# SonicWall – Network Configuration Management Set-Up

This guide will help you to configure your SonicWall appliance in order to get Domotz to retrieve and backup its configuration file.

**Is your SonicWall running SonicOS 7.3.2+ or 8.2.0+**
You might need to use the non 2FA enabled API account to unlock configuration backup feature for the SonicWall. Click [here](#sonicos-732-authentication) for further details.

## SonicOS 7.x

1. Please access the 'Device' section and then click on the 'Audit/SonicOS' API tab:

Navigating to the Audit/SonicOS API Section in SonicWall.

1. In the top navigation bar, click on the "Device" tab to access device settings.
2. Select the "Audit/SonicOS API" tab to view the audit logging support and SonicOS API section.

2. In the 'Audit/SonicOS API' tab, please make sure that the 'SonicOS API', the 'CHAP authentication, and the 'RFC-26 HTTP Basic Access authentication' widgets are enabled, **and all the others are 'disabled'.**
Then click the 'Accept' button.

Configuring SonicOS API and Authentication Settings

1. Ensure the "SonicOS API" toggle is enabled to activate the API.
2. Enable "CHAP authentication" for secure password exchange.
3. Activate the "RFC-2617 HTTP Basic Access authentication" option for basic access control.
4. If Two-Factor Authentication (2FA) is used, enable the "Two-Factor and Bearer Token Authentication" setting.
5. Click the "Accept" button to save the configuration changes.

Please note that all the other widgets except for the highlighted ones should be disabled.

If you are using **2FA**, you must enable the **Two-Factor and Bearer Token Authentication.**
Note that **2FA**is only supported with the **Configuration Backup Driver**:

SonicWall Firewall Backup Configuration Script Overview

1. The script version is 1.0.4 and its purpose is to back up the SonicWall Firewall configuration.
2. It requires credentials when used.
3. The script uses HTTPS as the communication protocol and requires two parameters: a custom port and a TOTP seed.
4. The sample period for the backup is set for 24 hours, with an execution timeout of 30 seconds.
5. It has been tested on SonicWall SonicOS version 7.1.1-7058.
6. Use the "Use the Script" button to proceed with executing the script, or "Back" to return to the previous page.

You can now use an main Administrator user to unlock the device in Domotz.

If the unlock option is not present. Make sure the **SNMP**service is enabled and readable at the agent side. This is needed to extract the SonicOS version.

## SonicOS 7.3.2+ and 8.2.0+ - API Access Limitations

Starting with SonicOS 7.3.2 (Gen-7) and 8.2.0 (Gen-8), SonicWall changed how API sessions are authenticated:

- **2FA is not supported for non-GUI (API) sessions when bearer token validation is enabled.** In practice, this means an API account with 2FA turned on cannot be used for non-interactive access, such as Domotz's configuration backup.

**What to do:** Use an API admin account that does **not** have 2FA enabled. With a non-2FA account, configuration backup works normally on these firmwares, no other changes are required on your end.

## SonicOS 6.5

1. Please click the 'MANAGE' button in the top menu, then click on 'Appliance' in the right menu and then select the 'Base Settings' section.
2. Make sure the HTTP and HTTPS Web Management ports are the default ones (HTTP: 80 / HTTPS: 443):

SonicWall Web Management Settings Configuration

1. Under "Web Management Settings," you can opt to allow management via HTTP by checking the relevant box.
2. Set the "HTTP Port" to 80 and the "HTTPS Port" to 443 for secure communications.
3. Choose the certificate type from the "Certificate Selection" dropdown, selecting "Use Selfsigned Certificate."
4. Enter the "Certificate Common Name" as 192.168.168.168.
5. Set the "Default Table Size" to display 50 items per page.
6. Adjust the "Auto-updated Table Refresh Interval" to update every 10 seconds.
7. Optionally, enable "Use Threat Protection View as starting page" by checking the box.
8. Enable tooltips by checking "Enable Tooltip," and set "Form Tooltip Delay" to 2000 milliseconds and "Button Tooltip Delay" to 3000 milliseconds.

SonicWall 6.5 Management Settings Page

1. Ensure that the SonicOS API is enabled and that the 'CHAP authentication, and the 'RFC-26 HTTP Basic Access authentication' methods are enabled.

Enable SonicOS API Authentication Options

1. In the left navigation menu, select "Appliance" and then click on "Base Settings".
2. Check the box labeled "Enable SonicOS API" to activate the API.
3. Ensure "Enable RFC-7616 HTTP Digest Access authentication" is also checked for additional security layers. Configure digest algorithms by selecting either "SHA256" or "MD5".
4. Under "Integrity protection", choose between "Disabled", "Allowed", or "Enforced".
5. Check "Enable CHAP authentication" for CHAP protocol integration.
6. Check "Enable RFC-2617 HTTP Basic Access authentication" to support basic authentication.

These configurations enhance the security and functionality of the SonicOS API.

If the unlock option is not present. Make sure the **SNMP**service is enabled and readable at the agent side. This is needed to extract the SonicOS version.

**Please Note:** Due to limitations on the SonicWall Rest APIs, Domotz is only able to read configuration out of the devices, so the in the Config section your device will be unlocked in Read-Only mode.

Device Configuration Management Interface in Read-Only Mode

1. Verify that all services are unlocked, indicated by the padlock symbol near the top.
2. Note that the interface is in "Device Configuration Management in read-only mode."
3. Use the tabs for navigation: Info, Connect, Alerts, History, SNMP, TCP, Interfaces, and Config.
4. Under Configuration Management, access the backup and restore options for device configuration.
5. Automatic Backup is set to check every 6 hours; the last check was 18 minutes ago.
6. To perform an immediate backup, select "Backup Now."
7. Under Last Configuration Backup, view details of the most recent automatic backup conducted on April 19, 2023, at 09:26:55 PM (CDT).
8. Options to "Restore" or "View" the backup are available.

## I do not want to use the 'main' Administrator user

In order not to use the 'main' Administrator user, but a custom created user which is in the SonicWALL Administrator group, you have to:

1. Go inside the tab 'Local Users &Groups':

Managing Local Users and Groups in SonicWall.

1. Navigate to the "Device" tab in the top menu.
2. Select "Users" from the left sidebar to expand options.
3. Click on "Local Users & Groups."
4. In the main panel, choose between "Local Users" or "Local Groups" at the top to manage users or groups.
5. Use the search bar to find specific users or groups.
6. Users are listed with columns for name, guest services, admin roles, VPN access, and comments, displaying their roles and access types.

2. Modify the SonicWALL Administrators group in the 'Administration' tab and toggle the 'Members go straight to the management UI on web login:

Local Group Settings Administration Tab Instructions

1. Navigate to the "Administration" tab within the Local Group Settings.
2. Locate the toggle option labeled "Members go straight to the management UI on web login" and switch it on if required.
3. Confirm your changes by clicking the "Save" button. Use "Cancel" to discard any changes.

See below for SonicOS 6.5

Manage User Groups in SonicWall Interface

1. Navigate to the "Users" section in the SonicWall interface, and select "Local Users & Groups" from the left-hand menu.

2. In the main panel, select "Local Groups" to view a list of predefined user groups. Options include "Content Filtering Bypass," "Everyone," and "Guest Administrators," among others.

3. To modify a group's settings, click on the desired group such as "Administrators" or "Guest Services."

4. The right panel displays details about the selected group, like user privileges (Admin, VPN Access) and configuration settings, allowing you to adjust as needed for guest or admin access.

Remember that you need to have created a user and placed it as a member of the 'SonicWALL Administrators' group first.

You might find more information on the SonicOS Rest APIs here: [https://www.sonicwall.com/support/knowledge-base/introduction-to-sonicos-api/200818060121313/](https://www.sonicwall.com/support/knowledge-base/introduction-to-sonicos-api/200818060121313/)
