T Techclick ← All lessons
SonicWall · Evidence desk · Interactive lesson

Prove SonicWall is working — first tool + proof field

01:40. Slack: “Is the firewall even working?” The CIO is already in the channel. A green System Status tile is not proof. This desk is five official SonicOS surfaces — Connection Monitor / session, Log > Monitor, Access Rule hit, VPN status, Capture ATP — each mapped to one ticket, one first click, and one field you paste before you disable GAV or bounce IKE.

~20 min read · L2 primary · Quiz at end · Blog 1 · Factory

⚡ Quick Answer

How you prove SonicWall is working: Connection Monitor / session, Log > Monitor, Access Rule hit, VPN status, Capture ATP. Five tickets with first tool and one official SonicOS proof field.

After this page you can

Quick answer (say this out loud)

Connections answers “did this 5-tuple become a session on this NSa?” MONITOR | Logs > System Logs (operators still say Log > Monitor) answers “which Access Rule Name wrote the event?” Access Rule traffic statistics answers “did that named rule actually increment?” Currently Active VPN Tunnels answers “is this site-to-site in the active table — and is the subnet in Local / Destination Networks?” Capture ATP answers “is the file still waiting on a verdict, or already judged?” A green tile is not a session. An Allow is not a hit. An IPsec SA in the list is not the printer subnet.

1. Why “is it working?” is five questions

Concept: Operators collapse five failures into one sentence. The packet never became a connection. A Deny (or Discard) wrote a log. The rule you are staring at has zero traffic statistics since Restore. The tunnel is in Currently Active VPN Tunnels while 10.50.0.0/24 is missing from Destination Networks. Capture ATP is holding the download until a verdict returns. Those are five first clicks.

Path: Write the 5-tuple + UTC. Then pick the tile: Connections → System Logs → Access Rule hits → Currently Active VPN Tunnels → Capture ATP. The factory taught the stamps (X-port, zone, access rule, NAT, ARP, DPI-SSL, proxy ID). Here you learn the five SonicOS tools you actually open when someone asks you to prove the firewall is working.

Do: Quote one official field before you change POLICY | Capture ATP, bounce IKE, or add a second LAN→WAN Allow. Lab identities below are RFC 5737 / example.com only.

Hero · five tiles, one ticket
Night-shift operations desk with five glowing SonicWall proof tiles on a wall monitor
Notice: five tiles, not one “SonicOS dashboard.” You pick the tile that matches the question, then you quote one official field.
Interview line

If they say “prove SonicWall is working,” do not say “I opened the Management Interface.” Say: “I prove the session on MONITOR | Tools & Monitors > Connections with Src IP + Src Port, the event with System Logs Access Rule Name, the rule with Access Rule traffic statistics, the tunnel with Currently Active VPN Tunnels plus Local / Destination Networks, and the file with Capture ATP verdict / Block until verdict.”

Name drift (official)

Night-shift veterans still say Connection Monitor and Log > Monitor — those are the SonicOS 6 labels. SonicOS 7 / 8 technical documentation titles the same work MONITOR | Tools & Monitors > Connections and MONITOR | Logs > System Logs. This desk uses both names on purpose. The fields did not move; the left-nav did.

2. Mental model — five proof tools

Memorise five named objects before you click. Each tool is allowed to prove one thing. Over-claiming a field is how you disable Capture ATP at 02:00 for a SYN that never left X0.

1 · Connection Monitor / session

SonicOS 7/8: MONITOR | Tools & Monitors > Connections. IPv4 or IPv6. Official columns include Src IP, Src Port, Dst MAC, Dst Vendor. Filter the table. Proves the appliance built (or never built) a connection. Does not prove which Access Rule wrote the log.

2 · Log > Monitor

SonicOS 7/8: MONITOR | Logs > System Logs. Official column: Access Rule Name — “Name of the Access Rule triggering the event, if any.” Also Access and IDP Rules. Filter icon + Grid Settings. One event. Not a hit counter.

3 · Access Rule hit

POLICY | Rules and Policies > Access Rules. Display traffic statistics from Settings > Grid Settings. Restore restarts the counts. Zone Matrix / From Zone–To Zone first. Action is Allow, Deny, or Discard. A written Allow with zero stats is not a hit.

4 · VPN status

NETWORK | IPSec VPN > Rules and Settings. Proof object: Currently Active VPN Tunnels (Refresh at the top). Policy Type Site to Site. Then open the policy Network tab: Local Networks / Destination Networks. Active ≠ that subnet.

5 · Capture ATP

POLICY | Capture ATP > Settings plus Dashboard | Capture ATP. Official hold: Block file download until a verdict is returned. Files can sit in Files Blocked Until Completely Analyzed. GAV + Cloud Gateway Anti-Virus must be on or Capture ATP stops.

Hard words, once

Connection = the session row, not the cable. Access Rule Name = the log column. Traffic statistics = the hit counter. Currently Active VPN Tunnels = the live table. Verdict = Capture ATP’s clean / malicious / still-analyzing answer. Classic Mode uses Access Rules; Policy Mode uses a unified Security Policy table — same isolate idea.

Flow 1 · five tools, one question each
Write 5-tuple + UTC first · then pick the tool Is the firewall even working? five SonicOS questions, not one Connections This 5-tuple a session? Src IP + Src Port Dst MAC · Dst Vendor Tools & Monitors not a verdict System Logs Which rule wrote it? Access Rule Name Access and IDP Rules MONITOR | Logs not a hit count Rule hit Did this rule increment? traffic statistics Grid Settings · Restore Access Rules table Allow ≠ hit VPN status This tunnel active? Currently Active Local / Dest Networks IPSec VPN > Rules not the printer /24 Capture ATP This file judged? verdict Block until verdict POLICY | Capture ATP not a missing Allow Empty Connections is data. It usually means the packet never became a session. Do not invent a Capture ATP outage from an empty session table. Start at X-port / zone / Access Rule — the factory.

Read left → right. Each box is allowed one claim. If you cannot name the official field, you are not proving — you are guessing.

Say this out loud

I prove the session, then the log row, then the hit counter, then the active tunnel plus proxy ID, then the ATP verdict. I do not disable Capture ATP, bounce IKE, or add Any-Any until I can quote the field that made me do it.

3. Decision flow — ticket → first tool

Flowchart first. Do not open POLICY | Capture ATP until a diamond says the file is the question.

Path · pick the branch before the menu
Abstract diamond splitting into five SonicWall proof paths
Notice: the diamond is the ticket. The path is the SonicOS tool. The field comes last. Do not reverse that order.
Flow 2 · first-tool diamond
Symptom first · tool second · field third What must we prove? A live session? or already inside? HTTPS “dead” Connections Src IP · Src Port One flow denied System Logs Access Rule Name “Rule 14 allows” Access Rule hit traffic statistics SA “up”, /24 dead VPN status Active + Networks Download hung Capture ATP verdict / hold Empty Connections → stop. There is no Access Rule Name to chase yet. Fix X-port / zone / first-match rule / ARP (factory). Then re-open Connections. Diamond = decision. Do not disable Capture ATP from the bottom box. Older tenants still say Connection Monitor and Log > Monitor. Official 7/8 path is MONITOR | …

Read the diamond first. A hung download never starts on Access Rules. A dead printer /24 never starts on Capture ATP. Empty Connections never starts on a new Allow.

4. How to choose — first tool + proof field

Print this next to the SonicOS tab. If you cannot recite the proof field, you are not ready to change anything.

If the ticket says…First tool (official path)Proof fieldDo not open first
Laptop / “is the firewall even working?” / HTTPS stuck MONITOR | Tools & Monitors > Connections (Connection Monitor). IPv4 or IPv6. Use Filter. A row for this 5-tuple: official Src IP + Src Port (plus Dst MAC / Dst Vendor when L2 matters) POLICY | Capture ATP
One flow denied or discarded after a policy change MONITOR | Logs > System Logs (Log > Monitor). Filter icon. Access Rule Name of the Access Rule triggering the event (+ Access and IDP Rules) A second LAN→WAN Allow
“Rule 14 already allows” / “that rule never hits” POLICY | Rules and Policies > Access Rules → Settings > Grid Settings → traffic statistics Traffic statistics on that named rule since last Restore. Action = Allow / Deny / Discard Disable GAV
Site-to-site “up”, one remote subnet dead NETWORK | IPSec VPN > Rules and Settings → Currently Active VPN Tunnels (Refresh) Tunnel present in Currently Active VPN Tunnels, then Local Networks / Destination Networks on the policy Bounce IKE / change Phase 1
Download hung; “disable Capture ATP” POLICY | Capture ATP > Settings and Dashboard | Capture ATP Block file download until a verdict is returned / Files Blocked Until Completely Analyzed / the verdict A new Access Rule, or unchecking GAV
Factory hand-off

If Connections is empty, you are not on this desk’s ticket 2–5 yet. You are back in the factory: name the X-port and zone on Network | Interfaces, then the zone-pair Access Rule, then NAT, then ARP on the egress X-port. Lesson: SonicOS speaks X0 and X1. Allow is not a session. Incomplete ARP ends the policy debate.

5. Runbook Side A → B → C

Side A proves the session and the Access Rule hit. Side B proves the log store. Side C proves the overlay — IPsec and Capture ATP. On a messy Sev-2, do them in this order until a field lights up. Every step cites SonicWall technical documentation.

Side A — Session + Access Rule hit

  1. Open Connections, not Capture ATP

    Path: MONITOR | Tools & Monitors > Connections. Official: Viewing Connections — click IPv4 or IPv6. The appliance “maintains a connections log for tracking all active connections.” Use Filter so the table shows only the ticket 5-tuple. Source: SonicOS 7.0 / 7.3 / 8 Monitor — Connections.

  2. Quote the official columns that close a session ticket

    Documented Viewing Connections columns include Src IP (IP address of the source device), Src Port (port number of the source device), Dst MAC, Dst Vendor. Match 10.10.8.22 (lab) to the destination you were given. A matching row means SonicOS built a connection. An empty filtered table means the packet never became a session — stop. Do not hunt a verdict.

  3. If someone claims “the rule allows,” open traffic statistics

    Path: POLICY | Rules and Policies > Access Rules. Use the Zone Matrix Selector or From Zone / To Zone. Open Settings > Grid Settings and display traffic statistics. Official: to restart the counts, click Restore. Quote the named rule’s statistics after a reproduce. Action values on the rule are Allow, Deny, or Discard. Source: SonicOS 7.1 Rules and Policies for Classic Mode — Display Traffic Statistics.

  4. Empty session + zero statistics = factory, not ATP

    If Connections has no row and the intended rule’s traffic statistics did not increment, the packet never reached that rule. Confirm X-port / Zone on Network | Interfaces, then the first-match Access Rule for that zone pair. That is the factory, not this desk’s Capture ATP ticket.

https://192.168.168.168/sonicos · MONITOR | Tools & Monitors > Connections
Training mock · not live

MONITOR / Tools & Monitors / Connections / IPv4

Connections

IPv4IPv6
Src IP = 10.10.8.22
IPv4
Src IPSrc PortDst MACDst Vendor
10.10.8.225184400:53:00:11:22:33Lab-ISP
10.10.8.404431200:53:00:aa:bb:ccLab-Core

Official Viewing Connections columns shown. Empty filtered table = no session. Training mock · RFC 5737 / lab MACs only.

Source: SonicOS 7.0 Tools & Monitors — Viewing Connections; SonicOS 7.3 / 8 Monitor — Connections (Src IP, Src Port, Dst MAC, Dst Vendor; IPv4 / IPv6; Filter). Lab identities only.

Side B — Log > Monitor (System Logs)

  1. Open System Logs, not the policy editor

    Path: MONITOR | Logs > System Logs. Operators: Log > Monitor. Official: navigate to MONITOR | Logs > System Logs, then use the Filter icon. Grid Settings chooses which columns display. Source: SonicOS 7.3 Monitor — System Logs display options / filter view / functions.

  2. Read Access Rule Name — that is the ticket

    Official column: Access Rule Name — “Name of the Access Rule triggering the event, if any.” Also documented under Access and IDP Rules. Filter source 10.10.8.22 (lab) + the UTC window. Quote the name, not “a deny somewhere.”

  3. Empty System Logs is not “SonicWall is down”

    If Connections already showed a session and System Logs has no row, check Grid Settings, the Filter, and the time window. Logging can be off on that Access Rule. That is a Track / logging problem — not a reason to add Any-Any “so we get a log.” Packet Monitor (MONITOR | Tools & Monitors > Packet Monitor) is a different isolate tool; it is not one of this desk’s five first tiles.

https://192.168.168.168/sonicos · MONITOR | Logs > System Logs
Training mock · not live

MONITOR / Logs / System Logs

System Logs

Source = 10.10.8.22
Last 15 minutes
Time (UTC)PriorityCategoryAccess Rule Name
01:41:08InformNetwork AccessLAN WAN HTTPS Allow
01:42:11WarningNetwork AccessLAN WAN Cleanup Deny

Source: SonicOS 7.3 Monitor — System Logs (display options, filter view, functions). Official column Access Rule Name — name of the Access Rule triggering the event, if any. Lab identities only.

Side B — fields you write in the ticket
Path:              MONITOR | Logs > System Logs   (aka Log > Monitor)
Filter:            Source 10.10.8.22 + UTC window
Quote:             Access Rule Name = LAN WAN Cleanup Deny
If empty + session: Grid Settings / Filter / logging on that rule
Do not:            add Any-Any “to generate a log”

Side C — VPN status + Capture ATP

  1. Prove the tunnel from Currently Active VPN Tunnels

    Path: NETWORK | IPSec VPN > Rules and Settings. Official: a list of currently active VPN tunnels is displayed; Refresh the active tunnels at the top of the Policies view. Policy Type on the General screen includes Site to Site. Source: SonicOS/X 7 IPSec VPN — Currently Active VPN Tunnels; site-to-site policies.

  2. Then open Local Networks / Destination Networks

    Active in the table is not the printer subnet. Open the VPN Policy → Network. Quote Local Networks and Destination Networks (the proxy ID / interesting traffic). Official: when adding VPN Policies, SonicOS auto-creates non-editable Access Rules so traffic can traverse Trusted Zones and the VPN Zone — those auto-rules are not a substitute for listing 10.50.0.0/24. Do not bounce IKE first.

  3. If the ticket is a hung download, prove the verdict

    Path: POLICY | Capture ATP > Settings. Official enable set: Capture ATP, Gateway Anti-Virus (GAV), and Cloud Gateway Anti-Virus. Official hold: Block file download until a verdict is returned — “ensures no packets get through until the file is completely analyzed.” Dashboard: Dashboard | Capture ATP (status of files sent to the backend). Files can remain in Files Blocked Until Completely Analyzed. Capture ATP stops working when GAV or Cloud GAV is disabled — unchecking GAV is not isolate. Source: SonicOS 7.0 / 7.1 / 8 Capture ATP; SonicOS 7.3 Monitor Dashboard — Capture ATP.

https://192.168.168.168/sonicos · POLICY | Capture ATP > Settings
Training mock · not live

POLICY / Capture ATP / Settings

Capture ATP

Enabled
Enabled
Enabled
On
Dashboard | Capture ATP (lab)
Files Blocked Until Completely Analyzed: 1
file=finance-q4.xlsx src=10.10.8.22 state=analyzing
Do not uncheck GAV — Capture ATP stops when GAV or Cloud GAV is disabled.

Source: SonicOS 7.0.1 / 7.1 / 8 Capture ATP (enable GAV + Cloud GAV; Block file download until a verdict is returned; Files Blocked Until Completely Analyzed); SonicOS 7.3 Monitor Dashboard — Capture ATP. Training mock · not live.

Green success on each side

6. Five tickets as full stories

These five land every quarter. Memorise first tool + proof field. Times and identities below are lab-only.

Proof · named field, then Closed
Operations desk with abstract green health checks and one highlighted SonicWall proof field
Notice: Connections can already show a session while Capture ATP is still holding the file. That is an ATP ticket, not a missing Allow.
TicketSymptomFirst toolProof field
SWEVD-01“Is the firewall even working?” Finance HTTPS stuckMONITOR | Tools & Monitors > ConnectionsSrc IP + Src Port row — or an empty Filter
SWEVD-02After a cleanup, one host cannot reach SaaSMONITOR | Logs > System LogsAccess Rule Name on that event
SWEVD-03“Rule 14 already allows” but the app never loadsPOLICY | Rules and Policies > Access RulesTraffic statistics since Restore (zero vs increment)
SWEVD-04IPsec “up”, printers on 10.50.0.0/24 deadNETWORK | IPSec VPN > Rules and SettingsCurrently Active VPN Tunnels + Destination Networks
SWEVD-05Download hung; L1 wants Capture ATP offPOLICY | Capture ATP + Dashboard | Capture ATPBlock until verdict / Files Blocked Until Completely Analyzed / verdict

SWEVD-01 — Prove the session (Connections)

01:42 · P2. Priya: Finance HTTPS to 198.51.100.80:443 is stuck. Someone pasted a green HOME / System Status screenshot. L1 already drafted “disable Capture ATP.”

First tool: MONITOR | Tools & Monitors > Connections → IPv4 → Filter Src IP = 10.10.8.22 (lab host).

If empty: SonicOS never built a connection. Quote the empty Filter. Next station is the factory — X-port / zone / first-match Access Rule / ARP on the egress X-port — not POLICY | Capture ATP. The factory dummy lab would then print state=SYN_SENT and bytes=…/0; that is isolate language for “forward done, return not done.” Official Connections proof is still the row (or its absence) with Src IP + Src Port.

If a row exists: you proved a session. You are now allowed to open System Logs for Access Rule Name, or Capture ATP if the symptom is a hung file. The Connections row is not a verdict.

Trap

Do not trust a colleague’s Connections tab from a different NSa or the idle HA peer. Official HA: retest on the current active unit. Empty tables on standby are expected.

SWEVD-02 — Prove the event (System Logs)

02:05 · P2. A cleanup change shipped at 01:18. Outlook on the Web opens from some desks. Priya’s host cannot reach 198.51.100.80. Someone wants “another LAN→WAN Allow at the top.”

First tool: MONITOR | Logs > System Logs. Filter Source = 10.10.8.22, last hour.

Proof field: Access Rule Name = LAN WAN Cleanup Deny (lab). That name is the ticket. Change that one rule — or the object it missed — then reproduce and re-read the same column. If Category points at an IDP / security-service event under Access and IDP Rules, you are not in a missing-Allow story.

Close

I would not add a second LAN→WAN Allow. I would quote Access Rule Name on the failing 5-tuple. A saved rule is not proof until the same Filter returns the intended name after reproduce.

SWEVD-03 — Prove the hit (Access Rule traffic statistics)

02:20 · P2. L1: “Rule 14 already Allows HTTPS. SonicWall is broken.” They are looking at the Action column, not the counters.

First tool: POLICY | Rules and Policies > Access Rules. Zone pair LAN → WAN. Settings > Grid Settings → display traffic statistics. Note the counts. Click Restore if you need a clean window. Reproduce once. Re-read the same rule.

Proof field: traffic statistics still zero after reproduce → this rule never saw the packet (wrong zone pair, shadowed by a higher-priority rule, or the session never started — go back to Connections). Statistics increment and Action = Allow → the rule is doing its job; the next station is ARP / NAT / DPI-SSL (factory) or Capture ATP if the file is the hold.

Close

Allow is permission. Traffic statistics are the hit. I would paste the rule name + Action + statistics since Restore. I would not add Any-Any on top of a rule that already Allows and already increments.

SWEVD-04 — Prove the tunnel (Currently Active VPN Tunnels)

02:40 · P2. DC printers on 10.50.0.0/24 are dead. The channel screenshot shows the site-to-site policy Enabled. L1 wants IKE bounced.

First tool: NETWORK | IPSec VPN > Rules and Settings. Refresh. Confirm the policy is in Currently Active VPN Tunnels.

Proof field: the tunnel is in the active table, and Destination Networks does not list 10.50.0.0/24. Active ≠ the subnet. Official Network objects on the VPN Policy are Local Networks and Destination Networks. Auto-added Access Rules between Trusted Zones and the VPN Zone only pass what the policy’s networks include. Do not bounce IKE. Do not change Phase 1.

Trap

Restarting a healthy IKE SA is change-control, not isolate. A missing Destination Network is a Network-tab ticket. Quote the object list.

SWEVD-05 — Prove the file (Capture ATP)

03:00 · P3. Finance cannot download finance-q4.xlsx. Connections already shows Src IP 10.10.8.22. System Logs Access Rule Name is the HTTPS Allow. L1 typed “disable Capture ATP” in the channel.

First tool: POLICY | Capture ATP > Settings and Dashboard | Capture ATP.

Proof field: Block file download until a verdict is returned is On, and the file is in Files Blocked Until Completely Analyzed (or the dashboard shows analyzing / the later verdict). Official: that option holds packets until analysis finishes. Official: Capture ATP stops when GAV or Cloud Gateway Anti-Virus is disabled — unchecking GAV to “make the download work” turns the sandbox off. Wait for the verdict, or use a documented exclusion after change-control — do not disable the service from a Sev-3 download.

Close

I would leave Access Rules alone. I would paste Block until verdict + the dashboard file state. A session + an Allow + a hold is Capture ATP doing what you asked.

7. Traps + close-the-ticket proof

Weak closes reuse a screenshot. Strong closes reuse a named SonicOS field.

You seeWeak closeStrong close
Green HOME / System Status tile“SonicWall is working”Connections row for the 5-tuple: Src IP + Src Port
Empty Connections FilterDisable Capture ATPQuote the empty table; factory: X-port / zone / rule / ARP
Access Rule Action = Allow“Policy is fine”Traffic statistics since Restore — Allow ≠ hit
System Logs empty, session existsAny-Any “to get a log”Grid Settings + Filter + logging on that rule; quote Access Rule Name when it appears
Access Rule Name = Cleanup DenySecond LAN→WAN Allow at the topChange that named rule; re-read the same column
VPN policy EnabledBounce IKECurrently Active VPN Tunnels + Local / Destination Networks
Tunnel in Currently Active, one /24 dead“IPsec is down”Quote the missing Destination Network object
Download hung, session + Allow existUncheck GAV / Capture ATPBlock until verdict / Files Blocked Until Completely Analyzed / verdict
Idle HA peer, empty Connections“The pair is down”Retest the current active unit — idle standby is expected
Capture ATP “not working”Reboot the NSaOfficial: it stops when GAV or Cloud GAV is disabled. Re-read Settings.
Proof checklist before you leave the bridge
Interview close

I name the question, then the first tool, then one official field. Connections proves the session. System Logs proves Access Rule Name. Access Rule traffic statistics prove the hit. Currently Active VPN Tunnels plus Local / Destination Networks prove the site-to-site. Capture ATP proves the file hold / verdict. I do not disable Capture ATP, bounce IKE, or add Any-Any until that field is on the ticket. Factory model: SonicOS speaks X0 and X1.

Knowledge check

Six night-shift judgments. Each maps to a first tool or a proof field. Check answers, then Reset if you picked the wrong surface.

Q1

01:40. “Is the firewall even working?” HOME looks green. You have not opened POLICY. First proof?

Correct: b. Official Viewing Connections path and columns. A green tile is not a session. Re-read Side A steps 1–2 and SWEVD-01.
Q2

A cleanup change shipped an hour ago. One finance host cannot reach SaaS on tcp/443. Which proof field closes SWEVD-02?

Correct: a. Official System Logs column Access Rule Name is the Access Rule triggering the event. VPN and ATP are different tickets. Re-read Side B and SWEVD-02.
Q3

L1 says “Rule 14 already Allows HTTPS.” The app still fails. First tool + field?

Correct: c. Official: Settings > Grid Settings displays traffic statistics; Restore restarts the counts. Allow is not a hit. Re-read Side A step 3 and SWEVD-03.
Q4

Site-to-site looks Enabled. Printers on 10.50.0.0/24 are dead. First tool + proof?

Correct: b. Official Currently Active VPN Tunnels + Local / Destination Networks. Auto-added Access Rules only pass listed networks. Re-read Side C steps 1–2 and SWEVD-04.
Q5

Connections already shows Src IP 10.10.8.22. Access Rule Name is the HTTPS Allow. The xlsx download never finishes. What do you do first?

Correct: d. Official hold and dashboard. Unchecking GAV officially stops Capture ATP. Re-read Side C step 3 and SWEVD-05.
Q6

Connections Filter for the finance 5-tuple is empty. What is that empty table allowed to mean?

Correct: a. Empty Connections is data: the packet never became a session. Factory first. Re-read Flow 2 bottom box and SWEVD-01.

Sources

Related: Blog 1 · SonicWall session factory · SonicWall interview hub · Dummy lab (simulator key sonicwall) · Access rules and NAT · DPI-SSL deep dive