Reach a Resource on Your Network
The shortest path to reaching a resource inside your network, validated with one user. Requires a Secure Private Access (SPA) license
- Last validated: Oct 1, 2026
- 15 minutes to read
- Overview
- Scope
- Prerequisites
- Step 1. Activate Cloud Secure Edge and select a deployment model
- Step 2. Install a Connector
- Step 3. Publish a Service Tunnel
- Step 4. Create a local test user
- Step 5. Configure access for the test user
- Step 6. Connect from the test device
- Step 7. Validate
- Next steps
Overview
This quick start configures Secure Private Access (SPA) in its most basic form: one user, on one device, reaching one resource inside a private network through CSE, with no inbound firewall rule.
The configuration uses a Service Tunnel, which is the most direct method of publishing private access and is included in SPA Basic. Access to individually named resources is configured later.
This quick start serves the Replace your legacy VPN use case, and is the starting point for Set up ZTNA, which additionally requires SPA Advanced. To configure filtering of public internet traffic instead, see the Filter Internet Content quick start.
For the full organization-wide configuration, see Replace Your Legacy VPN in Use Cases.
Scope
The following are not required to complete this quick start:
- Any inbound firewall rule, or any resource exposed to the public internet. The Connector installed in Step 2 makes an outbound connection to SonicWall’s Edge Network, and access is returned through it.
- An identity provider. A single local account is used to validate the configuration, and the production directory is integrated afterwards. See Next steps.
Prerequisites
- A SonicWall Cloud Secure Edge (CSE) SPA activation key.
- A MySonicWall or SonicWall Unified Management account with permission to register products.
- A private network containing the resource to be reached, and a host on that network able to make outbound connections: HTTPS on TCP port 443, and User Datagram Protocol (UDP) on ports 21000 to 59999.
- One test device on which software can be installed.
Step 1. Activate Cloud Secure Edge and select a deployment model
Register the activation key so that SonicWall provisions the organization. See Activate Cloud Secure Edge.
A deployment model is selected during provisioning. On the Global Edge model, the geographic Points of Presence (PoPs) in which the infrastructure runs are also selected at this stage. This quick start assumes Global Edge, in which SonicWall hosts the edge infrastructure. See edge deployment models for a comparison, and Points of Presence for the available locations.
Provisioning takes several minutes to complete after Done is selected.
Step 2. Install a Connector
Install a Connector on a host inside the private network. The Connector establishes an outbound connection to SonicWall’s Edge Network, which is why no inbound firewall rule is required.
See the Connector install guides for the available installation methods.
Note: On the Private Edge deployment model, in which the edge infrastructure is self-hosted, install an Access Tier in place of a Connector.
Step 3. Publish a Service Tunnel
A Service Tunnel grants an assigned user access to a range of addresses on the private network. See Service Tunnel.
Define the smallest address range that includes the target resource, so that the outcome of the validation in Step 7 is unambiguous.
Step 4. Create a local test user
Create a single account using local user management rather than integrating a directory. See Local User Management, and Invite Code and Device Enrollment to register the account on a device.
Step 5. Configure access for the test user
Access in CSE is granted through a role and a policy rather than by naming individual users on a resource:
- Create a role that matches the test user. See Roles.
- Attach a policy that permits access, and assign it to the Service Tunnel. See Access Policies.
Step 6. Connect from the test device
Install the CSE desktop app on the test device and register it. See Register the Desktop App.
Sign in as the test user, select the Service Tunnel in the app, and connect.
Step 7. Validate
On the test device, with the tunnel connected:
- Confirm that the app reports the tunnel as Connected.
- Reach the private resource, by hostname where internal name resolution is configured, or by address where it is not.
- Disconnect the tunnel and confirm that the resource is no longer reachable. This second check establishes that CSE is carrying the traffic.
In the CSE console, confirm that the connection is recorded. See Visibility and Logging.
If the resource is not reachable, see Service Tunnel troubleshooting.
Next steps
The path is now validated for one user. Extend the configuration in the following order:
- Integrate an identity provider, replacing the local test account with the production directory, such as Entra ID or Okta. See Set Up an Identity Provider.
- Distribute the app to the organization using a device manager. See Roll Out with a Device Manager.
- Configure Connector high availability before the deployment is relied upon. See Set up High Availability.
The following capabilities narrow what has been granted:
- Trust Scoring, which requires a device to meet a defined security standard before access is granted.
- Hosted websites and Set Up ZTNA, which replace broad network access with access to individually named resources.