcan
connecttoresourcesonyournetwork,including:
Applicationserversandfileservers,includingWeb
servers,client/serverapplications,andWindowsfile
servers.
Externalauthenticationrepositories(suchasanLDAP,
MicrosoftActiveDirectory,or
RADIUSserver).
OneormoreDomainNameSystem(DNS)servers.
Optionally,aWindowsInternetNameService(WINS)
server.ThisisrequiredforbrowsingWindowsnetworks
usingWorkPlace.
Althoughnotrequired,enablingtheappliancetocommunicate
withtheseadditionalresourcesprovidesgrea terfunctionality
andeaseofuse:
NetworkTimeProtocol(NTP)
serverforsynchronizing
thetimeontheappliance.
Externalserverforstoringsyslogoutput.
Administratorsworkstationforsecureshell(SSH)
access.
Youcanconfiguretheappliancetouseaselfsignedserver
certificate,or,forenhancedsecurity,youcanobtaina
certificatefromacommercialcertificateauthority(CA).For
moreinformation,
refertotheSMAAdministrationGuide.
CAUTION:TheSMA6200/7200appliancedoesnot
providefullfirewallcapabilitiesandshouldbesecured
behindafirewall.Runningwithoutafirewallmakesthe
appliancevulnerabletoattacksthatcancompromise
securityanddegradeperformance.
16
SonicWallSecureMobileAccess6200/7200GettingStartedGuide
PreparingfortheInstallation
Beforebeginningtheinstallation,youneedtogather
informationaboutyournetworkingenvironmentandverify
thatyourfirewallsareproperlyconfiguredtopermittrafficto
andfromtheapplianceasexplainedinthefollowingsections:
GatheringInformationonpage16
VerifyingyourFirewallPoliciesonpage17
GatheringInformation
Beforeconfiguringtheappliance,youneedtogatherthe
followinginform ation.Youarepromptedforsomeofthis
informationwhenrunningtheSetupWizard,butmostofitwill
beusedwhenyouconfiguretheapplianceintheAppliance
ManagementConsole(AMC).RefertotheSMAAdministration
Guide.
Settingsrequired
tostartApplianceManagementConsole
Therootpasswordforadministeringtheappliance
Thenamefortheappliance(becausethisnameisused
onlyinlogfiles,youdonotneedtoaddittoDNS)
TheinternalIPaddressand,optionally,anexternalIP
address
Selectaroutingmodeandsupply
IPaddressesforthe
networkgatewaystotheInt ernet,andyourcorporate
network.
Certificateinformation
Severalpiecesofinformationareusedtogener atetheserver
andAMCcertificates:
Afullyqualifieddomainname(FQDN)fortheappliance
andforanyWorkPlacesitesthatuseauniquename.
Thesenamesshouldbe
addedtoyourpublicDNS;they
arealsovisibletouserswhentheyconnecttoWeb
basedresources.
AFQDNfortheApplianceManagementConsole(AMC)
server.TheAMCservernameisusedtoaccessAMC,
whichisaWebbasedtoolforadministeringthe
appliance.
Namelookupinformation
InternalDNS
domainnameofthenetworktowhichthe
applianceisconnected
PrimaryinternalDNSserveraddress(additionalDNS
serversareoptional)
IPaddressforaninternalWINSserverandthenameof
yourWindowsdomain(requiredtobrowsefilesona
WindowsnetworkusingWorkPlace,butareotherwise
optional)
SonicWallSecureMobileAccess6200/7200GettingStartedGuide
17
Authenticationinformation
Servernameandlogininformationforyourauthentication
servers(LDAP,ActiveDirectory,orRADIUS)
VirtualAddresspoolinformation
Ifyouareplanningtodeployeithernetworktunnelclient
(ConnectTunnelorOnDemandTunnel),youmustallocateIP
addressesforoneormoreaddresspools.Formore
information,refertothe
SMAAdministration Guide.
Optionalconfigurationinformation
ToenableSSHaccessfromaremotemachine,youneed
toknowtheremotehosts IPaddress.
TosynchronizewithanNTPserver,youneedtoknow
theIPaddressesforoneormoreNTPservers.
Tosenddatatoasyslogserver,
youneedtoknowtheIP
addressandportnumberforoneormoresyslog
servers.
VerifyingyourFirewallPolicies
Fortheappliancetofunctioncorrectly,youmustopenports
onyourexternal(Internetfacing)andinternalfirewalls.
ExternalFirewall
Forsecureaccesstotheapp liancefromaWebbrowseror
OnDemand,youmustmakesurethatports80and443are
openonfirewallsatyoursite.Openingyourfirewalltopermit
SSHaccessisoptional,butcanbeusefulforperforming
administrativetasksfromaremotesystem.
ExternalFirewall
Traffic
Type
Port/
protocol
Usage Required?
ESP 4500/UDP ESPTunnel Yes
HTTP 80/tcp Unencryptednetwork
access
Yes
HTTPS 443/tcp Encryptednetworkaccess Yes
SSH 22/tcp Administrativeaccessto
theapplication
No
18
SonicWallSecureMobileAccess6200/7200GettingStartedGuide
InternalFirewall
Ifyouhaveafirewallontheinternalnetwork,youmayneedto
adjustitspolicytoopenportsforbackendapplicationswith
whichtheappliancemustcommunicate.Inadditionto
openingportsforstandardnetworkser vicessuchasDNSand
email,youmayneedtomodifyyourfirewallpolicy
beforethe
appliancecanaccessthefollowingservices.
InternalFirewall
TrafficType Port/protocol Usage
Microsoft
networking
138/tcpand
138/udp
137/tcpand
137/udp
139/udp
162/snmp
445/smb
UsedbyWorkPlaceto
performWINSname
resolution,browse
requests,andaccess
fileshares
LDAP
(unencrypted)
389/tcp Communicatewithan
LDAPdirectoryor
MicrosoftActive
Directory
LDAPoverSSL
(encrypted)
636/tcp Communicatewithan
LDAPdirectoryor
MicrosoftActive
DirectoryoverSSL
RADIUS 1645/udpor
1812/udp
Communicatewitha
RADIUSauthentication
server
NTP 123/udp Synchronizethe
applianceclockwithan
NTPserver
Syslog 514/tcp Sendsystemlog
informationtoasyslog
server
SNMP 161/udp Monitortheappliance
fromanSNMP
managementtool
InternalFirewall
TrafficType Port/protocol Usage
SonicWallSecureMobileAccess6200/7200GettingStartedGuide
19
AboutInstallationand
Deployment
Thissectionoutlinestheprocessofinstalling,configuring,and
testingtheappliance,andthendeployingitinaproduction
environment.TheInstallationandDeploymentProcesstable
providesanoverviewofthesteps.
InstallationandDeploymentProcess
InstallationStep Description
Makeanoteofyour
applianceserial
numberand
authenticationcode.
Youllneedthisinformation
when you
registeryourproducton
MySonicWall.Theserialnumberand
authenticationcodeareprintedon
yourappliancelabel;theyarealso
displayedontheGeneralSettings
pageinAMC.
Rackmountthe
applianceand
connectthecables.
SeeRackMountingtheApplianceon
page37andConnectingthe
Appliance on
page22.
Turnontheappliance
andbegin
configuration.
Toconnect toyourapplianceonyour
internalnetworkyoumustspecifyan
internalIPaddressandthesubnet
mask.Usethecontrolsonthe frontof
theappliance.SeeEnteringNetwork
SettingsUsingtheLCDonpage23.
RunSetupWizard. Thewizardguides
youthroughthe
processofinitialsetupforyourSMA
appliance.SeeRunningtheSetup
Wizardonpage23.
Registeryour
applianceon
MySonicWall.
Registeryourapplianceon
MySonicWall.Productregistration
givesyouaccesstoessential
resources,suchasyourlicensefile
andupdates.Toregister,youneed
boththeserial
numberforyour
applianceanditsauthentication
code.
InstallationandDeploymentProcess
InstallationStep Description
20
SonicWallSecureMobileAccess6200/7200GettingStartedGuide
  • Page 1 1
  • Page 2 2
  • Page 3 3
  • Page 4 4
  • Page 5 5
  • Page 6 6
  • Page 7 7
  • Page 8 8
  • Page 9 9
  • Page 10 10
  • Page 11 11
  • Page 12 12
  • Page 13 13
  • Page 14 14
  • Page 15 15
  • Page 16 16
  • Page 17 17
  • Page 18 18
  • Page 19 19
  • Page 20 20
  • Page 21 21
  • Page 22 22
  • Page 23 23
  • Page 24 24
  • Page 25 25
  • Page 26 26
  • Page 27 27
  • Page 28 28
  • Page 29 29
  • Page 30 30
  • Page 31 31
  • Page 32 32
  • Page 33 33
  • Page 34 34
  • Page 35 35
  • Page 36 36
  • Page 37 37
  • Page 38 38
  • Page 39 39
  • Page 40 40
  • Page 41 41
  • Page 42 42
  • Page 43 43
  • Page 44 44
  • Page 45 45
  • Page 46 46
  • Page 47 47
  • Page 48 48
  • Page 49 49
  • Page 50 50
  • Page 51 51
  • Page 52 52
  • Page 53 53
  • Page 54 54
  • Page 55 55
  • Page 56 56
  • Page 57 57
  • Page 58 58
  • Page 59 59

SonicWALL SMA 6200 Quick start guide

Type
Quick start guide
This manual is also suitable for

Ask a question and I''ll find the answer in the document

Finding information in a document is now easier with AI