Call a Specialist Today! 800-886-4880

SonicWALL SuperMassive E10200 Series Next-Generation Firewall
Delivers Scalability, Reliability and Deep Security at Multi-Gigabit Speeds

SonicWALL SuperMassive E10200 Series Next-Generation Firewall

SonicWALL SuperMassive Series
SuperMassive E10200
SuperMassive E10200, 6 SFP+ 10GbE Ports, 16 SFP 1GbE Ports, Dual Fans, Dual AC Power Supplies
#01-SSC-8882
Please Call for Pricing!

More pricing below, click here!

Extensible architecture for extreme scalability and performance.

The SonicWALL SuperMassive™ E10000 Series is SonicWALL’s Next-Generation Firewall platform designed for large networks to deliver scalability, reliability and deep security at multi-gigabit speeds. Built to meet the needs of enterprise, government, university, and service provider deployments, the SuperMassive E10000 Series is ideal for securing enterprise networks, data centers and server farms. Combining its massively multi-core architecture and SonicWALL’s patented* Reassembly-Free Deep Packet Inspection® (RFDPI) technology, the SuperMassive E10000 Series delivers industry-leading application control, intrusion prevention, malware protection and SSL inspection at multi-gigabit speeds. The SonicWALL E10000 Series is designed with power, space, and cooling (PSC) in mind, providing the leading Gbps/Watt Next-Generation Firewall in the industry for application control and threat prevention.

SonicWALL’s Reassembly-Free Deep Packet Inspection engine scans every byte of every packet delivering full content inspection of the entire stream while providing high performance and low latency. This technology is superior to outdated proxy designs that reassemble content using sockets bolted to anti-malware programs that are plagued with inefficiencies and overhead of socket memory thrashing that leads to high latency, low performance and file size limitations. The RFDPI engine delivers full content inspection to eliminate threats before they enter the network and provides protection against millions of unique malware variants without file size, performance or latency limitations. The RFDPI engine also provides full inspection of SSL-encrypted traffic as well as non-proxyable applications enabling complete protection regardless of transport or protocol.

Application traffic analytics allows for the identification of productive and unproductive application traffic in real time which can then be controlled through powerful application-level policies. Application control can be exercised on both a per-user and per-group basis, along with schedules and exception lists. All application, intrusion prevention, and malware signatures are constantly updated by SonicWALL’s Research Team. Additionally, SonicWALL’s advanced operating system, SonicOS, provides integrated tools that allow for custom application identification and control.

The design provides near-linear performance increases and scales up to 96 cores of processing power to deliver 40+ Gbps of Firewall throughput, 30+ Gbps of Application Inspection, 30+ Gbps of Intrusion Prevention, and 10+ Gbps of Anti-Malware protection. Consisting of the E10200, E10400 and E10800, the SuperMassive E10000 Series is field upgradeable, future-proofing the security infrastructure investment as network bandwidth and security requirements increase.

* U.S. Patents 7,310,815; 7,600,257; 7,738,380; 7,835,361

  • Massively Scalable Multicore Architecture Designed for 10/40 Gbps Infrastructure
  • Superior Granular Application Intelligence, Control and Visualization
  • Complete Threat Protection Including High Performance Intrusion Prevention and Low Latency Malware Protection
  • Full Inspection of SSL Encrypted Traffic Without Overhead, Latency, and Memory Thrashing Associated with Socket Based SSL Proxies

Model Comparison:

The SonicWALL SuperMassive chassis includes 6 x 10-GbE SFP+ and 16 x 1-GbE SFP ports, redundant 850W AC power supplies, hot swappable dual redundant fan modules, and massively scales up to 96 processing cores.

SonicWALL SuperMassive E10000 Series Appliance Views

Models: E10200 E10400 E10800
Capability
Processing Cores 24 48 96
Firewall Inspection Throughput 10 Gbps 20 Gbps 40 Gbps
Application Inspection Throughput 7.5 Gbps 15 Gbps 30 Gbps
IPS Throughput 7.5 Gbps 15 Gbps 30 Gbps
Anti-Malware Inspection Throughput 3.0 Gbps 6.0 Gbps 12 Gbps
Maximum Connections (SPI) 3.0M 6.0M 12.0M
Upgrade Path Upgradeable to the E10400 Upgradeable to the E10800 -

 

Features:

 

Application Intelligence and Control
Feature: Description:
Application Control Identify and control applications or individual components of an application based on RFDPI technology instead of relying on well known ports and protocols.
Application Bandwidth Management Allocate bandwidth to critical applications while throttling unproductive application traffic for an efficient and productive network.
Custom Application Identification Create and configure custom application identification based on traffic parameters or on patterns unique to an application in its network communications.
AppFlow Visualization Advanced visualization along with comprehensive statistics provide administrators with a clear view into exactly what applications and application components are in use on the network and by whom in real time.
Application Signature Database A continuously expanding database of over 3,500 application signatures ensures that administrators are able to control the usage of all the latest applications on their network at a category or individual level.
IPFIX/NetFlow Reporting Export application usage data through IPFIX or through Netflow protocols for third-party monitoring and reporting of network data and application usage data.
Deep Packet Inspection for SSL SSL traffic is decrypted and inspected for malware and intrusions by the Reassembly-Free Deep Packet Inspection engine in addition to applying application, URL, and content control policies on potentially evasive traffic.
User Activity Tracking User identification is seamlessly integrated with Microsoft® Active Directory and other authentication systems enabling tracking and reporting of individual user identification.
GeoIP Country Traffic Identification Identify and control network traffic going to or coming from specific countries.
Gateway Threat Prevention
Feature: Description:
Gateway Anti-Malware SonicWALL's proprietary RFDPI engine scans all ports and protocols for viruses without file size or stream length limitation. SonicLabs Researchers constantly provide updated threat protection, providing faster response times and threat prevention.
Reassembly-Free Deep Packet Inspection (RFDPI) Reassembly-Free Deep Packet Inspection keeps track of malware regardless of the order or the timing with which the packets arrive, allowing for extreme low latency while eliminating file size and stream size limitation, and providing greater performance and security than outdated proxy designs that reassemble content using sockets bolted to traditional anti-virus programs that are plagued with inefficiencies and overhead of socket memory thrashing that leads to high latency, low performance and file size limitations.
Cloud Anti-Virus (AV) In addition to utilizing the on-board database, the RFDPI engine also consults with the SonicWALL Cloud Services for additional information on over four million malware signatures and growing.
Bi-directional Inspection RFDPI can be performed on both inbound and outbound connections to provide protection in all network traffic directions.
24x7 Signature Updates SonicLabs Research Team team creates and updates signature databases that are propagated automatically to the firewalls in the field, with those signatures taking immediate effect without any reboot or service interruption required.
Intrusion Prevention
Feature: Description:
Signature-based Scanning Tightly integrated, signature-based intrusion prevention scans packet payloads for vulnerabilities and exploits that target critical internal systems.
Automatic Signature Updates SonicWALL's Research Team continuously updates and deploys an extensive list of over 5,400 IPS signatures covering 52 attack categories. These signatures take immediate effect and do not require reboots or any other interruption in service.
Outbound Threat Prevention The ability to inspect both inbound and outbound traffic ensures that the network will not unwittingly be used in Distributed Denial of Service attacks and will prevent any Command and Control Botnet communication.
Intra-Zone IPS Protection Intrusion prevention can be deployed between internal security zones to protect sensitive servers and to prevent internal attacks.
VPN
Feature: Description:
IPSec VPN for Site-to-site Connectivity High-performance IPSec VPN allows the SuperMassive E10000 Series to act as a VPN concentrator for thousands of other large sites, branch offices or home offices.
SSL VPN or IPSec Client Remote Access Utilize clientless SSL VPN technology or an easy-to-manage IPSec client for easy access to email, files, computers, intranet sites and applications from a variety of platforms.
Redundant VPN Gateway When using multiple WANs, a primary and secondary VPN can be configured to allow seamless automatic failover and failback of all VPN sessions.
Route-based VPN The ability to perform dynamic routing over VPN links ensures continuous uptime in the event of a temporary VPN tunnel failure by seamlessly re-routing traffic between endpoints through alternate routes.
VoIP
Feature: Description:
Advanced QoS Guarantee critical communications with 802.1p and DSCP tagging and remapping of VoIP traffic on the network.
DPI of VoIP Traffic Predefined signatures detect and block VoIP specific threats.
H.323 Gatekeeper and SIP Proxy Support Block spam calls by requiring that all incoming calls are authorized and authenticated by H.323 gatekeeper or SIP proxy.
Firewall and Networking
Feature: Description:
Stateful Packet Inspection All network traffic is inspected, analyzed and brought into compliance with firewall access policies.
DOS Attack Protection SYN Flood protection provides defense against DOS attacks using both layer 3 SYN proxy and layer 2 SYN blacklisting technologies.
Flexible Deployment Can be deployed in traditional NAT, Layer 2 Bridge, Wire Mode and Network Tap modes.
Policy-based Routing Create routes based on protocol to direct traffic to a preferred WAN connection with the ability to fail back to a secondary WAN in the event of an outage.
High Availability Supports Stateful Active/Passive, Active/Active DPI and Active/Active Clustering failover to ensure not only increased reliability by protecting against hardware or software faults, but also an increase in performance through Reassembly-Free Deep Packet Inspection workload offloading to the cores available on stand-by units.
WAN Load Balancing Load balance up to four WAN interfaces using Round Robin, Spillover or Percentage based methods.
Management and Monitoring
Feature: Description:
Web GUI An intuitive Web-based interface allows quick and convenient configuration in addition to management through SonicWALL Global Management System or the CLI.
SNMP SNMP provides the ability to protectively monitor and respond to threats and alerts.
Netflow/IPFIX Export an extended set of data through IPFIX or through Netflow protocols for third-party monitoring and reporting of network data and application usage data correlated with factors such as user identification and others.
Centralized Policy Management With SonicWALL Global Management System (GMS®), monitor, configure and report on multiple SonicWALL appliances from a single intuitive interface and customize your security environment to suit your individual policies.

 

 

SonicOS Feature Summary:

Firewall:

  • Reassembly-Free Deep Packet Inspection
  • Deep Packet Inspection for SSL
  • Stateful Packet Inspection
  • DOS Attack Protection
  • TCP Reassembly
  • Stealth Mode

Application Control:

  • Application Control
  • Application Component Blocking
  • Application Bandwidth Management
  • Custom Application Signature Creation
  • AppFlow Visualization
  • Data Leakage Prevention
  • IPFIX with Extensions Reporting
  • User Activity Tracking
  • GeoIP Country Traffic Identification
  • Comprehensive Application Signature Database

Intrusion Prevention:

  • Signature-based Scanning
  • Automatic Signature Updates
  • Outbound Threat Prevention
  • IPS Exclusion List
  • Hyperlinked Log Messages
  • Unified CFS and App Control with Bandwidth Throttling

Anti-Malware:

  • Stream-based Malware Scanning
  • Gateway Anti-Virus
  • Gateway Anti-Spyware
  • SSL Decryption
  • Anti-Spam
  • Bi-directional Inspection
  • No File Size Limitation

VPN:

  • IPSec VPN for Site-to-site Connectivity
  • SSL VPN or IPSec Client Remote Access
  • Redundant VPN Gateway
  • Route-based VPN

Web Content Filtering:

  • URL Filtering
  • Anti-proxy Technology
  • Keyword Blocking
  • Bandwidth Manage CFS Rating Categories
  • Unified Policy Model with App Control

VoIP:

  • Advanced QoS
  • Bandwidth Management
  • DPI of VoIP Traffic
  • Full Interoperability
  • H.323 Gatekeeper and SIP Proxy Support

Networking:

  • Dynamic Routing
  • Policy-based Routing
  • Advanced NAT
  • DHCP Server
  • Bandwidth Management
  • IPv6
  • Link Aggregation
  • Port Redundancy
  • High Availability
  • Load Balancing

Management and Monitoring:

  • Web GUI
  • Command Line Interface
  • SNMP
  • ViewPoint Reporting
  • Logging
  • Netflow/IPFIX
  • App Visualization
  • LCD Management Screen
  • Centralized Policy Management
  • Single Sign-On
  • Terminal Service/Citrix Support
  • Solera Networks Forensics Integration

Security Services:

  • Intrusion Prevention Service
  • Gateway Anti-Malware Service
  • Content Filtering Service
  • Enforced Client Anti-Virus and Anti-Spyware Service
  • Application Intelligence, Control and Visualization Service

Technical Specifications:

 

Models: E10200 E10400 E10800
System Specifications:
Operating System SonicOS
Cores 12 (+ 12 HA) 24 48 96
10 GbE Interfaces 6 x 10-GbE SFP+
1 GbE Interfaces 16 x 1-GbE SFP
Management Interfaces 1 GbE, 1 Console
Memory (RAM) 16 GB 32 GB 64 GB
Storage 80 GB SSD, Flash
Firewall Inspection Throughput 10 Gbps 20 Gbps 40 Gbps
Application Inspection Throughput 7.5 Gbps 15 Gbps 30 Gbps
IPS Throughput 7.5 Gbps 15 Gbps 30 Gbps
Anti-Malware Inspection Throughput 3.0 Gbps 6.0 Gbps 12 Gbps
VPN Throughput 5.0 Gbps 10 Gbps 20 Gbps
Connections/sec. 160,000/sec 320,000/sec 640,000/sec
Maximum Connections (SPI) 3.0M 6.0M 12.0M
Maximum Connections (DPI) 1.5M 5.0M 10.0M
VPN:
Site-to-site Tunnels 10,000 (20,000)* 10,000 (40,000)* 10,000 (80,000)*
IPSec VPN Clients 2,000 (4,000)* 2,000 (8,000)* 2,000 (16,000)*
SSL VPN Licenses 50 (2,000)* 50 (4,000)* 50 (80,000)*
Encryption DES, 3DES, AES (128, 192, 256-bit)
Authentication MD5, SHA-1
Key Exchange Diffie Hellman Groups 1, 2, 5, 14
Route-based VPN RIP, OSPF
Networking:
IP Address Assignement Static (DHCP PPPoE, L2TP and PPTP client), Internal DHCP server, DHCP Relay
NAT Modes 1:1, many:1, 1:many, flexible NAT (overlapping IPS), PAT, transparent mode
VLAN Interfaces 512
Routing Protocols BGP*, OSPF, RIPv1/v2, static routes, policy-based routing, multicast
QoS Bandwidth priority, max bandwidth, guaranteed bandwidth, DSCP marking, 802.1p
Authentication XAUTH/RADIUS, Active Directory, SSO, LDAP, Novell, internal user database, terminal services, Citrix
IPv6 IPv6 RFDPI, firewall, VPN, NAT; Dual stack IPv4/IPv6; IPv6 to/from IPv4 translations; ICMPv6; DHCPv6; DNSv6
VoIP Full H323-v1-5, SIP
Standards TCP/IP, ICMP, HTTP, HTTPS, IPSec, ISAKMP/IKE, SNMP, DHCP, PPPoE, L2TP, PPTP, RADIUS, IEEE 802.3
Certifications Pending FIPS 140-2, Common Criteria EAL4+, NEBS, ICSA Firewall
Common Access Card (CAC) Support Pending

Hardware:

Power Supply Dual, Redundant, Hot Swappable, 850 W
Fans Dual, Redundant, Hot Swappable
Display Front LED Display
Input Power 100-240 VAC, 60-50 Hz
Maximum Power Consumption (W) 400 550 750
Form Factor 4U Rack Mountable
Dimensions 17x18x7in (43x43.5x17.8 cm)
Weight 58 lb (26.3 kg) 58 lb (26.3 kg) 58 lb (26.3 kg)
WEEE Weight 58 lb (26.3 kg) 58 lb (26.3 kg) 58 lb (26.3 kg)
Shipping Weight 58 lb (26.3 kg) 58 lb (26.3 kg) 58 lb (26.3 kg)
Major Regulatory FCC Class A, CE, C-Tick, VCCI, Compliance MIC, UL, cUL, TUV/GS, CB, NOM, RoHS, WEEE
Environment 40-105 F, 5-40 deg C
Humidity 10-90% non-condensing
*Available with expanded license.
All specifications, features and availability are subject to change.

Documentation:

Download the SonicWALL SuperMassive E10000 Series Datasheet (.PDF)

Pricing Notes:

SonicWALL SuperMassive Series
SuperMassive E10200
SuperMassive E10200, 6 SFP+ 10GbE Ports, 16 SFP 1GbE Ports, Dual Fans, Dual AC Power Supplies
#01-SSC-8882
Please Call for Pricing!