Technical13 min read

SonicWall TZ Firewall Setup Guide for India — Initial Configuration Checklist

SonicWall TZ Firewall Setup Guide for India — Initial Configuration Checklist

Getting a SonicWall TZ firewall deployed and fully configured is typically a 2–4 hour process for a competent IT team. This guide walks through the critical configuration steps for an Indian business environment — from first boot to Capture ATP activation.

Note: This guide is for SonicWall TZ series appliances running SonicOS 7.x. Some menu paths differ slightly on older SonicOS 6.5 devices.


Before You Start — Pre-Deployment Checklist

Before touching the firewall, have the following ready:

  • ISP details: WAN IP address (static) or DHCP/PPPoE credentials from your Indian ISP
  • Your existing network IP scheme (LAN subnet — e.g. 192.168.1.0/24)
  • A laptop with an Ethernet port (or USB-C to Ethernet adapter)
  • Your SonicWall MySonicWall account credentials (create at my.sonicwall.com if you don't have one)
  • Your TotalSecure serial number (printed on the box and the appliance label)
  • NSM (Network Security Manager) URL and licence if you are doing centralised management

Step 1: Physical Setup

Connections

  1. Connect WAN (X1 port) to your ISP router or modem
  2. Connect LAN (X0 port) to your office switch
  3. Connect your laptop to the X2 port (or any LAN port) using an Ethernet cable
  4. Power on the TZ appliance

Default access

  • Default management IP: 192.168.168.168
  • Default credentials: admin / password (you will be forced to change this on first login)
  • Set your laptop to static IP 192.168.168.100, subnet 255.255.255.0, no gateway
  • Browse to https://192.168.168.168 and accept the self-signed certificate warning

Step 2: Initial Setup Wizard

SonicOS 7 presents a setup wizard on first login. Work through it:

2a. Admin Password

Change the default admin password to a strong passphrase. Write this in your password manager or IT documentation — there is no recovery mechanism other than factory reset.

2b. Network Mode

Select NAT Mode for most Indian office deployments (your LAN will be behind NAT).

2c. WAN Configuration

If your ISP provides a static IP (common for leased lines in India):

  • Select Static IP
  • Enter: WAN IP address, subnet mask, gateway IP, primary DNS (8.8.8.8 or your ISP's DNS)

If your ISP uses DHCP (common for broadband — ACT Fibernet, Hathway, Jio Fiber):

  • Select DHCP
  • No manual IP entry needed

If your ISP uses PPPoE (some BSNL, MTNL connections):

  • Select PPPoE
  • Enter your ISP-provided username and password

2d. LAN Subnet

Set your internal LAN subnet. Default is 192.168.168.0/24 — you may want to change this to match your existing scheme (e.g. 10.0.0.0/24 or 172.16.0.0/24).


Step 3: Register Your Device

Registration activates your TotalSecure subscription and is required before Capture ATP and RTDMI will function.

  1. Go to Device > Settings > Licenses in SonicOS
  2. Click Activate or Register
  3. Log in with your MySonicWall account
  4. Enter your TotalSecure serial number
  5. All purchased services (RTDMI, Capture ATP, IPS, Content Filtering) should show as Licensed

If services do not activate, check:

  • Serial number is entered without spaces
  • MySonicWall account email matches your Cloudfy purchase record
  • Internet access is working on the WAN port before registration

Step 4: Enable Security Services

After registration, verify each service is actively enabled:

4a. Gateway Anti-Virus & RTDMI

Go to Security Services > Gateway Anti-Virus

  • Status: Enabled
  • RTDMI: Enabled
  • Enable inspection for: HTTP, HTTPS, FTP, SMTP, POP3, IMAP

4b. Capture ATP

Go to Security Services > Capture ATP

  • Status: Enabled
  • Block Until Verdict: Enable this — it holds suspicious files at the gateway until a clean verdict is received
  • File Types to Inspect: enable All (PE, Office docs, PDFs, archives)
  • Email attachments: Enable for SMTP scanning

Critical for Indian businesses: Block Until Verdict should always be enabled. Without it, Capture ATP only provides analysis and alerting — it does not block the file during sandboxing. The slight increase in file delivery time (seconds) is worth the protection.

4c. IPS (Intrusion Prevention System)

Go to Security Services > Intrusion Prevention

  • Status: Enabled on all zones
  • Prevention Mode: Prevent (not just detect)
  • Signature update: Enable automatic updates

4d. Content Filtering

Go to Security Services > Content Filter

  • Enable for LAN zone
  • Configure blocked categories appropriate for your business (typically: Adult Content, Gambling, Hacking Tools, Botnets, P2P)
  • Whitelist any business domains that are incorrectly blocked

Step 5: Basic Firewall Rules

SonicWall creates default allow rules for LAN-to-WAN traffic. For a typical Indian office deployment, you should add the following:

5a. Default Deny Rule (Already exists)

SonicWall's default rule set includes an implicit deny-all at the bottom. Do not delete this.

5b. Allow Outbound Traffic (LAN to WAN)

A default "LAN to WAN: Allow All" rule exists. You should restrict this if your policy requires application-level control — but leaving it open is acceptable for initial deployment.

5c. Block Unwanted Outbound Categories

Using Application Intelligence (available in Advanced/Premier bundles):

  • Block: BitTorrent, peer-to-peer file sharing
  • Block: Anonymizers/VPN bypass tools (common in Indian BPOs and schools)
  • Alert: Personal cloud storage (Dropbox personal, WeTransfer — for DLP visibility)

5d. WAN to LAN (Inbound Rules)

By default, all inbound traffic from WAN is blocked. Create explicit allow rules only for:

  • RDP (if required — use a non-standard port and restrict source IPs)
  • VPN (IPSec/SSL — typically handled by the VPN service, not a manual firewall rule)
  • Any hosted services (web server, email server) — restrict source IPs where possible

Step 6: VPN Configuration

For Indian offices needing site-to-site or remote access VPN:

Site-to-Site IPSec VPN (Branch offices)

  1. Go to VPN > Settings > Add
  2. Select Site to Site
  3. Enter remote site's WAN IP and pre-shared key
  4. Configure Phase 1: IKEv2, AES-256, SHA-256
  5. Configure Phase 2: AES-256, SHA-256, PFS enabled
  6. Define local and remote network subnets

Remote Access VPN (Work from home)

SonicWall supports SSL-VPN via SonicWall Mobile Connect (free app for Windows, Mac, iOS, Android):

  1. Go to VPN > SSL VPN > Server Settings
  2. Enable SSL VPN, set port (default 443 — may conflict with HTTPS management; use 4433 instead)
  3. Configure user authentication (Local or LDAP/AD)
  4. Define access group and network resources the VPN user can reach

Step 7: Dual WAN / SD-WAN Setup (if applicable)

For offices with two ISP connections (common in Indian businesses — leased line + Jio Fiber backup):

  1. Go to Network > Interfaces and configure X2 port as WAN2
  2. Assign your backup ISP details to WAN2
  3. Go to Network > SD-WAN > Groups
  4. Create a WAN Group with WAN1 (primary) and WAN2 (backup)
  5. Set Load Balancing: Spillover (use WAN2 only when WAN1 fails) or Round Robin (use both simultaneously)
  6. Go to Network > SD-WAN > Rules to create application-based routing rules (e.g. video conferencing always via leased line)

Step 8: NSM (Network Security Manager) Enrollment

For businesses managing multiple SonicWall appliances, or for central monitoring:

  1. Log in to NSM at unm.sonicwall.com (or your NSM URL from Cloudfy)
  2. Click Add Device
  3. From the appliance web interface: go to Device > Settings > NSM and enter the NSM server details
  4. Alternatively: the appliance auto-discovers NSM if registered to the same MySonicWall account

Once enrolled, you can manage all firewall policies, view real-time threats and push firmware updates from the NSM console.


Step 9: Test Your Configuration

Before declaring the firewall live:

  • Can you browse to an external website from a LAN device?
  • Does Capture ATP show verdicts in Logs > Capture ATP?
  • Does the IPS show blocked events in Logs > Event?
  • Does Content Filtering block a test URL in a blocked category?
  • Can a remote access VPN user connect and reach internal resources?
  • Does WAN failover work? (Unplug WAN1 and verify traffic continues on WAN2)
  • Are all Security Services showing Licensed and Active in Device > Licenses?

Common Issues in Indian Deployments

ISP gives a /30 subnet

Some Indian leased lines provide a /30 block (e.g. 202.x.x.x /30). Configure the WAN interface with the usable host IP and set the gateway to the other usable IP in the block.

BSNL/MTNL PPPoE authentication failing

Check the PPPoE username format — BSNL often requires username@bsnl.in not just username.

Jio Fiber with CGNAT

Jio residential plans use CGNAT — your WAN IP will be a private IP like 100.x.x.x. Site-to-site VPN will not work over Jio residential without a static IP plan. Contact Jio Business for a static IP.

Content filter blocking legitimate Indian websites

SonicWall's content filtering database occasionally miscategorises Indian sites. Use Security Services > Content Filter > Allowed Sites to whitelist specific domains.


Need Professional Deployment?

Cloudfy Systems provides SonicWall deployment services in India — from initial sizing through on-site installation, rule configuration, VPN setup and NSM enrollment. We include Capture ATP Block Until Verdict configuration and a post-deployment security review in every engagement.

Contact us: +91 97600 50555 · connect@cloudfysystems.com


Frequently Asked Questions

How long does a SonicWall TZ initial setup take?

A straightforward single-site deployment with WAN config, LAN setup, security services activation and basic firewall rules takes approximately 2–3 hours for an experienced IT engineer. Add 1–2 hours for VPN configuration or SD-WAN setup.

What is the default SonicWall admin password?

The default username is admin and the default password is password. SonicOS 7 forces a password change on first login.

How do I update SonicWall firmware?

Go to Device > Settings > Firmware & Backups. Click Check for Updates to see available firmware. Download and schedule the upgrade — it typically requires a 2–3 minute reboot. Cloudfy recommends keeping firmware current as part of your TotalSecure subscription.

Does SonicWall work with Zoho One / Microsoft 365 / Google Workspace?

Yes. SonicWall does not block any of these services by default. Application Intelligence can be used to prioritise or restrict specific SaaS applications. No special configuration is needed for Indian SaaS services.

Free Consultation

Talk to a Cloud Expert

Tell us about your team and stack — we'll recommend the right cloud and SaaS setup with transparent pricing in INR.

Google Cloud PartnerMicrosoft PartnerZoho Authorised
Already decided? Submit your details to start provisioning

Request a Callback

Fill the form — we'll get back within one business day.

We respond within one business day · No spam, ever.