SonicWall NSv Series On Microsoft Azure

3y ago
56 Views
2 Downloads
4.31 MB
77 Pages
Last View : 4d ago
Last Download : 3m ago
Upload by : Oscar Steel
Transcription

SonicWall NSv Series on MicrosoftAzureGetting Started Guide

Contents1Introducing NSv Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4Feature Support Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5Node Counts per NSv Platform . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6Product Matrix and Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7Github Repository . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7Backup and Recovery Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7Exporting and Importing NSv Configurations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8Upgrading to a Higher Capacity NSv Model . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8Creating a MySonicWall Account . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8Installing NSv Series on Azure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10Supported NSv Series Models on Azure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10Task List for NSv Azure VM Setup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11Installing NSv on Azure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11Configuring HA in Azure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16Deploying an Active/Active HA Pair . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20Accessing Your NSv in the Azure Portal . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27Updating Your Dashboard and Accessing the NSv Resource Group . . . . . . . . . . . . . . . . . . . . . . . . 27Finding the Public IP Address of Your NSv . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29Logging into Your NSv for SonicOS Management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29Viewing and Configuring Security Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30Forwarding Traffic to Your NSv in Azure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32Testing Traffic Through Your NSv in Azure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36Troubleshooting Installation Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38Licensing and Registering Your NSv . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 41Registering the NSv Appliance from SonicOS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 41Registering with Zero Touch Deployment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43Deploying from CSC Management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43Getting the Latest Firmware for the NSv . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44Deploying from GMS On-Premises . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44Getting the Latest Firmware for the NSv . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45Registering an NSv Manually in a Closed Network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45Deregistering Your NSv . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 46Converting a Free Trial License to Full License . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47SonicOS Management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49Managing SonicOS on the NSv Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49Using SonicOS on an Unregistered NSv . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49Using System Diagnostics in SonicOS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 52Check Network Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 53Using the Virtual Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54Connecting to the Console with SSH . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54SonicWall NSv Series Azure Getting Started GuideContents2

Navigating the NSv Management Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56System Info . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58Management Network or Network Interfaces . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59Test Management Network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 60Diagnostics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61NTP Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62Lockdown Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 63System Update . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64Reboot Shutdown . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64About . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 65Logs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 65Using SafeMode on the NSv . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 65Enabling SafeMode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66Disabling SafeMode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 67Configuring the Management Network in SafeMode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 68Installing a New SonicOS Version in SafeMode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 71Downloading Logs in SafeMode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72Glossary: Azure Networking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74SonicWall Support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76About This Document . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 77SonicWall NSv Series Azure Getting Started GuideContents3

1Introducing NSv SeriesThis SonicWall NSv Series on Azure Getting Started Guide describes how to install SonicWall NSv on MicrosoftAzure and provides basic configuration information.To jump directly to the installation instructions, go to Installing NSv Series on Azure on page 10.SonicWall NSv on Azure MarketplaceThe SonicWall Network Security Virtual Series (SonicWall NSv Series) is SonicWall’s virtualizednext-generation firewall appliance that provides Deep Packet Inspection (DPI) security and segmentation invirtual environments. SonicOS running on the NSv Series offers the feature functionality and security featuresof a physical appliance, with comparable performance. SonicOS Virtual is a fully featured 64-bit SonicOSpowered by SonicCore.Topics: Feature Support Information on page 5 Node Counts per NSv Platform on page 6 Product Matrix and Requirements on page 7 Github Repository on page 7 Backup and Recovery Information on page 7 Exporting and Importing NSv Configurations on page 8 Upgrading to a Higher Capacity NSv Model on page 8 Creating a MySonicWall Account on page 8SonicWall NSv Series Azure Getting Started GuideIntroducing NSv Series4

Feature Support InformationThe SonicWall NSv Series on Azure has nearly all the features and functionality of a SonicWall NSa hardwareappliance running SonicOS 6.5.4 firmware.SonicWall GMS 8.4 and higher versions are supported for management of SonicWall NSv Series virtualappliances. The SonicOS 6.5 NSv Series About SonicOS book contains the list of features not supported on NSv.The Feature Support List table lists key SonicOS features and whether or not they are supported in deploymentsof the NSv SeriesFeature Support ListComponentFeatureStatusNetwork InterfacesOverride MAC AddressNot supportedNetwork InterfacesDHCPv6 Prefix Delegation (PD)Not supportedNetwork InterfacesIPv6 ManagementSupportedNetwork Interfaces6rdNot supportedNetwork InterfacesPortshield GroupsNot supportedNetwork InterfacesL2 Bridge ModeNot supportedNetwork InterfacesNative BridgeNot supportedNetwork InterfacesWire Mode v4Not supportedNetwork InterfacesWire Mode v6Not supportedNetwork InterfacesPPPoENot supportedNetwork InterfacesPPTPNot supportedNetwork InterfacesL2TPNot supportedNetwork InterfacesTap ModeNot supportedNetwork InterfacesLink AggregationNot supportedNetwork InterfacesPort RedundancyNot supportedNetwork InterfacesIP UnnumberedNot supportedNetwork InterfacesVLAN TranslationNot supportedNetwork InterfacesUsers IPv6SupportedNetwork InterfacesDHCP ServerNot supportedNetwork InterfacesVLAN InterfacesNot supportedNetwork InterfacesJumbo FramesNot supportedFirewall SettingsGlobal BWMNot supportedFirewall SettingsQoS MappingNot supportedFirewall SettingsMulticastNot supportedSwitchingNot supportedAnti spamNot supported3G/4G ModemNot supportedWirelessNot supportedSonicPointsNot supportedVirtualAssistNot supportedHigh AvailabilityActive/PassiveSupportedHigh AvailabilityStateful SyncNot supportedSonicWall NSv Series Azure Getting Started GuideIntroducing NSv Series5

Feature Support ListComponentFeatureStatusHigh AvailabilityFirmware SyncNot supportedHigh AvailabilityActive-Active DPINot supportedWAN AccelerationNot supportedSSL VPNSSL VPN for g PageUnsupported OptionsPartially supportedExternal Storage SupportNot supportedNOTE: Per Microsoft, “Azure does not support any Layer-2 semantics.” Therefore, SonicOS Layer 2functionality is disabled in NSv deployments in Azure. Consequently, NSv appliances operating in Azure donot support VLAN interfaces and DHCP Server functionality.See work/virtual-networks-faq azure-virtual-machines for more information.For information about supported features, refer to the SonicOS 6.5.4 NSv Series administration documentation.This and other documents for the SonicWall NSv Series are available by selecting NSv Series as the Product umentation.Node Counts per NSv PlatformThe node count is the maximum number of nodes/users that can connect to the NSv at any one time, and isdisplayed on the System Status page in the MONITOR view.Maximum Node Counts Per PlatformPlatformMaximum Node CountNSv 1010NSv 2525NSv 5050NSv 100100NSv 200 and higherUnlimitedFor reference, node counts are calculated by SonicOS as follows: Each unique IP address is counted. Only flow to the WAN side is counted. GVC and SSL VPN connections terminated to the WAN side are counted. Internal zone to zone is not counted. Guest users are not counted.A log event is generated when the node count exceeds the limit.SonicWall NSv Series Azure Getting Started GuideIntroducing NSv Series6

Product Matrix and RequirementsThe following table shows the hardware resource requirements for the SonicWall NSv Series virtual appliances.Product 00Maximum Cores1222224816Minimum Total Cores22222222Management Cores11111111Maximum Data Plane Cores111113715Minimum Data Plane Cores11111111Network Interfaces22222488Supported IP/Nodes102550100No limit No limit No limit No limitMinimum Memory Required4G4G4G4G6G8G10G12GMinimum Hard Disk/Storage35G35G35G35G35G35G35G35G1. If the actual number of cores allocated exceeds he number of cores defined in the above table, extra cores willbe used as CPs. Multiple CP support is introduced in 6.5.4.v.Github RepositorySonicWall NSv Azure templates are available in the github repository: https://github.com/sonicwall emplatesBackup and Recovery InformationIn certain situations, it might be necessary to contact SonicWall Technical Support, use SafeMode, or deregisterthe NSv appliance: If the splash screen remains displayed, this can indicate that the disk is corrupted. Please contactSonicWall Technical Support for assistance. If the disk is not recoverable, then the NSv appliance needs to be deregistered with MySonicWall. SeeDeregistering Your NSv on page 46 for information. If SonicOS does not boot up, you can go into SafeMode and download the log files, upload a new SonicOSimage, or take other actions. For information about SafeMode, see Using SafeMode on the NSv on page65. If SonicOS fails three times during the boot process, it will boot into SafeMode. Verify that the minimumrequired memory is available and allocated based on the NSv model. If it still cannot boot up, downloadthe logs while in SafeMode and contact SonicWall Technical Support for assistance.SonicWall NSv Series Azure Getting Started GuideIntroducing NSv Series7

Exporting and Importing NSvConfigurationsMoving configuration settings from SonicWall physical appliances to the NSv Series is not supported. However,configuration settings may be moved from one NSv to another. See the SonicOS 6.5 NSv Series Updatesadministration book and the SonicOS 6.5.4 NSv Series Upgrade Guide on the Technical Publications portal formore information about exporting and importing configuration settings. Go mentation/ and select “NSv Series” as the product.Upgrading to a Higher Capacity NSv ModelIt is possible to move up to a higher capacity NSv model, but not down to a lower capacity model. Forinstructions refer to the SonicOS 6.5.4 NSv Series Upgrade Guide on the Technical Publications portal. Go mentation/ and select “NSv Series” as the product.For details on the number of processors and memory to allocate to the VM to upgrade, refer to Product Matrixand Requirements on page 7.Creating a MySonicWall AccountA MySonicWall account is required to obtain the image file for initial installation of the NSv Series virtualfirewall, for product registration to enable full functionality of SonicOS features, and for access to licensedsecurity services. For a High Availability configuration, MySonicWall provides a way to associate a secondary NSvthat can share security service licenses with your primary appliance.NOTE: MySonicWall registration information is not sold or shared with any other company.To create a MySonicWall account:1 In your web browser, navigate to https://www.mysonicwall.com.2 In the login screen, click the SIGN UP link.SonicWall NSv Series Azure Getting Started GuideIntroducing NSv Series8

3 Complete the account information, including email and password.NOTE: Your password must be at least 8 characters, but no more than 30 characters.4 Enable two-factor authentication if desired.5 If you enabled two-factor authentication, select one of the following authentication methods: Email (one-time passcode) where an email with a one-time passcode is sent each time you loginto your MySonicWall account. Microsoft/Google Authentication App where you use a Microsoft or Google authenticatorapplication to scan the code provided. If you are unable to scan the code, you can click on a linkfor a secret code. Once the code is scanned, you need only click on a button.6 Click on CONTINUE to go to the Company page.7 Complete the company information and click CONTINUE.8 On the Your Info page, select whether you want to receive security renewal emails.9 Identify whether you are interested in beta testing new products.10 Click CONTINUE to go to the Extras page.11 Select whether you want to add additional contacts to be notified for contract renewals.12 If you opted for additional contacts, input the information and click ADD CONTACT.13 Click DONE.14 Check your email for a verification code and enter it in the Verification Code* field. If you did not receivea code, contact Customer Support by clicking on the link.Click DONE. You are returned to the login window so you can login into MySonicWall with your new account.Next Steps Installing NSv Series on Azure on page 10 Licensing and Registering Your NSv on page 41SonicWall NSv Series Azure Getting Started GuideIntroducing NSv Series9

2Installing NSv Series on AzureTopics: Supported NSv Series Models on Azure on page 10 Task List for NSv Azure VM Setup on page 11 Installing NSv on Azure on page 11 To install from Azure Marketplace: on page 11 Configuring HA in Azure on page 16 Accessing Your NSv in the Azure Portal on page 27 Forwarding Traffic to Your NSv in Azure on page 32 Testing Traffic Through Your NSv in Azure on page 36 Troubleshooting Installation Configuration on page 38Supported NSv Series Models on AzureNSv Models (VM Sizes) on AzureSonicWall NSv ModelAzureInterface Count1Core CountNSv 10Standard D2 v222NSv 25Standard D2 v222NSv 50Standard D2 v222NSv 100Standard D2 v222NSv 200Standard D2 v222NSv 400Standard D3 v244NSv 800Standard D4 v288NSv 1600Standard D5 v28161. The maximum number of interfaces supported on an NSv instance is defined by thetype of Azure VM. For example, if more than 2 interfaces are required for an NSv200, use the NSv200 with an Azure VM supporting a higher number of interfaces.NOTE: The maximum number of NICs supported by SonicWall NSv is always eight for all models. But thetotal number of interfaces in an NSv instan

SonicWall GMS 8.4 and higher versions are supported for management of SonicWall NSv Series virtual appliances. The SonicOS 6.5 NSv Series About SonicOS book contains the list of features not supported on NSv. The Feature Support List table lists key SonicOS features and whether or not they are supported in deployments of the NSv Series

Related Documents:

SonicWall SonicOS NSv Series Upgrade Guide 2 4 Click the Firmware icon. 5 Optionally, click the Browse All Firmware button to display all available firmware versions. Depending on your NSv platform, the following file types are available: SWI - Upgrade image file for an existing deployment on any platform. If not displayed, a fresh installation may be required for this release.

SonicWall Capture Security Center Management for TZ Series, SOHO-W, SOHO 250, SOHO 250W NSv 10 to 100 3Yr 01-SSC-9152 SonicWall Capture Security Center Management for NSA 2600 to 6600, NSa 2650 to 6650 and NSv 200 to 400 1Yr 01-SSC-3665 SonicWall Capture Security Center Management for NSA 2600 to 6600, NSa 2650 to 6650 and NS

SonicWall University utilizes an online proctoring solution to proctor the SonicWall certification exams. The ProctorFree online proctoring software allows . SonicWall University students to take their certification exams anywhere, anytime using facial recognition software to verify a test taker's identity and proctor exams. SonicWall .

SonicWall Product Lines Table of Contents SonicWall SuperMassive 9000 series 2 SonicWall NSA series 3 SonicWall TZ series 4 . 4 For every 125,000 DPI connections reduced, the number of available DPI SSL connections increases by 750. *Future use. All specifications, features and availability are subject to change. 4

SonicWall Product Lines Contents SonicWall SuperMassive E10000 series 2 SonicWall SuperMassive 9000 series 3 SonicWall NSA series 4 . SSL Inspection and Decryption (DPI SSL)2 200 Mbps 300 Mbps 500 Mbps 800 Mbps 1.3 Gbps VPN throughput3 1.1 Gbps 1.5 Gbps 3.0 Gbps 4.5 Gbps 5.0 Gbps

Bently Nevada* Asset Condition Monitoring 3300 XL NSv* Proximity Transducer System Description The 3300 XL NSv* Proximity Transducer system is intended for use with centrifugal air compressors, refrigeration compressors, process gas compressors and other machines with tight installation requirements. The 3300 XL NSvFile Size: 426KB

SonicWall Global Management System 9.1 Getting Started Guide Introduction to GMS 1 5 Introduction to GMS SonicWall Global Management System (GMS) is a Web‐based application that can configure and manage thousands of SonicWall firewall appliances and NetMonitor non‐SonicWall appliances from a central location.

Anatomy 2-5 Indications 5 Contra-indications 5 General preparation 6 Landmarks 6-7 Performing the block 7-8 Complications 8 Trouble shooting 9 Summary 9 References 10 Appendix 1 11. 6/10/2016 Fascia Iliaca Compartment Block: Landmark Approach 2 FASCIA ILIACA COMPARTMENT BLOCK: LANDMARK APPROACH INTRODUCTION Neck of femur fracture affect an estimated 65,000 patients per annum in England in .