SonicWALL Content Security Manager 2200 Getting Started Manual

Sonicwall network device user's manual

Advertisement

Quick Links

COMPREHENSIVE INTERNET SECURITY
SonicWALL Content Security Manager Series
b
SonicWALL CSM 2200
Getting Started Guide

Advertisement

Table of Contents
loading

Summary of Contents for SonicWALL Content Security Manager 2200

  • Page 1 COMPREHENSIVE INTERNET SECURITY ™ SonicWALL Content Security Manager Series SonicWALL CSM 2200 Getting Started Guide...
  • Page 2: Table Of Contents

    SonicWALL Content Security Manager 2200 Getting Thank you for purchasing a SonicWALL Content Security Manager (CSM) series appliance. The SonicWALL CSM is an Internet content and application filter that enhances security and employee productivity, optimizes network bandwidth and mitigates legal liabilities. The SonicWALL CSM integrates into virtually any network to provide powerful, scalable, cost-effective Internet content filtering that is easy to implement, requiring no change to your network clients.
  • Page 3: Before You Begin

    This section contains the following subsections: • “Check Package Contents” on page 3 • “What You Need to Provide” on page 4 • “Important Information You Need” on page 4 • “SonicWALL CSM 2200 Front and Back Panels Overview” on page 5 Page 2...
  • Page 4: Check Package Contents

    Für Europaïsche Union (EU) Kunden, ist ein Netzkabel nicht eingeschlossen. Note: SonicWALL ADConnector and SonicWALL ViewPoint software for the SonicWALL CSM are available for download from the SonicWALL Web site <https://www.mysonicwall.com>. SonicWALL CSM Series Appliance Getting Started Guide Page 3...
  • Page 5: What You Need To Provide

    PC or Macintosh computer to act as an out-of-band management station for initial configuration of the SonicWALL CSM • Web browser for accessing the SonicWALL CSM’s Web-based management interface. The Web browser must support Java and HTTP uploads. Internet Explorer 5.0 or higher or Netscape Navigator 4.7 or higher are recommended.
  • Page 6: Sonicwall Csm 2200 Front And Back Panels Overview

    Provides access to command-line interface. Indicates the SonicWALL CSM appliance is powered on. Indicates the SonicWALL CSM appliance is in test mode. Indicates a critical error or failure. Provides a connection to your LAN. Provides a primary (Ethernet) connection to the Internet.
  • Page 7: Configuring Your Sonicwall Csm

    The Power LED shines green when you activate the power switch. The Test LED and Alarm LED light up and may blink while the appliance performs a series of diagnostic tests. When the Test LED and Alarm LED are no longer lit, the SonicWALL CSM is ready for configuration.
  • Page 8: Accessing The Sonicwall Management Interface

    Accessing the SonicWALL Management Interface To access the Web-based management interface of the SonicWALL CSM, configure your out-of-band management station (the computer you are using to manage the SonicWALL CSM) with the following static TCP/IP address properties: • IP address: Use an available IP address on the 192.168.168.0/24 subnet. For example, 192.168.168.20.
  • Page 9 Note: For additional security, you may also access the appliance using HTTPS. 4. In the SonicWALL CSM authentication page, enter admin in the Name field and password in the Password field and click Login. The Setup Wizard page is displayed.
  • Page 10: Configuring Your Sonicwall Csm Using The Setup Wizard

    Time zone • Network setup To configure your SonicWALL CSM using the Setup Wizard, perform the following steps: 1. The SonicWALL Setup Wizard will automatically launch. 2. The Welcome to the SonicWALL Configuration Wizard screen displays. Confirm that the radio button next to Setup Wizard is selected and click Next> to continue.
  • Page 11 Daylight Saving Time. Click Next> to continue. Note: For best performance, you need to configure the time zone to accurately reflect geographic location. It is important that you set the time zone correctly before you register your SonicWALL CSM appliance. Page 10...
  • Page 12 Next> to continue. Alert: You must configure the network interfaces before connecting the SonicWALL CSM to your network. If you have already connected cables to the X0 and X1 interfaces, disconnect them before continuing this step. Field...
  • Page 13 7. When the configuration has been stored, you will see the Setup Wizard Complete screen. Click Close to close the Wizard. Continue to “Connecting the SonicWALL CSM to Your Network” on page 14. Keep a hardcopy record of your IP address, user name and password for your SonicWALL CSM appliance for administrator login.
  • Page 14 8. Disconnect your crossover cable from your management station and the CSM appliance and refer to “Connecting the SonicWALL CSM to Your Network” on page 14. Note: After initial configuration using the X2 out-of-band management interface, you can now perform management from the LAN (X0) interface.
  • Page 15: Connecting The Sonicwall Csm To Your Network

    Figure 1: SonicWALL CSM Configuration Between the LAN and WAN Alert: Do not connect the SonicWALL CSM to your network until you have configured the X0 and X1 interfaces. Refer to “Configuring Your SonicWALL CSM Using the Setup Wizard” on page 9.
  • Page 16: Connecting The Ethernet Cables

    1. Connect one end of the Ethernet cable connected to your internal network (your LAN hub, switch, or router) to the X0 (Internal) port of the SonicWALL CSM. The LEDs on the X0 port light up indicating an active connection.
  • Page 17 DNS servers, and your SonicWALL ADConnector. Refer to “Figure 1: SonicWALL CSM Configuration Between the LAN and WAN” on page 14. To add static routes in the SonicWALL CSM management interface, perform the following steps: 1.
  • Page 18: Registering Your Sonicwall Csm

    Registering Your SonicWALL CSM Once you have established an Internet connection for your SonicWALL CSM, you must register the SonicWALL CSM to activate: • Allowed Nodes/Users license • SonicWALL Content Filtering Service subscription • Client Anti-Virus • Gateway Anti-Virus •...
  • Page 19 Alert: Verify that the DNS and Time settings on your SonicWALL CSM are correct when you register the device. Your DNS and Time settings should have been configured with the Setup Wizard. You can verify the Time settings in the System >...
  • Page 20 “Registering Your SonicWALL CSM Using the Management Interface” on page 20. 1. If you are not logged into the SonicWALL CSM management interface, log in with the SonicWALL CSM administrative user name and password. 2. The System > Status page automatically displays. If the System > Status page does not automatically display, click System in the left-navigation menu, and then click Status.
  • Page 21 4. Enter your mySonicWALL.com account username and password in the User Name and Password fields, then click Submit. 5. At the top of the Product Survey page, Enter a “friendly name” for your SonicWALL CSM appliance in the Friendly Name field. The friendly name allows you to easily identify your SonicWALL content security appliance in your mySonicWALL.com...
  • Page 22: Understanding The *Default Policy

    The SonicWALL CSM includes a pre-configured *Default Policy with pre-defined Web Filter Category Sets. The default settings are automatically applied when you add users from the network segment protected by the SonicWALL CSM, unless you assign a custom filtering policy to them.
  • Page 23 SonicOS CF 2.5 Administrator’s Guide. If this screen appears without the names of the optional application filters, you need to re-register your appliance. Refer to “Registering Your SonicWALL CSM Using the Management Interface” on page 20. Page 22...
  • Page 24: Verifying The *Default Policy

    Users and Hosts > Hosts and that is on the same LAN as the SonicWALL CSM. For each *Default Policy Web filter category, visit a well-known Web site in that category. If the SonicWALL CSM has been correctly configured, you will see a page indicating that the site has been blocked by policy.
  • Page 25: Integrating The Sonicwall Csm With Microsoft Active Directory

    The following instructions assume Active Directory is fully operational on your network. AD Domain Controller Note: If you are not using Active Directory, the SonicWALL CSM includes a built-in Category Set authentication database. Refer to the SonicOS CF 2.5 Administrator’s Guide. Page 24...
  • Page 26 SonicWALL ADConnector Requirements The Windows PC on which you install the SonicWALL ADConnector must meet the following requirements: • A direct or routable access to both the Active Directory Domain Controller and the SonicWALL CSM • An always on computer, so that the SonicWALL CSM can communicate with the Windows computer as needed •...
  • Page 27 Download SonicWALL ADConnector Software Note: You must register your SonicWALL CSM before you can download the SonicWALL ADConnector Software. For instructions registering, refer to “Registering Your SonicWALL CSM” on page 17. 1. Go to https://www.mySonicWALL.com and log in. 2. Click Download Center under Download in the left-hand column.
  • Page 28 11. Click Next. 12. On the CFA User Configuration page, enter information for the domain user account the SonicWALL ADConnector will use to log into the AD Domain Controller. The account must have AD administrator privileges. Enter the ADConnector Username, ADConnector Password, and Domain Name.
  • Page 29 Starting the SonicWALL ADConnector After installing the SonicWALL ADConnector, start the service. The agent service must be running at all times for the SonicWALL CSM to communicate with Active Directory. 1. On your Windows desktop, double click the ADConnector Configuration Tool icon, or from the Windows Start menu, select Programs >...
  • Page 30 Preparing the SonicWALL ADConnector Configuration Tool for First Use 1. Expand the Users list to view the users. 2. The first time you click on a user, the SonicWALL ADConnector prompts you for the Active Directory attributes for the SonicWALL ADConnector. Click OK in the Warning dialog box.
  • Page 31 1. In the management interface, click System and then click Diagnostics. 2. In the System > Diagnostics page, Select Ping from the Diagnostic Tool list. 3. In the Ping host or IP address field, enter the IP address of your SonicWALL ADConnector and click Go.
  • Page 32 Adding a Static Route to the SonicWALL ADConnector If the SonicWALL ADConnector is installed on a computer in a different subnet than the SonicWALL CSM, you need to add a static route in the SonicWALL CSM to the SonicWALL ADConnector station: 1.
  • Page 33: Advanced Configuration

    Advanced Configuration After you initially set up and configure your SonicWALL CSM, these are the key steps you take to provide content filtering to your LAN: 1. Organize your Web Filters and determine the content filtering needs for each Category Set. These can be local users, RADIUS users, or Active Directory users.
  • Page 34 5. Type an available IP address, for example, 192.168.168.20 in the IP Address field. 6. Type 255.255.255.0 in the Subnet Mask field. 7. Click OK, and then click OK again. 8. Restart the computer for changes to take effect. SonicWALL CSM Series Appliance Getting Started Guide Page 33...
  • Page 35 IP addresses. These names are called fully qualified domain names (FQDN). hardware failover - The capability of a mission-critical device, such as a SonicWALL CSM, to automatically failover to a backup device in the event of a hardware failure on the primary unit.
  • Page 36 IP address. WAN - A Wide Area Network is a geographically distributed network composed of multiple networks joined into a single large network. The Internet is a global WAN. SonicWALL CSM Series Appliance Getting Started Guide Page 35...
  • Page 37 Caution: Modifying this equipment or using this equipment for purposes not shown in this manual without the written consent of SonicWALL, Inc. could void the user’s authority to operate this equipment.
  • Page 38: Vcci Statement

    National Deviations: AT, AU, BE, CH, CN, CZ, DE, DK, FI, FR, GB, GR, HU, IE, IL, IN, IT, JP, KR, NL, NO, PL, SE, SG, SI BMSI Statement VCCI Statement SonicWALL CSM Series Appliance Getting Started Guide Page 37...
  • Page 39: Cable Connections

    All certificates held by NetSonic, Inc. Lithium Battery Warning The Lithium Battery used in the SonicWALL Internet security appliance may not be replaced by the user. Call SonicWALL technical support in U.S./Canada at 888-777-1476 or visit the SonicWALL Web site at <http://www.sonicwall.com> for international customer support telephone numbers.
  • Page 40 The following conditions are required for proper installation: • Use the mounting hardware recommended by the rack manufacturer and ensure that the rack is adequate for the application. SonicWALL includes a rack mounting kit with the SonicWALL CSM that is compatible with most computer equipment racks. •...
  • Page 41 Kabelverbindungen Alle Ethernet- und RJ45 Konsole-Kabel eignen sich für die Verbindung von Geräten in Innenräumen. Schließen Sie an die Anschlüsse der SonicWALL keine Kabel an, die aus dem Gebäude herausgeführt werden, in dem sich das Gerät befindet. Weitere Hinweise zur Montage der Modell Die oben genannten SonicWALL-Modelle sind für eine Montage in einem...
  • Page 42: Copyright Notice

    Specifications and descriptions subject to change without notice. Trademarks SonicWALL is a registered trademark of SonicWALL, Inc. Microsoft Windows 98, Windows NT, Windows 2000, Windows XP, Windows Server 2003, Internet Explorer, and Active Directory are trademarks or registered trademarks of Microsoft Corporation.
  • Page 43 Notes Page 42...
  • Page 44 F: 408.745.9300 © 2006 SonicWALL, I n c . SonicWALL is a registered trademark of SonicWALL, I n c . Other product and company names mentioned herein may be t rademarks and/ or registered trademarks of their respective companies. Specifications and descriptions subject to change with out notice.

This manual is also suitable for:

Csm 2200

Table of Contents