Industry-validated security effectiveness and performance
for mid-sized networks
The SonicWall Network Security
Appliance (NSA) series provides mid-
sized networks, branch ofces and
distributed enterprises with advanced
threat prevention in a high-performance
security platform. Combining next-
generation rewall technology with
our patented* Reassembly-Free Deep
Packet Inspection (RFDPI) engine on a
multi-core architecture, the NSA series
offers the security, performance and
control organizations require.
Superior threat prevention and
performance
NSA series next-generation rewalls
(NGFWs) integrate a series of advanced
security technologies to deliver a
superior level of threat prevention.
Our patented single-pass RFDPI
threat prevention engine examines
every byte of every packet, inspecting
both inbound and outbound trafc
simultaneously. The NSA series
leverages on-box capabilities including
intrusion prevention, anti-malware
and web/URL ltering in addition to
cloud-based services such as CloudAV
and SonicWall Capture multi-engine
sandboxing to block zero-day threats
at the gateway. Unlike other security
products that cannot inspect large les
for hidden threats, NSA rewalls scan
les of any size across all ports and
protocols. The security architecture in
SonicWall NGFWs has been validated
as one of the industry’s best for security
effectiveness by NSS Labs which
awarded SonicWall its “Recommended”
rating for the fourth consecutive year.
Going beyond intrusion prevention,
anti-malware and web ltering,
SonicWall NGFWs provide a further
level of protection by decrypting and
inspecting SSL/TLS encrypted web
trafc for hidden threats in real time.
With the continued growth of encrypted
web trafc, organizations are effectively
blind to an estimated one-third of their
network trafc. This makes SSL/TLS
decryption and inspection a critical
component of any security solution.
When organizations activate deep
packet inspection functions such as
intrusion prevention, anti-virus, antispyware, SSL decryption/inspection
and others on their rewalls network
performance often slows down,
sometimes dramatically. NSA series
rewalls feature a multi-core hardware
architecture that utilizes specialized
security microprocessors. Combined
with our RFDPI engine, this unique
design eliminates the performance
degradation networks experience
with other rewalls.
In today’s security environment it’s not
enough to rely on solely on outside
parties for threat information. That’s why
SonicWall formed its own in-house threat
research team more than 15 years ago.
This dedicated team gathers, analyzes
and vets data from over one million
sensors in its Global Response Intelligent
Defense (GRID) network. SonicWall also
participates in industry collaboration
efforts and engages with threat research
communities to gather and share
samples of attacks and vulnerabilities.
Benets:
Superior threat prevention
and performance
• Patented reassembly-free deep
packet inspection technology
to develop real-time countermeasures
that are automatically deployed to our
customers’ rewalls.
Network control and exibility
At the core of the NSA series is SonicOS,
SonicWall’s feature-rich operating
system. SonicOS provides organizations
with the network control and exibility
they require through application
intelligence and control, real-time
visualization, an intrusion prevention
system (IPS) featuring sophisticated antievasion technology, high-speed virtual
private networking (VPN) and other
robust security features.
Using application intelligence and
control, network administrators can
identify and categorize productive
applications from those that are
unproductive or potentially dangerous,
and control that trafc through powerful
application-level policies on both a peruser and a per-group basis (along with
schedules and exception lists). Businesscritical applications can be prioritized
and allocated more bandwidth
while non-essential applications are
bandwidth-limited. Real-time monitoring
and visualization provides a graphical
representation of applications, users and
bandwidth usage for granular insight
into trafc across the network.
For organizations that require advanced
exibility in their network design,
SonicOS offers the tools to securely
segment the network through the use
of virtual LANs (VLANs) which enable
network administrators to create a virtual
LAN interface that allows for network
separation into one or more logical
groups. Administrators create rules that
determine the level of communication
with devices on other VLANs.
Built into every NSA series rewall is a
wireless access controller that enables
organizations to extend the network
perimeter securely through the use of
wireless technology. Together, SonicWall
rewalls and SonicPoint 802.11ac
wireless access points create a wireless
network security solution that combines
industry-leading next-generation rewall
technology with high-speed wireless for
enterprise-class network security and
performance across the wireless network.
Easy deployment, setup and
ongoing management
Like all SonicWall rewalls, the NSA
series tightly integrates key security,
connectivity and exibility technologies
into a single, comprehensive solution.
This includes SonicPoint wireless
access points and the SonicWall WAN
Acceleration Appliance (WXA) series,
both of which are automatically detected
and provisioned by the managing
NSA rewall. Consolidating multiple
capabilities eliminates the need to
purchase and install point products that
don’t always work well together. This
reduces the effort it takes to deploy the
solution into the network and congure
it, saving both time and money.
Ongoing management and monitoring
of network security are handled centrally
through the rewall or through the
SonicWall Global Management System
(GMS), providing network administrators
with a single pane of glass from which
to manage all aspects of the network.
Together, the simplied deployment
and setup along with the ease of
management enable organizations to
lower their total cost of ownership and
realize a high return on investment.
d
e
t
a
c
i
t
s
n
i
o
i
h
s
p
a
o
v
s
e
-
i
h
t
t
i
n
a
w
S
P
I
N
m
a
l
N
e
x
t
-
g
e
2
Patented
single pass
e
t
w
w
o
r
a
r
e
w
n
e
r
a
t
i
RFDPI
engine
k
-
b
a
i
t
c
h
o
n
h
t
S
S
L
a
n
d
d
e
i
n
c
s
r
p
y
p
e
c
t
i
t
o
i
o
n
n
-
i
t
t
s
n
i
a
d
e
s
o
l
e
r
s
s
a
d
u
e
r
p
t
a
n
o
i
t
n
e
v
Page 3
Network Security Appliance 2600
The SonicWall NSA 2600 is designed to address the
needs of growing small organizations, branch ofces and
school campuses.
Network Security Appliance 3600/4600
The SonicWall NSA 3600/4600 is ideal for branch ofce and
small- to medium-sized corporate environments concerned
about throughput capacity and performance.
Dual
USB ports
Console
8 x 1GbE
ports
1GbE
Expansion
module
management
Dual fansPower
FirewallNSA 2600
Firewall throughput1.9 Gbp s
IPS throughput700 Mbps
Anti-malware throughput400 Mbps
Full DPI throughput300 Mbps
IMIX throughput600 Mbps
Maximum DPI connections125,000
New connections/sec15,000/sec
DescriptionSKU
NSA 2600 rewall only01-SSC-3860
NSA 2600 TotalSecure (1-year)01-SSC-3863
Dual
USB ports
Console
2 x 10GbE
SFP+ por t s
1GbE
management
12 x 1GbE
ports
4 x 1GbE
SFP ports
Expansion bay
for future use
FirewallNSA 3600NSA 4600
Firewall throughput3.4 Gbps6.0 Gbps
IPS throughput1.1 Gb ps2.0 Gbps
Anti-malware throughput600 Mbps1.1 Gb ps
Full DPI throughput500 Mbps800 Mbps
IMIX throughput900 Mbps1.6 Gbps
Maximum DPI connections175,000200,000
New connections/sec20,000/sec40,000/sec
DescriptionSKU
Firewall only01-SSC-385001-SSC-3840
TotalSecure (1-year)01-SSC-385301-SSC-3843
Dual fansPower
3
Page 4
Network Security Appliance 5600
The SonicWall NSA 5600 is ideal for distributed,
branch ofce and corporate environments needing
signicant throughput.
Network Security Appliance 6600
The SonicWall NSA 6600 is ideal for large distributed and
corporate central site environments requiring high throughput
capacity and performance.
Dual
USB ports
Console
2 x 10GbE
SPF+ ports
1GbE
management
12 x 1GbE
ports
4 x 1GbE
SPF ports
Expansion bay
for future usePower
Firewall throughput9.0 Gbps
IPS throughput3.0 Gbps
Anti-malware throughput1.7 Gbps
Full DPI throughput1.6 Gb ps
IMIX throughput2.4 Gbps
Maximum DPI connections375,000
New connections/sec60,000/sec
DescriptionSKU
NSA 5600 rewall only01-SSC-3830
NSA 5600 TotalSecure (1-year)01-SSC-3833
Dual fans
FirewallNSA 5600
Dual
USB ports
Console
4 x 10GbE
SFP+ por t s
1GbE
management
Expansion bay
for future use
Firewall throughput12.0 Gbps
IPS throughput4.5 Gbps
Anti-malware throughput3.0 Gbps
Full DPI throughput3.0 Gbps
IMIX throughput3.5 Gbps
Maximum DPI connections500,000
New connections/sec90,000/sec
DescriptionSKU
NSA 6600 rewall only01-SSC-3820
NSA 6600 TotalSecure (1-year)01-SSC-3823
Dual hot
swappable fansPower
FirewallNSA 6600
8 x 1GbE
ports
4 x 1GbE
SFP ports
4
Page 5
Reassembly-Free Deep Packet
Traffic out
Traffic out
Proxy
Scanning
Packet
disassembly
Packet assembly-based process
SonicWall architectureCompetitive architecture
When proxy
becomes full or
content too large,
files bypass
scanning.
Traffic in
Traffic in
Packet reassembly-free process
Reassembly-free packet
scanning eliminates proxy
and content size limitations.
Inspection time
LessMore
Inspection capacity
MinMax
Inspection time
LessMore
Inspection capacity
MinMax
Inspection engine
The SonicWall Reassembly-Free Deep
Packet Inspection (RFDPI) engine
provides superior threat protection
and application control without
compromising performance. It relies on
streaming trafc payload inspection to
detect threats at Layers 3-7, and takes
network streams through extensive and
repeated normalization and decryption
in order to neutralize advanced evasion
techniques that seek to confuse
detection engines and sneak malicious
code into the network.
Once a packet undergoes the
necessary pre-processing, including
SSL decryption, it is analyzed
against a single, proprietary memory
representation of three signature
databases: intrusion attacks, malware
and applications. The connection state is
then advanced to represent the position
of the stream relative to these databases
until it encounters a state of attack, or
other “match” event, at which point a
pre-set action is taken.
In most cases, the connection is
terminated and proper logging and
notication events are created. However,
the engine can also be congured for
inspection only or, in case of application
detection, to provide Layer 7 bandwidth
management services for the remainder
of the application stream as soon as the
application is identied.
Flexible, customizable deployment
options – NSA series at-a-glance
Every SonicWall NSA appliance utilizes
a breakthrough, multi-core hardware
design and RFDPI for internal and
external network protection without
compromising network performance.
The NSA series NGFWs combine
high-speed intrusion prevention, le
and content inspection, and powerful
application intelligence and control
with an extensive array of advanced
networking and exible conguration
features. The NSA series offers an
affordable platform that is easy to
deploy and manage in a wide variety
of large, branch ofce and distributed
network environments.
5
NSA series as central-site gateway
Internet
InternetInternet
Dual ISP failoverMulti-WAN redundancy
NSA series as in-line NGFW solution
Full L2-L7
signature-based
inspection
application
Internet
awareness
User zoneAdministrativeServers
HA data link
HF link
Stateful high availability
Page 6
Security and protection
The dedicated, in-house SonicWall
Threat Research Team works on
researching and developing counter-
measures to deploy to the rewalls in
the eld for up-to-date protection. The
team leverages more than one million
sensors across the globe for malware
samples, and for telemetry feedback
on the latest threat information,
which in turn is fed into the intrusion
prevention, anti-malware and application
detection capabilities.
which extends the onboard signature
intelligence with over 30 million
signatures. This CloudAV database is
accessed via a proprietary, light-weight
protocol by the rewall to augment
the inspection done on the appliance.
With Geo-IP and botnet ltering
capabilities, SonicWall NGFWs are able
to block trafc from dangerous domains
or entire geographies in order to reduce
the risk prole of the network.
SonicWall NGFW customers benet from
continuously updated threat protection
around the clock, with new updates
taking effect immediately without
reboots or interruptions. The signatures
resident on the appliances are designed
to protect against wide classes of
attacks, covering tens of thousands of
individual threats with a single signature.
In addition to the countermeasures on
the appliance, NSA appliances also have
access to the SonicWall CloudAV Service,
Application intelligence and control
Application intelligence informs
administrators of application trafc
traversing their network, so they can
schedule application controls based on
business priority, throttle unproductive
applications and block potentially
dangerous applications. Real-time
visualization identies trafc anomalies
as they happen, enabling immediate
countermeasures against potential
inbound or outbound attacks or
performance bottlenecks.
Protection
Creation
The SonicWall Global Management
System (GMS®) simplies management
Collection
Classification
of application intelligence and control
using an intuitive, web-based interface.
SonicWall Application Trafc Analytics
provide granular insight into application
trafc, bandwidth utilization and
security threats, as well as powerful
troubleshooting and forensics
capabilities. Additionally, secure Single
Sign-On (SSO) capabilities ease the user
experience, increase productivity and
reduce support calls.
6
Page 7
Features
RFDPI engine
FeatureDescription
Reassembly-Free Deep Packet
Inspection (RFDPI)
Bi-directional inspectionScans for threats in both inbound and outbound traf c simultaneously to ensure that the network is not used to distribute
Stream-based inspectionProxy-less and non-buffering inspection technology provides ultra-low latency per formance for DPI of millions of simultaneous
Highly parallel and scalableThe unique design of the RFDPI engine works with the multi-core architecture to provide high DPI throughput and extremely
Single-pass inspectionA single-pass DPI architecture simultaneously scans for malware, intrusions and application identication, drastically reducing
FeatureDescription
Multi-engine sandboxingThe multi- engine sandbox platform, which includes virtualized sandboxing, full system emulation and hypervisor level analysis
Broad le type and size analysisAnalyzes a broad range of le t ypes including executable programs (PE), DLL, PDFs, MS Ofce documents, archives, JAR, and
Rapid deployment of signaturesWhen a le is identied as malicious, a signature is immediately deployed to rewalls with an ac tive SonicWall Capture subscription
Block until verdictTo prevent potentially malicious les from entering the network, les sent to the cloud for analysis can be held at the gateway
FeatureDescription
Countermeasure-based protection Tightly integrated intrusion prevention system (IPS) leverages signatures and other countermeasures to scan packet payloads
Automatic signature updatesThe SonicWall Threat Research Team continuously researches and deploys updates to an extensive list of IPS countermeasures
Intra-zone IPS protectionBolsters internal security by segmenting the network into multiple security zones with intrusion prevention, preventing threats
Botnet command and control
(CnC) detection and blocking
Protocol abuse/anomaly detection
and prevention
Zero-day protectionProtects the network against zero-day attacks with constant updates against the lates t exploit methods and techniques that
Anti-evasion technologyExtensive stream normalization, decoding and other techniques ensure that threats do not enter the network undetec ted by
This high-performance, proprietary and patented inspection engine per for ms stream-based, bi-directional trafc analysis,
without prox ying or buffering, to uncover intrusion attempt s and malware and to identif y application trafc regardless of por t.
malware and does not become a launch platform for attacks in case an infected machine is brought inside.
network streams without introducing le and stream size limitations, and can be applied on common protocols as well as raw
TCP streams.
high new session establishment rates to deal with trafc spikes in demanding networks.
DPI latency and ensuring that all threat information is correlated in a single architecture.
Capture advanced threat protection
technology, executes suspicious code and analyzes behavior, providing comprehensive visibility into malicious activity.
APK plus multiple operating systems (Windows, Android, Mac OS X) and multi-browser environments.
as well as GRID Gateway Anti-vir us and IPS signature databases plus URL, IP and domain reputation databases within 48 hours.
until a verdict is determined.
Intrusion prevention
for vulnerabilities and exploits, covering a broad spectrum of attacks and vulnerabilities.
that covers more than 50 attack categories. The new updates take effect immediately, without any reboot or service
interruption required.
from propagating across the zone boundaries.
Identies and blocks command and control trafc originating from bots on the local network to IPs and domains that are
identied as propagating malware or are known CnC points.
Identies and blocks attacks that abuse protocols in an attempt to sneak past the IPS.
cover thousands of individual exploits.
utilizing evasion techniques in Layers 2-7.
7
Page 8
Features
Threat prevention
FeatureDescription
Network-based malware protection
CloudAV malware protection
Cloud-based sandboxing
Around-the-clock security updates
SSL decryption and inspection
Bi-directional raw TCP inspection
Extensive protocol support
Enforced Anti-Virus and
Anti-Spyware Client software
*Requires the SonicWall Anti-Virus and Anti-Spyware Client sof tware
FeatureDescription
Application controlControls applications, or individual application features, which are identied by the RFDPI engine against a continuously
Custom application identicationControls custom applications by creating signatures based on specic parameters or pat terns unique to an application in its
Application bandwidth management Granularly allocates and regulates available bandwidth for critical applications or application categories while inhibiting non-
On-box/off-box trafc visualizationIdenties bandwidth utilization and analyzes net work behavior with real-time, on-box application trafc visualization and of f-
Granular controlControls applications, or specic components of an application, based on schedules, user groups, exclusion lists and a range
The SonicWall RFDPI engine scans all inbound, outbound and intra-zone traf c for viruses, Trojans, key loggers and other
malware in les of unlimited length and size across all ports and TCP streams.
A continuously updated database of over 30 million threat signatures resides in the SonicWall cloud servers and is referenced
to augment the capabilities of the onboard signature database, providing RFDPI with extensive coverage of threats.
SonicWall Capture Advance Threat Protection Service uses cloud-based, multi-engine sandboxing, including full system
emulation, vir tualization and hyper visor level techniques, to analyze suspicious les, detec t malicious behavior and block
unknown and zero-day attacks at the gateway.
The SonicWall Threat Research Team analyzes new threats and releases countermeasures 24 hours a day, 7 days a week. New
threat updates are automatically pushed to rewalls in the eld with ac tive security services, and take effect immediately
without reboots or interruptions.
Decr ypts and inspec ts SSL trafc on the y, without proxying, for malware, intrusions and data leakage, and applies
application, URL and content control policies in order to protect against threats hidden in SSL encrypted traf c.
The RFDPI engine is capable of scanning raw TCP streams on any port bi-directionally, preventing at tacks that try to sneak by
outdated security systems that focus on securing a few well-known ports.
Identies common protocols such as HTTP/S, FTP, SMTP, SMBv1/v2 and others, which do not send data in raw TCP, and
decodes payloads for malware inspection, even if they do not run on standard, well-known por ts.
Automatically detect non-compliant endpoint machines and install the Anti-Virus and Anti-Spyware software* machine-bymachine across the network regardless of whether devices are inside the corporate network or outside connected via VPN.
Windows only.
Application intelligence and control
expanding database of over 3600 application signatures, to increase network securit y and enhance network produc tivity.
network communications, in order to gain fur ther control over the network.
essential application trafc.
box application traf c reporting via NetFlow/IPFix.
of actions with full SSO user identication through LDAP/AD/Terminal Services/Citrix integration.
Content ltering
FeatureDescription
Inside/outside content lteringContent Filtering Service enforces acceptable use policies and blocks access to websites containing information or images
Granular controlsBlocks content using the predened categories or any combination of categories. Filtering can be scheduled by time of day,
Dynamic rating architectureAll requested web sites are cross-referenced against a dynamically updated database in the cloud categorizing millions of
Web cachingURL ratings are cached locally on the SonicWall rewall so that the response time for subsequent access to frequently visited
that are objec tionable or unproductive. Content Filtering Client extends policy enforcement to block internet content for
devices located outside the rewall perimeter.
such as during school or business hours, and applied to individual users or groups.
URLs, IP addresses and domains in real time.
sites is only a fraction of a second.
8
Page 9
Features
Enforced anti-virus and anti-spyware
FeatureDescription
Multi-layered protectionA rewall’s gateway anti-virus solution provides the rst layer of defense at the perimeter; however, viruses can still enter
Automated enforcementEnsures every computer accessing the network has the most recent version of anti-virus and anti-spyware signatures
Automated deployment and installationMachine-by-machine deployment and installation of anti-virus and anti-spyware clients is automatic across the network,
Always on, automatic virus protectionFrequent anti-virus and anti-spyware updates are delivered transparently to all desk tops and le servers to improve end-
Spyware protectionPowerful spyware protec tion scans and blocks the installation of a comprehensive array of spyware programs on desktops
FeatureDescription
Stateful packet inspectionAll network traf c is inspected, analyzed and brought into compliance with rewall access policies.
DDoS/DoS attack protectionSYN ood protection provides a defense against DOS attacks using both Layer 3 SYN proxy and Layer 2 SYN blacklisting
Flexible deployment optionsThe NSA series can be deployed in traditional NAT, Layer 2 bridge, wire and network tap modes.
IPv6 supportInternet Protocol version 6 (IPv6) is in its early stages to replace IPv4. With the latest SonicOS 6.2, the hardware will
High availability/clusteringThe NSA series supports Active/Passive (A/P) with state synchronization, Active/Active (A/A) DPI and Active/Active
WAN load balancingLoad-balances multiple WAN interfaces using Round Robin, Spillover or Percentage methods.
Policy-based routingCreates routes based on protocol to direct trafc to a preferred WAN connection with the ability to fail back to a
Advanced quality of service (QoS)Guarantees critical communications with 802.1p, DSCP tagging, and remapping of VoIP trafc on the network.
H.323 gatekeeper and SIP proxy support Blocks spam calls by requiring that all incoming calls are authorized and authenticated by H.323 gatekeeper or SIP proxy.
FeatureDescription
Global Management SystemSonicWall GMS monitors, congures and reports on multiple SonicWall appliances through a single management console
Powerful single device managementAn intuitive web-based inter face allows quick and convenient conguration, in addition to a comprehensive command-line
Application ow reportingExport s application trafc analytics and usage data for real-time and historical monitoring and reporting with tools such as
FeatureDescription
IPSec VPN for site-to-site connectivityHigh-performance IPSec VPN allows the NSA series to act as a VPN concentrator for thousands of other large sites, branch
SSL VPN or IPSec client remote access Utilizes clientless SSL VPN technology or an easy-to-manage IPSec client for easy access to email, les, computers,
Redundant VPN gatewayWhen using multiple WANs, a primary and secondary VPN can be congured to allow seamless, automatic failover and
Route-based VPNThe ability to perform dynamic routing over VPN links ensures continuous uptime in the event of a temporary VPN tunnel
FeatureDescription
User activity trackingUser identication and activit y are made available through seamless AD/LDAP/Citrix1/Terminal Services1 SSO integration
GeoIP countr y trafc identicationIdenties and controls network trafc going to or coming from specic countries to either protect against attacks from
Regular expression DPI lteringPrevents data leakage by identifying and controlling content crossing the network through regular expression matching.
the net work through laptops, thumb drives and other unprotected systems. Utilizes a layered approach to anti-virus and
anti-spyware protec tion to extend to both client and server.
installed and active, eliminating the costs commonly associated with desktop anti-virus and anti-spyware management.
minimizing administrative overhead.
user productivity and reduce security management.
and laptops before they can transmit condential data, providing greater desktop security and performance.
Firewall and networking
technologies. Additionally, it protects against DOS/DDoS through UDP/ICMP ood protec tion and connection rate limiting.
support ltering and wire mode implementations.
clustering high availability modes. Active/Active DPI ofoads the deep packet inspection load to cores on the passive
appliance to boost throughput.
secondary WAN in the event of an outage.
Management and reporting
with an intuitive interface, reducing management costs and complexity.
inter face and suppor t for SNMPv2/3.
SonicWall GMS or Analyzer.
Virtual private networking (VPN)
ofces or home ofces.
intranet sites and applications from a variety of platforms.
failback of all VPN sessions.
failure, by seamlessly re-routing trafc between endpoints through alternate routes.
Content/context awareness
combined with extensive information obtained through DPI.
known or suspected origins of threat activity, or to investigate suspicious trafc originating from the network.
9
Page 10
SonicOS feature summary
Firewall
• Reassembly-Free Deep
Packet Inspection
• Deep packet inspection for SSL
• Stateful packet inspection
• Stealth mode
• Common Access Card (CAC) support
• DOS attack protection
• UDP/ICMP/SYN ood protection
• SSL decryption and inspection
• IPv6 security
Intrusion prevention
• Signature-based scanning
• Automatic signature updates
• Bidirectional inspection engine
• Granular IPS rule capability
• GeoIP and reputation-based ltering
• Regular expression matching
Anti-malware
• Stream-based malware scanning
• Gateway anti-virus
• Gateway anti-spyware
• Bi-directional inspection
• No le size limitation
• Cloud malware database
Application control
• Application control
• Application component blocking
• Application bandwidth management
• Custom application signature creation
• Data leakage prevention
• Application reporting over
NetFlow/IPFIX
• User activity tracking (SSO)
• Comprehensive application
signature database
Web content ltering
• URL ltering
• Anti-proxy technology
• Keyword blocking
• Bandwidth manage CFS
rating categories
• Unied policy model with app control
• 56 content ltering categories
• Content Filtering Client
VPN
• IPSec VPN for site-to-site connectivity
• SSL VPN and IPSec client remote access
• Redundant VPN gateway
• Mobile Connect for iOS, Mac OS
X, Windows, Chrome, Android and
Kindle Fire
• Route-based VPN (OSPF, RIP)
Networking
• Jumbo frames
• Layer-2 network discover y
• IPv6
• Path MTU discovery
• Enhanced logging
• VLAN trunking
• RSTP (Rapid Spanning Tree Protocol)
• Port mirroring
• Layer-2 QoS
• Port security
• Dynamic routing
• SonicPoint wireless controller
• Policy-based routing
• Advanced NAT
• DHCP server
• Bandwidth management
• Link aggregation
• Port redundancy
• A/P high availability with state sync
• A/A clustering
• Inbound/outbound load balancing
• L2 bridge, wire mode, tap mode,
NAT mode
VoIP
• Granular QoS control
• Bandwidth management
• DPI for VoIP trafc
• H.323 gatekeeper and SIP proxy support
Management and monitoring
• Web GUI
• Command line interface (CLI)
• SNMPv2/v3
• Centralized management and reporting
• Logging
• Netow/IPFix exporting
• App trafc visualization
• Centralized policy management
• Single Sign-On (SSO)
• Terminal service/Citrix support
• BlueCoat Security Analytics Platform
• Application and bandwidth visualization
• IPv4 and IPv6 Management
IPv6
• IPv6 ltering
• 6rd (rapid deployment)
• DHCP prex delegation
• Wire mode
• BGP
Capt u r e ATP
• Cloud-based multi-engine analysis
• Vir tualized sandboxing
• Hypervisor level analysis
• Full system emulation
• Broad le type examination
• Automated and manual submission
• Real-time threat intelligence updates
• Auto-block capability
10
Page 11
NSA series system specications
Operating systemSonicOS 6.2.2
Security processing cores4 x 800 MHz6 x 80 0 MHz8 x 1.1 GHz10 x 1.3 GHz24 x 1.0 GHz10 GbE interfaces—2 x 10-GbE SFP+4 x 10-GbE SFP+
Connections per second15,000/sec20,000/sec40,000/sec60,000/sec90,000/sec
Maximum connections (SPI)225,000325,000400,000562,500750,000
Maximum connections (DPI)125,000175,000200,000375,000500,000
SonicPoints supported (Maximum)32486496128
Single Sign-on (SSO) Users30,00040,00050,00060,00070,000
VPNNSA 2600 NSA 3600NSA 4600NSA 5600NSA 6600
Site-to-site tunnels2501,0003,0004,0006,000
IPSec VPN clients (Maximum)10 (250)50 (1,000)500 (3,000)2,000 (4,000)2,000 (6,000)
SSL VPN licenses (Maximum)2 (250)2 (350)2 (500)2 (1000)2 (1500)
Encryption/AuthenticationDES, 3DES, AES (128, 192, 256-bit)/MD5, SHA-1, Suite B Cryptography
Key exchangeDife Hellman Groups 1, 2, 5, 14
Route-based VPNR I P, OS P F
Environment32-105 F, 0-40 deg C
Humidity10-90% non-condensing
MTBF (Years)20.216.816.015.413. 3
1
Testing Methodologies: Maximum performance based on RFC 2544 (for rewall). Actual per formance may vary depending on network conditions and ac tivated ser vices.
2
Full DPI/GatewayAV/Anti-Spyware/IPS throughput measured using industry standard Spirent WebAvalanche HTTP performance test and Ixia test tools. Testing done
with multiple ows through multiple port pairs.
3
VPN throughput measured using UDP trafc at 1280 byte packet size adhering to RFC 2544. All specications, features and availability are subject to change.
*Future use.
NSA 2600 NSA 3600NSA 4600NSA 5600NSA 6600
4 x 1-GbE SFP,
12 x 1 GbE
1.9 Gbp s3.4 Gbps6.0 Gbps9.0 Gbps12.0 Gbps
300 Mbps500 Mbps800 Mbps1.6 Gbps3.0 Gbps
700 Mbps1.1 G bps2.0 Gbps3.0 Gbps4.5 Gbps
700 Mbps1.1 G bps2.0 Gbps3.0 Gbps4.5 Gbps
400 Mbps 600 Mbps1.1 G b ps1.7 Gbps3.0 Gbps
600 Mbps900 Mbps1.6 G bps2.4 Gbps3.5 Gbps
200 Mbps300 Mbps500 Mbps 800 Mbps1.3 Gbps
1.1 Gb ps1.5 G bps3.0 Gbps4.5 Gbps5.0 Gbps
XAUTH/RADIUS, Ac tive Directory, SSO, LDAP, Novell, internal user database, Terminal Ser vices, Citrix,
Common Access Card (CAC)
1.75 x 10.25 x 17 in
(4.5 x 26 x 43 cm)
1.75 x 19.1 x 17 in
(4.5 x 48.5 x 43 cm)
FCC Class A, CE (EMC, LVD, RoHS), C-Tick, VCCI Class A, MSIP/KCC Class A, UL, cUL, TUV/GS, CB,
SonicWall GMS 10 Node Software License01-SSC-3363
SonicWall GMS E-Class 24x7 Software Support for 10 node (1-year)01-SSC - 6 514
*Please consult with your local SonicWall reseller for a complete list of supported SFP and SFP+ modules
Regulatory model numbers:
NSA 2600–1RK29-0A9
NSA 3600 –1RK26-0A2
NSA 4600–1RK26-0A3
NSA 5600 –1RK26-0A4
NSA 660 0 –1RK 27-0A5
About Us
Over a 25 year history, SonicWall has been the industry’s trusted security partner. From network security to access security to email
security, SonicWall has continuously evolved its product portfolio, enabling organizations to innovate, accelerate and grow. With
over a million security devices in almost 200 countries and territories worldwide, SonicWall enables its customers to condently
say yes to the future.
SonicWall, Inc.
5455 Great America Parkway | Santa Clara, CA 95054
Refer to our website for additional information.
www.sonicwall.com