Chat now with support
Chat with Support

Security Analytics Engine 1.1 - SonicWALL Configuration Guide

SonicWALL Processor service configuration

SonicWALL Firewall Configuration Settings

Introduction

Required SonicWALL configuration

1
Select AppFlow in the left-hand pane to display the Flow Reporting page.
2
Open the Settings tab.
4
Open the External Collector tab and make the following configuration changes:
Select the Send Flows and Real-Time Data To External Collector check box.
Select the Send IPFIX/Netflow Templates At Regular Interval check box.
Select the Send StaticAppFlow At Regular Interval check box.
In the Send Static AppFlow For Following Tables field, use the drop-down menu to select the following tables:
In the Send Dynamic AppFlow For Following Tables field, use the drop-down menu to select the following tables:
Clear the Report On Connection OPEN check box.
Select the Report On Connection CLOSE check box.
Clear the Report Connection On Active Timeout check box.
Clear the Report Connection On Kilo BYTES Exchanged check box.
In the Report Connections On Following Updates field, use the drop-down menu to select the following options:
5
Click the Accept button in the upper left corner of the Flow Reporting page to accept the configuration changes. If prompted, do NOT select to restart the firewall at this time.
6
Expand Security Services in the left-hand pane and select Gateway Anti-Virus.
7
In the Gateway Anti-Virus Global Settings pane, select the Enable Gateway Anti-Virus check box. Optionally, configure the remaining Gateway Anti-Virus Global Settings pane options.
1
Click the Configure Gateway AV Settings button.
2
On the Gateway AV Config View dialog, clear the Enable HTTP Clientless Notification Alerts check box.
3
Click OK to save and close the dialog.
8
Click the Accept button in the upper left corner of the Gateway Anti-Virus page to accept the configuration changes.
12
Click the Accept button in the upper left corner of the Intrusion Prevention page to accept the configuration changes.
1
Click the Configure Anti-Spyware Settings button.
2
On the Anti-Spyware Config View dialog, clear the Enable HTTP Clientless Notification Alerts check box.
3
Click OK to save and close the dialog.
16
Click the Accept button in the upper left corner of the Anti-Spyware page to accept the configuration changes.
18
Verify that the Check Block connections to/from Botnet Command and Control Servers check box is selected. You may also make changes to the current settings.
19
Click the Accept button to save any configuration changes.
20
Expand Firewall in the left-hand pane and select App Control Advanced.
22
Click Accept to save.
23
Expand Network in the left-hand pane and select Zones.
26
Click the OK button to close the dialog and return to the Zone page.
27
Repeat Step 24 through Step 26 to configure each desired zone.
28
Once you have finished configuring zones, click the Accept button to save the configuration.
Expand System in the left-hand pane and select Restart.
Click the Restart button.
30
Once the firewall has rebooted, select AppFlow in the left-hand pane to display the Flow Reporting page.
31
Open the External Collector tab and sequentially click the following buttons approximately 2 minutes apart, to generate template and static data for the configured SonicWALL Processor service:
Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating