TECHNOLOGIES: SONICWALL

SonicWall Penetration Testing

A SonicWall firewall only protects what its admin roles, zones and VPN settings actually allow through. We test that configuration, from remote access to firmware state. CREST-certified testers, fixed price from £2,460 for a 2-day single-device scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
SonicWall Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Zones

SonicOS groups every interface into a security zone such as LAN, WAN, DMZ or WLAN, and the access rules between those zones decide what can reach what, not the appliance itself.

Why SonicWall risk sits in zones and access, not the appliance

SonicOS assigns every interface to a security zone, and SonicWall’s own documentation sets out the default zones as LAN, WAN, MGMT, DMZ, VPN, SSLVPN, MULTICAST and WLAN, each with its own security type. A dedicated MGMT zone exists for appliance management, but SonicOS also allows interfaces in other zones to be enabled for management, so we test exactly which interfaces the management GUI actually answers on.

Administrator access is controlled through local groups rather than a single admin account: SonicWall’s documentation describes a SonicWall Administrators group alongside a Read-Only Admins group, with administration rights that can be layered so a user’s effective access shows as full, limited or read-only. We test whether every administrator actually holds the narrowest of those roles their job needs, and whether two-factor authentication, which SonicOS supports through a TOTP one-time password method on the Device Administration page, is switched on for every one of them.

Remote access runs through two separate clients: the SSL VPN NetExtender client for browser-initiated access, and the Global VPN Client for IPsec connections that SonicWall’s own documentation describes as virtually identical to a traditional IPsec VPN client. Both routes are gated by VPN Access lists that decide which network resources a signed-in user can actually reach, so we test those lists rather than assume the group name tells the whole story. Where remote access sits behind the same appliance, our dedicated VPN penetration testing covers the client and server sides in more depth.

SCOPE

What we pen test on a SonicWall deployment

SW-01

Management Zone and Interface Access

SonicOS assigns appliance management to a dedicated MGMT zone, but SonicWall’s own documentation confirms interfaces in other zones can also be enabled for management. We test exactly which interfaces and zones the management GUI actually answers on, not just the ones the design intended.

SW-02

Administrator Accounts and Local Group Roles

Administrator access runs through local groups such as SonicWall Administrators and Read-Only Admins, and a user’s effective rights can be layered to show as full, limited or read-only. We test whether every administrator actually holds the narrowest role their job needs, not the one that was easiest to assign.

SW-03

Two-Factor Authentication on Administrator Login

SonicOS supports a TOTP one-time password method for administrator login, configured on the Device Administration page and paired with an authenticator app. We confirm it is actually enforced for every administrator account, not just the one used to set it up.

SW-04

Security Zones and Inter-Zone Access Rules

SonicOS groups interfaces into zones such as LAN, WAN, DMZ, VPN and WLAN, and the access rules between them decide what can reach what. We test those inter-zone rules for exceptions that have outgrown the design they were written for.

SW-05

SSL VPN Remote Access (NetExtender)

NetExtender gives remote users SSL VPN access to the internal network, and only accounts placed in the SSLVPN Services group with a matching VPN Access list can use it. We test who that access list actually opens the network to.

SW-06

Global VPN Client IPsec Access

The Global VPN Client provides IPsec remote access that SonicWall’s own documentation describes as virtually identical to a traditional IPsec VPN client, reaching the internal network once authenticated. We test how that access is authenticated and what VPN Access list each user is actually held to.

SW-07

Application Control and Content Filtering Policy

App Control and the Content Filtering Service are licensed features configured through global policies that block or log by category, application, signature or website, scoped to users, groups or IP ranges. We test whether those policies actually match the access your team intended, not just the categories switched on by default.

SW-08

Capture ATP Cloud Sandboxing

Capture ATP sends files over an encrypted connection to SonicWall’s cloud service for analysis before a verdict is returned to the firewall, and it depends on an active licence being enabled. We confirm it is actually licensed and enabled on the interfaces and file types your policy assumes it covers.

SW-09

High Availability Active/Standby Configuration

An Active/Standby HA pair fails over from the Primary to the Secondary appliance when the Primary loses connectivity, and configuration changes are pushed to the Standby unit through incremental or complete synchronisation. We test whether the Standby unit’s configuration and access controls actually match the Primary’s once failover happens.

SW-10

SonicOS Firmware and Support Status

SonicWall’s own product lifecycle guidance recommends running the latest available firmware and supports the latest General Release plus the two latest Feature or Maintenance Releases. We record the SonicOS version actually running against that guidance during scoping, purely as a configuration-hygiene check.

OUR PROCESS

SonicWall Penetration Testing: From Scope to Attestation

01

Scope and Access

We agree the SonicWall model, SonicOS version, and which admin accounts, VPN clients and security services are in scope before testing starts.

02

Configuration and Zone Mapping

We map zone assignments, inter-zone access rules, administrator group roles and VPN Access lists across NetExtender and the Global VPN Client.

03

Hands-On Testing

A CREST-certified tester manually tests management interface exposure, administrator role boundaries, remote access permissions and security service policy configuration.

04

Report and Retest

You receive a technical report with CVSS-scored findings, a walkthrough call, a free retest once fixes are in place, and an attestation letter.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST SonicWall pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent SonicWall Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,460–£3,620
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£5,780–£8,810
4 to 6 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From SonicWall Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our SonicWall deployment?

A read-only administrator account is usually enough for the zone, rule and role review, plus a separate low-privilege account if NetExtender or Global VPN Client access is in scope. We agree the exact accounts and permissions with you before testing starts.

Will testing touch our live traffic or take the appliance down?

We review the configuration, zones, roles and VPN settings directly rather than flooding the appliance with traffic. Any higher-risk checks, such as repeated authentication attempts against SSL VPN or the Global VPN Client, are scheduled for a testing window you control.

How long does a SonicWall test take?

A single appliance sits in our 2-day single-device scope, with a report typically landing around 5 working days after kickoff. An HA pair, multiple appliances or additional security services in scope moves into a wider scope with more testing days.

Do you test physical appliances and virtual SonicWall deployments the same way?

The zone, role and VPN access checks are largely the same whether your SonicWall runs as a physical TZ, NSa or NSsp appliance or as a virtual instance on VMware, Azure or AWS. We agree the exact access method, whether that is a VPN into your management network or access to a cloud console, during scoping.

Do you test a High Availability pair or just one appliance?

Our single-device scope covers one SonicWall appliance and its configuration. Where two appliances form an Active/Standby HA pair, we scope both, since a difference between the Primary and Standby configuration can go unnoticed until a failover happens.

What is out of scope for a single-device SonicWall test?

The servers and applications sitting behind the SonicWall are out of scope for this test and covered by our web application penetration testing or internal network penetration testing instead. Testing SonicWall’s own firmware code, rather than how your team configured it, is also out of scope.

Does SonicWall have a customer penetration-testing policy we need to follow?

SonicWall publishes a vulnerability reporting process for security researchers, which is separate from a customer testing their own SonicWall appliance. We confirm SonicWall’s current terms for your specific licence and support agreement during scoping rather than assume none apply.

Are your testers CREST certified?

Yes. Every test is delivered by CREST-certified, UK-based testers, and EJN Labs holds CREST Approved Provider status.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your SonicWall test

A SonicWall firewall only protects what its admin roles, zones and VPN settings actually allow through. We test that configuration, from remote access to firmware state. CREST-certified testers, fixed price from £2,460 for a 2-day single-device scope, quoted within 24 hours.