Troubleshooting
Identify which part of CSE is failing, then go straight to the page that fixes it
- Last validated: Oct 1, 2026
- 8 minutes to read
- Overview
- Question 1. How many people are affected?
- Question 2. What exactly fails, and when?
- Question 3. Is the shared infrastructure healthy?
- Two causes that look like something else
- Before you contact support
Overview
Most SonicWall Cloud Secure Edge (CSE) problems arrive as one sentence: a user cannot get to something. That sentence does not say which part of the system failed, and CSE has several parts that can fail independently.
This page narrows it down. Work through the three questions below in order, then follow the link for the symptom you end up with. If you already know which component is at fault, go straight to it in the Troubleshooting section of the sidebar.
Question 1. How many people are affected?
This is the fastest way to halve the search, so ask it first.
- One user, one device. The problem is almost certainly on that device or in that user’s account: the app, its registration, the user’s group membership, or the device’s trust score. Go to Question 2.
- One user, every device they own. Look at the account rather than the device: group membership, licence, and the policies attached to their role. See Access Policies.
- Everyone, or everyone at one site. Look at the shared pieces: the Connector or Access Tier serving that resource, a policy change, or a licence or subscription state. Go to Question 3.
Question 2. What exactly fails, and when?
Find the row that matches what you are seeing.
| What you see | Where to look |
|---|---|
| The desktop app will not install, register, or sign in | Desktop app troubleshooting |
| The mobile app will not register or connect | Mobile app troubleshooting |
| The tunnel says connected, but the resource is unreachable | Service Tunnel troubleshooting |
| The tunnel drops, or will not restart after dropping | Loss of connectivity and trouble restarting |
| It fails only on hotel, airport, or other restrictive networks | Loss of connectivity on a restrictive public network |
| Pages load slowly or only partly | Slow performance or requests timing out |
| A hostname will not resolve, but the address works | Hostname searches not resolving |
| Domain resolution fails when a SonicOS firewall is the Connector | Domain resolution failing on firewall Connector |
| Trusted network settings are not taking effect | Trusted network settings not taking effect |
| A site is blocked that should not be, or allowed that should not be | Internet Traffic troubleshooting |
| Sites are blocked only in Microsoft Edge | Blocked access in Edge with URL filtering |
| Private domains will not resolve, and the org has SIA only | Private domains failing to resolve |
| Access is refused and you suspect the device, not the user | Trust Scoring |
| You cannot get onto the user’s device to investigate | Remote Diagnostics |
Two details are worth pinning down before you go further, because they change the answer:
- Did it ever work? A resource that has never worked points at configuration. A resource that stopped working points at a change: an upgrade, a policy edit, a certificate expiry, or a network change on your side.
- What changed most recently? If the failure started after an upgrade, check Known Issues before anything else.
Question 3. Is the shared infrastructure healthy?
If the problem is wider than one person, check the components that everyone depends on.
| Component | Where to look |
|---|---|
| Access Tier, on the Private Edge deployment model | Access Tier troubleshooting |
| Access Tier health and metrics | Status Reporting and Monitoring |
| Connector installed from the OVA image | Monitoring and troubleshooting the OVA Connector |
| Whether traffic reaches CSE at all | Visibility and Logging |
Two causes that look like something else
These two account for a large share of cases that get misdiagnosed, so rule them out early.
You are looking in the wrong console. CSE is administered across more than one portal. Licences, admin accounts, and tenant access are managed in MySonicWall or SonicWall Unified Management. Policies, resources, and users are managed in the CSE Command Center. A setting that looks wrong in one console may simply not be owned by it. See MySonicWall.
The licence is not doing what you assume. A user consumes a licence only after they have both been granted one and authenticated into the app. Creating or syncing a user does not, by itself, grant access. See CSE Licenses.
Before you contact support
Collect the logs before you change anything, because some of the evidence disappears once settings change. You do not need the device in front of you, or the user on a call.
Collect the logs yourself, from the Command Center:
- Go to Directory > Devices and select the affected device.
- Run Remote Diagnostics and download the collected logs.
Collection takes up to 15 minutes, and the device needs CSE desktop app 3.6.0 or later.
If Remote Diagnostics is not available for that device, because it is on an older app version or has not checked in, ask the user to send the logs from the app themselves: Settings > Health Check > Run Diagnostic Tool > Send Log Files to SonicWall CSE Support.
Include the following in the case: the affected username, the device and its operating system version, the CSE app version, the resource being reached, the exact time of a failed attempt, and whether it has ever worked.