Get Started

Choose an outcome, confirm the license it needs, and complete the shortest path to a working configuration
Updated On: Oct 02, 2026

Overview

Setting up SonicWall Cloud Secure Edge (CSE) starts with the outcome you want, because the outcome determines which license you need and which steps apply.

Work through this page in order:

  1. Choose your use case from the table below.
  2. Confirm the license that use case requires.
  3. Complete the quick start for that license, which produces a working configuration on one device.
  4. Then follow the full guide for your use case, which configures it for the whole organization.

Prerequisites

Have the following in place before you start:

  1. CSE activation keys registered in MySonicWall, so that SonicWall provisions the org. See registering CSE.
  2. If you are connecting users to resources inside your own network: a private network, or a private service, that you want to reach, and a host on that network that can make outbound connections over HTTPS (port 443) and over UDP to the CSE Global Edge Network (ports 21000 to 59999). Not needed if you are only filtering internet content.
  3. A backup of your Gen 7 or later firewall, if you intend to use that firewall as the Connector.

Step 1. Choose your use case and confirm your license

{:.table.table-bordered.table-responsive}

Use caseWhat it gives youLicense requiredQuick start
Replace your legacy VPNA Service Tunnel carrying remote users into your private networkSecure Private Access (SPA)Reach a Resource on Your Network quick start
Block internet contentCompliance and threat filtering applied on the endpointSecure Internet Access (SIA)Filter Internet Content quick start
Set up ZTNAAccess to individually named resources rather than to a networkSecure Private Access (SPA) AdvancedReach a Resource on Your Network quick start
Protect SaaS appsDevice trust enforced on SaaS sign-inSecure Internet Access (SIA) AdvancedFilter Internet Content quick start

Protecting SaaS apps can also be achieved with IP allowlisting, which is included in SPA Basic rather than requiring SIA Advanced. The two techniques are compared in SaaS Apps. For what each license tier covers, see CSE Licenses.

Holding more than one license is common. The paths are independent, and neither is a prerequisite for the other.

Step 2. Complete the quick start for your license

Each quick start produces a working configuration on a single device, so that the path is proven before it is rolled out. Both follow the same shape:

  1. Activate Cloud Secure Edge. Register your activation key so SonicWall provisions the org. If you are connecting users to your own network, you also choose a deployment model at this point.
  2. Deploy network infrastructure. Only when connecting users to your own network: install a Connector in the network holding your private resources, or deploy an Access Tier if you are self-hosting on Private Edge. Nothing is needed here when you are only filtering internet content.
  3. Create a local test user. A single local account, rather than your production directory, so that a failure later is easy to attribute.
  4. Install and register the desktop app on one test device.
  5. Configure the feature. One Service Tunnel when connecting users to your own network, or one Internet Threat Protection policy when filtering internet content.
  6. Validate. Confirm the expected result, and confirm it appears in the console logs.

The two quick starts:

Why a local test user rather than your identity provider. Directory integration is the step most likely to need troubleshooting. Proving the tunnel or the policy works for one local account first means that if the directory integration then fails, you already know the underlying path is sound. The identity provider is integrated after validation, before the app is distributed widely. See Set Up an Identity Provider.

Step 3. Follow the full guide for your use case

A quick start stops at one working device. The guides in Use Cases take the same outcome and configure it properly for an organization, including the identity provider, the device manager rollout, and the policy set. They take longer than a quick start and assume the org is already activated.

Deployment models apply only when connecting users to your own network

CSE offers two deployment models for reaching private resources:

  • Global Edge, in which SonicWall hosts your edge infrastructure. This is the model most customers use, and you select the geographic Points of Presence during provisioning.
  • Private Edge, in which you self-host the edge infrastructure by deploying an Access Tier.

Choosing one model does not prevent you from adding the other later. For a full comparison, see edge deployment models.

This choice does not arise when you are only filtering internet content, because that traffic never routes through your own infrastructure.

Using a SonicWall firewall as your Connector. When connecting users to your own network, a Gen 7 or later firewall can act as the Connector instead of a dedicated host. See SonicOS Firewall as a Connector.

Guided Onboarding Set-up

The Cloud Secure Edge admin console offers a one-time guided onboarding set-up for orgs that meet all of the following conditions:

  • Global Edge deployment, or a combined Global Edge and Private Edge deployment
  • A Secure Private Access (SPA) license
  • A MySonicWall provisioned org, meaning not a Managed Service Provider org, accessed via admin single sign-on

If you want to set up a Service Tunnel, which is to say set up remote access, this guided onboarding set-up will help you accomplish that.

If the admin directly exits the Guided Onboarding Set Up, by selecting Exit at any point, they will not be able to return to it. If the admin indirectly exits the Guided Onboarding Set Up, by closing their browser, the Onboarding Set Up will be available exactly where they left off.