Free delivery

McAfee SECURE sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams

Dynamic search > >
UK Sales: 0330 1340 230
• SonicWall Specialist
• Expert Advice
• Free next working day delivery if ordered before 4.00pm (Mon-Fri)*
• Live Stock Feed
• Secure Ordering
• Established 2006
SonicWall NSA 5650 Secure Upgrade Plus - Advanced Edition (3 Years)

SonicWall NSA 5650 Secure Upgrade Plus - Advanced Edition (3 Years)

  1. Firewall inspection throughput: 6.25 Gbps,
  2. Threat prevention throughput: 3.4 Gbps,
  3. Interfaces: 2 x 10-GbE SFP+, 2 x 10-GbE, 4 x 2.5-GbE SFP, 4 x 2.5-GbE, 16 x 1-GbE,
  4. Max. SSL VPN Clients: 1,500



(£23,877.60 inc VAT)
Out of stock

The SonicWall Network Security appliance (NSa) series provides mid-sized networks, branch offices and distributed enterprises with advanced threat prevention in a high-performance security platform. Combining next-generation firewall technology with our patentpending Real-Time Deep Memory Inspection (RTDMI) and patented Reassembly-Free Deep Packet Inspection (RFDPI) engines on a multi-core architecture, the NSa series offers the security, performance and control organizations require.

  • Superior threat prevention
  • High-performance architecture
  • Network control and flexibility
  • 802.11ac Wave 2 wireless
  • Broad mobility support
  • High port density

All NSa Models: NSa 2650 / NSa 3650 / NSa 5650 / NSa 5650

*** This product is a promotional upgrade - for customers upgrading from earlier SonicWall firewalls, or from competitive products

Firewall Product Features

2 x 10-GbE SFP+, 2 x 10-GbE, 4 x 2.5-GbE SFP, 4 x 2.5-GbE, 16 x 1-GbE
1.45 Gbps
6.25 Gbps
3.4 Gbps
800 Mbps
3.5 Gbps
4,000,000 (1,500,000 with DPI / 37,000 with DPI SSL)
2,000 (6,000)
2 (1,500)
3-Year Subscription Included
3-Year Subscription Included
3-Year Subscription Included
3-Year Subscription Included
3-Year Subscription Included
3-Year Subscription Included
30-Day FREE Trial

Warranty & Support

3-Yr hardware/3-Yr support, firmware updates
24x7 Support
Hardware overview NSa 5650
Operating system SonicOS 6.x
Security processing cores 10
Interfaces 2 x 10-GbE SFP+, 2 x 10-GbE, 4 x 2.5-GbE SFP, 4 x 2.5-GbE, 16 x 1-GbE, 1 GbE Management, 1 Console
Expansion 1 Expasion Slot (Rear) *
Built-in storage
64 GB
Management CLI, SSH, Web UI, Capture Security Center, GMS, REST APIs
Single Sign On (SSO) Users 70,000
Access points supported (max) 192
Logging Analyzer, Local Log, Syslog, IPFIX, NetFlow
Firewall/VPN performance
Firewall inspection throughput1 6.25 Gbps
Threat Prevention throughput2 (Max Security) 3.4 Gbps
Application inspection throughput2 4.25 Gbps
IPS throughput2 3.4 Gbps
Anti-malware inspection throughput2 2.8 Gbps
IMIX throughput3 1.45 Gbps
TLS/SSL inspection and decryption throughput (DPI SSL)2 800 Mbps
VPN throughput2 3.5 Gbps
Connections per second 40,000
Maximum connections (SPI) 4,000,000
Maximum connections (DPI) 1,500,000
Maximum connections (DPI SSL) 37,000
Default connections (DPI/DPI SSL)4 1,000,000/19,000
Site-to-site VPN tunnels 6,000
IPSec VPN clients (maximum) 2,000 (6,000)
SSL VPN licenses (maximum) 2 (1,500)
Encryption/authentication DES, 3DES, AES (128, 192, 256-bit)/MD5, SHA-1, Suite B Cryptography
Key exchange Diffie Hellman Groups 1, 2, 5, 14v
Route-based VPN RIP, OSPF, BGP
IP address assignment Static (DHCP, PPPoE, L2TP and PPTP client), Internal DHCP server, DHCP Relay
NAT modes 1:1, many:1, 1:many, flexible NAT (overlapping IPS), PAT, transparent mode
VLAN interfaces
Routing protocols BGP, OSPF, RIPv1/v2, static routes, policy-based routing
QoS Bandwidth priority, max bandwidth, guaranteed bandwidth, DSCP marking, 802.1p
Authentication LDAP (multiple domains), XAUTH/RADIUS, SSO, Novell, internal user database, Terminal Services, Citrix, Common Access Card (CAC)
VoIP Full H.323-v1-5, SIP
Certifications(in progress)
ICSA Firewall, ICSA Anti-Virus, FIPS 140-2, Common Criteria NDPP (Firewall and IPS), UC APL, USGv6, CsFC
High Availability Active/Passive with State Sync, Active/Active DPI with State Sync, Active/Active Clustering
Power supply Dual, redundant 350W (one included)
Fans Dual, Removable
Input power
100-240 VAC, 50-60 Hz
Maximum power consumption (W) 103.6
MTBF @25ºC in hours 153,243
MTBF @25ºC in years 17.5
Form factor
1U Rack Mountable
Dimensions 16.9 x 16.3 x 1.8 in (43 x 41.5 x 4.5 cm)
Weight 15.2 lb (6.9 kg)
WEEE weight 19.6 lb (8.9 kg)
Shipping weight 24.9 lb (11.3 kg)
Major regulatory FCC Class A, CE (EMC, LVD, RoHS), C-Tick, VCCI Class A, MSIP/KCC Class A, UL, cUL, TUV/GS, CB, Mexico CoC by UL, WEEE , REACH, ANATEL, BSMI
Environment(Operatin/Storage) 32°-105° F (0°-40° C)/-40° to 158° F (-40° to 70° C)
Humidity 10-90% non-condensing

1Testing Methodologies: Maximum performance based on RFC 2544 (for firewall). Actual performance may vary depending on network conditions and activated services.

2Threat Prevention/Gateway AV/Anti-Spyware/IPS throughput measured using industry standard Spirent WebAvalanche HTTP performance test and Ixia test tools. Testing done with multiple flows through multiple port pairs. Threat Prevention throughput measured with Gateway AV, Anti-Spyware, IPS and Application Control enabled. DPI SSL performance measured on HTTPS traffic with IPS enabled.

3VPN throughput measured using UDP traffic at 1280 byte packet size adhering to RFC 2544. All specifications, features and availability are subject to change.

4For every 125,000 DPI connections reduced, the number of available DPI SSL connections increases by 3,000 except for NSa 9250 and above.

5Active/Active Clustering and Active/Active DPI with State Sync require purchase of Expanded License.

*Future use. All specifications, features and availability are subject to change.

Advanced Gateway Security Suite (AGSS)

At a glance

Gateway Anti-Virus, Anti-Spyware and Intrusion Prevention, Application Intelligence and Control Service - CGSS & AGSS

  • Real-time gateway anti-virus engine that scans for viruses, worms, Trojans and other Internet threats in real-time.
  • Dynamic spyware protection blocks the installation of malicious spyware and disrupts existing spyware communications.
  • Powerful intrusion prevention protects against an array of network-based threats such as worms, Trojans and other malicious code.
  • Application intelligence and control provides application classification and policy enforcement.
  • Dynamically updated signature database for continuous threat protection.

Content Filtering Service (CFS) - CGSS & AGSS

  • Comprehensive content filtering provides control of internal access to inappropriate, unproductive and potentially illegal web content.
  • Website ratings cached locally on SonicWall firewalls make response time to frequently visited sites virtually instantaneous.
  • Dynamically updated rating architecture cross-references all requested websites against a database in the cloud containing millions of URLs, IP addresses and domains and then compares each rating to the local policy setting.

24x7 Support - CGSS & AGSS

  • Software and firmware updates and upgrades maintain network security to keep your solution as good as new.
  • Around-the-clock access to chat, telephone, email and web-based support for basic configuration and troubleshooting assistance.
  • Advance Exchange hardware replacement in the event of failure.
  • Annual subscription to SonicWall’s Service Bulletins and access to electronic support tools and moderated discussion groups.

Capture Advanced Threat Protection (Capture ATP) - AGSS

  • Block zero-day attacks before they enter your network.
  • Rapidly deploy remediation signatures to other network security appliances.
  • Establish advanced protection against the changing threat landscape.
  • Analyze a broad range of file types.

No posts found

Product Info

SonicWall NSa 5650 Links

NSa 5650 Live Demo
NSa 5650 General Info
NSa 5650 Getting Started Guide
NSa 5650 Out of Box Setup
NSa 5650 Product Support
NSa 5650 Technical Documentation
NSa 5650 Datasheet

*** All NSa 5650 Subscriptions ***

SonicWall remote access client licences

SonicWall centralised management & reporting