SonicWALL SMA 6200 User manual

SonicWall™SecureMobileAccess6200/7200
GettingStartedGuide
RegulatoryModelNumbers:
1RK31‐0B0–SMA6200
1RK30‐0AF–SMA7200

Copyright©2017SonicWallInc.Allrightsreserved.
SonicWallisatrademarkorregisteredtrademarkofSonicWallInc.and/oritsaffiliatesintheU.S.A.and/orothercountries.Allothertrademarksandregistered
trademarksarepropertyoftheirrespectiveowners
TheinformationinthisdocumentisprovidedinconnectionwithSonicWallInc.and/oritsaffiliates’products.Nolicense,expressorimplied,byestoppelor
otherwise,toanyintellectualpropertyrightisgrantedbythisdocumentorinconnectionwiththesaleofSonicWallproducts.EXCEPTASSETFORTHINTHETERMS
ANDCONDITIONSASSPECIFIEDINTHELICENSEAGREEMENTFORTHISPRODUCT,SONICWALLAND/ORITSAFFILIATESASSUMENOLIABILITYWHATSOEVERAND
DISCLAIMSANYEXPRESS,IMPLIEDORSTATUTORYWARRANT YRELATINGTOITSPRODUCTSINCLUDING,BUTNOTLIMITEDTO,THEIMPLIEDWARRANT YOF
MERCHANTABILITY,FITNESSFORAPA RT I C U L A R PURPOSE,ORNON‐INFRINGEMENT.INNOEVENTSHALLSONICWALLAND/ORITSAFFILIATESBELIABLEFORANY
DIRECT,INDIRECT,CONSEQUENTIAL,PUNITIVE,232‐003431‐51RevBfthisdocumentandreservestherighttomakechangestospecificationsandproduct
descriptionsatanytimewithoutnotice.SonicWallInc.and/oritsaffiliatesdonotmakeanycommitmenttoupdatetheinformationcontainedinthisdocument.
Formoreinformation,visithttps://www.sonicwall.com/legal/.
SMA6200/7200GettingStartedGuide
Updated‐June2017
232‐003431‐51RevB
Legend
WARNING:AWARNINGiconindicatesapotentialforpropertydamage,personalinjury,ordeath.
CAUTION:ACAUTIONiconindicatespotentialdamagetohardwareorlossofdataifinstructionsarenotfollowed.
IMPORTANT,NOTE,TIP,MOBILE,orVIDEO:Aninformationiconindicatessupportinginformation.

SonicWallSecureMobileAccess6200/7200GettingStartedGuide 3
1
InthisGuide
ThisGettingStartedGuideprovidesinstructionsforbasicinstallationandconfigurationoftheSonicWall™SecureMobileAccess
6200/7200appliances.
ForQuickPolicySetupCharts,refertoQuickPolicySetuponpage57.
Contents
Chapter1Sectionsincluded:
InthisGuideonpage3Contentsonpage3
Chapter2Sectionsincluded:
IntroductiontotheSMA6200/7200onpage7SMA6200/7200PackageContentsonpage8
SMA6200/7200FrontPanelsonpage10
SMA6200/7200BackPanelsonpage11

4SonicWallSecureMobileAccess6200/7200GettingStartedGuide
Chapter3Sectionsincluded:
PreparingtoDeploytheSMA6200/7200onpage13 NetworkArchitectureonpage14
PreparingfortheInstallationonpage16
AboutInstallationandDeploymentonpage19
Chapter4Sectionsincluded:
InstallationandConfigurationonpage21 ConnectingtheApplianceonpage22
StartingtheApplianceonpage22
EnteringNetworkSettingsUsingtheLCDonpage23
RunningtheSetupWizardonpage23
ConnectingtoAMConpage25
ConfiguringBasicWorkPlacePortalAccessonpage26
Chapter5Sectionsincluded:
RegisteringandObtainingaLicenseonpage31 UsingMySonicWallonpage32
CreatingaMySonicWallaccountonpage32
RegisteringyourApplianceonpage33
DownloadingyourLicenseFileonpage33
ImportingyourLicensesonpage34

SonicWallSecureMobileAccess6200/7200GettingStartedGuide 5
Forgeneralsupportinformation,seeSonicWallSupportonpage55.
Chapter6Sectionsincluded:
RackMountingtheApplianceonpage37 AttachingInnerRailstotheApplianceonpage40
InstallingtheOuterRailsonpage40
InstallingtheApplianceintheRackonpage42
RemovingtheAppliancefromtheRackonpage42
Chapter7Sectionsincluded:
SafetyandRegulatoryInformationonpage45 SafetyInstructionsonpage46
Sicherheitsanweisungenonpage48
安全說明onpage51
DeclarationofConformityonpage53
WarrantyInformationonpage53
台灣 RoHS/限用物質含有情況標示資訊onpage54

6SonicWallSecureMobileAccess6200/7200GettingStartedGuide

SonicWallSecureMobileAccess6200/7200GettingStartedGuide 7
2
IntroductiontotheSMA6200/7200
ThissectiondescribestheitemsshippedwiththeSonicWallSecureMobileAccess6200/7200appliancesandprovidesfrontand
rearillustrationsoftheappliances.
•SMA6200/7200PackageContentsonpage8
•SMA6200/7200FrontPanelsonpage10
•SMA6200/7200BackPanelsonpage11

8SonicWallSecureMobileAccess6200/7200GettingStartedGuide
SMA6200/7200PackageContents
Beforeyoubeginthesetupprocess,verifythatyourpackagecontainsthefollowingitems:
1OneSMA6200orSMA7200appliance
2Onerackmountingkit
3OneRJ45toDB9consolecable
4OneEthernetcable
5OnepowercordforSMA6200ortwopowercordsforSMA7200*
6OneSonicWallSecureMobileAccess6200/7200GettingStartedGuide
*Theincludedpowercord(s)areapprovedforuseonlyinspecificcountriesorregions.Beforeusingapowercord,verifythatitis
ratedandapprovedforuseinyourlocation.ThepowercordsareforACmainsinstallationonly.SeeSafetyandRegulatory
Informationonpage45forminimumpowercordratingandadditionalsafetyinformation.
添付の電源コ ー ド に関 し て
電気安全を確保する ために、 弊社製品にご使用いただ く 電源 コ ー ド は必ず製品同梱の電源コ ー ド を ご使用 く だ さ い。
こ の電源コ ー ド は他の製品では使用で き ません。

SonicWallSecureMobileAccess6200/7200GettingStartedGuide 9
Packagecontents
Ifanyitemsaremissingfromyourpackage,contactSupportathttps://support.sonicwall.com.
1
45
6
3
2
SonicWall™ Secure Mobile Access 6200/7200
Geƫng Started Guide
Regulatory Model Numbers:
1RK31-0B0 – SMA 6200
1RK30-0AF – SMA 7200

10 SonicWallSecureMobileAccess6200/7200GettingStartedGuide
SMA6200/7200FrontPanels
LCD controls
Console port
DisplayPort
USB ports LED Indicators
(top to bottom)
Hard disk drive activity
Alarm condition
Test - Quick blinking: Initializing;
Solid: Test mode
Power 1/2 - Blue: operating correctly;
Yellow: Unconnected power supply or failure
X1 / X0
X3 / X2
X5 / X4
SFP+ ports
(10 Gb)
Diagnostics port
(for future use)
(Disabled)
(1 Gb)
(1 Gb)
Digital audio/video

SonicWallSecureMobileAccess6200/7200GettingStartedGuide 11
SMA6200/7200BackPanels
SMA6200:
Hard drives (2) Power supply
Fans (3)

12 SonicWallSecureMobileAccess6200/7200GettingStartedGuide
SMA7200:
Hard drives (2) Power supplies (2)
Fans (3)

SonicWallSecureMobileAccess6200/7200GettingStartedGuide 13
3
PreparingtoDeploytheSMA6200/7200
Thissectionprovidesanoverviewofsingle‐homedanddual‐homednetworkarchitectureanddiscussesfirewallsettingsandother
informationyouneedaboutcomponentsofyournetworktosuccessfullydeploytheSMA6200/7200.
•NetworkArchitectureonpage14
•PreparingfortheInstallationonpage16
•AboutInstallationandDeploymentonpage19

14 SonicWallSecureMobileAccess6200/7200GettingStartedGuide
NetworkArchitecture
AllSMA6200/7200appliancescanbesetupineitheradual
interfaceorsingleinterfaceconfiguration,alsoknownasdual‐
homedandsingle‐homed.
Ineitherconfiguration,appliancemanagementwithAMCis
accomplishedbyaccessingtheinternal(X0)interface.
Thisguidestepsyouthroughabasicsingle‐homedinterface
configuration.Forthehighestlevelofsecurityand
performance,SonicWallrecommendsadual‐homed
configuration.RefertotheDeploymentPlanningGuideand
SMAAdministrationGuideforfurtherinformation.
Dual‐HomedConfiguration(Internal
andExternalInterfaces)
Onenetworkinterfaceisusedforexternaltraffic(thatis,to
andfromtheInternet),andtheotherinterfaceisusedfor
internaltraffic(toandfromyourcorporatenetwork).
Single‐HomedInterfaceConfiguration
(InternalInterface)
Asinglenetworkinterfaceisusedforbothinternaland
externaltraffic.Inthisconfiguration,theapplianceisusually
installedinthedemilitarizedzone(orDMZ,alsoknownasa
perimeternetwork).
SMA appliance
Firewall
Corporate network
Internet
File
Server
Application
Server Web
Server
Firewall
DMZ
Internal interface
SMA appliance

SonicWallSecureMobileAccess6200/7200GettingStartedGuide 15
Inbothconfigurations,incomingrequeststotheSMA6200/
7200services—includingHTTP/StrafficfortheWebproxy
service—aresentoverport80(HTTP)andport443(HTTPS).
TrafficfromtheOnDemandagentisalwayssentoverport443.
Becausemostnetworksareconfiguredtoenabletrafficover
theseports,youshouldnotneedtoreconfigurefirewallson
yournetwork.
Youshouldinstalltheapplianceinalocationwhereitcan
connecttoresourcesonyournetwork,including:
•Applicationserversandfileservers,includingWeb
servers,client/serverapplications,andWindowsfile
servers.
•Externalauthenticationrepositories(suchasanLDAP,
MicrosoftActiveDirectory,orRADIUSserver).
•OneormoreDomainNameSystem(DNS)servers.
•Optionally,aWindowsInternetNameService(WINS)
server.ThisisrequiredforbrowsingWindowsnetworks
usingWorkPlace.
Althoughnotrequired,enablingtheappliancetocommunicate
withtheseadditionalresourcesprovidesgreaterfunctionality
andeaseofuse:
•NetworkTimeProtocol(NTP)serverforsynchronizing
thetimeontheappliance.
•Externalserverforstoringsyslogoutput.
•Administrator’sworkstationforsecureshell(SSH)
access.
Youcanconfiguretheappliancetouseaself‐signedserver
certificate,or,forenhancedsecurity,youcanobtaina
certificatefromacommercialcertificateauthority(CA).For
moreinformation,refertotheSMAAdministrationGuide.
CAUTION:TheSMA6200/7200appliancedoesnot
providefullfirewallcapabilitiesandshouldbesecured
behindafirewall.Runningwithoutafirewallmakesthe
appliancevulnerabletoattacksthatcancompromise
securityanddegradeperformance.

16 SonicWallSecureMobileAccess6200/7200GettingStartedGuide
PreparingfortheInstallation
Beforebeginningtheinstallation,youneedtogather
informationaboutyournetworkingenvironmentandverify
thatyourfirewallsareproperlyconfiguredtopermittrafficto
andfromtheapplianceasexplainedinthefollowingsections:
•GatheringInformationonpage16
•VerifyingyourFirewallPoliciesonpage17
GatheringInformation
Beforeconfiguringtheappliance,youneedtogatherthe
followinginformation.Youarepromptedforsomeofthis
informationwhenrunningtheSetupWizard,butmostofitwill
beusedwhenyouconfiguretheapplianceintheAppliance
ManagementConsole(AMC).RefertotheSMAAdministration
Guide.
SettingsrequiredtostartApplianceManagementConsole
•Therootpasswordforadministeringtheappliance
•Thenamefortheappliance(becausethisnameisused
onlyinlogfiles,youdonotneedtoaddittoDNS)
•TheinternalIPaddressand,optionally,anexternalIP
address
•SelectaroutingmodeandsupplyIPaddressesforthe
networkgatewaystotheInternet,andyourcorporate
network.
Certificateinformation
Severalpiecesofinformationareusedtogeneratetheserver
andAMCcertificates:
•Afullyqualifieddomainname(FQDN)fortheappliance
andforanyWorkPlacesitesthatuseauniquename.
ThesenamesshouldbeaddedtoyourpublicDNS;they
arealsovisibletouserswhentheyconnecttoWeb‐
basedresources.
•AFQDNfortheApplianceManagementConsole(AMC)
server.TheAMCservernameisusedtoaccessAMC,
whichisaWeb‐basedtoolforadministeringthe
appliance.
Namelookupinformation
•InternalDNSdomainnameofthenetworktowhichthe
applianceisconnected
•PrimaryinternalDNSserveraddress(additionalDNS
serversareoptional)
•IPaddressforaninternalWINSserverandthenameof
yourWindowsdomain(requiredtobrowsefilesona
WindowsnetworkusingWorkPlace,butareotherwise
optional)

SonicWallSecureMobileAccess6200/7200GettingStartedGuide 17
Authenticationinformation
Servernameandlogininformationforyourauthentication
servers(LDAP,ActiveDirectory,orRADIUS)
VirtualAddresspoolinformation
Ifyouareplanningtodeployeithernetworktunnelclient
(ConnectTunnelorOnDemandTunnel),youmustallocateIP
addressesforoneormoreaddresspools.Formore
information,refertotheSMAAdministrationGuide.
Optionalconfigurationinformation
•ToenableSSHaccessfromaremotemachine,youneed
toknowtheremotehost’sIPaddress.
•TosynchronizewithanNTPserver,youneedtoknow
theIPaddressesforoneormoreNTPservers.
•Tosenddatatoasyslogserver,youneedtoknowtheIP
addressandportnumberforoneormoresyslog
servers.
VerifyingyourFirewallPolicies
Fortheappliancetofunctioncorrectly,youmustopenports
onyourexternal(Internet‐facing)andinternalfirewalls.
ExternalFirewall
ForsecureaccesstotheappliancefromaWebbrowseror
OnDemand,youmustmakesurethatports80and443are
openonfirewallsatyoursite.Openingyourfirewalltopermit
SSHaccessisoptional,butcanbeusefulforperforming
administrativetasksfromaremotesystem.
ExternalFirewall
Traffic
Type
Port/
protocol Usage Required?
ESP 4500/UDP ESPTunnel Yes
HTTP 80/tcp Unencryptednetwork
access
Yes
HTTPS 443/tcp Encryptednetworkaccess Yes
SSH 22/tcp Administrativeaccessto
theapplication
No

18 SonicWallSecureMobileAccess6200/7200GettingStartedGuide
InternalFirewall
Ifyouhaveafirewallontheinternalnetwork,youmayneedto
adjustitspolicytoopenportsforback‐endapplicationswith
whichtheappliancemustcommunicate.Inadditionto
openingportsforstandardnetworkservicessuchasDNSand
email,youmayneedtomodifyyourfirewallpolicybeforethe
appliancecanaccessthefollowingservices.
InternalFirewall
TrafficType Port/protocol Usage
Microsoft
networking
138/tcpand
138/udp
137/tcpand
137/udp
139/udp
162/snmp
445/smb
UsedbyWorkPlaceto
performWINSname
resolution,browse
requests,andaccess
fileshares
LDAP
(unencrypted)
389/tcp Communicatewithan
LDAPdirectoryor
MicrosoftActive
Directory
LDAPoverSSL
(encrypted)
636/tcp Communicatewithan
LDAPdirectoryor
MicrosoftActive
DirectoryoverSSL
RADIUS 1645/udpor
1812/udp
Communicatewitha
RADIUSauthentication
server
NTP 123/udp Synchronizethe
applianceclockwithan
NTPserver
Syslog514/tcp Sendsystemlog
informationtoasyslog
server
SNMP161/udp Monitortheappliance
fromanSNMP
managementtool
InternalFirewall
TrafficType Port/protocol Usage

SonicWallSecureMobileAccess6200/7200GettingStartedGuide 19
AboutInstallationand
Deployment
Thissectionoutlinestheprocessofinstalling,configuring,and
testingtheappliance,andthendeployingitinaproduction
environment.TheInstallationandDeploymentProcesstable
providesanoverviewofthesteps.
InstallationandDeploymentProcess
InstallationStep Description
Makeanoteofyour
applianceserial
numberand
authenticationcode.
You’llneedthisinformationwhenyou
registeryourproducton
MySonicWall.Theserialnumberand
authenticationcodeareprintedon
yourappliancelabel;theyarealso
displayedontheGeneralSettings
pageinAMC.
Rack‐mountthe
applianceand
connectthecables.
SeeRackMountingtheApplianceon
page37andConnectingthe
Applianceonpage22.
Turnontheappliance
andbegin
configuration.
Toconnecttoyourapplianceonyour
internalnetworkyoumustspecifyan
internalIPaddressandthesubnet
mask.Usethecontrolsonthefrontof
theappliance.SeeEnteringNetwork
SettingsUsingtheLCDonpage23.
RunSetupWizard. Thewizardguidesyouthroughthe
processofinitialsetupforyourSMA
appliance.SeeRunningtheSetup
Wizardonpage23.
Registeryour
applianceon
MySonicWall.
Registeryourapplianceon
MySonicWall.Productregistration
givesyouaccesstoessential
resources,suchasyourlicensefile
andupdates.Toregister,youneed
boththeserialnumberforyour
applianceanditsauthentication
code.
InstallationandDeploymentProcess
InstallationStep Description

20 SonicWallSecureMobileAccess6200/7200GettingStartedGuide
This manual suits for next models
1
Table of contents
Other SonicWALL Security System manuals
Popular Security System manuals by other brands

FireAngel
FireAngel Wi-Safe 2 W2-CO-10X Installation and user guide

ACR Electronics
ACR Electronics RLB-33S - REV D Product support manual

Interlogix
Interlogix advisorone Installation sheet

Wheelock
Wheelock MZC-144 installation instructions

SpeedTech Lights
SpeedTech Lights APEX S-AP100 instruction manual

Resolution Products
Resolution Products RE151 GE manual