SonicWall Firewall Best Practices: A Security-First Configuration Guide
SonicWall firewalls are capable platforms when properly configured. Most deployments leave significant security capabilities unused. Here is how to configure SonicWall for maximum protection.
By Tom Brennan
SonicWall firewalls are deployed across hundreds of thousands of organizations worldwide. Their effectiveness depends entirely on configuration. The following best practices reflect SonicWall's documented guidance and real-world findings from Proactive Risk penetration testing.
Security Services Configuration
- Enable Gateway Anti-Virus on all zones, including LAN-to-WAN traffic
- Enable Intrusion Prevention Service (IPS) with automatic signature updates
- Configure Deep Packet Inspection (DPI) to inspect SSL/TLS traffic
Access Control and Zone Policies
- Follow least-privilege principles for all zone access rules
- Segment the network: LAN, DMZ, Guest, IoT, Management
- Disable management access from the WAN interface unless absolutely required
- Enable Geo-IP filtering to block connections from high-risk countries
Authentication and Remote Access
- Require MFA for all VPN and remote access connections
- Disable SSLVPN if not in use; disable legacy VPN protocols
- Restrict VPN user access to only required network segments
Logging and Monitoring
- Configure syslog forwarding to a SIEM
- Enable logging for all blocked traffic
- Review firmware update status monthly
Free Infrastructure Security Resources
Put these firewall best practices into action with Proactive Risk's free resources, available in the Downloads library:
- Security Incident Response Plan (SIRP) Template — a ready-to-use incident response plan template aligned to NIST SP 800-61, covering detection, containment, eradication, and recovery for network security incidents
- Proactive Risk GitHub Repositories — open-source security tools and scripts published by the Proactive Risk team, including network security utilities