Skip to main content
SonicWall NSM supplies firewall inventory, firmware, reachability, reported update availability, licence and VPN-topology observations. Its SaaS and on-prem authentication paths use different credentials.

Choose the authentication path

Prepare a MySonicWall API key with access to the intended NSM tenants. SonicWall describes generating this key through My Workspace, User Groups and the user list. Follow SonicWall’s MySonicWall API instructions and API guide.Enter the regional NSM endpoint URL and MySonicWall API key. If the key sees several tenants, enter NSM tenant ID using the intended tenant’s productGroupID. A single visible tenant can be discovered automatically. NSM tenant serial can be discovered from its NSM service when omitted.

Field checklist

Connect and verify

  1. Open Integrations, add SonicWall NSM and give it a name that identifies the account or deployment.
  2. Enter the fields for one authentication path and review the connection outcome.
  3. Open Clients & sites, refresh the tenant list and assign each intended source tenant to the correct client. Compare tenant identifiers, not just display names.
  4. Use Sync now and inspect Sync history. Confirm a known firewall appears in the intended client with the expected source and observation time.
  5. Compare the observations with a network baseline before running checks.
For SaaS, discovery may list several tenants, but this connection collects the selected NSM tenant. Configure separate connections for other tenant scopes. Mapping every discovered tenant does not make one tenant-scoped credential collect them all. Checkpoint: the credential reaches the intended NSM service, tenant assignments are correct and one client’s firewall evidence matches its environment.

Recover from a setup problem

An inventory observation does not prove a firewall rule set is safe, and a VPN topology does not establish that access is appropriately restricted. Treat policy quality, recovery and remote-access governance as separate checks. Rotate or replace the connection when its credentials or endpoint change.