Filter Internet Content

The shortest path to working content filtering, validated on one device. Requires a Secure Internet Access (SIA) license

  • Last validated: Oct 1, 2026
  • 10 minutes to read

Overview

This quick start configures Secure Internet Access (SIA) in its most basic form: one Internet Threat Protection (ITP) policy applied to one registered device. Completing it confirms that filtering is enforced on the endpoint and recorded in the console before the configuration is extended to the wider organization.

This quick start serves the Block internet content use case, and the Protect SaaS apps use case where device trust is enforced on SaaS sign-in. To configure access to private resources instead, see the Reach a Resource on Your Network quick start.

For the full organization-wide configuration, see Block Malicious Internet Content in Use Cases.

Terminology

Two terms describe the same capability at different levels:

  • Secure Internet Access (SIA) is the license. It covers filtering of the public internet and of Software as a Service (SaaS) applications.
  • Internet Threat Protection (ITP) is the feature in the CSE console in which the corresponding policies are configured.

A license is purchased as SIA, and the policies are configured under ITP.

Scope

SIA is enforced on the endpoint. The following are therefore not required to complete this quick start:

  • A Connector or an Access Tier
  • A deployment model selection
  • Any change to the configuration of your network

An identity provider is also not required at this stage. A single local account is used for validation, and the directory integration is completed afterwards. See Next steps.

Prerequisites

  • A SonicWall Cloud Secure Edge (CSE) SIA activation key.
  • A MySonicWall or SonicWall Unified Management account with permission to register products.
  • One test device on which software can be installed, running a supported operating system.

Step 1. Activate Cloud Secure Edge

Register the activation key so that SonicWall provisions the organization. See Activate Cloud Secure Edge.

Provisioning takes several minutes to complete after Done is selected.

Step 2. Create a local test user

A user must exist in CSE before a policy can be applied to that user. For this quick start, create a single account using local user management rather than integrating a directory.

See Local User Management, and Invite Code and Device Enrollment to register the account on a device.

Step 3. Install and register the desktop app

Install the CSE desktop app on the test device and register it against the organization. See Register the Desktop App.

Install the app manually for this validation. For an organization-wide rollout, use a device manager instead, as described in Roll Out with a Device Manager.

Note: The Chrome extension is an alternative to the desktop app where filtering is required only within the Chrome browser. See Chrome Extension.

Step 4. Configure an ITP policy

Configure a single policy that blocks one content category, so that the outcome of the validation in Step 5 is unambiguous. See Manage ITP Policies.

Assign the policy to the user account created in Step 2.

Step 5. Validate

On the test device:

  1. Confirm that the desktop app reports the device as registered.
  2. Navigate to a site within the blocked category. The request is expected to be refused.
  3. Navigate to a site outside the blocked category. The request is expected to succeed.

In the CSE console, confirm that the blocked request is recorded. See Visibility and Logging.

If the request is not blocked, see Internet Traffic troubleshooting.

Next steps

Filtering is now validated on one device. Extend the configuration in the following order:

  1. Integrate an identity provider, such as Entra ID or Okta, so that policies follow existing directory groups. See Set Up an Identity Provider.
  2. Distribute the app to the organization using a device manager. See Roll Out with a Device Manager.

The following capabilities extend what SIA inspects:

Was this page helpful?