SonicOS Cloud Secure Edge Feature Guide

Connector Concepts

The Connector is a dial-out connector that establishes a secure tunnel with the Global Edge Network. It deploys in any location that has connectivity to your internal services. Each Connector only connects outbound and does not need any inbound open ports to operate correctly.

The CSE Connector for SonicOS firewall allows secure remote access to private resources behind the firewall. CSE infrastructure enforces access control, not by the SonicOS firewall. Traffic ingresses SonicOS via WireGuard tunnels from CSE POPs. Only inbound access (WAN to protected zones from a firewall perspective) is allowed. SonicOS Group Address Object is created automatically (per Connector). The firewall admin configures the allowed private IPv4 addresses (Group address object) and private domains, if any, that SonicOS firewall needs to resolve for the CSE clients. The Connector establishes a WireGuard tunnel to CSE POPs.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden