SonicWall Penetration Testing
A SonicWall firewall only protects what its admin roles, zones and VPN settings actually allow through. We test that configuration, from remote access to firmware state. CREST-certified testers, fixed price from £2,460 for a 2-day single-device scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
SonicOS groups every interface into a security zone such as LAN, WAN, DMZ or WLAN, and the access rules between those zones decide what can reach what, not the appliance itself.
Why SonicWall risk sits in zones and access, not the appliance
SonicOS assigns every interface to a security zone, and SonicWall’s own documentation sets out the default zones as LAN, WAN, MGMT, DMZ, VPN, SSLVPN, MULTICAST and WLAN, each with its own security type. A dedicated MGMT zone exists for appliance management, but SonicOS also allows interfaces in other zones to be enabled for management, so we test exactly which interfaces the management GUI actually answers on.
Administrator access is controlled through local groups rather than a single admin account: SonicWall’s documentation describes a SonicWall Administrators group alongside a Read-Only Admins group, with administration rights that can be layered so a user’s effective access shows as full, limited or read-only. We test whether every administrator actually holds the narrowest of those roles their job needs, and whether two-factor authentication, which SonicOS supports through a TOTP one-time password method on the Device Administration page, is switched on for every one of them.
Remote access runs through two separate clients: the SSL VPN NetExtender client for browser-initiated access, and the Global VPN Client for IPsec connections that SonicWall’s own documentation describes as virtually identical to a traditional IPsec VPN client. Both routes are gated by VPN Access lists that decide which network resources a signed-in user can actually reach, so we test those lists rather than assume the group name tells the whole story. Where remote access sits behind the same appliance, our dedicated VPN penetration testing covers the client and server sides in more depth.
SCOPE
What we pen test on a SonicWall deployment
Management Zone and Interface Access
SonicOS assigns appliance management to a dedicated MGMT zone, but SonicWall’s own documentation confirms interfaces in other zones can also be enabled for management. We test exactly which interfaces and zones the management GUI actually answers on, not just the ones the design intended.
Administrator Accounts and Local Group Roles
Administrator access runs through local groups such as SonicWall Administrators and Read-Only Admins, and a user’s effective rights can be layered to show as full, limited or read-only. We test whether every administrator actually holds the narrowest role their job needs, not the one that was easiest to assign.
Two-Factor Authentication on Administrator Login
SonicOS supports a TOTP one-time password method for administrator login, configured on the Device Administration page and paired with an authenticator app. We confirm it is actually enforced for every administrator account, not just the one used to set it up.
Security Zones and Inter-Zone Access Rules
SonicOS groups interfaces into zones such as LAN, WAN, DMZ, VPN and WLAN, and the access rules between them decide what can reach what. We test those inter-zone rules for exceptions that have outgrown the design they were written for.
SSL VPN Remote Access (NetExtender)
NetExtender gives remote users SSL VPN access to the internal network, and only accounts placed in the SSLVPN Services group with a matching VPN Access list can use it. We test who that access list actually opens the network to.
Global VPN Client IPsec Access
The Global VPN Client provides IPsec remote access that SonicWall’s own documentation describes as virtually identical to a traditional IPsec VPN client, reaching the internal network once authenticated. We test how that access is authenticated and what VPN Access list each user is actually held to.
Application Control and Content Filtering Policy
App Control and the Content Filtering Service are licensed features configured through global policies that block or log by category, application, signature or website, scoped to users, groups or IP ranges. We test whether those policies actually match the access your team intended, not just the categories switched on by default.
Capture ATP Cloud Sandboxing
Capture ATP sends files over an encrypted connection to SonicWall’s cloud service for analysis before a verdict is returned to the firewall, and it depends on an active licence being enabled. We confirm it is actually licensed and enabled on the interfaces and file types your policy assumes it covers.
High Availability Active/Standby Configuration
An Active/Standby HA pair fails over from the Primary to the Secondary appliance when the Primary loses connectivity, and configuration changes are pushed to the Standby unit through incremental or complete synchronisation. We test whether the Standby unit’s configuration and access controls actually match the Primary’s once failover happens.
SonicOS Firmware and Support Status
SonicWall’s own product lifecycle guidance recommends running the latest available firmware and supports the latest General Release plus the two latest Feature or Maintenance Releases. We record the SonicOS version actually running against that guidance during scoping, purely as a configuration-hygiene check.
OUR PROCESS
SonicWall Penetration Testing: From Scope to Attestation
Scope and Access
We agree the SonicWall model, SonicOS version, and which admin accounts, VPN clients and security services are in scope before testing starts.
Configuration and Zone Mapping
We map zone assignments, inter-zone access rules, administrator group roles and VPN Access lists across NetExtender and the Global VPN Client.
Hands-On Testing
A CREST-certified tester manually tests management interface exposure, administrator role boundaries, remote access permissions and security service policy configuration.
Report and Retest
You receive a technical report with CVSS-scored findings, a walkthrough call, a free retest once fixes are in place, and an attestation letter.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST SonicWall pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent SonicWall Penetration Testing Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 4 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote4 to 6 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test SonicWall For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From SonicWall Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our SonicWall deployment?
A read-only administrator account is usually enough for the zone, rule and role review, plus a separate low-privilege account if NetExtender or Global VPN Client access is in scope. We agree the exact accounts and permissions with you before testing starts.
Will testing touch our live traffic or take the appliance down?
We review the configuration, zones, roles and VPN settings directly rather than flooding the appliance with traffic. Any higher-risk checks, such as repeated authentication attempts against SSL VPN or the Global VPN Client, are scheduled for a testing window you control.
How long does a SonicWall test take?
A single appliance sits in our 2-day single-device scope, with a report typically landing around 5 working days after kickoff. An HA pair, multiple appliances or additional security services in scope moves into a wider scope with more testing days.
Do you test physical appliances and virtual SonicWall deployments the same way?
The zone, role and VPN access checks are largely the same whether your SonicWall runs as a physical TZ, NSa or NSsp appliance or as a virtual instance on VMware, Azure or AWS. We agree the exact access method, whether that is a VPN into your management network or access to a cloud console, during scoping.
Do you test a High Availability pair or just one appliance?
Our single-device scope covers one SonicWall appliance and its configuration. Where two appliances form an Active/Standby HA pair, we scope both, since a difference between the Primary and Standby configuration can go unnoticed until a failover happens.
What is out of scope for a single-device SonicWall test?
The servers and applications sitting behind the SonicWall are out of scope for this test and covered by our web application penetration testing or internal network penetration testing instead. Testing SonicWall’s own firmware code, rather than how your team configured it, is also out of scope.
Does SonicWall have a customer penetration-testing policy we need to follow?
SonicWall publishes a vulnerability reporting process for security researchers, which is separate from a customer testing their own SonicWall appliance. We confirm SonicWall’s current terms for your specific licence and support agreement during scoping rather than assume none apply.
Are your testers CREST certified?
Yes. Every test is delivered by CREST-certified, UK-based testers, and EJN Labs holds CREST Approved Provider status.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your SonicWall test
A SonicWall firewall only protects what its admin roles, zones and VPN settings actually allow through. We test that configuration, from remote access to firmware state. CREST-certified testers, fixed price from £2,460 for a 2-day single-device scope, quoted within 24 hours.



