Setting up SonicWall Cloud Secure Edge (CSE) starts with the outcome you want, because the outcome determines which license you need and which steps apply.
Work through this page in order:
Have the following in place before you start:
{:.table.table-bordered.table-responsive}
| Use case | What it gives you | License required | Quick start |
|---|---|---|---|
| Replace your legacy VPN | A Service Tunnel carrying remote users into your private network | Secure Private Access (SPA) | Reach a Resource on Your Network quick start |
| Block internet content | Compliance and threat filtering applied on the endpoint | Secure Internet Access (SIA) | Filter Internet Content quick start |
| Set up ZTNA | Access to individually named resources rather than to a network | Secure Private Access (SPA) Advanced | Reach a Resource on Your Network quick start |
| Protect SaaS apps | Device trust enforced on SaaS sign-in | Secure Internet Access (SIA) Advanced | Filter Internet Content quick start |
Protecting SaaS apps can also be achieved with IP allowlisting, which is included in SPA Basic rather than requiring SIA Advanced. The two techniques are compared in SaaS Apps. For what each license tier covers, see CSE Licenses.
Holding more than one license is common. The paths are independent, and neither is a prerequisite for the other.
Each quick start produces a working configuration on a single device, so that the path is proven before it is rolled out. Both follow the same shape:
The two quick starts:
Why a local test user rather than your identity provider. Directory integration is the step most likely to need troubleshooting. Proving the tunnel or the policy works for one local account first means that if the directory integration then fails, you already know the underlying path is sound. The identity provider is integrated after validation, before the app is distributed widely. See Set Up an Identity Provider.
A quick start stops at one working device. The guides in Use Cases take the same outcome and configure it properly for an organization, including the identity provider, the device manager rollout, and the policy set. They take longer than a quick start and assume the org is already activated.
CSE offers two deployment models for reaching private resources:
Choosing one model does not prevent you from adding the other later. For a full comparison, see edge deployment models.
This choice does not arise when you are only filtering internet content, because that traffic never routes through your own infrastructure.
Using a SonicWall firewall as your Connector. When connecting users to your own network, a Gen 7 or later firewall can act as the Connector instead of a dedicated host. See SonicOS Firewall as a Connector.
The Cloud Secure Edge admin console offers a one-time guided onboarding set-up for orgs that meet all of the following conditions:
If you want to set up a Service Tunnel, which is to say set up remote access, this guided onboarding set-up will help you accomplish that.
If the admin directly exits the Guided Onboarding Set Up, by selecting Exit at any point, they will not be able to return to it. If the admin indirectly exits the Guided Onboarding Set Up, by closing their browser, the Onboarding Set Up will be available exactly where they left off.