URGENT SONICWALL 5600 CONFIGURATION
Budget: $200 – $220 CAD
I need a SonicWall specialist who can configure a new SonicWALL for me as a matter of urgency.
Key Tasks:
- Firewall Configuration: The main task is to set up the firewall configuration on the SonicWALL 5600.
- Specific Security Settings: I have some specific security settings that need to be addressed. These settings are related to:
- Intrusion Prevention System (IPS)
- Content Filtering
- Application Control
SSL self-signed certificates on port TCP 443. Even if you are using a secured port 443 HTTPS, a self-signed certificate will be a security threat if the Management page is accessed from WAN. How do I generate a new SSL certificate from my SonicWall firewall? The certificate will have a domain name that needs to be resolved to the public IP of SonicWall
HTTP Security Header Not Detected - Upgrade firmware to the latest. The HSTS error is fixed. How can I upgrade SonicOS Firmware?
General remote services on port TCP 4433. SSL VPN Certificate self-signed certificate. How to upload a CA signed certificate to SSL VPN service?
TLSv1.1 is supported - the latest browsers have all disabled TLSv1.1 and SSLv3 Disable TLS 1.1 Support
SSL Certificate has an IP Address as the Common Name. The certificate used in HTTP web management or SSL VPN has an IP address instead of FQDN in the Common Name (CN) field. Obtain a certificate with an FQDN as its CN or Subject Alternative Name
Subject Common Name Does Not Match Server FQDN. Obtain a certificate whose Subject Common Name (CN) or Subject Alternative Name (SAN) matches the FQDN used to access it. For example, if the scan is being done using the FQDN www.example.com, the certificate must have its CN or SAN as www.example.com or *.example.com.
SSL Certificate - Signature Verification Failed Vulnerability This error occurs when the certificate in the HTTP web management or SSL VPN is signed by an unknown Certificate Authority (CA). In most cases, this happens when the CA is private. For example, a Windows CA. Obtain a certificate signed by a public CA.
Pre-shared Key Off-line Bruteforcing Using IKE Aggressive Mode. UDP 500 is for all types of IPsec VPN tunnels, which includes the WAN GroupVPN (GVC) connections. Please increase the complexity of the shared secret by including special characters, numbers, and don't include any patterns. A digital certificate is the most secure option available with WANGroup VPN.
Use 2FA for any login - IPsec VPN client, SSL VPN client or HTTPS admin login. How to configure two-factor authentication using TOTP for HTTPS Management and How do I configure 2FA for SSL VPN with TOTP? Two factor authentication using RSA Radius and SecurID for SonicWall GVC
Restrict inbound access. Do not allow inbound access over unsecured ports like HTTP, FTP, SSH, RDP and so forth. Wherever possible have source-based access rules. How to Configure Access Rules
Requirements:
- Previous experience with SonicWall, specifically with the 5600 model is a MUST.
- Strong knowledge of firewall configuration and security settings is essential.
- Proven experience with Intrusion Prevention Systems (IPS) and Content Filtering is highly preferred.
Timeframe:
I am looking to get this project completed as soon as possible. The quicker you can work on it, the better.
Key Tasks:
- Firewall Configuration: The main task is to set up the firewall configuration on the SonicWALL 5600.
- Specific Security Settings: I have some specific security settings that need to be addressed. These settings are related to:
- Intrusion Prevention System (IPS)
- Content Filtering
- Application Control
SSL self-signed certificates on port TCP 443. Even if you are using a secured port 443 HTTPS, a self-signed certificate will be a security threat if the Management page is accessed from WAN. How do I generate a new SSL certificate from my SonicWall firewall? The certificate will have a domain name that needs to be resolved to the public IP of SonicWall
HTTP Security Header Not Detected - Upgrade firmware to the latest. The HSTS error is fixed. How can I upgrade SonicOS Firmware?
General remote services on port TCP 4433. SSL VPN Certificate self-signed certificate. How to upload a CA signed certificate to SSL VPN service?
TLSv1.1 is supported - the latest browsers have all disabled TLSv1.1 and SSLv3 Disable TLS 1.1 Support
SSL Certificate has an IP Address as the Common Name. The certificate used in HTTP web management or SSL VPN has an IP address instead of FQDN in the Common Name (CN) field. Obtain a certificate with an FQDN as its CN or Subject Alternative Name
Subject Common Name Does Not Match Server FQDN. Obtain a certificate whose Subject Common Name (CN) or Subject Alternative Name (SAN) matches the FQDN used to access it. For example, if the scan is being done using the FQDN www.example.com, the certificate must have its CN or SAN as www.example.com or *.example.com.
SSL Certificate - Signature Verification Failed Vulnerability This error occurs when the certificate in the HTTP web management or SSL VPN is signed by an unknown Certificate Authority (CA). In most cases, this happens when the CA is private. For example, a Windows CA. Obtain a certificate signed by a public CA.
Pre-shared Key Off-line Bruteforcing Using IKE Aggressive Mode. UDP 500 is for all types of IPsec VPN tunnels, which includes the WAN GroupVPN (GVC) connections. Please increase the complexity of the shared secret by including special characters, numbers, and don't include any patterns. A digital certificate is the most secure option available with WANGroup VPN.
Use 2FA for any login - IPsec VPN client, SSL VPN client or HTTPS admin login. How to configure two-factor authentication using TOTP for HTTPS Management and How do I configure 2FA for SSL VPN with TOTP? Two factor authentication using RSA Radius and SecurID for SonicWall GVC
Restrict inbound access. Do not allow inbound access over unsecured ports like HTTP, FTP, SSH, RDP and so forth. Wherever possible have source-based access rules. How to Configure Access Rules
Requirements:
- Previous experience with SonicWall, specifically with the 5600 model is a MUST.
- Strong knowledge of firewall configuration and security settings is essential.
- Proven experience with Intrusion Prevention Systems (IPS) and Content Filtering is highly preferred.
Timeframe:
I am looking to get this project completed as soon as possible. The quicker you can work on it, the better.