SonicWall – Network Configuration Management Set-Up

2 min

This guide will help you to configure your SonicWall appliance in order to get Domotz to retrieve and backup its configuration file.

Is your SonicWall running SonicOS 7.3.2+ or 8.2.0+
You might need to use the non 2FA enabled API account to unlock configuration backup feature for the SonicWall. Click here for further details.

SonicOS 7.x

1. Please access the ‘Device’ section and then click on the ‘Audit/SonicOS’ API tab:


2. In the ‘Audit/SonicOS API’ tab, please make sure that the ‘SonicOS API’, the ‘CHAP authentication, and the ‘RFC-26 HTTP Basic Access authentication’ widgets are enabled, and all the others are ‘disabled’.
Then click the ‘Accept’ button.

Please note that all the other widgets except for the highlighted ones should be disabled.

If you are using 2FA, you must enable the Two-Factor and Bearer Token Authentication.

Note that 2FA is only supported with the Configuration Backup Driver:

You can now use an main Administrator user to unlock the device in Domotz.

If the unlock option is not present. Make sure the SNMP service is enabled and readable at the agent side. This is needed to extract the SonicOS version.

SonicOS 7.3.2+ and 8.2.0+ – API Access Limitations

Starting with SonicOS 7.3.2 (Gen-7) and 8.2.0 (Gen-8), SonicWall changed how API sessions are authenticated:

  • 2FA is not supported for non-GUI (API) sessions when bearer token validation is enabled. In practice, this means an API account with 2FA turned on cannot be used for non-interactive access, such as Domotz’s configuration backup.

What to do: Use an API admin account that does not have 2FA enabled. With a non-2FA account, configuration backup works normally on these firmwares, no other changes are required on your end.

SonicOS 6.5

  1. Please click the ‘MANAGE’ button in the top menu, then click on ‘Appliance’ in the right menu and then select the ‘Base Settings’ section.
  2. Make sure the HTTP and HTTPS Web Management ports are the default ones (HTTP: 80 / HTTPS: 443):
SonicWall 6.5 Management Settings Page
  1. Ensure that the SonicOS API is enabled and that the ‘CHAP authentication, and the ‘RFC-26 HTTP Basic Access authentication’ methods are enabled.

If the unlock option is not present. Make sure the SNMP service is enabled and readable at the agent side. This is needed to extract the SonicOS version.

Please Note: Due to limitations on the SonicWall Rest APIs, Domotz is only able to read configuration out of the devices, so the in the Config section your device will be unlocked in Read-Only mode.

I do not want to use the ‘main’ Administrator user

In order not to use the ‘main’ Administrator user, but a custom created user which is in the SonicWALL Administrator group, you have to:

1. Go inside the tab ‘Local Users &Groups’:

2. Modify the SonicWALL Administrators group in the ‘Administration’ tab and toggle the ‘Members go straight to the management UI on web login:

See below for SonicOS 6.5

Remember that you need to have created a user and placed it as a member of the ‘SonicWALL Administrators’ group first.

You might find more information on the SonicOS Rest APIs here: https://www.sonicwall.com/support/knowledge-base/introduction-to-sonicos-api/200818060121313/

Share via Social Networks

You might also like…

Read more top posts in this category