SonicWall
Prepare SonicWall devices for QUARK Config Backup.
This guide covers SonicWall firewalls (TZ, NSa, NSsp, and NSv) running SonicOS.
Create a dedicated backup account
Create a local user named netwatch-backup in the firewall's local users and groups settings — on SonicOS 7 under Device > Users > Local Users & Groups, on SonicOS 6.5 under MANAGE > System Setup > Users > Local Users & Groups. Add the user to the SonicWall Read-Only Admins group so it can view the configuration without change rights. If the read-only level cannot produce the complete configuration on your firmware release, move the account to the full administrators group instead; QUARK still performs read operations only.
Enable SSH access
SSH management is enabled per interface. Edit the interface the QUARK collector will connect through (Network > System > Interfaces on SonicOS 7) and enable SSH under the interface's management options. Then restrict the built-in management access rule for that zone so SSH management is only permitted from the collector's IP address.
Platform notes
- SonicOS allows only one administrator in configuration mode at a time. A read-only account never requests configuration mode, so scheduled backups will not preempt an administrator who is making changes — one more reason to prefer the read-only group.
- There is no separate enable password; the CLI privilege follows the account's group membership.
Enable backup in Netwatch
Once the device is prepared, open its host in Netwatch (Data collection > Hosts) and add the Config Backup macros — the supported status flag, the model code for this platform, and the credentials you created. See Getting started for the full macro list and values.