RIS Terms of Service & FAQs: Firewall
11/08/2024 0 People found this article helpful 44,418 Views
Description
The Remote Implementation Service for a SonicWall Firewall appliance is a deployment service (“Activity”) that deploys and integrates the SonicWall Firewall physical or virtual appliance into a customer environment. This Activity is typically implemented within 10 business days after the SonicWall Advanced Services Partner receives the completed implementation planning document(s). The Activities will be limited to those stated herein.
What is RIS for SonicWall Firewalls?
SonicWall Remote Implementation Services are delivered by SonicWall’s Advanced Services partners who have completed extensive training, certification and have demonstrated expertise in all aspects and products of SonicWall’s solution platform. Upon the completion of purchase and processing, the Advanced Services partner will begin the coordination of the Remote Implementation Service within five (5) business days. Upon completion of the Remote Implementation Service, the Advanced Services partner will continue to support the configuration for thirty (30) calendar days.
What is Included?
The planned Activities include the following:
Pre-Deployment Steps
- Review existing network topology and configuration
- Review firewall intended use and compliance requirements
- Review of underlying virtual infrastructure for appropriate sizing (if applicable)
Configuration
- Register unit and upgrade firmware
- Pre-configuration of the unit remotely
- Convert all NAT and Firewall rules from existing security appliance(s)
- Configure General Settings (e.g. System Time, DHCP, etc.)
- Configure Network Interfaces and VLAN
- Define Address Objects and Groups
- Define Service Objects and Groups
- Define Access Control Rules
- Define NAT policies
- Configure advanced authentication (Local, LDAP, TACACS or RADIUS)
- Configure Global VPN Client and/or SSL-VPN
- Configure Global VPN Client and/or SSL-VPN
- Configuration of appropriate remote access client on up to three supported devices
- Configure Site-to-Site VPN Tunnels (up to 10) with other firewalls (if applicable – need access to remote firewalls)
- Configure High Availability unit in Active/Passive Mode (if applicable – requires additional HA appliance)
- Configure Security Services to recommended settings
- Gateway Anti-Virus
- Intrusion Protection Service
- Anti-Spyware
- Geo-IP
- Botnet
- Content Filter Service (No more than two policies)
- Application Visualization (if requested)
- Application Control (Best practice standard configuration)
- Capture ATP
- Configure integrated wireless (if applicable) with a up to two SSIDs
Installation
- Work with customer over the phone to complete the physical or virtual installation
- Verify NAT and Firewall rules are working as expected
- Verify Site-to-Site VPN(s) are passing data
- Verify Global Client VPN and/or SSL-VPN users are able to connect
- High Availability Failover testing (if applicable)
- WAN Failover testing
- Content Filter Service testing
- Application Visualization testing
- After testing is complete, provide customer with a backup of all settings
- Configurations will be completed during normal business hours 0800 – 1700 hours Monday – Friday Local Standard Time
- Service Cutover may be after hours from 1700 – 1800 hours Monday – Friday Local Standard Time
Does the configuration include any changes to my current configuration?
MSS will implement Industry standard security best practices, along with MSS recommended best practices for all Security Services. This includes making sure all the available security services are enabled and configured in order to provide a balance between maintaining a strong security posture and the flexibility for users to work without interference.
How long will the network be down?
Downtime is typically as long as it takes you to move cables from the old device to the new one. If followed, our RIS process and procedures have allowed us to maintain a 99.9% success rate for remote implementations. We take the time to make sure everything is configured properly beforehand to minimize downtime. Most customers are down for less than 60 seconds.
How long does the entire process take?
While we will not know exact time frames until we have more specific information about the configuration and environment, we strive to have most remote implementations completed in about 10 business days after we receive the completed implementation planning document(s). This is of course subject to change based on complexity of customer’s environment/ configuration.
Are same-day or after hours installs supported?
Same-day configurations and implementations are not supported due to the ongoing support and other scheduled appointments of our customers. After hours appointments are done on a case-by-case basis and largely depend on the engineer’s schedule. Under NO circumstances will MSS do a Sunday install.
Does MSS provide support after the implementation?
Yes! We provide a 30-day trial of our level 3 firewall monitoring and threat analytic service. During this time, all support by MSS is included at no charge. After the 30-days, you have the option to continue with the service or upgrade to one of our many other levels of Firewall Monitoring and Threat Analytic services. More information about the services can be found here MSS Firewall Monitoring & Management Services. Support is provided during MSS’s normal business hours (Monday - Friday, 8:00am - 5:00pm EST).
Is there anything NOT included?
Yes! While we will do our best to go above and beyond to help with everything that we possibly can, there are a few things that are not included in the standard RIS to allow our engineers to complete your implementation in the allotted time. We offer configuration/assistance with the below out of scope items on hourly or project cost basis:
- Configuration of SonicPoint or SonicWave Wireless Access Points
- Configuration of Software Defined WAN (SDWAN) components
- Integration with management platforms
- Physical or Virtual Switch configuration
- Configuration of more than 5 local users for authentication
- Enforced Anti-Virus implementation
- Configuration of Comprehensive Anti-Spam Service
- Configuration of WAN Acceleration
- Configuration of additional VPN Tunnels
- Virtual Assist configuration
- Client software deployment
- GMS installation/configuration
- Training/Consulting Services
- Provide configuration after hours
- Provide Landing page or Automated certificate enrollment method
Scope of Work Prerequisites and Terms
- The customer must ensure that the existing infrastructure, hardware and (if applicable) virtualized configuration is enough to support the environment
- The customer must commit a technical resource on a full-time basis to provide SonicWall or the partner with the assistance required
- Customer is required to present DPI-SSL certificate to the installation technician
- Customer is required to perform self-enrollment of DPI-SSL Certificate
- Customer is required to have health Active Directory and will make all Microsoft configurations.
- All activities will be performed remotely utilizing Zoom phone and web conferencing
- SonicWall and/or the provider of the Activities may require execution of additional documentation before performance of the Activities begin. This additional documentation may include (without limitation) dates for the work to begin. If the provider of the Activities can accommodate a change in schedule related to the Activities, the provider may require a two (2) week lead time (or more before Activities can be performed.
- If a customer makes any changes during or after the Activities begin, additional charges and/or schedule changes may apply.
- Only configured features publicly posted by SonicWall in the Datasheets may be configured.
- Not all Activities may need to be configured.
- The information provided herein is a general description of Activities. Any services delivered that are not explicitly outlined herein are not a part of this offer.
- The duration for the provision of Activities may vary based on many factors including, but not limited to, the complexity of the customer’s environment.
SonicWall Partner Enabled Service Version: SonicWall Remote Implementation Service - Firewall Appliances
Related Articles
Categories