Exceptional security and stellar performance at a disruptively low TCO
The SonicWall TZ series of Unied Threat
Management (UTM) rewalls is ideally
suited for any organization that requires
enterprise-grade network protection.
SonicWall TZ series rewalls provide
broad protection with advanced
security services consisting of onbox and cloud-based anti-malware,
anti-spyware, application control,
intrusion prevention system (IPS), and
URL ltering. To counter the trend of
encrypted attacks, the TZ series has the
processing power to inspect encrypted
SSL/TLS connections against the latest
threats. Combined with Dell X-Series
switches, selected TZ series rewalls can
directly manage the security of these
additional ports.
Backed by the SonicWall Capture
Threat Network, the SonicWall TZ
series delivers continuous updates to
maintain a strong network defense
against cybercriminals. The SonicWall
TZ series is able to scan every byte of
every packet on all ports and protocols
with almost zero latency and no le
size limitations.
The SonicWall TZ series features Gigabit
Ethernet ports, optional integrated
802.11ac wireless*, IPSec and SSL VPN,
failover through integrated 3G/4G
support, load balancing and network
segmentation. The SonicWall TZ series
UTM rewalls also provide fast, secure
mobile access over Apple iOS, Google
Android, Amazon Kindle, Windows,
Mac OS X and Linux platforms.
The SonicWall Global Management
System (GMS) enables centralized
deployment and management of
SonicWall TZ series rewalls from a
single system.
Managed security for
distributed environments
Schools, retail shops, remote sites,
branch ofces and distributed
enterprises need a solution that
integrates with their corporate
rewall. SonicWall TZ series rewalls
share the same code base—and
same protection—as our agship
SuperMassive next-generation rewalls.
This simplies remote site management,
as every administrator sees the same
user interface (UI). GMS enables
network administrators to congure,
monitor and manage remote SonicWall
rewalls through a single pane of
glass. By adding high-speed, secure
wireless, the SonicWall TZ series extends
the protection perimeter to include
customers and guests frequenting the
retail site or remote ofce.
Benets:
• Enterprise grade network
protection
• Deep packet inspection of all trafc
without restrictions on le size or
protocol
• Secure 802.11ac wireless
connectivity using integrated
wireless controller or via
external SonicPoint wireless access
points
• SSL VPN mobile access for Apple
iOS, Google Android, Amazon
Kindle, Windows, Mac OS and
Linux devices
• Over 100 additional por ts can
be securely managed by the
TZ console when deployed in
combination with Dell X-Series
switches
* 802.11ac currently not available on SOHO models; SOHO models support 802.11a/b/g/n
Page 2
SonicWall TZ600 series
For emerging enterprises, retail and branch ofces looking for security performance at a value price, the SonicWall TZ600 nextgeneration rewall secures networks with enterprise-class features and uncompromising performance.
SpecicationTZ600 series
Firewall throughput1.5 Gbps
Full DPI throughput500 Mbps
Anti-malware throughput500 Mbps
IPS throughput1.1 Gbps
IMIX throughput900 Mbps
Max DPI connections125,000
New connections/sec12,000
Power LED Test LED
USB port
(3G/4G WAN
failover)
Link and
activity
indicator LEDs
Expansion
module
Console
port
8x1-GbE
switch
(congurable)
X0 LAN port
X1 WAN port
SonicWall TZ500 series
For growing branch ofces and SMBs, the SonicWall TZ500 series delivers highly effective, no-compromise protection with
network productivity and optional integrated 802.11ac dual-band wireless.
SpecicationTZ500 series
Firewall throughput1.4 Gbps
Full DPI throughput400 Mbps
Anti-malware throughput400 Mbps
IPS throughput1.0 Gbps
IMIX throughput700 Mbps
Max DPI connections100,000
New connections/sec8,000
Optional
802 .11ac
wireless
Secure
power
Power LEDTest LED6x1-GbE
USB port
(3G/4G WAN
failover)
Link and
activity
indicator LEDs
Console
port
switch
(congurable)
X0 LAN port
X1 WAN port
Secure
power
2
Page 3
SonicWall TZ400 series
For small business, retail and branch ofce locations, the SonicWall TZ400 series delivers enterprise-grade protection. Flexible
wireless deployment is available with optional 802.11ac dual-band wireless integrated into the rewall.
SpecicationTZ400 series
Firewall throughput1.3 Gbps
Full DPI throughput300 Mbps
Anti-malware throughput300 Mbps
IPS throughput900 Mbps
IMIX throughput500 Mbps
Max DPI connections90,000
New connections/sec6,000
Optional
802 .11ac
wireless
Power LED Test LED5x1-GbE switch
USB port
(3G/4G WAN
failover)
Link and
activity
indicator
Console
port
(congurable)
X0 LAN port
X1 WAN port
Secure
power
LEDs
SonicWall TZ300 series
The SonicWall TZ300 series offers an all-in-one solution that protects networks from attack. Unlike consumer grade products, the
SonicWall TZ300 series rewall combines effective intrusion prevention, anti-malware and content/URL ltering with optional
802.11ac integrated wireless and broadest secure mobile platforms support for laptops, smartphones and tablets.
SpecicationTZ300 series
Firewall throughput750 Mbps
Full DPI throughput100 Mbps
Anti-malware throughput100 Mbps
IPS throughput300 Mbps
IMIX throughput200 Mbps
Max DPI connections50,000
New connections/sec5,000
Optional
802 .11ac
wireless
Power LED Test LED
USB port
(3G/4G WAN
failover)
Link and
activity
indicator LEDs
Console
port
3x1-GbE switch
(congurable)
X0 LAN port
X1 WAN port
Secure
power
3
Page 4
SonicWall SOHO series
For wired and wireless small and home ofce environments, the SonicWall SOHO series delivers the same business-class protection
large organizations require at a more affordable price point.
SpecicationSOHO series
Firewall throughput300 Mbps
Full DPI throughput50 Mbps
Anti-malware throughput50 Mbps
IPS throughput100 Mbps
IMIX throughput60 Mbps
Max DPI connections10,000
New connections/sec1,8 00
Optional
802 .11n
wireless
Power LED Test LED
Link and
activity
indicator LEDs
USB port
(3G/4G WAN
failover)
Extensible architecture for extreme scalability
and performance
The Reassembly-Free Deep Packet Inspection (RFDPI) engine
is designed from the ground up with an emphasis on providing
security scanning at a high performance level, to match both
the inherently parallel and ever-growing nature of network
trafc. When combined with multi-core processor systems, this
parallel-centric software architecture scales up perfectly to
NSA or SuperMassive
Corporate
Headquarters
Console
port
3x1-GbE switch
(congurable)
X0 LAN port
X1 WAN port
Secure
power
address the demands of deep packet inspection at high trafc
loads. The SonicWall TZ Series platform relies on processors
that, unlike x86, are optimized for packet, crypto and network
processing while retaining exibility and programmability in
the eld — a weak point for ASICs systems. This exibility is
essential when new code and behavior updates are necessary
to protect against new attacks that require updated and more
sophisticated detection techniques.
SOHO
Home office
Internet
TZ400
Global Management System
TZ600
18 port
X-Series switch
Small
branch office
Large
branch office
4
Page 5
Reassembly-Free Deep Packet Inspection
(RFDPI) engine
The RFDPI engine provides superior threat protection and
application control without compromising performance. This
patented engine inspects the trafc stream to detect threats
at Layers 3-7. The RFDPI engine takes network streams through
extensive and repeated normalization and decryption in
order to neutralize advanced evasion techniques that seek
to confuse detection engines and sneak malicious code
into the network. Once a packet undergoes the necessary
preprocessing, including SSL decryption, it is analyzed against
a single proprietary memory representation of three signature
databases: intrusion attacks, malware and applications. The
connection state is then advanced to represent the position
of the stream relative to these databases until it encounters
a state of attack, or another “match” event, at which point a
pre-set action is taken. As malware is identied, the SonicWall
rewall terminates the connection before any compromise
can be achieved and properly logs the event. However, the
engine can also be congured for inspection only or, in the
case of application detection, to provide Layer 7 bandwidth
management services for the remainder of the application
stream as soon as the application is identied.
Packet assembly-based process
Packet
disassembly
Traffic out
Inspection capacity
MinMax
Traffic in
Inspection time
LessMore
Proxy
Scanning
When proxy
becomes full or
content too large,
files bypass
scanning.
Global management and reporting
For larger, distributed enterprise deployments, the optional
SonicWall Global Management System (GMS) provides
administrators a unied, secure and extensible platform to
manage SonicWall security appliances and Dell X-Series
switches. It enables enterprises to easily consolidate the
management of security appliances, reduce administrative
and troubleshooting complexities and governs all operational
aspects of the security infrastructure including centralized
policy management and enforcement, real-time event
monitoring, analytics and reporting, and more. GMS also meets
the rewall change management requirements of enterprises
through a workow automation feature. GMS provides a
better way to manage network security by business processes
and service levels that dramatically simplify the lifecycle
management of your overall security environments rather than
on a device-by-device basis.
5
Page 6
Security and protection
The dedicated, in-house SonicWall
Capture Labs threat research team
works on researching and developing
countermeasures to deploy to the
rewalls in the eld for up-to-date
protection. The team leverages more
than one million sensors across the
globe for malware samples, and for
telemetry feedback on the latest threat
information, which in turn is fed into
the intrusion prevention, anti-malware
and application detection capabilities.
SonicWall rewall customers with current
subscriptions are provided continuously
updated threat protection around
the clock, with new updates taking
effect immediately without reboots
or interruptions. The signatures on
the appliances protect against wide
classes of attacks, covering up to tens
of thousands of individual threats with
a single signature. In addition to the
countermeasures on the appliance, all
SonicWall rewalls also have access to
SonicWall CloudAV, which extends the
onboard signature intelligence with
more than 20 million signatures, and
growing. This CloudAV database is
accessed via a proprietary light-weight
protocol by the rewall to augment the
inspection done on the appliance. With
Geo-IP and botnet ltering capabilities,
SonicWall next-generation rewalls are
able to block trafc from dangerous
domains or entire geographies in order
to reduce the risk prole of the network.
Corporate
Headquarters
$
Engineering network
Finance network
Internet
NSA or SuperMassive
Global Management System
Sales network
TZ product line
Home office / small office LAN
Internet
18-port X-Series switch
Protected server network
TZ product line
3G/analog failover
Secure wireless zone
Printers
Storage
PoE
cameras
Application intelligence
and control
granular insight into application
trafc, bandwidth utilization and
security threats, as well as powerful
Application intelligence informs
administrators of application trafc
traversing the network, so they can
schedule application controls based on
business priority, throttle unproductive
applications and block potentially
dangerous applications. Real-time
visualization identies trafc anomalies
troubleshooting and forensics
capabilities. Additionally, secure single
sign-on (SSO) capabilities enhance the
user experience, increase productivity
and reduce support calls. Management
of application intelligence and control
is simplied by using an intuitive webbased interface.
as they happen, enabling immediate
countermeasures against potential
inbound or outbound attacks or
performance bottlenecks. SonicWall
application trafc analytics provide
* 802.11ac currently not available on SOHO models; SOHO models support 802.11a/b/g/n
Flexible and secure wireless
Available as an optional feature, highspeed 802.11ac wireless* combines
with SonicWall next-generation
6
rewall technology to create a wireless
network security solution that delivers
comprehensive protection for wired and
wireless networks.
This enterprise-level wireless
performance enables WiFi-ready devices
to connect from greater distances
and use bandwidth-intensive mobile
apps, such as video and voice, in
higher density environments without
experiencing signal degradation.
Page 7
Features
RFDPI engine
FeatureDescription
Reassembly-Free Deep Packet Inspection This high-performance, proprietary and patented inspection engine performs stream based bi-directional trafc
Bi-directional inspection Scans for threats in both inbound and outbound trafc simultaneously to ensure that the network is not used to
Single-pass inspection A single-pass DPI architecture simultaneously scans for malware, intrusions and application identication, drastically
Stream-based inspectionProxy-less and non-buffering inspection technology provides ultra-low latency performance for deep packet
Deep Packet Inspection of Secure Socket Shell
(DPI-SSH)
Capture Advanced Threat Protection
FeatureDescription
Multi-engine sandboxingThe multi-engine sandbox platform, which includes virtualized sandboxing, full system emulation, and hypervisor
Broad le type analysis Supports analysis of a broad range of le types, including executable programs (PE), DLL, PDFs, MS Ofce
Rapid deployment of signaturesWhen a le is identied as malicious, a signature is immediately deployed to rewalls with SonicWall Capture
Block until verdictTo prevent potentially malicious les from entering the network, les sent to the cloud for analysis can be held at the
Encrypted threat prevention
FeatureDescription
TLS/SSL decryption and inspection
SSH inspection
Intrusion prevention
FeatureDescription
Countermeasure-based protection Tightly integrated intrusion prevention system (IPS) leverages signatures and other countermeasures to scan packet
Automatic signature updates The SonicWall Capture Labs threat research team continuously researches and deploys updates to an extensive list of
Intra-zone IPS protection Bolsters internal security by segmenting the network into multiple security zones with intrusion prevention, preventing
Botnet command and control (CnC) detection
and blocking
Protocol abuse/anomalyIdenties and blocks attacks that abuse protocols in an attempt to sneak past the IPS.
Zero-day protection Protects the network against zero-day attacks with constant updates against the latest exploit methods and
Anti-evasion technology Extensive stream normalization, decoding and other techniques ensure that threats do not enter the network
Threat prevention
FeatureDescription
Gateway anti-malware The RFDPI engine scans all inbound, outbound and intra-zone trafc for viruses, Trojans, key loggers and other
CloudAV malware protection A continuously updated database of over 20 million threat signatures resides in the SonicWall cloud servers and is
Around-the-clock security updates New threat updates are automatically pushed to rewalls in the eld with active security services, and take effect
analysis, without proxying or buffering, to uncover intrusion attempts, malware and identify application trafc
regardless of port.
distribute malware, and does not become a launch platform for attacks in case an infected machine is brought inside.
reducing DPI latency and ensuring that all threat information is correlated in a single architecture.
inspection of simultaneous network streams without introducing le and stream size limitations, and can be applied
on common protocols as well as raw TCP streams.
Detects and prevents advanced encrypted attacks that leverage SSH, blocks encrypted malware downloads, ceases
the spread of infections, and thwarts command and control communications and data exltration.
level analysis technology, executes suspicious code and analyzes behavior, providing comprehensive visibility to
malicious activity.
documents, archives, JAR, and APK plus multiple operating systems including Windows, Android, Mac OSX and
multi-browser environments.
subscriptions and Gateway Anti-Virus and IPS signature databases and the URL, IP and domain reputation databases
within 48 hours.
gateway until a verdict is determined.
Decrypts and inspects SSL trafc on the y, without proxying, for malware, intrusions and data leakage, and applies
application, URL and content control policies in order to protect against threats hidden in TLS/SSL encrypted trafc.
Included with security subscriptions for all models except SOHO. Sold as a separate license on SOHO.
Deep packet inspection of SSH (DPI-SSH) decrypts and inspects data traversing over SSH tunnels to prevent attacks
that leverage SSH.
payloads for vulnerabilities and exploits, covering a broad spectrum of attacks and vulnerabilities.
IPS countermeasures that covers more than 50 attack categories. The new updates take immediate effect without any
reboot or service interruption required.
threats from propagating across the zone boundaries.
Identies and blocks command and control trafc originating from bots on the local network to IPs and domains that
are identied as propagating malware or are known CnC points.
techniques that cover thousands of individual exploits.
undetected by utilizing evasion techniques in Layers 2-7.
malware in les of unlimited length and size across all ports and TCP streams.
referenced to augment the capabilities of the onboard signature database, providing RFDPI with extensive coverage
of threats.
immediately without reboots or interruptions.
7
Page 8
Threat prevention con't
FeatureDescription
SSL decryption and inspection Decrypts and inspects SSL trafc on the y, without proxying, for malware, intrusions and data leakage, and applies
Bi-directional raw TCP inspectionThe RFDPI engine is capable of scanning raw TCP streams on any port bi-directionally preventing attacks that they to
Extensive protocol support Identies common protocols such as HTTP/S, FTP, SMTP, SMBv1/v2 and others, which do not send data in raw TCP,
Application intelligence and control
FeatureDescription
Application control Control applications, or individual application features, that are identied by the RFDPI engine against a continuously
Custom application identicationControl custom applications by creating signatures based on specic parameters or patterns unique to an application
Application bandwidth management Granularly allocate and regulate available bandwidth for critical applications or application categories while inhibiting
Granular control Control applications, or specic components of an application, based on schedules, user groups, exclusion lists and a
Content ltering
FeatureDescription
Inside/outside content ltering Enforce acceptable use policies and block access to websites containing information or images that are objectionable
Granular controlsBlock content using the predened categories or any combination of categories. Filtering can be scheduled by time
YouTube for SchoolsEnable teachers to choose from hundreds of thousands of free educational videos from YouTube EDU that are
Web cachingURL ratings are cached locally on the SonicWall rewall so that the response time for subsequent access to frequently
Enforced anti-virus and anti-spyware
FeatureDescription
Multi-layered protectionUtilize the rewall capabilities as the rst layer of defense at the perimeter, coupled with endpoint protection to
Automated enforcement optionEnsure every computer accessing the network has the most recent version of anti-virus and anti-spyware signatures
Automated deployment and installation optionMachine-by-machine deployment and installation of anti-virus and anti-spyware clients is automatic across the
Always on, automatic virus protectionFrequent anti-virus and anti-spyware updates are delivered transparently to all desktops and le servers to improve
Spyware protection
Firewall and networking
FeatureDescription
Stateful packet inspection All network trafc is inspected, analyzed and brought into compliance with rewall access policies.
DDoS/DoS attack protection SYN Flood protection provides a defense against DOS attacks using both Layer 3 SYN proxy and Layer 2 SYN
Flexible deployment options
IPv6 support Internet Protocol version 6 (IPv6) is in its early stages to replace IPv4. With the latest SonicOS, the hardware will
Biometric authentication for remote accessSupports mobile device authentication such as ngerprint recognition that cannot be easily duplicated or shared to
Dell X-Series switch integrationManage security settings of additional ports, including POE and POE+, under a single pane of glass using TZ series
application, URL and content control policies in order to protect against threats hidden in SSL encrypted trafc
Included with security subscriptions for all models except SOHO. Sold as a separate license on SOHO.
sneak by outdated security systems that focus on securing a few well-known ports.
and decodes payloads for malware inspection, even if they do not run on standard, well-known ports.
expanding database of over 3,500 application signatures, to increase network security and enhance network
productivity.
in its network communications, in order to gain further control over the network.
nonessential application trafc.
range of actions with full SSO user identication through LDAP/AD/Terminal Services/Citrix integration.
or unproductive with Content Filtering Service. Extend policy enforcement to block internet content for devices
located outside the rewall perimeter with the Content Filtering Client.
of day, such as during school or business hours, and applied to individual users or groups.
organized by subject and grade and align with common educational standards.
visited sites is only a fraction of a second.
block, viruses entering network through laptops, thumb drives and other unprotected systems.
installed and active, eliminating the costs commonly associated with desktop anti-virus and anti-spyware
management.
network, minimizing administrative overhead.
end user productivity and decrease security management.
Powerful spyware protection scans and blocks the installation of a comprehensive array of spyware programs on
desktops and laptops before they transmit condential data, providing greater desktop security and performance.
blacklisting technologies. Additionally, it provides the ability to protect against DOS/DDoS through UDP/ICMP ood
protection and connection rate limiting.
The SonicWall TZ Series can be deployed in traditional NAT, Layer 2 Bridge, Wire Mode and Network Tap modes.
support ltering implementations.
securely authenticate the user's identity for network access.
dashboard with X-Series switch (not available with the SOHO model)
8
Page 9
Firewall and networking con't
FeatureDescription
High availability SonicWall TZ500 and SonicWall TZ600 models support high availability with Active/Standby with
Threat APIEnables the rewall to receive any and all proprietary, original equipment manufacturer and third-party intelligence
Wireless Network SecurityIEEE 802.11ac wireless technology can deliver up to 1.3 Gbps of wireless throughput with greater range and
Management and reporting
FeatureDescription
Global Management System SonicWall GMS monitors, congures and reports on multiple SonicWall appliances and Dell X-Series switches through
Powerful, single device management An intuitive, web-based interface allows quick and convenient conguration. Also, a comprehensive command line
IPFIX/NetFlow application ow reporting Exports application trafc analytics and usage data through IPFIX or NetFlow protocols for real-time and historical
Virtual Private Networking
FeatureDescription
Auto-provision VPNSimplies and reduces complex distributed rewall deployment down to a trivial effort by automating the initial
IPSec VPN for site-to-site connectivity High-performance IPSec VPN allows the SonicWall TZ Series to act as a VPN concentrator for thousands of other
SSL VPN or IPSec client remote access Utilizes clientless SSL VPN technology or an easy-to-manage IPSec client for easy access to email, les, computers,
Redundant VPN gateway When using multiple WANs, a primary and secondary VPN can be congured to allow seamless automatic failover
Route-based VPN The ability to perform dynamic routing over VPN links ensures continuous uptime in the event of a temporary VPN
Content/context awareness
FeatureDescription
User activity trackingUser identication and activity are made available through seamless AD/LDAP/Citrix1/TerminalServices SSO
GeoIP country trafc identication
Regular expression DPI lteringPrevents data leakage by identifying and controlling content crossing the network through regular
state synchronization. SonicWall TZ300 and SonicWall TZ400 models support high availability without Active/Standby
synchronization. There is no high availability on SonicWall SOHO models.
feeds to combat advanced threats such as zero-day, malicious insider, compromised credentials, ransomware and
advanced persistent threats.
reliability. Available on SonicWall TZ600 through SonicWall TZ300 models. Optional 802.11 a/b/g/n is available on
SonicWall SOHO models.
a single management console with an intuitive interface to reduce management costs and complexity.
interface and support for SNMPv2/3.
monitoring and reporting with tools such as SonicWall GMSFlow Server or other tools that support IPFIX and NetFlow
with extensions.
site-to-site VPN gateway provisioning between SonicWall rewalls while security and connectivity occurs instantly and
automatically.
large sites, branch ofces or home ofces.
intranet sites and applications from a variety of platforms.
and failback of all VPN sessions.
tunnel failure, by seamlessly re-routing trafc between endpoints through alternate routes.
integration combined with extensive information obtained through DPI.
Identies and controls network trafc going to or coming from specic countries to either protect against attacks from
known or suspected origins of threat activity, or to investigate suspicious trafc originating from the network.
expression matching.
9
Page 10
SonicOS feature summary
Firewall
• Stateful packet inspection
• Reassembly-Free Deep Packet
Inspection
• DDoS attack protection
(UDP/ICMP/SY N ood)
• IPv4/IPv6 support
• Biometric authentication for remote
access
• DNS proxy
• Threat API
SSL/SSH decryption and inspection
1
• Deep packet inspection for TLS/SSL/SSH
• Inclusion/exclusion of objects, groups or
hostnames
• SSL control
Capture Advanced Threat Protection
1
• Cloud-based multi-engine analysis
• Virtualized sandboxing
• Hyper visor level analysis
• Full system emulation
• Broad le type examination
• Automated & manual submission
• Real-time threat intelligence updates
• Auto-Block capability
Intrusion prevention
1
• Signature-based scanning
• Automatic signature updates
• Bidirectional inspection
• Granular IPS rule capability
• GeoIP/Botnet ltering
2
• Regular expression matching
Anti-malware
1
• Stream-based malware scanning
• Gateway anti-virus
• Gateway anti-spyware
• Bi-directional inspection
• No le size limitation
• Cloud malware database
Application identication
1
• Application control
• Application visualization
2
• Application component blocking
• Application bandwidth management
• Custom application signature creation
• Data leakage prevention
• Application reporting over NetFlow/
IPFIX
• User activity tracking (SSO)
• Comprehensive application signature
database
Web content ltering
1
• URL ltering
• Anti-proxy technology
• Keyword blocking
• Bandwidth manage CFS rating
categories
• Unied policy model with app control
• Content Filtering Client
VPN
• Auto-provision VPN
• IPSec VPN for site-to-site connectivity
• SSL VPN and IPSec client remote access
• Redundant VPN gateway
• Mobile Connect for iOS, Mac OS X,
Windows, Chrome, Android and
Kindle Fire
• Route-based VPN (OSPF, RIP, BGP)
Networking
• PortShield
• Enhanced logging
• Layer-2 QoS
• Port security
• Dynamic routing (RIP/OSPF/BGP)
• SonicWall wireless controller
• Policy-based routing
(ToS/metric and ECMP)
• Asymmetric routing
• DHCP ser ver
• NAT
• Bandwidth management
• High availability - Active/Standby with
state sync
3
• Inbound/outbound load balancing
• L2 bridge mode, NAT mode
• 3G/4G WAN failover
• Common Access Card (CAC) support
VoIP
• Granular QoS control
• Bandwidth management
• DPI for VoIP trafc
• H.323 gatekeeper and SIP proxy support
Management and monitoring
• Web GUI
• Command line interface (CLI)
• SNMPv2/v3
• Centralized management and reporting
with SonicWall GMS
• Logging
• Netow/IPFix exporting
• Cloud-based conguration backup
• Application and bandwidth visualization
• IPv4 and IPv6 management
• Dell X-Series switch management
including cascaded switches
Integrated Wireless
• Dual-band (2.4 GHz and 5.0 GHz)
• 802.11 a/b/g/n/ac wireless standards
• Wireless intrusion detection and
prevention
• Wireless guest services
• Lightweight hotspot messaging
• Virtual access point segmentation
• Captive portal
• Cloud ACL
2
1
Requires added subscription
2
Not available on SOHO series
3
State sync high availability only on SonicWall TZ50 0 and SonicWall TZ60 0 models
Frequency Division Multiplexing (OFDM); 802.11ac: Orthogonal
Frequency Division Multiplexing (OFDM)
EAP-PEAP, EAP-TTLS
2.472 GHz, 5.180-5.825 GHz
36-48, Spain 36-48/52-64
system administrator
585, 650, 780, 866.7 Mbps per channel
-
-
-
-
-
-
*Future u se.
1
Testing Methodologies: Maximum performance based on RFC 2544 (for rewall). Actual performance may var y depending on network conditions and activated services.
2
Full DPI/GatewayAV/Anti-Spyware/IPS throughput measured using industry standard Spirent WebAvalanche HTTP per formance test and Ixia test tools. Testing done with
multiple ows through multiple port pairs.
3
VPN throughput measured using UDP trafc at 1280 byte packet size adhering to RFC 2544. All specications, features and availability are subjec t to change.
4
BGP is available only on SonicWall TZ40 0, TZ500 and TZ600.
5
All TZ integrated wireless models can support either 2.4GHz or 5GHz band. For dual-band support, please use SonicWall's wireless access points products (SonicPoints)
SonicWall TZ Series ordering information
ProductSKU
SonicWall SOHO with 1-year TotalSecure01-SSC-0651
SonicWall SOHO Wireless-N with 1-year TotalSecure01-SSC-0653
SonicWall TZ300 with 1-year TotalSecure01-SSC-0581
SonicWall TZ300 Wireless-AC with 1-year TotalSecure01-SSC-0583
SonicWall TZ400 with 1-year TotalSecure01-SSC-0514
SonicWall TZ400 Wireless-AC with 1-year TotalSecure01-SSC-0516
SonicWall TZ500 with 1-year TotalSecure01-SSC-0445
SonicWall TZ500 Wireless-AC with 1-year TotalSecure01-SSC-0446
SonicWall TZ600 with 1-year TotalSecure01-SSC-0219
High availability options (each unit must be the same model)
SonicWall TZ500 High Availability01-SSC-0439
SonicWall TZ600 High Availability01-SSC-0220
13
Page 14
SonicWall TZ Series ordering information con't
ServicesSKU
For SonicWall SOHO Series
Comprehensive Gateway Security Suite 1-year01-SSC-0688
Gateway Anti-Virus, Intrusion Prevention and Application Control 1-year01-SSC-0670
Content Filtering Service 1-year01-SSC-0676
Comprehensive Anti-Spam Service 1-year01-SSC-0682
24x7 Support 1-year01-SSC-0700
For SonicWall TZ300 Series
Advanced Gateway Security Suite – Capture ATP, Threat Prevention,
Content Filtering and 24x7 Support for TZ300 (1-year)
Capture Advanced Threat Protection for TZ300 (1-year)01-SSC-1435
Gateway Anti-Virus, Intrusion Prevention and Application Control 1-year01-SSC-0602
Content Filtering Service 1-year01-SSC-0608
Comprehensive Anti-Spam Service 1-year01-SSC-0632
24x7 Support 1-year01-SSC-0620
For SonicWall TZ400 Series
Advanced Gateway Security Suite – Capture ATP, Threat Prevention,
Content Filtering and 24x7 Support for TZ400 (1-year)
Capture Advanced Threat Protection for TZ400 (1-year)01-SSC-1445
Gateway Anti-Virus, Intrusion Prevention and Application Control 1-year01-SSC-0534
Content Filtering Service 1-year01-SSC-0540
Comprehensive Anti-Spam Service 1-year01-SSC-0561
24x7 Support 1-year01-SSC-0552
For SonicWall TZ500 Series
Advanced Gateway Security Suite – Capture ATP, Threat Prevention,
Content Filtering and 24x7 Support for TZ500 (1-year)
Capture Advanced Threat Protection for TZ500 (1-year)01-SSC-1455
Gateway Anti-Virus, Intrusion Prevention and Application Control 1-year01-SSC-0458
Content Filtering Service 1-year01-SSC-0464
Comprehensive Anti-Spam Service 1-year01-SSC-0482
24x7 Support 1-year01-SSC-0476
For SonicWall TZ600
Advanced Gateway Security Suite – Capture ATP, Threat Prevention,
Content Filtering and 24x7 Support for TZ600 (1-year)
Capture Advanced Threat Protection for TZ600 (1-year)01-SSC-1465
Gateway Anti-Virus, Intrusion Prevention and Application Control 1-year01-SSC-0228
Content Filtering Service 1-year01-SSC-0234
Comprehensive Anti-Spam Service 1-year01-SSC-0252
24x7 Support 1-year01-SSC-0246
01-SSC-1430
01-SSC-1440
01-SSC-1450
01-SSC-1460
About Us
SonicWall has been ghting the cyber-criminal industry for over 25 years, defending small, medium size businesses and enterprises
worldwide. Our combination of products and partners has enabled a real-time cyber defense solution tuned to the specic needs of
the more than 500,000 global businesses in over 150 countries, so you can do more business with less fear.
SonicWall, Inc.
5455 Great America Parkway | Santa Clara, CA 95054
Refer to our website for additional information.