Page 1
TZ_210_GSG.book Page 1 Thursday, November 13, 2008 7:41 PM SonicWALL Network Security Appliances TZ 210 Series NET WORK SECURIT Y Getting Started Guide...
Page 2
SonicWALL TZ 210 Series Quick Start Start here if you are new to SonicWALL appliances. The next few pages provide a Quick Start to connecting your appliance. For a complete listing of contents, including more advanced network deployments, see the Table of Contents on page i of this guide.
Page 3
TZ_210_GSG.book Page 2 Thursday, November 13, 2008 7:41 PM SonicWALL TZ 210 Series Quick Start Connect the SonicWALL TZ 210 series appliance using standard CAT-5 Ethernet cables as shown in the illustration below. Verify Contents Connect Network Connect Power Boot Appliance...
Page 4
TZ_210_GSG.book Page 3 Thursday, November 13, 2008 7:41 PM SonicWALL TZ 210 Series Quick Start Connect the included power cable and adaptor and plug into a properly grounded 120V AC outlet. Verify Contents Connect Network Connect Power Boot Appliance Setup Wizard...
Page 5
SonicWALL TZ 210 Series Quick Start The TZ 210 series appliance powers on and the orange “test” LED blinks during the boot sequence. Continue to the next step when the “test” LED is no longer lit. This process may take up to 2 minutes.
Page 6
TZ_210_GSG.book Page 5 Thursday, November 13, 2008 7:41 PM SonicWALL TZ 210 Series Quick Start Using a computer connected to the LAN port of the SonicWALL TZ 210 series appliance, navigate to “http://192.168.168.168/” in a Web browser. The SonicWALL Setup Wizard displays.
TZ_210_GSG.book Page i Thursday, November 13, 2008 7:41 PM SonicWALL TZ 210 Series Getting Started Guide This Getting Started Guide provides instructions for basic installation and configuration of the SonicWALL TZ 210 series appliance running SonicOS Enhanced. Document Contents This document contains the following sections:...
Page 9
TZ_210_GSG.book Page ii Thursday, November 13, 2008 7:41 PM SonicWALL TZ 210 Series Front Panel LAN/WAN Port Status 10/100 Ethernet Port Status Provides dedicated LAN/WAN port status as follows: link/spd: Off=10M Green=100M activity: Solid=link Blinking=activity Provides Solid=wireless radio on Page ii...
Page 10
DB9 -> RJ45 cable Reset Button LAN Port (X0) Press and hold to manually reset Provides dedicated LAN access the appliance to SafeMode to local area network resources SonicWALL TZ 210 Series Getting Started Guide Page iii...
Page 11
TZ_210_GSG.book Page iv Thursday, November 13, 2008 7:41 PM SonicWALL TZ 210 Series LED Reference X0 X1 X2 X5 X6 Page iv SonicWALL TZ 210 Series LED Reference...
Page 12
TZ_210_GSG.book Page 1 Thursday, November 13, 2008 7:41 PM Setting Up Your Network In this Section: This section provides pre-configuration information. Review this section before setting up your SonicWALL TZ 210 series appliance. System Requirements • - page 2 Recording Configuration Information •...
SonicWALL appliance. Supported Browsers Browser Version Authentication Code: Record the authentication code found on Number the bottom panel of your SonicWALL appliance. Internet Explorer 6.0 or higher Networking Information Firefox 2.0 or higher LAN IP Address:...
Page 14
Primary DNS: (IP Address): Secondary DNS Primary DNS: (optional): Dial-in to a PPTP Secondary DNS server Server Address: (optional): Dial-in to a PPTP User Name: server Server Address: Password: User Name: Password: SonicWALL TZ 210 Series Getting Started Guide Page 3...
The Setup Wizard takes you through several basic steps to get specifying a DHCP range, or use the default. your SonicWALL TZ 210 series appliance configured for your Ports Assignment—Configure the extra interfaces (X2-X6) for network. Use the Recording Configuration Information different network requirements.
DHCP, or with a static IP address in your chosen subnet. The default subnet for LAN zone ports is 192.168.168.x. If your SonicWALL TZ 210 series appliance required a reboot after completing the Setup Wizard, wait until the LED is no longer lit before continuing.
Enter “http://www.sonicwall.com” in the address bar and Each interface may be configured for a different zone (LAN, WAN, DMZ) press Enter on the keyboard. The SonicWALL website displays. If you are unable to browse to a Website, see “Troubleshooting Internet Connection” on page 7.
SonicWALL TZ 210 series appliance correctly. • Log into the security appliance using “admin” as the If you cannot view the SonicWALL home page, try the following: user name and “password” as the password. After • Renew your management station DHCP address if you log in, click the Wizards button at the top right.
Page 19
Windows XP Configuring DHCP IP Addressing From the Start menu, highlight Connect To and then If you are having trouble connecting to the SonicWALL TZ 210 select Show All Connections. series appliance, complete the following section based on your Right-click on your Local Area Connection and select Windows operating system flavor.
Registering and Licensing Your Appliance on MySonicWALL • - page 10 Note: Registration is an important part of the setup process and is necessary to receive the benefits of SonicWALL security services, firmware updates, and technical support. SonicWALL TZ 210 Series Getting Started Guide Page 9...
Page 21
In the login screen, click the Not a registered user? link. Product Registration You must register your SonicWALL security appliance on MySonicWALL to enable full functionality. Login to your MySonicWALL account. If you do not have an account, you can create one at www.mysonicwall.com.
Page 22
Enforced Client Anti-Virus and Anti-Spyware • Global VPN Client • Global VPN Client Enterprise • ViewPoint • Support Services: • Dynamic Support 8x5 • Dynamic Support 24x7 • Software and Firmware Updates SonicWALL TZ 210 Series Getting Started Guide Page 11...
Page 23
Service Management page. You have successfully registered your SonicWALL appliance. And now you need to enable Unified Threat Management (UTM) security services. SonicWALL UTM security services are not enabled by default. Page 12 Registering and Licensing Your Appliance on MySonicWALL...
Enabling Security Services In this Section: Security services are an essential component of a secure network deployment. This section provides instructions for registering and enabling security services on your SonicWALL TZ 210 series appliance. Enabling Security Services in SonicOS •...
Enabling Content Filtering Service • - page 18 display as licensed, you need to synchronize your SonicWALL with the licensing server. If initial setup is already complete, click the Synchronize button to synchronize licenses from the System > Licenses page.
Page 26
See the following table for an explanation of these protocols. Tip: For a complete overview of GAV features, refer to the SonicOS Enhanced Administrator’s Guide. SonicWALL TZ 210 Series Getting Started Guide Page 15...
Page 27
TZ_210_GSG.book Page 16 Thursday, November 13, 2008 7:41 PM Intrusion Prevention contains other useful features, including: Enabling Intrusion Prevention Services To enable Intrusion Prevention (IPS) in SonicOS: • Exclusion Lists for network nodes where IPS Navigate to the Security Services > Intrusion Prevention enforcement is not necessary.
Page 28
Prevent all blocks attacks of the chosen priority, Detect All saves a log of these attacks which can be viewed in the Log > View screen. Click the Accept button to apply changes. SonicWALL TZ 210 Series Getting Started Guide Page 17...
Page 29
• URL Rating Review allows the administrator and users to review blocked URL ratings if they think a URL is rated Select SonicWALL CFS in the Content Filter Type drop- down list and then click the Configure button. incorrectly. •...
TZ_210_GSG.book Page 19 Thursday, November 13, 2008 7:41 PM Congratulations! Your SonicWALL TZ 210 series appliance is Verifying Security Services on Zones registered and fully functional with active UTM security services Security services such as Gateway Anti-Virus are automatically enabled.
Page 31
TZ_210_GSG.book Page 20 Thursday, November 13, 2008 7:41 PM Page 20 Verifying Security Services on Zones...
Advanced Network Configuration In this Section: This section provides detailed overviews of advanced deployment scenarios, as well as configuration instructions for connecting your SonicWALL TZ 210 series appliance to various network devices. An Introduction to Zones and Interfaces • - page 22 SonicWALL Wireless Firewalling •...
Page 33
The security features and settings that zones carry are Wireless Clients Wireless Devices enforced by binding a zone to one or more physical interfaces (such as, X0, X1, or X2) on the SonicWALL TZ 210 series appliance. Front Lobby Sales...
Intrusion Prevention Service Security Services WLAN Zone Many security products on the market share this potential vulnerability when two users connected by a common hub or wireless access point wish to exchange data. SonicWALL TZ 210 Series Getting Started Guide Page 23...
TZ_210_GSG.book Page 24 Thursday, November 13, 2008 7:41 PM Configuring Interfaces Note: If only X0 and X1 interfaces are displayed in the Interfaces, also known as ports, are physical network Interfaces list, click the Show PortShield Interfaces connections that can be configured to provide different button to show all interfaces.
Page 36
The SonicWALL PortShield feature enables WAN/LAN X0, X2-X6: LAN Connect any local network device to X0, or you to easily configure the ports on the SonicWALL TZ 210 X1: WAN X2-X6 for local and Internet connectivity. series appliance into common deployments.
Page 37
TZ_210_GSG.book Page 26 Thursday, November 13, 2008 7:41 PM Manual PortShield Configuration Note: You can also manually group ports together using the graphical Interfaces must be configured before being grouped PortShield Groups interface. Grouping ports allows them to with PortShield. For instructions, see the Configuring an Interface section, on page 24.
Deny table is the Any rule. Note: SonicWALL’s default firewall rules are set in this way for ease of initial configuration, but do not reflect best practice installations. Firewall rules should only allow the required traffic and deny all other traffic.
Page 39
TZ_210_GSG.book Page 28 Thursday, November 13, 2008 7:41 PM In the Add Rule page on the General tab, select Allow or Configure the other settings on the General tab as Deny or Discard from the Action list to permit or block IP explained below: traffic.
Click on the QoS tab to apply DSCP marking to traffic governed by this rule. Click OK to add the rule. SonicWALL TZ 210 Series Getting Started Guide Page 29...
Page 41
For Range, enter the starting and ending IP addresses • Default Address Objects – displays Address Objects in the Starting IP Address and Ending IP Address configured by default on the SonicWALL security fields. appliance. For Network, enter the network IP address and netmask in the Network and Netmask fields.
• Many-to-One NAT Policy interfaces. • Many-to-Many NAT Policy You can create multiple NAT policies on a SonicWALL running • One-to-One NAT Policy for Outbound Traffic SonicOS Enhanced for the same object – for instance, you can • One-to-One NAT Policy for Inbound Traffic (Reflexive) specify that an internal server uses one IP address when •...
Page 43
IP The Add NAT Policy dialog box displays. addresses are translated from the IP address of the SonicWALL For Original Source, select Any. security appliance WAN port to the IP address of the internal For Translated Source, select Original.
The advanced deployments contained in this chapter are based on the most common customer deployments and contain best-practice guidelines for deploying your SonicWALL TZ 210 series appliances. These deployments are designed as modular concepts to help in deploying your SonicWALL as a comprehensive security solution.
Page 45
SonicPoints for Wireless Access This section describes how to configure SonicPoints with the SonicWALL TZ 210 series appliance. SonicPoints can be used to add wireless features to a SonicWALL TZ 210 wired appliance, or to create a more robust distributed wireless network with a SonicWALL TZ 210 Wireless-N appliance.
Page 46
TZ_210_GSG.book Page 35 Thursday, November 13, 2008 7:41 PM Internet Gateway with SonicPoint Wireless In this deployment, the SonicWALL TZ 210 is configured to operate as a network gateway with the following zones: Hotel / Home Office Local Network (LAN) - wired local client...
Page 47
TZ_210_GSG.book Page 36 Thursday, November 13, 2008 7:41 PM In the 802.11g Radio tab: Configuring Provisioning Profiles • Select Enable Radio. SonicPoint Profile definitions include all of the settings that can • Optionally, select a schedule for the radio to be be configured on a SonicPoint, such as radio settings for the enabled from the drop-down list.
Page 48
Rules to allow traffic to flow between the interfaces of a zone instance. For example, if the WLAN Zone has both the X2 and X3 interfaces assigned to it, selecting the Allow Interface Trust checkbox on the WLAN Zone creates the SonicWALL TZ 210 Series Getting Started Guide Page 37...
Page 49
In the Wireless Settings section, select Only allow traffic generated by a SonicPoint to allow only traffic from SonicWALL SonicPoints to enter the WLAN Zone interface. This provides maximum security on your WLAN. Uncheck this option if you want to allow any traffic on your WLAN Zone regardless of whether or not it is from a SonicPoint.
Page 50
HTTP and/or HTTPS in User Login. Click OK. In the Edit Interface dialog box on the General tab, select WLAN or the zone that you created from the Zone drop- down list. Additional fields are displayed. SonicWALL TZ 210 Series Getting Started Guide Page 39...
Page 51
This section provides instructions for configuring your attempts to find a SonicOS device with which to peer. If it is SonicWALL TZ 210 series appliance to support a public Web unable to find a peer SonicOS device, it will enter into a stand- server on a DMZ zone.
Page 52
*For the TZ 210 wired appliance, wireless is achieved by adding a SonicWALL SonicPoint appliance to any free interface Network Security Appliance (X3-X5) and zoning that interface as WLAN. SonicWALL TZ 210 Series Getting Started Guide Page 41...
Page 53
TZ_210_GSG.book Page 42 Thursday, November 13, 2008 7:41 PM Enter a Server Comment (optional) and click Next. Completing the Public Server Wizard The Public Server Wizard guides you through a few simple steps, automatically creating address objects and rules to allow server access.
Page 54
Change the Zone Assignment to DMZ and click OK. Select Static as the IP assignment. Enter an IP Address for the interface. This IP address must be in the same subnet as your Web server’s local IP address. SonicWALL TZ 210 Series Getting Started Guide Page 43...
Click the Delete button corresponding to the WAN My Web This section provides instructions for configuring a pair of Server Services rule. Click OK when prompted. SonicWALL TZ 210 series appliances for redundant High Availability (HA) networking. This section contains the following subsections: On the Firewall >...
Page 56
X1 WAN Internet (WAN) - linked to your internet service provider using a hub or switch connected to your modem. HA - linked between two TZ 210 series appliances X0 LAN X0 LAN using the X6 port Local Network (LAN)
Verify that the Primary SonicWALL appliance is registered During normal operation, the Primary SonicWALL is in Active and licensed for SonicOS Enhanced and the desired mode and the Backup SonicWALL is in Idle mode. If the SonicWALL security services. Primary device loses connectivity, the Backup SonicWALL...
Note: You can configure HA license synchronization by associating After registering new SonicWALL appliances on two SonicWALL security appliances as HA Primary and HA MySonicWALL, you must also register each appliance from the SonicOS management interface by clicking the Secondary on MySonicWALL. Note that the Backup appliance of your HA pair is referred to as the HA Secondary unit on registration link on the System >...
Click Register. Disabling PortShield Before Configuring HA The HA feature can only be enabled if PortShield is disabled on In the SonicWALL Configuration Summary screen, click all interfaces of both the Primary and Backup appliances. You Apply. can disable PortShield either by using the PortShield Wizard, or manually from the Network >...
SonicWALL security appliance, or in the System > Status screen of the backup unit. The serial number for the To configure the HA Pair so that the Primary SonicWALL Primary SonicWALL is automatically populated. resumes the Active role when coming back online after a Click Apply to retain these settings.
Page 61
This is used in logical 13. When finished with all High Availability configuration, click monitoring. SonicWALL recommends that you set the Accept. All settings will be synchronized to the Idle unit interval for at least 5 seconds. The default is 20 seconds, automatically.
In the Primary IP Address field, enter the unique LAN management IP address of the Primary unit. In the Backup IP Address field, enter the unique LAN management IP address of the Backup unit. SonicWALL TZ 210 Series Getting Started Guide Page 51...
HA Peer Firewall has been updated notification at the bottom problem is with the target, and not the SonicWALL of the management interface page. Also note that the appliances. But, if one appliance can ping the target but the...
Primary fixed WAN port and the user- assigned Secondary WAN port. From your management workstation, test connectivity through the Backup SonicWALL by accessing a site on the public This section contains the following subsections: Internet. Note that unless virtual MAC is enabled, the Backup Configuring Secondary WAN Interface •...
Page 65
TZ_210_GSG.book Page 54 Thursday, November 13, 2008 7:41 PM Multiple ISP / WAN Failover and Load Balancing In this scenario, the SonicWALL TZ 210 is configured in NAT/Route mode to operate X1 WAN as a network gateway with multiple Internet Service Providers (ISPs) to allow load balancing and/or failover.
Page 66
Configuring Secondary WAN Interface Activating and Configuring WAN Failover Perform the following steps to configure WAN Failover and To configure the SonicWALL for WAN failover and load Load Balancing on the SonicWALL security appliance: balancing, follow the steps below: On Network > Interfaces page, configure the chosen port On Network >...
Page 67
WAN Probe Monitoring Overview SonicWALL security appliance starts sending traffic through the Secondary WAN interface. If Probe Monitoring is not activated, the SonicWALL security Percentage- Specifies the percentages of traffic sent through appliance performs physical monitoring only on the Primary and Based the Primary WAN and Secondary WAN interfaces.
Page 68
ISP (also connected to this hub Configuring WAN Probe Monitoring or switch) were to fail, the SonicWALL will continue to believe To configure WAN probe monitoring, follow these steps: the WAN link is usable, because the connection to the hub or switch is good.
Page 69
11. Select the SNWL? checkbox if the target device is a 14. Configure the Secondary WAN Probe Settings, which SonicWALL security appliance. Do not select the SNWL? provide the same options as the Primary WAN Probe Settings.
TZ_210_GSG.book Page 59 Thursday, November 13, 2008 7:41 PM Support and Training Options In this Section: This section provides overviews of customer support and training options for the SonicWALL TZ 210 series appliances. Customer Support • - page 60 Knowledge Portal •...
Support Contract. Please review our Warranty Support Policy • Browse for product coverage. SonicWALL also offers a full range of • Search for keywords consulting services to meet your needs, from our innovative •...
SonicWALL Live Product Demos SonicOS features a dynamic Onboard Help in the form of The SonicWALL Live Demo Site provides free test drives of helpful tooltips that appear over various elements of the GUI SonicWALL security products and services through interactive when the mouse hovers over them.
TZ_210_GSG.book Page 62 Thursday, November 13, 2008 7:41 PM User Forums The SonicWALL User Forums is a resource that provides users the ability to communicate and discuss a variety of security and appliance subject matters. In this forum, the following categories are available for users: •...
TZ_210_GSG.book Page 63 Thursday, November 13, 2008 7:41 PM Training SonicWALL offers an extensive sales and technical training curriculum for Network Administrators, Security Experts and SonicWALL Medallion Partners who need to enhance their knowledge and maximize their investment in SonicWALL Products and Security Applications.
This 512 page book is available in hardcopy. Order the book SonicWALL Secure Wireless Network directly from Elsevier Publishing at: Integrated Solutions Guide <http://www.elsevier.com> The Official Guide to SonicWALL’s market-leading wireless networking and security devices. SonicWALL TZ 210 Series Getting Started Guide Page 65...
Safety and Regulatory Information for the SonicWALL TZ 210 Wireless Appliance • - page 71 Safety and Regulatory Information in German for the SonicWALL TZ 210 Wireless Appliance • - page 72 FCC Part 15 Class B Notice for the SonicWALL TZ 210 Wireless Appliance •...
Lithium Battery Warning The Lithium Battery used in the SonicWALL security appliance Mounting the SonicWALL may not be replaced by the user. Return the SonicWALL Mount in a location away from direct sunlight and sources • security appliance to a SonicWALL-authorized service center for of heat.
Page 80
Verbindung von Geräten in Innenräumen. Schließen Sie an die Stellen Sie sicher, dass die Luft um das Gerät herum • Anschlüsse der SonicWALL keine Kabel an, die aus dem zirkulieren kann und die Lüftungsschlitze an der Seite des Gebäude herausgeführt werden, in dem sich das Gerät befindet.
003 du Canada. All products with country code “B” are made in China. All products with country code “C” or “D” are made in Taiwan R.O.C. Page 70 FCC Part 15 Class B Notice for the SonicWALL TZ 210 Appliance...
Page 82
The Lithium Battery used in the SonicWALL security appliance of heat. A maximum ambient temperature of 104º F (40º C) may not be replaced by the user. Return the SonicWALL security is recommended. appliance to a SonicWALL-authorized service center for Route cables away from power lines, fluorescent lighting •...
Page 83
Dieses Produkt darf nur in Verbindung mit einem nach den Normen der Underwriter Laboratories, USA als „UL-gelistet“ zugelassenen Netzteil der Kategorie „Class 2“ oder „LPS“ verwendet werden. Ausgang: 12 VDC Gleichsspannung, mind. 1,66 A. Page 72 Safety and Regulatory Information in German for the SonicWALL TZ 210 Wireless Appliance...
Page 84
I, the undersigned, hereby declare that the equipment specified above conforms to the above Directives and Standards. Quality control SonicWALL declares that APL20-065 contains FCC ID QWU-06C, and procedures will ensure series production of equipment will be compliant. APL20-064 contains FCC ID QWU-06D, and when sold in US or Canada is limited to CH1~Ch11 by specified firmware controlled in the USA.
Page 85
SonicWALL izjavlja, da je ta APL20-065/APL20-064 v skladu z bistvenimi zahtevami in ostalimi relevantnimi določili direktive 1999/5/ES. Por medio de la presente SonicWALL declara que el APL20-065/APL20-064 cumple con los requisitos esenciales y cualesquiera otras disposiciones aplicables o exigibles de la SonicWALL týmto vyhlasuje, že APL20-065/APL20-064 spĺňa základné...
Specifications and descriptions subject to change without notice. Trademarks SonicWALL is a registered trademark of SonicWALL, Inc. Microsoft Windows 98, Windows Vista, Windows 2000, Windows XP, Windows Server 2003, Internet Explorer, and Active Directory are trademarks or registered trademarks of Microsoft Corporation.
Need help?
Do you have a question about the TZ 210 Series and is the answer not in the manual?
Questions and answers