Lost Password? No account yet? Sign up! Why bother?
  • Narrow screen resolution
  • Wide screen resolution
  • Auto width resolution
  • Increase font size
  • Decrease font size
  • Default font size

SmallNetBuilder - Small Network Help

  
Home arrow Security arrow Security Reviews arrow Sonicwall SSL-VPN-200 Review: SSL for SMBs
Sonicwall SSL-VPN-200 Review: SSL for SMBs Print E-mail
Tim Higgins   
April 16, 2007

Installation / Configuration

The 200 is basically set up in a "one armed" connection (Figure 3). Unlike a router that has separate WAN and LAN ports, traffic flows in and out of the single X0 port, which you just plug into your LAN's switch. The four X1 ports are there mainly because the same chassis is used for Sonicwall's TZ150 firewall. But it also possible to establish a separate subnet behind the 200 using these ports and put clients there that will only be able to be accessed via the appliance.

The 200 comes set to 192.168.200.1, so you'll need to change the IP address of the computer that you use to access its built-in secure (HTTPS) web admin interface.

VPN 200 connection

Figure 3: VPN 200 connection

Upon login, you'll be presented with the System > Status screen (Figure 4). A browse through the other System menus will find options for NTP server (Time), saving and restoring system settings and upgrading firmware (Settings), failed login attempt lockout (Administration), generating and managing security certificates (Certificates), various Diagnostics and Restarting the 200.

System Status screen
Click to enlarge image

Figure 4: System Status screen

One of your first stops will be the Network > Interfaces screen, where you'll change the IP address of the X0 port to match your LAN, as I did in Figure 5.

Network Interfaces screen

Figure 5: Network Interfaces screen

I also stopped at the DNS and Routes screens to enter my LAN's DNS server and Gateway IP addresses. I didn't bother defining any Hosts in Host Resolution, so it held only the default "sslvpn" for the 200 itself. The Network Objects screen lets you define combinations of services and IP addresses that are handy to have when defining access policies later. Since my needs were simple I made no entries there.

Now we're ready to add a user to the 200 via the Users > Local Users page (Figure 6). There is a wealth of options available for controlling what users can see and do via the 200 and also how and from where they can log in. Options include idle timeout, ability to add, edit and delete "Bookmarks" (explained shortly) and permit/deny policies based on user, IP address, IP range and more.

Note that the same configuration options are available for Groups and both User and Groups have Global Policies, too. Note that policies can be edited and deleted, but not temporarily disabled.

Users > Local Users screen

Figure 6: Users > Local Users screen

Check out the slideshow Check out the slideshow for more 200 configuration options

Once you've finished defining a user, you're ready to see the 200 in action. But in order to access the 200 from outside your LAN, you'll need to forward port 443 (HTTPS) through your router to the 200's IP address—as you would for any server that you access from the Internet. If you want to have automatic redirection from HTTP to HTTPs, then also forward port 80 (HTTP). Contrary to the description in the Administrator's Guide, neither of these ports can be changed for the 200.



Comments (6)Add Comment

New comments have been disabled. Please use the Forums

busy

Tags: Sonicwall, SSL, VPN,

Related Articles:

SonicWALL updates SSL-VPNs
Slideshow - Sonicwall SSL-VPN 200
Slideshow: Netgear FVS336G ProSafe Dual WAN Gigabit Firewall
Netgear's Breakthrough SSL312 VPN Gateway
Slideshow: Linksys RVL200 4-Port SSL/IPSec VPN Router
 

Top Security Products

Asa 5505 Security Appliance - 10 User K9
Lowest Price: $ 343.00

ProSafe Dual WAN Gigabit Firewall
Lowest Price: $ 254.66

TZ 190 3G Wireless Broadband Security Appliance
Lowest Price: $ 452.85

Cisco ASA 5510 Security Plus Appliance
Lowest Price: $ 2450.00

FortiGate 60B Security Appliance
Lowest Price: $ 541.00

Most Read

 
 

Over at the Forums

Don't send password in clear text upon registration
Don't send password in clear text upon (Main - not forum) registration

Vista / XP home workgroup setup?
I recently purchased a new HP desktop for the home (mainly for my wife), and it came with Vista 64bit. I also upgraded my laptop to Vista 64bit. Both...

IPCop Router
IPCop has just release its newest version today, 1.4.20 http://ipcop.org/ For all you small to enterprise size network admins, this is the router...

Navbar - forums links
On the main site, when hovering over things such as Wireless, NAS, LAN & WAN, etc. in the main nav bar, a secondary nav bar appears that shows...

WHS Power Pack 1 - Retest?
They say File transfer speed and I/O improvement. Will see a retest or review of other WHS products?

Slideshows

D-Link DNS-343 4-Bay Network Storage Enclosure Thecus N3200 RAID 5 NAS D-Link DIR-628 RangeBooster N Dual Band Router Adtran NetVanta 3120 Buffalo LinkStation Mini Intel Entry Storage System SS4200-E More
 
Go Shopping with PriceGrabber

Get Email Updates

Enter your email address:

Delivered by FeedBurner once a day

 


This page took 0.413435935974 seconds to load.