Latest News
Latest blogs and updates from SonicWall-Sales.com
SonicWall Re-introduce Essential Protection Security Suite (EPSS)
For some reason (we don't understand) SonicWall have re-introduced the Essential Protection Security Suite (EPSS) bundle to more products. For the first time, Gen 8 models are included as well.
The Advanced Protection Security Suite (APSS) still remains the minimum we recommend as it includes more security, and greater reporting through the SaaS NSM portal.
SonicOS 8 0 Version 8.2.2-8015 Released
SonicOS 8 - Release Notes
These release notes provide information about the SonicWall SonicOS 8 release.
Version Overview
| SonicOS 8.2.x Version |
|---|
Release Description: Version 8.2.2 is a feature release built on top of SonicOS 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.1.0, 8.2.0, and 8.2.1 |
|
Upgrade path: Anyone operating on SonicOS 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.1.0, 8.2.0, and 8.2.1 should upgrade to SonicOS 8.2.2 to take advantage of the new features and fixes.
CAUTION: Downgrading from 8.2.2 to any prior firmware version is not supported. Downgrading could result in the deletion of all LDAP users and a complete reset of all MFA settings. If a downgrade is required, all LDAP users and MFA configurations must be manually reconfigured afterward. A full configuration backup is strongly recommended before upgrading. |
SonicOS 8.2.x Version — Version 8.2.2-8015
Compatibility and Installation Notes
- Most popular browsers are supported, but Google Chrome is preferred for the real-time graphics display on the Dashboard.
- A MySonicWall account is required.
Important
- The TZ80:
- Must be licensed before it can be configured or used.
- Must always be connected to the Internet. It cannot be used in a closed network environment.
- Beginning with SonicOS 8.0.0, these SonicPoint devices are no longer supported:
- SonicPoint-N
- SonicPoint-NDR
- SonicPoint-Ni/Ne
- SonicPoint-ACe/ACi/N2
- Support for the WEP and TKIP security protocols has been deprecated.
- Support for the Radio Role > Mesh Gateway has been deprecated in the TZ wireless models.
- Settings from Gen 7 firewalls running SonicOS 7.3.x can be imported into Gen 8 firewalls operating on SonicOS 8.2.2 version.
- All features introduced in SonicOS 7.3.3 are available in SonicOS 8.2.2.
The platform-specific version for this unified release is the same:
| TZ Series | Firmware Version | NSa Series | Firmware Version | NSv Series | Firmware Version |
|---|---|---|---|---|---|
| TZ80 | 8.2.2-8015 | NSa 2800 | 8.2.2-8015 | NSv XS | 8.2.2-8015 |
| TZ280 | 8.2.2-8015 | NSa 3800 | 8.2.2-8015 | NSv S | 8.2.2-8015 |
| TZ280P | 8.2.2-8015 | NSa 4800 | 8.2.2-8015 | NSv M | 8.2.2-8015 |
| TZ280W | 8.2.2-8015 | NSa 5800 | 8.2.2-8015 | NSv L | 8.2.2-8015 |
| TZ380 | 8.2.2-8015 | NSa 6800 | 8.2.2-8015 | ||
| TZ380W | 8.2.2-8015 | ||||
| TZ480 | 8.2.2-8015 | ||||
| TZ580 | 8.2.2-8015 | ||||
| TZ680 | 8.2.2-8015 |
Deprecation Notice
Support for customizing guest login pages using external web servers with the CGI mechanism has been deprecated. This functionality will no longer be enhanced, and customers are advised to migrate to the supported API-based guest login customization mechanism.
For migration guidance and additional details, refer to the following Knowledge Base article: Deprecation of CGI-Based Guest Login Page Customization.
What's New
- Security Services Enabled by Default — Gateway Anti-Virus, Anti-Spyware, Intrusion Prevention, Botnet Filtering, and Geo-IP Filtering are automatically enabled on SonicOS 8 appliances at the point of registration, without requiring post-deployment configuration.
- Let’s Encrypt Integration — SonicOS 8.2.2 now supports the ACME v2 protocol for automated issuance, renewal, and installation of SSL/TLS certificates directly from the firewall.
- Supports HTTP-01 domain validation.
- Certificates are renewed automatically ahead of expiry.
- Configurable from both the SonicOS management UI and CLI.
- Two-Factor Authentication for GVC — TOTP-based two-factor authentication is now available for Global VPN Client (GVC) connections.
- Indicator of Compromise (IoC) – Hash Detection — Administrators can import MD5, SHA-1, and SHA-256 hash lists from threat intelligence feeds (up to 500,000 entries). Files matching an imported hash are blocked in transit and logged for audit purposes.
- Non-Reversible Password Storage — Stored credentials now use one-way cryptographic hashing (bcrypt) rather than a reversible format. Existing credentials are automatically migrated during the first login after the upgrade, and configuration exports no longer contain recoverable credentials. This feature is not enabled by default.
- SD-WAN Site Support Increase — The maximum number of supported SD-WAN sites per SonicOS 8 appliance has increased, extending single-hub SD-WAN coverage for larger branch deployments.
- SonicOS UI/UX Improvements — This release includes a consolidated set of usability improvements across rule and policy pages, App Control, VPN monitoring, and logging, aligned with updated NSM 4.3 terminology:
- Redesigned change-notification banner, repositioned so it no longer blocks key workflow actions.
- Standardized placement of Add, Edit, Delete, Move, and Clone controls across Access Rules, NAT Rules, Route Rules, DNS Rules, Content Filter Rules, and App Rules.
- Create Another option added for NAT, Route, DNS, Content Filter, and App Rules.
- App Control list now sorts by Category Name, then App Name, then Signature ID, with the selected category persisting across changes.
- VPN tunnel status now updates in real time.
- ACL/NAT live counters no longer force a full grid reload or lose the last-hit timestamp.
- Log entries now link directly to the related App Control, IPS, or Anti-Spyware signature settings.
- LLDP now supports both transmit (Tx) and receive (Rx).
- The Network > System > Interfaces page supports ascending and descending sort, with sub-interfaces sorted within their parent.
- SonicOS 8 NSv Small / Medium / Large — Three new SonicOS 8 NSv virtual firewall sizes are introduced: Small (2 vCPU / 2 GB), Medium (4 vCPU / 8 GB), and Large (8 vCPU / 16 GB), supporting VMware, KVM, Hyper-V, Proxmox, AWS, and Azure. The maximum supported number of groups per NSv instance has increased to 500.
- NSM Enhancements — SonicOS 8.2.2 is a co-release with NSM 4.3, which includes the following firewall-side capabilities:
- Source and destination MAC addresses are now captured for user-based system events, including sessions established via SSL VPN or GVC remote access clients.
- Firewall audit log data can now be delivered to NSM as flow events via a new IPFIX template.
- User Management Enhancements — Guest Wi-Fi now supports a branded captive portal experience with Acceptable Use Policy (AUP) enforcement. RADIUS attribute support has been extended for advanced identity provider and access management integrations.
- Platform Capacity Increases — The following per-platform limits have been increased in this release:
- TZ80: maximum concurrent SSL VPN users increased to 10.
- NSv L Model: maximum supported groups increased to 500.
This release also resolves previously reported issues.
Resolved Issues
| Issue ID | Description |
|---|---|
| GEN8-14363 | Host header injection vulnerability in SonicOS (CVSS 4.3 - Medium). |
| GEN8-15431 | SD-WAN load balancing does not occur when the SLA strategy is set to Lowest Cost with the LB type set to Ratio. |
| GEN8-15723 | Unable to pass traffic over a LAG member when its LAG Agg is disabled on NSa 2800. |
| GEN8-16196 | NSa 3800 intermittently reports false fan failure alerts. |
| GEN8-16283 | The tooltip on the Geo-IP Filter Settings page was too narrow to display its full text. |
| GEN8-16355 | An error pops up when opening an SSH terminal session in the GUI using the Firefox browser. |
| GEN8-16421 | Bandwidth management parameters under access rules display an incorrect value. |
| GEN8-16558 | Sometimes the auto-download of IoC files still occurs even when file auto-download is disabled. |
| GEN8-16603 | SSL VPN UDP packets are dropped on NSa 2800. |
| GEN8-16711 | The GUI displayed IPv6 traffic under the IPv4 traffic view. |
| GEN8-16932 | SSL VPN users are unable to connect when SYN Flood Protection Mode is set to Always Proxy WAN Client Connections on firmware 8.1.0, 8.2.0, and 8.2.1. |
| GEN8-17108 | The firewall drops Cloud Secure Edge (CSE) egress traffic as “Destination IP unreachable” on NSa 4800. |
| GEN8-17115 | After a factory default, navigating to the Access Rules page and downloading a TSR shows “Licensing must be activated for this feature”. |
Known Issues
| Issue ID | Description |
|---|---|
| GEN8-2677 | The user is not logged out from the firewall even after the inactivity time is reached. |
| GEN8-10895 | On NSa 6800, a 40G Twinax connection shows no link when the port is set to auto-negotiation; it works only in 40G force mode with Cisco. |
| GEN8-11359 | NSa 4800 intermittently does not detect SFP modules when 10GBASE-T type SFPs are frequently plugged and unplugged. |
| GEN8-15639 | An NSv firewall drops Cloud Secure Edge (CSE) client traffic after a fresh deployment; traffic works only after a firewall reboot. |
| GEN8-16066 | Hashed passwords break the CLDAP periodic check functionality. |
| GEN8-16864 | Admin/user IP lockout does not work for NSv S/M/L on AWS Pay-As-You-Go with UPE/Policy mode; it works on hardware platforms. |
| GEN8-17572 | On NSa 2800, traffic fails after a reboot or restart when the X0 LAG Aggregator is disabled. |
| GEN8-17959 | The “No space available on device” error appears during firmware upload when ZTv3 debug logging is enabled and set to level 13. |
| GEN8-17990 | When storing user passwords non-reversibly is enabled, a new user's password is stored non-reversibly even when the user's group memberships specify that it should be stored reversibly. |
| GEN8-18136 | TACACS user authentication fails when the user logs in with a domain name for the SSL VPN portal. |
| GEN8-18145 | On the System Monitor Real-Time Charts, Interface Usage data is not displayed consistently. |
| GEN8-18167 | Botnet Filtering is automatically enabled after upgrading from 8.2.1 to 8.2.2, even if it was disabled in 8.2.1. |
| GEN8-18178 | On an NSa 6800 HA pair, saving an SSL VPN-to-LAN access rule on a sub-interface with Allow Management Traffic enabled (Optional Settings > Others) returns an error. |
| GEN8-18187 | The Test Email function for SFR mailing returns an “API not found” error. |
| GEN8-18311 | On an NSv firewall, vMotion cannot be enabled from the diagnostics page. |
| GEN8-18376 | A raw API error appears when performing a global search. |
Additional References
GEN8-16053, GEN8-16192, GEN8-16222, GEN8-16270, GEN8-16281, GEN8-16357, GEN8-16382, GEN8-16406, GEN8-16424, GEN8-16446, GEN8-16605, GEN8-16608, GEN8-16615, GEN8-16625, GEN8-16650, GEN8-16707, GEN8-16865, GEN8-16916, GEN8-16970, GEN8-16997, GEN8-17149, GEN8-17256, GEN8-17493, GEN8-17546, GEN8-17734
6 Reasons to Choose Cloud Secure Edge
Common Use Cases
Like any enterprise business, SMBs are leveraging cloud, mobile, and distributed workforce for performance, cost or competitive advantage. However, this shift also heightens their risk exposure, and cybercriminals are aware of it. Hackers target SMBs due to their limited cybersecurity expertise, resource imitations and budgets, making them vulnerable to attacks. This underscores the need for SMBs to take the first but important step of securing the user access to applications on-and off-cloud
SonicWall Cloud Secure Edge (CSE) is a highly effective and easily adopted security solution, enabling users to access any resource from any device securely. It delivers simple, secure ‘zero trust’ access to private and internet resources for all your employees and 3rd parties, regardless of their location. CSE combines the functionality of multiple traditional network appliances – remote access VPN, web proxy, firewall and more – into a unified cloud solution, improving the security posture and user experience for the entire user base.
CSE can help you secure your users, applications, and business by ensuring the right user is accessing the right application irrespective of their location. Here are the 6 use cases CSE helps you tackle:
1. Protect your Network
CSE’s Cloud VPN (aka VPNaaS) works seamlessly with IaaS and PaaS environments providing one-click access to corporate applications as well as resources like SSH/RDP servers.
You no longer need to purchase, install, configure, and manage VPN software and hardware on each device or location. Instead, you can simply connect to CSE via the internet and enjoy a cost-effective, fast, secure, and reliable Cloud VPN connection.
Capacity can be quickly and easily scaled up or down according to need, without having to purchase or deploy additional hardware or software. Best suited to securely connect remote users or branch offices to your network resources.
2. Protect User and Data from Web and Internet Threats
Do you use applications like Microsoft 365, Zoom, Google Workspace, and even YouTube to get things done? CSE protects users from being phished, straying onto malicious websites, and being exposed to malware attacks.
All needed functionality is built right into the lightweight CSE app. Protection is afforded even if the user hasn’t logged in!
3. Allow Business-only SaaS Applications
Achieve robust, consistent SaaS application security with CSE.
CSE provides visibility into all cloud applications being used as well as their risk level and usage patterns. It further helps in monitoring and reporting compliance with various regulations, making it easier for the institutions to ensure their compliance status.
4. Protect Access based on Roles
CSE provides comprehensive, zero-trust access to on-prem, hybrid, and multi-cloud infrastructure and applications – from anywhere.
Least-privilege access ensures users only have access to the resources they need to do their jobs. CSE Seamlessly integrates with existing Identity Provider (IdP), Endpoint Detection and Response (EDR), and Unified Endpoint Management (UEM) tools.
5. Prevent Device Compromise with Posture Assessment
CSE’s Device Trust ensures end users only access applications, data, and services from known trusted devices.
CSE is a device-based ZTNA solution, meaning it ensures that devices meet the minimum security requirements before being allowed to access corporate resources. This includes ensuring that devices have the latest security updates and patches, that they have anti-virus software installed, and that they are not jailbroken or rooted.
6. Modernize your existing VPN solution
SonicWall customers can leverage CSE Connector integration within their Gen7 fiewealls, enabling Zero Trust Network Access to their private apps hosted behind the firewall. With ZTNA you get a granular security approach, ensuring that user and device trust are repeatedly verified before granting access to specific applications, regardless of location and endpoint type.
CSE can run alongside existing VPN if desired, allowing low-risk incremental deployment by application or user group, retaining safety net of existing legacy services.

Upcoming Price Adjustments - Effective 1st August 2026
SonicWall is adjusting pricing on select SKUs effective August 1, 2026.
We recognize that pricing changes impact your business and your clients, and this decision was not made lightly. Our goal is to continue providing industry‑leading cybersecurity solutions while investing in the technologies, services and support that help drive long-term success for our partners.
To support you through this transition, we are providing a clear planning window ahead of these changes, giving you the time and visibility needed to align internally and with your customers before the updated pricing goes into effect.
Here is what is changing, what is not, and what you can do before the deadline.
What is NOT Changing
- TZ Gen 7 and Gen 8 bare hardware and 1-year bundles
- EPSS term subscriptions (Gen 7)
- MPSS term subscriptions (Gen 7, Gen 8 TZ, Gen 8 NSa)
What IS changing (effective August 1, 2026)
- Gen 8 NSa hardware and bundles: up to 10%
- Multi-year subscription bundles (3&Free, Secure Upgrade): up to 10%
- APSS subscriptions, Gen 7 and Gen 8: up to 10%
- MPSS Monthly Billing (SPP): up to 11%
- Other subscriptions via Monthly Billing (SPP): up to 15%
- NSM Basic and Advanced: up to 15%
- A la carte security subscriptions: up to 20%
- Support subscriptions (24x7, 8x5): up to 20%
Why are Prices Changing
Sustained increases in component, logistics, and cloud delivery costs, combined with continued investment in Gen 8, AI-powered threat intelligence, and unified management.
Your Window
All current quotes are honored through July 31, 2026. If you have renewals or open opportunities, placing them before August 1 locks in current pricing. Multi-year bundles are at the lower end of these adjustments and is worth a conversation with customers if the timing works.
End of Life Announcement: SonicWall Email Security
Overview
SonicWall is initiating the End of Life of the Email Security products – Email Security Software, Email Security Appliances (all physical and virtual models) as well as Hosted Email Security. Key dates for this process are as follows:
- Last Order Day:
April 30, 2026
- End of Sale and Limited Retirement Mode Begin: May 1, 2026
- End of Support:
May 1, 2027
For more information about Product Lifecycle phases, please visit Product Lifecycle.
Frequently Asked
Questions
- Why is SonicWall initiating this process now?
Over the last 3 years, there has been an explosion of growth in the use of cloud-based email services, led by Microsoft Office 365 and Google Workspace. The traditional Security Email Gateway (SEG) technology leveraged by SonicWall Email Security served its purpose for on-premise Email services but has now become obsolete. - Does this mean that SonicWall will no longer offer
Email Security products?
We have an existing partnership with Avanan (now part of Check Point), a market-leading provider of cloud-based Email Security and we will continue to offer their products. However, we will no longer offer email security solutions for on-premise email deployments. - What are the recommendations for current customers of
Email Security?
SonicWall highly recommends migrating to cloud-based email for long-term scalability and resilience. This will require either migrating email infrastructure to a Microsoft 365 deployment running entirely in the cloud or running as a hybrid cloud environment. With either of these deployment options, we offer the Avanan solution for maximum protection. - What happens to Email Security products that have
licenses due to expire after the End of Support date?
After May 1, 2027 (End of Support), customers still running deployments of the Email Security appliances/virtual appliances/software will no longer receive technical support, firmware updates/upgrades, or replacements for the product, and all remaining unique inventory or materials will become unavailable.
The SonicWall Hosted Email Security Service will be shut down on May 2nd 2027 and will no longer process any emails redirected to its servers.
SonicWall is committed to making this transition as smooth as possible – stay tuned for further communications on options to transition away. - What are the recommendations for a customer who wishes
to continue using on-premises email?
We recommend that all customers migrate their email services either entirely to cloud or run a hybrid cloud environment and take advantage of a modern cloud-based email security service. SonicWall will no longer sell email security based on legacy secure email gateways for on-premises only email services.
Managed Protection Security Suite - Leave the firewall configuration to our experts.
Firewalls need active management. With MPSS, our experts handle the management of your Generation 7 or 8 firewall, ensuring you always have the best firewall configuration to defend against cyber threats.
Read more here: /firewalls/managed-protection-security-suite.html
More information:
MPSS Frequently Asked Questions (FAQs)
FIPS 140-3 Validation: The Difference Between Proven and Assumed
By Georgy Thadathil (SonicWall Product Manager)
Overview
Cybersecurity is no longer just about blocking threats; it's about proving security works as intended, especially when auditors, regulators, or customers come asking. FIPS 140-3 validation plays a crucial role in delivering that assurance.
SonicWall's FIPS 140-3 Commitment
SonicWall firewalls incorporate FIPS 140-3-validated cryptographic modules, meeting the stringent security requirements demanded by government, defense, and regulated industry customers.
By achieving FIPS 140-3 validation, SonicWall demonstrates that:
- Cryptography is implemented securely and according to federal standards
- Products meet compliance expectations required for regulated procurement
- Security claims are independently verified, not self-certified
This validation provides enterprises with assurance that SonicWall solutions are built on a strong technical and compliance foundation.
What Enterprises Gain from FIPS 140-3 Validation
1. Independently Verified Cryptographic Security
FIPS 140-3 validation ensures that encryption and authentication mechanisms are:
- Correctly implemented according to cryptographic standards
- Resistant to known weaknesses such as side-channel attacks
- Independently tested by accredited laboratories, not self-certified by vendors
This reduces the risk of hidden implementation flaws that attackers could exploit.
Real-world context: Over the years, security researchers have discovered critical vulnerabilities in products that claimed "military-grade encryption" but had flawed key generation, weak random number generators, or improper memory handling. FIPS 140-3 validation helps prevent these issues from reaching production.
2. Simplified Compliance and Audit Success
Organizations operating under regulations such as:
- Federal government security mandates (FedRAMP, FISMA, DoD)
- Financial compliance frameworks (PCI-DSS, SOX, GLBA)
- Healthcare regulations (HIPAA)
- Critical infrastructure requirements (NERC CIP)
…often require or strongly prefer FIPS 140-3 validated products to pass audits.
Using FIPS 140-3 validated solutions simplifies:
Security audits and compliance reporting
- Vendor risk assessments
- Third-party security questionnaires
- Regulatory documentation requirements
Bottom line: When auditors ask, "How do you know your encryption works?", you can point to an independent government validation.
3. Reduced Operational and Security Risk
Weak or incorrectly implemented cryptography can lead to:
- Data breaches exposing sensitive customer or operational data
- Compliance violations resulting in fines and legal liability
- Loss of customer trust and competitive damage
- Incident response costs and remediation expenses
FIPS 140-3 validation minimizes these risks by enforcing rigorous design, implementation, and testing standards before products reach customers.
4. Future-Proof Security Architecture
Security standards and threats evolve continuously. Products designed with FIPS 140-3 discipline are typically:
- Built with modular, standards-based cryptography that can be upgraded
- Easier to migrate as new algorithms and requirements emerge
- Better positioned for post-quantum cryptography transitions
- Aligned with long-term security roadmaps rather than short-term fixes
Choosing FIPS 140-3 validated products today means fewer disruptive replacements tomorrow.
5. Performance Without Compromise
A common concern is whether FIPS mode impacts performance.
Modern FIPS 140-3 validated implementations:
- Leverage hardware acceleration for cryptographic operations
- Maintain high throughput for VPN, SSL/TLS, and encrypted traffic
- Use optimized algorithms that balance security and speed
With SonicWall firewalls, FIPS mode can be enabled without significant performance degradation, ensuring security doesn't come at the cost of user experience.
Where FIPS 140-3 Matters in Real Deployments
Whether securing:
- Enterprise perimeter networks with next-generation firewalls
- Remote access VPNs for hybrid and distributed workforces
- Cloud workloads with virtual security appliances
- Service provider infrastructure supporting government or regulated customers
- Critical operational technology (OT)in industrial environments
...FIPS 140-3 validated solutions provide confidence that security controls will behave reliably, even under attack, stress, or error conditions.
Deploying SonicWall in FIPS Mode
SonicWall firewalls make FIPS 140-3 compliance straightforward:
- Enable FIPS mode through the management interface
- Configure approved algorithms for VPN and encryption
- Verify operation using built-in diagnostics
- Document configuration for audit and compliance purposes
SonicWall's management tools provide visibility into FIPS status, making it easy to maintain compliance over time.
Security That is Proven
For enterprises, FIPS 140-3 validation means peace of mind. It ensures that the cryptographic security protecting critical data and operations is not just claimed by marketing teams but independently validated by experts.
When the stakes are high and compliance matters, FIPS 140-3 is the difference between "we think we're secure" and "we can prove we're secure."
Resources:
- Verify FIPS validations: Search the NIST CMVP database
- Learn more: Contact your SonicWall representative for FIPS-specific documentation and deployment guides
- Need help? SonicWall support and professional services can assist with FIPS mode configuration and compliance requirements
Key Factors for Firewall Sizing
Throughput Requirements - Firewall vs threat protection
Concurrent Sessions - Max number of simultaneous connections
New Connections Per Second - Speed in establishing new sessions
Number of Users & Devices -Total internal clients, IoT devices, servers and guest devices
Network Architecture & Segmentation - Number of zones, VLANs, DMZs
Security Services Enabled - DPI, IPS, Anti-malware, application control, SSL/TLS Decryption
Redundancy & High Availability - Active/Passive or Active/Active
VPN & Remote Access Needs - Number Of concurrent remote VPN users
Understanding Throughput Metrics
Firewall Throughput - Routing/switching vs real-world security
Threat Prevention Throughput - Includes all major security services
IPS Throughput - Only IPS/IDS engine is active
TLS/SSL Inspection (DPI-SSL) - Most CPU and memory-intensive operation
IPSec VPN Throughput - Measures data transfer capability tor encrypted site-to-site or client VPNs
Sessions and Connections - Firewall Sizing Considerations
Concurrent Sessions
- Total number of active sessions at any given time
- Essential in high user/device density or heavy internal traffic environment
- Need to account for Internal and external connections (e.g.. LAN Internet. LAN LAN)
New Connections Per Second (CPS)
- Number of new sessions pet second
- Important for bursty environments like web servers. application gateways. or VoIP
- Low CPS capacity can create bottlenecks
Session Table Capacity
- Tracks every connection's state — once full. new connections are dropped or delayed
- Need to account for peak usage and expected growth
Session Persistence and Cleanup
- Long-lived sessions (e.g., VPNs, streaming) consume resources longer
- Proper timeout settings and idle session cleanup help optimize resource use
Impact of Security Services
- DPI, AV, SSL Inspection. etc. increase session processing load
- Must handle session state tracking and inspection concurrently
Check numbers multiple times a day to get an average number,
8am, 1 pm, and 3pm are good times to record the connections and connections per second, compare with SonicWall's datasheet.
User & Application Profiles - Impact on Firewall Sizing
| Normal Users |
Power Users Workers |
Guest / BYOD Users |
| Activities: Web browsing, email, SaaS apps like 0365 |
Activities: Zoom, Teams, cloud storage, file transfer |
Activities: Mixed, often unmanaged |
| Estimated Sessions: 50—100 |
Estimated Sessions: 200—500+ | Session Load: Unpredictable |
Sizing Impact:
|
Sizing Impact:
|
Sizing Impact:
|
Application Usage Impact
- Applications using real-time traffic (VoIP, video conferencing) are sensitive to latency and need low-lag inspection
- SaaS-heavy environments generate frequent SSL sessions, requiring DPI-SSL handling capacity
- Legacy apps using non-standard ports/protocols require flexible inspection and exception handling
- Firewalls must accommodate both session quantity and throughput demand per application type
Use Case- Small Business
Deployment Overview
- 30 users
- 1 Gbps bi-directional fibre internet
- Moderate web and VPN usage
- Full security services enabled (except DPI-SSL)
Key Assumptions
- "Basic firewall + antivirus" is a misnomer — all best-practice security services are considered enabled.
- Threat throughput should be used as the base for sizing unless DPI-SSL is implemented.
- VPN adds overhead, similar to attaching a trailer to a car — this impacts performance.
- SSL VPN is still in use (though ideally offloaded to CSE).
Current Option: TZ380
- Threat throughput: 1.5 Gbps
- May be insufficient once VPN overhead is considered.
- Limited headroom for future growth,
Recommended Upgrade: TZ480
- Threat throughput: 2 Gbps
- More powerful CPU for handling VPN load
- Headroom for growth and consistent performance under full inspection load
Use Case - Mid-Size Org
Deployment Overview
- 250 users
- SSL inspection, IPS, cloud applications in use
- Dual internet links:
- 1 Gbps fibre (bi-directional)
- 2 Gbps broadband (200 Mbps upload)
Traffic Calculation
- 1G up + 1G down + 2G down + 0.2G up = 4.2 Gbps Internet Traffic
- Additional intra-zone traffic assumed: 4.0 Gbps
- Total aggregate throughput requirement: —8.2 Gbps
- SSL inspection traffic: 4.2 Gbps
Sizing Recommendation
- Smallest model meeting requirements: NSA 3800
- For 5-year growth projection (I .6x load increase):
- NSA 4800 (100% capacity)
- NSA 5800 (75% capacity)
- Either model could support this use case depending on growth profile
Summary
- Right-sizing of firewalls is critical for:
- Preventing performance bottlenecks and limitations on threat inspection capacity
- Aligning threat protection throughput with security requirements
- Maintaining cost efficiency.
- Key factors for sizing go beyond throughput requirements
- Understand the different throughputs and how they apply to sizing
- The impact of sessions and connections varies with different types of environments
- The type of users and application usage must be considered for sizing
- Plan for user/traffic growth and high availability
SonicWall NSM 3.5 SaaS Released
With NSM 3.5 SaaS, SonicWall integrates credential protection, data security and visibility directly into everyday firewall operations.
Security shouldn't be an afterthought added after deployment, it should be integrated into the platform from the start. The latest NSM 3.5 SaaS release from SonicWall further emphasizes Secure by Design (SbD) philosophy, incorporating protections directly into the management, configuration and monitoring of firewalls.
NSM 3.5 doesn't rely on manual procedures or reactive measures; it automatically minimizes risk by securing credentials, configurations and operational data at scale.
Protecting Against Publicly Known Passwords
Compromised credentials remain among the most common attack vectors. With Credential Auditor now powered by Network Security Manager (NSM), this protection is no longer limited to specific firewall generations.
Credential Auditor automatically detects firewall passwords and keys that match publicly known exposed credentials, such as those found in breached credential databases. By identifying weak or compromised secrets early, NSM enables teams to remediate risk before attackers can exploit it, reinforcing secure configurations across your entire firewall fleet.
This is our Secure by Design principles in action: proactive, automated and built directly into platform operations.
Protecting Configuration Data by Default
Firewall configuration backups are often overlooked as a security risk. NSM 3.5 addresses this head-on with password-protected export backup files and per-tenant encryption.
Each tenant’s configuration backups can now be protected with a password and a unique encryption key, significantly reducing the risk of unauthorized access or misuse. This ensures that sensitive configuration data remains secure at rest and aligns with modern expectations for data protection and isolation in multi-tenant environments.
Turning Logs into Actionable Security Intelligence
Visibility is only valuable when it’s usable. NSM 3.5 enhances analytics logs and system events with advanced search and filtering capabilities, making it easier to surface meaningful security insights when they matter most.
With support for multi-column queries, logical operators, saved searches and custom report queries, security teams can quickly identify anomalies, investigate incidents and support auditing and compliance efforts without needing to export data or rely on external tools.
Improved Visibility into Your Overall Security Posture
The Security Assessment Report, previously only available to SonicWall’s Managed Security Services (MSS) team, is now available to all partners and customers through NSM with an advanced reporting and analytics license.
This report provides a structured view of your environment, highlighting areas for improvement and helping organizations take a more proactive, informed approach to risk reduction.
NSM 3.5 SaaS also supports SonicOS 8.x. Keeping your firewalls up to date and compliant has never been easier.
Why NSM 3.5 Matters
With these updates, NSM 3.5 SaaS not only simplifies management across multiple firewalls and tenants but also strengthens your security posture. From proactive credential auditing to enhanced analytics and secure backup options, NSM continues to empower IT teams and partners to operate confidently in today’s threat landscape.
For optimal results, SonicWall recommends upgrading to the latest firewall hardware to take full advantage of modern security, analytics and management capabilities.
New SonicWall Promotions - 1-YEAR REIGNITE PROMOTION; 2 & FREE PROMOTION; 3 & FREE PLUS FREE HIGH AVAILABILITY (HA) PROMOTION
SonicWall have released some new promotions (for moving to Gen 7 appliances).
1-YEAR REIGNITE PROMOTION:
Legacy SonicWall firewall customers can purchase a 1-year Advanced Protection Security Suite (APSS) subscription and receive a FREE Gen 7 firewall. This offer applies to legacy SonicWall firewalls that are inactive for 90 days or more and requires registration using the legacy SonicWall serial number. Not valid for competitive replacements.
2 & FREE PROMOTION:
Legacy SonicWall firewall customers can purchase a 2-year Advanced Protection Security Suite (APSS) subscription and receive a FREE Gen 7 firewall. This promotion is available for devices with either active or expired services and requires registration using the legacy SonicWall serial number. Not valid for competitive replacements.
3 & FREE PLUS FREE HIGH AVAILABILITY (HA) PROMOTION:
(Gen 7 TZ Only) Want the longest term? Includes two free next-generation firewalls (primary and high availability hardware) with the cost of a three-year APSS subscription. SonicWall Replacement and Competitive Takeout Eligible. Standard Secure Upgrade Matrix applies.
Available through a special pricing request, please contact us for more information.
This promotional offering may not be combined with any other sale, promotion, discount, rebate, coupon, or offering, nor may it be used in conjunction with stock rotations. Standard Deal Registration Eligible.
Datasheet: https://yoursonicwall.com/images/document/21925849...
DNS vs URL Filtering - What’s the Difference and Why it Matters.
Cyberattacks often begin with a single click. That’s why content filtering is more critical than ever in today’s digital landscape. But not all filtering technologies are the same and understanding the difference between DNS and URL filtering can help your organization build a smarter, layered security strategy for web access.
What is DNS Filtering?
DNS filtering works at the Domain Name System (DNS) level.
This is the same system that translates a website (like linkedin.com) into the IP address your device uses to connect.
When DNS filtering is enabled, requests for malicious, risky, or non-compliant domains are blocked before a full connection is established.
Benefits of DNS Filtering:
• Fast and lightweight – stops threats before a page even loads
• Great for remote/hybrid work – protection travels with users
• Broad protection – blocks entire domains known for hosting malware, phishing, or botnets.
Example:
If a user clicks a phishing link to malicious-phish.com, DNS filtering stops it from resolving so no connection or download is made (and no risk).
What is URL Filtering?
URL filtering goes deeper. It analyzes the full web address (URL), including the specific page, folder, or file path, after DNS resolution.
This allows organizations to enforce more granular web access policies and send the entire URL for more in-depth evaluation.
Benefits of URL Filtering:
• Granular control – Send specific pages for further risk-based evaluation (e.g., example.com/sports/basketball)
• Advanced Threat Protection – Stops users from accessing compromised subpages or dangerous downloads on otherwise “safe” domains
Example:
A site like example.com may be generally safe, but example.com/freeware.exe could contain malware. URL filtering catches this.
SonicOS 7.3.1 Released
Version 7.3.1-7013 - This version of SonicOS 7.3.1 is a maintenance release for existing platforms and also resolves issues found in previous releases.
Release notes: 232-006386-00_RevB_SonicOS_7.3.1_ReleaseNotes.pdf
A new feature included in this release is Credential Auditor.
Credential Auditor is a built-in security feature that helps organizations reduce credential-based risks. It validates user passwords against industry-recognized lists of compromised credentials and provides actionable insights for administrators.
Key Capabilities
- Automated Credential Checks: Compares user passwords against known compromised credential databases.
- Risk Identification: Flags accounts with exposed or weak credentials for immediate attention.
- Administrative Actions: Enables administrators to enforce security measures, such as issuing warnings to affected users and requiring password changes.
Key Features:
- Provides proactive protection against leaked credentials, securing both local and externally authenticated accounts.
- Improves password hygiene across the network.
- Reduces the risk of credential-based attacks.
- Simplifies compliance with security best practices
More information: Understanding and Using Credential Auditor on SonicWall Firewalls
