SSL VPN is one method of allowing remote users to connect to the SonicWall and access the internal network resources. SSL VPN connections can be setup with one of three methods:
This article details how to setup the SSL VPN Feature for NetExtender and Mobile Connect users, both of which are software based solutions.
NetExtender is available for the following Operating Systems:
Mobile Connect is available for the following Operating Systems:
Don't want to read? Watch instead!
This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.
Creating an Address Object for the SSL VPN IPv4 Address Range
TIP: This is only a Friendly Name used for Administration.
NOTE: This does not have to be a range and can be configured as a Host or Network as well. To avoid IP Spoof errors and routing issues, we recommend to use a subnet which is not configured anywhere else on the SonicWall.
SSL VPN Configuration
Adding Users to SSL VPN Services Group
NetExtender Users may either authenticate as a Local User on the SonicWall or as a member of an appropriate Group through LDAP. This article will cover setting up Local Users, however if you're interested in using LDAP please reference How to Configure LDAP Authentication for SSL VPN Users.
Checking Access rule Information for SSL VPN Zone
This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
Creating an Address Object for the SSL VPN IPv4 Address Range
TIP: This is only a Friendly Name used for Administration.
NOTE: This does not have to be a range and can be configured as a Host or Network as well. To avoid IP Spoof errors and routing issues, we recommend to use a subnet which is not configured anywhere else on the SonicWall.
SSL VPN Configuration
NOTE: The SSL VPN port will be needed when connecting using Mobile Connect and NetExtender unless the port number is 443. Port 443 can only be used if the management port of the firewall is not 443. The Domain is used during the user login process. If you want to be able to manage the firewall via GUI or SSH over SSL VPN these features can be enabled separately here as well.
CAUTION: NetExtender cannot be terminated on an Interface that is paired to another Interface using Layer 2 Bridge Mode. This includes Interfaces bridged with a WLAN Interface. Interfaces that are configured with Layer 2 Bridge Mode are not listed in the "SSL VPN Client Address Range" Interface drop-down menu. For NetExtender termination, an Interface should be configured as a LAN, DMZ, WLAN, or a custom Trusted, Public, or Wireless zone, and also configured with the IP Assignment of "Static".
CAUTION:All SSL VPN Users can see these routes but without appropriate VPN Access on their User or Group they will not be able to access everything shown in the routes. Please make sure to set VPN Access appropriately.
Adding Users to SSL VPN Services Group
NetExtender Users may either authenticate as a Local User on the SonicWall or as a member of an appropriate Group through LDAP. This article will cover setting up Local Users, however if you're interested in using LDAP please reference How to Configure LDAP Authentication for SSL VPN Users.
CAUTION: SSL VPN Users will only be able to access resources that match both their VPN Access and Client Routes.
Checking Access rule Information for SSL VPN Zone
NOTE: This does not grant access to all users, individual access is still granted to users based on their VPN access and SSL VPN routes. Access rules are needed for the firewall to allow this traffic through.
Testing the Connection with NeNetextender
Download and install SonicWall NetExtender that is available via SonicWall.com. You can follow this link for the instructions:
Configure NetExtender like the following example.
Server: specify the Ip Address of the SonicWall WAN (by default SSL VPN is enabled on every WAN Interface of the SonicWall) followed by the port (specified in Server Settings of SSL VPN)
You can also specify a DNS name if you have a DNS published for your organization, e.g. sslvpn.mycompany.com:4433
Username: insert the user that you want to connect with
Password: specify the password for that user
Domain: insert the Domain Name (case sensitive) specified in Server Settings of SSL VPN.
Click Connect.
Once reached the SSL VPN Server on the SonicWall NetExder will prompt for a Security Alert, click Accept to establish the connection.
Testing the Connection with Mobile Connect
Mobile Connect is available to download from Sonicwall.com. You can select the desired option amoong iOS, macOS, Android and Chrome OS.
Mobile Connect on Mac OS
Start the program and click on Add Connection, fill the forms like the example below and click Next
Click Continue
Fill the forms like the example below and click
Click Connect
When prompted click Allow to establish the VPN Connetion
TIP: Ping is a great tool to test access to resources once the VPN Connection has established. If Pings are Timing Out it's advisable to perform a Packet Monitor on the SonicWall to determine what is happening to the traffic. Keep in mind, pings to the SonicWall are considered management traffic and require specific access rules to allow this traffic..