Security Fundamentals

SonicWall Firewall Best Practices: A Security-First Configuration Guide

SonicWall firewalls are capable platforms when properly configured. Most deployments leave significant security capabilities unused. Here is how to configure SonicWall for maximum protection.

By Tom Brennan

Featured image for SonicWall Firewall Best Practices: A Security-First Configuration Guide

SonicWall firewalls are deployed across hundreds of thousands of organizations worldwide. Their effectiveness depends entirely on configuration. The following best practices reflect SonicWall's documented guidance and real-world findings from Proactive Risk penetration testing.

Security Services Configuration

  • Enable Gateway Anti-Virus on all zones, including LAN-to-WAN traffic
  • Enable Intrusion Prevention Service (IPS) with automatic signature updates
  • Configure Deep Packet Inspection (DPI) to inspect SSL/TLS traffic

Access Control and Zone Policies

  • Follow least-privilege principles for all zone access rules
  • Segment the network: LAN, DMZ, Guest, IoT, Management
  • Disable management access from the WAN interface unless absolutely required
  • Enable Geo-IP filtering to block connections from high-risk countries

Authentication and Remote Access

  • Require MFA for all VPN and remote access connections
  • Disable SSLVPN if not in use; disable legacy VPN protocols
  • Restrict VPN user access to only required network segments

Logging and Monitoring

  • Configure syslog forwarding to a SIEM
  • Enable logging for all blocked traffic
  • Review firmware update status monthly

Free Infrastructure Security Resources

Put these firewall best practices into action with Proactive Risk's free resources, available in the Downloads library:

Explore Related Resources

Back to the Proactive Risk blog · Talk with Proactive Risk