Securing Hosted Websites with SonicWall Cloud Secure Edge (CSE)
Protect your hosted websites and enable access without a VPN
- Last validated: Jul 15, 2026
Overview
Hosted Websites is a Cloud Secure Edge (CSE) capability that provides end users with secure Zero Trust access to internal websites and web applications through an ordinary web browser.
Internal web applications are traditionally reached over a VPN or by exposing the site to the public internet, both of which grant broad network access and increase risk. CSE instead brokers each request individually, so users reach only the specific website they are authorized to use, without a VPN.
CSE uses OpenID Connect (OIDC) authentication flows to enforce access. The security mechanism is designed to be completely transparent to both the user and the service it is securing.
How it works:
- A user navigates to a hosted website in a web browser.
- CSE intercepts the request and, using OIDC, authenticates the user against your CSE directory.
- CSE evaluates the Zero Trust policy for that website, including user identity and device trust.
- If the policy is satisfied, CSE brokers the connection to the internal web application on the user’s behalf.
The flow diagrams below describe how CSE’s Zero Trust access control security mechanism works for Hosted Websites. Review the Publish a Website to Users guide to see how to create a Zero Trust policy for a website and conveniently access it from a web browser.
Access to Hosted Websites
Next step: To create a Zero Trust policy and publish a web application to your users, see Register a Hosted Website to Users.
Sections
Publish a Hosted Website to Users
Use Let's Encrypt Certificates