Sonicwall Safe IPsec VPN Management Access
The IPsec VPN is utilized for router-to-router VPN tunnels. To prevent the unnecessary exposure of firewalls at multiple sites to WAN management, management access should be restricted to the IPsec VPN and routed through the VPN Hub location. This configuration is compatible with both Hub and Spoke VPN designs and Mesh VPN designs.
Configuration Steps for Remote Locations
To configure management access at a remote location, perform the following steps within the Sonicwall management interface at each (spoke/remote) location:
Select the Menu -> IPsec VPN tunnel and click edit.Navigate to the Advanced tab to locate the following two settings:

Management via this SA
The ‘management via this SA’ setting allows the user with the username ‘admin’ to log into the Sonicwall device from the Hub location (or from other locations in a mesh network) using the internal IP address and management port of the device. This setting exclusively permits the ‘admin’ username; other users will be unable to log in via this setting, regardless of whether those users possess administrative rights.
User login via this SA
The ‘User login via this SA’ setting allows users other than the ‘admin’ user to log into the management interface.
Access Requirements Summary
The following logic determines which settings must be enabled based on the required user access:
To permit only the 'admin' user to log in: Enable 'management via this SA'.To permit non-admin users with administrative rights (for example, a user named 'Spock') to log in: Enable both 'management via this SA' and 'User login via this SA'.
This content is (c) Falcon IT Services, 2026 and may not be scraped without explicit written permission. Ha! Who am I kidding?
