Troubleshooting

Identify which part of CSE is failing, then go straight to the page that fixes it

  • Last validated: Oct 1, 2026
  • 8 minutes to read

Overview

Most SonicWall Cloud Secure Edge (CSE) problems arrive as one sentence: a user cannot get to something. That sentence does not say which part of the system failed, and CSE has several parts that can fail independently.

This page narrows it down. Work through the three questions below in order, then follow the link for the symptom you end up with. If you already know which component is at fault, go straight to it in the Troubleshooting section of the sidebar.

Question 1. How many people are affected?

This is the fastest way to halve the search, so ask it first.

  • One user, one device. The problem is almost certainly on that device or in that user’s account: the app, its registration, the user’s group membership, or the device’s trust score. Go to Question 2.
  • One user, every device they own. Look at the account rather than the device: group membership, licence, and the policies attached to their role. See Access Policies.
  • Everyone, or everyone at one site. Look at the shared pieces: the Connector or Access Tier serving that resource, a policy change, or a licence or subscription state. Go to Question 3.

Question 2. What exactly fails, and when?

Find the row that matches what you are seeing.

What you see Where to look
The desktop app will not install, register, or sign in Desktop app troubleshooting
The mobile app will not register or connect Mobile app troubleshooting
The tunnel says connected, but the resource is unreachable Service Tunnel troubleshooting
The tunnel drops, or will not restart after dropping Loss of connectivity and trouble restarting
It fails only on hotel, airport, or other restrictive networks Loss of connectivity on a restrictive public network
Pages load slowly or only partly Slow performance or requests timing out
A hostname will not resolve, but the address works Hostname searches not resolving
Domain resolution fails when a SonicOS firewall is the Connector Domain resolution failing on firewall Connector
Trusted network settings are not taking effect Trusted network settings not taking effect
A site is blocked that should not be, or allowed that should not be Internet Traffic troubleshooting
Sites are blocked only in Microsoft Edge Blocked access in Edge with URL filtering
Private domains will not resolve, and the org has SIA only Private domains failing to resolve
Access is refused and you suspect the device, not the user Trust Scoring
You cannot get onto the user’s device to investigate Remote Diagnostics

Two details are worth pinning down before you go further, because they change the answer:

  • Did it ever work? A resource that has never worked points at configuration. A resource that stopped working points at a change: an upgrade, a policy edit, a certificate expiry, or a network change on your side.
  • What changed most recently? If the failure started after an upgrade, check Known Issues before anything else.

Question 3. Is the shared infrastructure healthy?

If the problem is wider than one person, check the components that everyone depends on.

Component Where to look
Access Tier, on the Private Edge deployment model Access Tier troubleshooting
Access Tier health and metrics Status Reporting and Monitoring
Connector installed from the OVA image Monitoring and troubleshooting the OVA Connector
Whether traffic reaches CSE at all Visibility and Logging

Two causes that look like something else

These two account for a large share of cases that get misdiagnosed, so rule them out early.

You are looking in the wrong console. CSE is administered across more than one portal. Licences, admin accounts, and tenant access are managed in MySonicWall or SonicWall Unified Management. Policies, resources, and users are managed in the CSE Command Center. A setting that looks wrong in one console may simply not be owned by it. See MySonicWall.

The licence is not doing what you assume. A user consumes a licence only after they have both been granted one and authenticated into the app. Creating or syncing a user does not, by itself, grant access. See CSE Licenses.

Before you contact support

Collect the logs before you change anything, because some of the evidence disappears once settings change. You do not need the device in front of you, or the user on a call.

Collect the logs yourself, from the Command Center:

  1. Go to Directory > Devices and select the affected device.
  2. Run Remote Diagnostics and download the collected logs.

Collection takes up to 15 minutes, and the device needs CSE desktop app 3.6.0 or later.

If Remote Diagnostics is not available for that device, because it is on an older app version or has not checked in, ask the user to send the logs from the app themselves: Settings > Health Check > Run Diagnostic Tool > Send Log Files to SonicWall CSE Support.

Include the following in the case: the affected username, the device and its operating system version, the CSE app version, the resource being reached, the exact time of a failed attempt, and whether it has ever worked.

Was this page helpful?