Call a Specialist Today! 800-886-4880

SonicWALL TZ300 Series
Network Security Firewall

SonicWALL TZ300 Series

Wireless Model Available!

TZ300 Hardware and Bundles
TZ300 Series
TZ300 Base Appliance
#01-SSC-0215
List Price: $645.00
Our Price: $484.00
TotalSecure Bundle
TZ300 TotalSecure
*Includes TZ300 Appliance & 1-Year Comprehensive Gateway Security Suite
#01-SSC-0581
List Price: $965.00
Our Price: $724.00
TZ300 TotalSecure Advanced Edition Appliance Bundle
*Includes TZ300 Appliance with 1 Year AGSS Bundle (Capture ATP, Threat Prevention, Content Filtering, 24x7 Support)
#01-SSC-1705
List Price: $1,214.00
Our Price: $911.00
GEN5 Firewall Replacement Bundle
Receive a discount to replace your existing 5th Generation Firewall. Note: an existing GEN5 firewall must be registered in your current MySonicWALL.com account to qualify for the upfront discount.
TZ300 GEN5 Replacement Bundle with 1 Year AGSS
*Includes TZ300 Appliance with 1 Year AGSS Bundle (Capture ATP, Threat Prevention, Content Filtering, 24x7 Support)
#01-SSC-1355
List Price: $971.00
Our Price: $728.00
Secure Upgrade Plus Program
TZ300 Secure Upgrade Plus with 2 Years CGSS
*Requires Qualifying Trade-up Product. Click here for details.
#01-SSC-0575
List Price: $965.00
Our Price: $724.00
TZ300 Secure Upgrade Plus Advanced Edition with 2 Years AGSS
*Requires Qualifying Trade-up Product. Click here for details.
#01-SSC-1742
List Price: $1,474.00
Our Price: $1,106.00
TZ300 Secure Upgrade Plus with 3 Years CGSS
*Requires Qualifying Trade-up Product. Click here for details.
#01-SSC-0576
List Price: $1,145.00
Our Price: $859.00
TZ300 Secure Upgrade Plus Advanced Edition with 3 Years AGSS
*Requires Qualifying Trade-up Product. Click here for details.
#01-SSC-1743
List Price: $1,668.00
Our Price: $1,251.00

More pricing below, click here!

Overview:

SonicWALL Live Demo Site - Experience SonicWALL for yourself! Click here.

Exceptional security and stellar performance at a disruptively low TCO

The SonicWALL TZ series of next generation firewalls (NGFW) is ideally suited for any organization that requires enterprise-grade network protection.

SonicWALL TZ series firewalls provide broad protection with advanced security services consisting of onbox and cloud-based anti-malware, anti-spyware, application control, intrusion prevention system (IPS), and URL filtering. To counter the trend of encrypted attacks, the SonicWALL TZ series has the processing power to inspect encrypted SSL connections against the latest threats.

Backed by the SonicWALL Global Response Intelligent Defense (GRID) network, the SonicWALL TZ series delivers continuous updates to maintain a strong network defense against cybercriminals. The SonicWALL TZ series is able to scan every byte of every packet on all ports and protocols with almost zero latency and no file size limitations.

The SonicWALL TZ series features Gigabit Ethernet ports, optional integrated 802.11ac wireless*, IPSec and SSL VPN, failover through integrated 3G/4G support, load balancing and network segmentation. The SonicWALL TZ series UTM firewalls also provide fast, secure mobile access over Apple iOS, Google Android, Amazon Kindle, Windows, MacOS and Linux platforms.

The SonicWALL Global Management System (GMS) enables centralized deployment and management of SonicWALL TZ series firewalls from a single system.

Managed security for distributed environments

Schools, retail shops, remote sites, branch offices and distributed enterprises need a solution that integrates with their corporate firewall. SonicWALL TZ series firewalls share the same code base—and same protection—as our flagship SuperMassive next-generation firewalls. This simplifies remote site management, as every administrator sees the same user interface (UI). GMS enables network administrators to configure, monitor and manage remote SonicWALL firewalls through a single pane of glass. By adding highspeed, secure wireless, the SonicWALL TZ series extends the protection perimeter to include customers and guests frequenting the retail site or remote office.

Benefits:

  • Enterprise grade network protection
  • Deep packet inspection of all traffic without restrictions on file size or protocol
  • Secure 802.11ac wireless* connectivity using integrated wireless controller or via external SonicWALL SonicPoint wireless access points
  • SSL VPN mobile access for Apple iOS, Google Android, Amazon Kindle, Windows, Mac OS and Linux devices

* 802.11ac currently not available on SOHO models; SOHO models support 802.11a/b/g/n

Features and Benefits:


SonicWALL TZ Series Features:
RFDPI engine
Feature Description
Reassembly-Free Deep Packet Inspection This high-performance, proprietary and patented inspection engine performs stream based bi-directional traffic analysis, without proxying or buffering, to uncover intrusion attempts, malware and identify application traffic regardless of port.
Bi-directional inspection Scans for threats in both inbound and outbound traffic simultaneously to ensure that the network is not used to distribute malware, and does not become a launch platform for attacks in case an infected machine is brought inside.
Single-pass inspection A single-pass DPI architecture simultaneously scans for malware, intrusions and application identification, drastically reducing DPI latency and ensuring that all threat information is correlated in a single architecture.
Stream-based inspection Proxy-less and non-buffering inspection technology provides ultra-low latency performance for deep packet inspection of simultaneous network streams without introducing file and stream size limitations, and can be applied on common protocols as well as raw TCP streams.
Intrusion prevention
Countermeasure-based protection Tightly integrated intrusion prevention system (IPS) leverages signatures and other countermeasures to scan packet payloads for vulnerabilities and exploits, covering a broad spectrum of attacks and vulnerabilities.
Automatic signature updates The SonicWALL Threat Research Team continuously researches and deploys updates to an extensive list of IPS countermeasures that covers more than 50 attack categories. The new updates take immediate effect without any reboot or service interruption required.
Intra-zone IPS protection Bolsters internal security by segmenting the network into multiple security zones with intrusion prevention, preventing threats from propagating across the zone boundaries.
Botnet command and control (CnC) detection and blocking Identifies and blocks command and control traffic originating from bots on the local network to IPs and domains that are identified as propagating malware or are known CnC points.
Protocol abuse/anomaly Identifies and blocks attacks that abuse protocols in an attempt to sneak past the IPS.
Zero-day protection Protects the network against zero-day attacks with constant updates against the latest exploit methods and techniques that cover thousands of individual exploits.
Anti-evasion technology Extensive stream normalization, decoding and other techniques ensure that threats do not enter the network undetected by utilizing evasion techniques in Layers 2-7.
Threat prevention
Gateway anti-malware The RFDPI engine scans all inbound, outbound and intra-zone traffic for viruses, Trojans, key loggers and other malware in files of unlimited length and size across all ports and TCP streams.
CloudAV malware protection A continuously updated database of over 17 million threat signatures resides in the SonicWALL cloud servers and is referenced to augment the capabilities of the onboard signature database, providing RFDPI with extensive coverage of threats.
Around-the-clock security updates New threat updates are automatically pushed to firewalls in the field with active security services, and take effect immediately without reboots or interruptions.
SSL decryption and inspection Decrypts and inspects SSL traffic on the fly, without proxying, for malware, intrusions and data leakage, and applies application, URL and content control policies in order to protect against threats hidden in SSL encrypted traffic Included with security subscriptions for all models except SOHO. Sold as a separate license on SOHO
Bi-directional raw TCP inspection The RFDPI engine is capable of scanning raw TCP streams on any port bi-directionally preventing attacks that they to sneak by outdated security systems that focus on securing a few well-known ports.
Extensive protocol support Identifies common protocols such as HTTP/S, FTP, SMTP, SMBv1/v2 and others, which do not send data in raw TCP, and decodes payloads for malware inspection, even if they do not run on standard, well-known ports.
Application intelligence and control*
Application control Control applications, or individual application features, that are identified by the RFDPI engine against a continuously expanding database of over 3,500 application signatures, to increase network security and enhance network productivity.
Custom application identification Control custom applications by creating signatures based on specific parameters or patterns unique to an application in its network communications, in order to gain further control over the network.
Application bandwidth management Granularly allocate and regulate available bandwidth for critical applications or application categories while inhibiting nonessential application traffic.
Granular control Control applications, or specific components of an application, based on schedules, user groups, exclusion lists and a range of actions with full SSO user identification through LDAP/AD/Terminal Services/Citrix integration
Content filtering
Inside/outside content filtering Enforce acceptable use policies and block access to websites containing information or images that are objectionable or unproductive with Content Filtering Service. Extend policy enforcement to block internet content for devices located outside the firewall perimeter with the Content Filtering Client.
Granular controls Block content using the predefined categories or any combination of categories. Filtering can be scheduled by time of day, such as during school or business hours, and applied to individual users or groups.
YouTube for Schools Enable teachers to choose from hundreds of thousands of free educational videos from YouTube EDU that are organized by subject and grade and align with common educational standards.
Web caching URL ratings are cached locally on the SonicWALL firewall so that the response time for subsequent access to frequently visited sites is only a fraction of a second.
Enforced anti-virus and anti-spyware
Multi-layered protection Utilize the firewall capabilities as the first layer of defense at the perimeter, coupled with endpoint protection to block, viruses entering network through laptops, thumb drives and other unprotected systems.
Automated enforcement option Ensure every computer accessing the network has the most recent version of anti-virus and anti-spyware signatures installed and active, eliminating the costs commonly associated with desktop anti-virus and antispyware management.
Automated deployment and installation option Machine-by-machine deployment and installation of anti-virus and anti-spyware clients is automatic across the network, minimizing administrative overhead.
Always on, automatic virus protection Frequent anti-virus and anti-spyware updates are delivered transparently to all desktops and file servers to improve end user productivity and decrease security management.
Spyware protection Powerful spyware protection scans and blocks the installation of a comprehensive array of spyware programs on desktops and laptops before they transmit confidential data, providing greater desktop security and performance.
Firewall and networking
Stateful packet inspection All network traffic is inspected, analyzed and brought into compliance with firewall access policies.
DDoS/DoS attack protection SYN Flood protection provides a defense against DOS attacks using both Layer 3 SYN proxy and Layer 2 SYN blacklisting technologies. Additionally, it provides the ability to protect against DOS/DDoS through UDP/ICMP flood protection and connection rate limiting.
Flexible deployment options The SonicWALL TZ Series can be deployed in traditional NAT, Layer 2 Bridge, Wire Mode and Network Tap modes.
IPv6 support Internet Protocol version 6 (IPv6) is in its early stages to replace IPv4. With the latest SonicOS, the hardware will support filtering implementations.
Dell X-Series switch integration Manage security settings of additional ports, including POE and POE+, under a single pane of glass using TZ series dashboard with Dell X series switch (not available with the SOHO model)
High availability SonicWALL TZ500 and SonicWALL TZ600 models support high availability with Active/Standby with state synchronization. SonicWALL TZ300 and SonicWALL TZ400 models support high availability without Active/Standby synchronization. There is no high availability on SonicWALL SOHO models.
Wireless Network Security IEEE 802.11ac wireless technology can deliver up to 1.3 Gbps of wireless throughput with greater range and reliability. Available on SonicWALL TZ600 through SonicWALL TZ300 models. Optional 802.11 a/b/g/n is available on SonicWALL SOHO models.
Management and reporting
Global Management System SonicWALL GMS monitors, configures and reports on multiple SonicWALL appliances and Dell X-Series switches through a single management console with an intuitive interface to reduce management costs and complexity.
Powerful, single device management An intuitive, web-based interface allows quick and convenient configuration. Also, a comprehensive command line interface and support for SNMPv2/3.
IPFIX/NetFlow application flow reporting Exports application traffic analytics and usage data through IPFIX or NetFlow protocols for real-time and historical monitoring and reporting with tools such as SonicWALL Scrutinizer or other tools that support IPFIX and NetFlow with extensions.
Virtual Private Networking
IPSec VPN for site-to-site connectivity High-performance IPSec VPN allows the SonicWALL TZ Series to act as a VPN concentrator for thousands of other large sites, branch offices or home offices.
SSL VPN or IPSec client remote access Utilizes clientless SSL VPN technology or an easy-to-manage IPSec client for easy access to email, files, computers, intranet sites and applications from a variety of platforms.
Redundant VPN gateway When using multiple WANs, a primary and secondary VPN can be configured to allow seamless automatic failover and failback of all VPN sessions.
Route-based VPN The ability to perform dynamic routing over VPN links ensures continuous uptime in the event of a temporary VPN tunnel failure, by seamlessly re-routing traffic between endpoints through alternate routes.
Content./context awareness
User activity tracking User identification and activity are made available through seamless AD/LDAP/Citrix1/TerminalServices SSO integration combined with extensive information obtained through DPI.
GeoIP country traffic identification Identifies and controls network traffic going to or coming from specific countries to either protect against attacks from known or suspected origins of threat activity, or to investigate suspicious traffic originating from the network.
Regular expression DPI filtering Prevents data leakage by identifying and controlling content crossing the network through regular expression matching.
* Application Control only on SOHO

SonicOS Features:

Firewall

  • Reassembly-Free Deep Packet Inspection
  • Deep packet inspection for SSL
  • Stateful packet inspection
  • Stealth mode
  • Common Access Card (CAC) support
  • DOS attack protection
  • UDP/ICMP/SYN flood protection
  • SSL decryption
  • IPv6 Security

Intrusion prevention

  • Signature-based scanning
  • Automatic signature updates
  • Bidirectional inspection engine
  • Granular IPS rule capability
  • GeoIP and reputation-based filtering
  • Regular expression matching

Anti-malware

  • Stream-based malware scanning
  • Gateway anti-virus
  • Gateway anti-spyware
  • Bi-directional inspection
  • No file size limitation
  • Cloud malware database

Application control

  • Application control
  • Application component blocking
  • Application bandwidth management
  • Custom application signature creation
  • Data leakage prevention
  • Application reporting over NetFlow/IPFIX
  • User activity tracking (SSO)
  • Comprehensive application signature database

Web content filtering

  • URL filtering
  • Anti-proxy technology
  • Keyword blocking
  • Bandwidth manage CFS rating categories
  • Unified policy model with app control
  • 55 content filtering categories
  • Content Filtering Service Client

VPN

  • IPSec VPN for site-to-site connectivity
  • SSL VPN and IPSec client remote access
  • Redundant VPN gateway
  • Mobile Connect for iOS and Android™
  • Route-based VPN (OSPF, RIP)

Networking

  • PortShield
  • Layer-2 network discovery
  • IPv6
  • Enhanced logging
  • Port mirroring
  • Layer-2 QoS
  • Port Security
  • Dynamic routing
  • SonicPoint Support (ACe, ACi, N2, NDR, Ne, Ni)
  • Policy-based routing
  • DHCP server
  • Bandwidth management
  • A/P high availability with state sync*
  • Inbound/outbound load balancing
  • L2 bridge, NAT mode DDNS
  • 3G/4G WAN Fail-over

VoIP

  • Granular QoS control
  • Bandwidth management
  • DPI for VoIP traffic
  • H.323 gatekeeper and SIP proxy support

Management and monitoring

  • Web GUI
  • Command line interface (CLI)
  • SNMPv2/v3
  • Off-box reporting (Scrutinizer)
  • Centralized management and reporting
  • Logging
  • Netflow/IPFix exporting
  • App traffic visualization
  • Centralized policy management
  • Single Sign-On (SSO)
  • Terminal service/Citrix support
  • Application and bandwidth visualization
  • IPv4 and IPv6 management

IPv6

  • IPv6 filtering
  • 6rd (rapid deployment)
  • DHCP prefix delegation
  • BGP

Wireless

  • Dual-band (2.4 GHz and 5.0 GHz)
  • 802.11 a/b/g/n/ac** wireless standards
  • Wireless intrusion detection and prevention
  • Wireless guest services
  • Lightweight hotspot messaging
  • Virtual access point segmentation
  • Captive portal
  • Cloud ACL
* State sync high availability only on SonicWALL TZ500 and SonicWALL TZ600 models
** 802.11ac currently not available on SOHO models; SOHO models support 802.11a/b/g/n

Deployment & Architecture:

Extensible architecture for extreme scalability and performance

The Reassembly-Free Deep Packet Inspection (RFDPI) engine is designed from the ground up with an emphasis on providing security scanning at a high performance level, to match both the inherently parallel and ever-growing nature of network traffic. When combined with multi-core processor systems, this parallel-centric software architecture scales up perfectly to address the demands of deep packet inspection at high traffic loads. The SonicWALL TZ Series platform relies on processors that, unlike x86, are optimized for packet, crypto and network processing while retaining flexibility and programmability in the field - a weak point for ASICs systems. This flexibility is essential when new code and behavior updates are necessary to protect against new attacks that require updated and more sophisticated detection techniques.

TZ Series Network Deployment

Reassembly-Free Deep Packet Inspection (RFDPI) engine

The RFDPI engine provides superior threat protection and application control without compromising performance. This patented engine inspects the traffic stream to detect threats at Layers 3-7. The RFDPI engine takes network streams through extensive and repeated normalization and decryption in order to neutralize advanced evasion techniques that seek to confuse detection engines and sneak malicious code into the network. Once a packet undergoes the necessary preprocessing, including SSL decryption, it is analyzed against a single proprietary memory representation of three signature databases: intrusion attacks, malware and applications. The connection state is then advanced to represent the position of the stream relative to these databases until it encounters a state of attack, or another “match” event, at which point a pre-set action is taken. As malware is identified, the SonicWALL firewall terminates the connection before any compromise can be achieved and properly logs the event. However, the engine can also be configured for inspection only or, in the case of application detection, to provide Layer 7 bandwidth management services for the remainder of the application stream as soon as the application is identified.

TZ Series Architecture vs competitors

Global management and reporting

For larger, distributed enterprise deployments, the optional SonicWALL Global Management System (GMS) provides administrators a unified, secure and extensible platform to manage SonicWALL security appliances and X-Series switches. It enables enterprises to easily consolidate the management of security appliances, reduce administrative and troubleshooting complexities and governs all operational aspects of the security infrastructure including centralized policy management and enforcement, real-time event monitoring, analytics and reporting, and more. GMS also meets the firewall change management requirements of enterprises through a workflow automation feature. GMS provides a better way to manage network security by business processes and service levels that dramatically simplify the lifecycle management of your overall security environments rather than on a device-by-device basis.

TZ Series Global Management and Reporting

Security and protection

The dedicated, in-house SonicWALL Threat Research Team works on researching and developing countermeasures to deploy to the firewalls in the field for up-to-date protection. The team leverages more than one million sensors across the globe for malware samples, and for telemetry feedback on the latest threat information, which in turn is fed into the intrusion prevention, antimalware and application detection capabilities. SonicWALL firewall customers with current subscriptions are provided continuously updated threat protection around the clock, with new updates taking effect immediately without reboots or interruptions. The signatures on the appliances protect against wide classes of attacks, covering up to tens of thousands of individual threats with a single signature. In addition to the countermeasures on the appliance, all SonicWALL firewalls also have access to the SonicWALL CloudAV service, which extends the onboard signature intelligence with more than 17 million signatures, and growing. This CloudAV database is accessed via a proprietary light-weight protocol by the firewall to augment the inspection done on the appliance. With GeoIP and botnet filtering capabilities, SonicWALL next-generation firewalls are able to block traffic from dangerous domains or entire geographies in order to reduce the risk profile of the network.

Application intelligence and control

Application intelligence informs administrators of application traffic traversing the network, so they can schedule application controls based on business priority, throttle unproductive applications and block potentially dangerous applications. Real-time visualization identifies traffic anomalies as they happen, enabling immediate countermeasures against potential inbound or outbound attacks or performance bottlenecks. SonicWALL application traffic analytics provide granular insight into application traffic, bandwidth utilization and security threats, as well as powerful troubleshooting and forensics capabilities. Additionally, secure single sign-on (SSO) capabilities enhance the user experience, increase productivity and reduce support calls. Management of application intelligence and control is simplified by using an intuitive web-based interface.

Flexible and secure wireless

Available as an optional feature, highspeed 802.11ac wireless* combines with SonicWALL next-generation firewall technology to create a wireless network security solution that delivers comprehensive protection for wired and wireless networks. This enterprise-level wireless performance enables WiFi-ready devices to connect from greater distances and use bandwidth-intensive mobile apps, such as video and voice, in higher density environments without experiencing signal degradation

* 802.11ac currently not available on SOHO models; SOHO models support 802.11a/b/g/n

Specifications:

SonicWALL TZ 300 Spec

Models: TZ SOHO TZ300 TZ400 TZ500 TZ600
Performance Overview
SonicOS Version SonicOS 5.9x / 6.2.x SonicOS 6.2.x
Security Processor 2 x 400 MHz / 2 x 800 MHz 2 x 800 MHz 4 x 800 MHz 4 x 1 GHz 4 x 1.4 GHz
Memory (RAM) 512 MB / 1GB 1 GB 1 GB 1 GB 1 GB
Memory (flash) 32 MB / 64 MB 64 MB 64 MB 64 MB 64 MB
1 GbE Copper Interfaces 5 5 7 8 9
Expansion USB USB USB 2 USB Expansion Slot (Rear)*, 2 USB
Firewall Inspection Throughput1 300 Mbps 750 Mbps 1,300 Mbps 1,400 Mbps 1,500 Mbps
Full DPI Throughput2 50 Mbps 100 Mbps 300 Mbps 400 Mbps 500 Mbps
Application Inspection Throughput2 - 300 Mbps 900 Mbps 1,000 Mbps 1,100 Mbps
IPS Throughput2 100 Mbps 300 Mbps 900 Mbps 1,000 Mbps 1,100 Mbps
Anti-malware Throughput2 50 Mbps 100 Mbps 300 Mbps 400 Mbps 500 Mbps
IMIX Throughput3 60 Mbps 200 Mbps 500 Mbps 700 Mbps 900 Mbps
SSL Inspection & Decryption (DPI SSL) Throughput2 15 Mbps 45 Mbps 100 Mbps 150 Mbps 200 Mbps
IPSec VPN Throughput3 100 Mbps 300 Mbps 900 Mbps 1,000 Mbps 1,100 Mbps
Connections per second 1,800 5,000 6,000 8,000 12,000
Maximum connections (SPI) 25,000 50,000 100,000 125,000 150,000
Maximum connections (DPI) 25,000 50,000 90,000 100,000 125,000
Single Sign-On (SSO) Users 250 500 500 500 500
VLAN Interfaces 25 25 50 50 50
SonicPoints Supported 2 8 16 16 24
Dell X-Series switch models Supported Not available X1008/P, X1018/P, X1026/P, X1052/P, X4012
VPN TZ SOHO TZ300 TZ400 TZ500 TZ600
Site-to-Site VPN Tunnels 10 10 20 25 50
IPSec VPN Clients (maximum) 1 (5) 1 (10) 2 (25) 2 (25) 2 (25)
SSL VPN Licenses (maximum) 1 (10) 1 (50) 2 (100) 2 (150) 2 (200)
Virtual Assist Bundled (Maximum) - 30-day trial (1) 30-day trial (1) 30-day trial (1) 30-day trial (1)
Encryption/Authentication DES, 3DES, AES (128, 192, 256-bit), MD5, SHA-1, Suite B Cryptography
Key Exchange Diffie Hellman Groups 1, 2, 5, 14
Route-based VPN RIP, OSPF
Certificate Support Verisign, Thawte, Cybertrust, RSA Keon, Entrust and Microsoft CA for SonicWALL-to-SonicWALL VPN, SCEP
VPN Features Dead Peer Detection, DHCP Over VPN, IPSec NAT Traversal, Redundant VPN Gateway, Route-based VPN
Global VPN Client Platforms Supported Microsoft® Windows Vista 32/64-bit, Windows 7 32/64-bit, Windows 8.0 32/64-bit, Windows 8.1 32/64-bit
NetExtender Microsoft Windows Vista 32/64-bit, Windows 7, Windows 8.0 32/64-bit, Windows 8.1 32/64-bit, Mac OS X 10.4+, Linux FC3+/Ubuntu 7+/OpenSUSE
Mobile Connect Apple® iOS, Mac OS X, Google® Android™, Kindle Fire, Windows 8.1 (Embedded)
Security Services TZ SOHO TZ300 TZ400 TZ500 TZ600
Deep Packet Inspection Services Gateway Anti-Virus, Anti-Spyware, Intrusion Prevention, DPI SSL
Content Filtering Service (CFS) HTTP URL, HTTPS IP, keyword and content scanning, ActiveX, Java Applet, and cookie blocking bandwidth management on filtering categories, allow/forbid lists
Enforced Client Anti-Virus and Anti-Spyware McAfee®, Kaspersky
Comprehensive Anti-Spam Service Supported
Application Visualization No Yes Yes Yes Yes
Application Control Yes Yes Yes Yes Yes
Networking TZ SOHO TZ300 TZ400 TZ500 TZ600
IP Address Assignment Static, (DHCP, PPPoE, L2TP and PPTP client), Internal DHCP server, DHCP relay
NAT Modes 1:1, 1:many, many:1, many:many, flexible NAT (overlapping IPs), PAT, transparent mode
Routing Protocols BGP, OSPF, RIPv1/v2, static routes, policy-based routing, multicast
QoS Bandwidth priority, max bandwidth, guaranteed bandwidth, DSCP marking, 802.1e (WMM)
Authentication XAUTH/RADIUS, Active Directory, SSO, LDAP, Novell, internal user database, Terminal Services, Citrix
Local User Database 150 250
VoIP Full H.323v1-5, SIP
Standards TCP/IP, UDP, ICMP, HTTP, HTTPS, IPSec, ISAKMP/IKE, SNMP, DHCP, PPPoE, L2TP, PPTP, RADIUS, IEEE 802.3
Certifications VPNC, IPv6 (Phase 2)
Certifications Pending Common Criteria NDPP, FIPS 140-2 (with Suite B) Level 2, ICSA Firewall, ICSA Anti-virus, UC APL
Common Access Card (CAC) Supported
High availability No Active/standby Active/standby Active/standby with stateful synchronization Active/standby with stateful synchronization
Hardware TZ SOHO TZ300 TZ400 TZ500 TZ600
Form Factor Desktop
Power Supply (W) 24W external 24W external 24W external 36W external 60W external
Maximum Power Consumption (W) 7.9 6.9 9.2 13.47 16.17
Input Power 100 to 240 VAC, 50-60 Hz, 1 A
Total Heat Dissipation 21.8 BTU 22.3 BTU 28.6 BTU 38.7 BTU 48.3 BTU
Dimensions (in) 1.4x5.6x7.5 1.3x5.3x7.5 1.3x5.3x7.5 1.4x5.9x8.9 1.4x7.1x11.0
Dimensions (cm) 3.6x14.1x19 3.5x13.4x19 3.5x13.4x19 3.5x15x22.5 3.5x18x28
Weight 0.34 Kg 0.725 Kg 0.725 Kg 0.915 Kg 1.47 Kg
WEEE Weight 0.8 Kg 1.145 Kg 1.148 Kg 1.338 Kg 1.893 Kg
Shipping Weight 1.2 Kg 1.373 Kg 1.373 Kg 1.928 Kg 2.483 Kg
MTBF (Years) 58.9 56.1 54 40.8 18.4
Environment 40-105° F, 0-40° C
Humidity 5-95% non-condensing
Major Regulatory Compliance (wired) FCC Class B, ICES Class B, CE (EMC, LVD, RoHS), C-Tick, VCCI Class B, UL, cUL, TUV/GS, CB, Mexico CoC by UL, WEEE , REACH, KCC/MSIP FCC Class B, ICES Class B, CE (EMC, LVD, RoHS), C-Tick, VCCI Class B, UL, cUL, TUV/GS, CB, Mexico CoC by UL, WEEE , REACH, KCC/MSIP FCC Class B, ICES Class B, CE (EMC, LVD, RoHS), C-Tick, VCCI Class B, UL, cUL, TUV/GS, CB, Mexico CoC by UL, WEEE , REACH, KCC/MSIP FCC Class B, ICES Class B, CE (EMC, LVD, RoHS), C-Tick, VCCI Class B, UL, cUL, TUV/GS, CB, Mexico CoC by UL, WEEE , REACH, KCC/MSIP FCC Class A, ICES Class A, CE (EMC, LVD, RoHS), C-Tick, VCCI Class A, UL cUL, TUV/GS, CB, Mexico CoC by UL, WEEE , REACH, KCC/MSIP
Regulatory Model APL41-0BA APL28-0B5 APL28-0B5 APL29-0B7 -
Major Regulatory Compliance (wired) FCC Class B, FCC RF ICES Class B, IC RF CE (R&TTE, EMC, LVD, RoHS), RCM, VCCI Class B, MIC/TELEC, UL, cUL, TUV/GS, CB, Mexico CoC by UL, WEEE , REACH FCC Class B, FCC RF ICES Class B, IC RF CE (R&TTE, EMC, LVD, RoHS), RCM, VCCI Class B, MIC/TELEC, UL, cUL, TUV/GS, CB, Mexico CoC by UL, WEEE , REACH FCC Class B, FCC RF ICES Class B, IC RF CE (R&TTE, EMC, LVD, RoHS), RCM, VCCI Class B, MIC/TELEC, UL, cUL, TUV/GS, CB, Mexico CoC by UL, WEEE , REACH FCC Class B, FCC RF ICES Class B, IC RF CE (R&TTE, EMC, LVD, RoHS), RCM, VCCI Class B, MIC/TELEC, UL, cUL, TUV/GS, CB, Mexico CoC by UL, WEEE , REACH -
Integrated Wireless TZ SOHO TZ300 TZ400 TZ500 TZ600
Standards 802.11 ac/a/b/g/n 802.11a/b/g/n/ac (WEP, WPA, WPA2, 802.11i, TKIP, PSK,02.1x, EAP-PEAP, EAP-TTLS 802.11 a/b/g/n/ac
Frequency bands - 802.11a: 5.180-5.825 GHz; 802.11b/g: 2.412-2.472 GHz; 802.11n: 2.412-2.472 GHz, 5.180-5.825 GHz; 802.11ac: 2.412-2.472 GHz, 5.180-5.825 GHz 802.11 a/b/g/n/ac
Operating Channels - 802.11a: US and Canada 12, Europe 11, Japan 4, Singapore 4, Taiwan 4; 802.11b/g: US and Canada 1-11, Europe 1-13, Japan 1-14 (14-802.11b only); 802.11n (2.4 GHz): US and Canada 1-11, Europe 1-13, Japan 1-13; 802.11n (5 GHz): US and Canada 36-48/149-165, Europe 36-48, Japan 36-48, Spain 36-48/52-64; 802.11ac: US and Canada 36-48/149- 165, Europe 36-48, Japan 36-48, Spain 36-48/52-64 802.11 a/b/g/n/ac
Transmit output power - Based on the regulatory domain specified by the system administrator 802.11 a/b/g/n/ac
Transmit power control - Supported 802.11 a/b/g/n/ac
Data rates supported - 802.11a: 6,9,12,18,24,36,48,54 Mbps per channel; 802.11b: 1,2,5.5,11 Mbps per channel; 802.11g: 6,9,12,18,24,36,48,54 Mbps per channel; 802.11n: 7.2, 14.4, 21.7, 28.9, 43.3, 57.8, 65, 72.2, 15,30, 45, 60, 90, 120, 135, 150 Mbps per channel; 802.11ac: 7.2, 14.4, 21.7, 28.9, 43.3, 57.8, 65, 72.2, 86.7, 96.3, 15, 30, 45, 60, 90, 120, 135, 150, 180, 200, 32.5, 65, 97.5, 130, 195, 260, 292.5, 325, 390, 433.3, 65, 130, 195, 260, 390, 520, 585, 650, 780, 866.7 Mbps per channel 802.11 a/b/g/n/ac
Modulation technology spectrum - 802.11a: Orthogonal Frequency Division Multiplexing (OFDM); 802.11b: Direct Sequence Spread Spectrum (DSSS); 802.11g: Orthogonal Frequency Division Multiplexing (OFDM)/ Direct Sequence Spread Spectrum (DSSS); 802.11n: Orthogonal Frequency Division Multiplexing (OFDM); 802.11ac: Orthogonal Frequency Division Multiplexing (OFDM) 802.11 a/b/g/n/ac
1 Testing Methodologies: Maximum performance based on RFC 2544 (for firewall). Actual performance may vary depending on network conditions and activated services.
2 Full DPI/GatewayAV/Anti-Spyware/IPS throughput measured using industry standard Spirent WebAvalanche HTTP performance test and Ixia test tools. Testing done with multiple flows through multiple port pairs.
3 VPN throughput measured using UDP traffic at 1280 byte packet size adhering to RFC 2544. All specifications, features and availability are subject to change.
4 Available only on SonicWALL TZ300, TZ400, TZ500 and TZ600
* Future use.

Documentation:

Download the SonicWALL TZ Series Datasheet (PDF).

Pricing Notes:

TZ300 Series
TZ300 Base Appliance
#01-SSC-0215
List Price: $645.00
Our Price: $484.00
TotalSecure Bundle
TZ300 TotalSecure
*Includes TZ300 Appliance & 1-Year Comprehensive Gateway Security Suite
#01-SSC-0581
List Price: $965.00
Our Price: $724.00
TZ300 TotalSecure Advanced Edition Appliance Bundle
*Includes TZ300 Appliance with 1 Year AGSS Bundle (Capture ATP, Threat Prevention, Content Filtering, 24x7 Support)
#01-SSC-1705
List Price: $1,214.00
Our Price: $911.00
GEN5 Firewall Replacement Bundle
Receive a discount to replace your existing 5th Generation Firewall. Note: an existing GEN5 firewall must be registered in your current MySonicWALL.com account to qualify for the upfront discount.
TZ300 GEN5 Replacement Bundle with 1 Year AGSS
*Includes TZ300 Appliance with 1 Year AGSS Bundle (Capture ATP, Threat Prevention, Content Filtering, 24x7 Support)
#01-SSC-1355
List Price: $971.00
Our Price: $728.00
Secure Upgrade Plus Program
TZ300 Secure Upgrade Plus with 2 Years CGSS
*Requires Qualifying Trade-up Product. Click here for details.
#01-SSC-0575
List Price: $965.00
Our Price: $724.00
TZ300 Secure Upgrade Plus Advanced Edition with 2 Years AGSS
*Requires Qualifying Trade-up Product. Click here for details.
#01-SSC-1742
List Price: $1,474.00
Our Price: $1,106.00
TZ300 Secure Upgrade Plus with 3 Years CGSS
*Requires Qualifying Trade-up Product. Click here for details.
#01-SSC-0576
List Price: $1,145.00
Our Price: $859.00
TZ300 Secure Upgrade Plus Advanced Edition with 3 Years AGSS
*Requires Qualifying Trade-up Product. Click here for details.
#01-SSC-1743
List Price: $1,668.00
Our Price: $1,251.00
Advanced Gateway Security Suite for TZ300 Series
Advanced Gateway Security Suite includes Gateway Anti-Virus, Anti-Spyware, Intrusion Prevention and Application Intelligence and Control Service, Content Filtering Service, Capture Advanced Threat Protection (ATP) Service, and 24x7 Support with Software & Firmware Updates and Advanced Hardware Replacement.
Advanced Gateway Security Suite for TZ300 Series (1 Year)
#01-SSC-1430
List Price: $649.00
Our Price: $486.00
Advanced Gateway Security Suite for TZ300 Series (2 Years)
#01-SSC-1431
List Price: $1,024.00
Our Price: $768.00
Advanced Gateway Security Suite for TZ300 Series (3 Years)
#01-SSC-1432
List Price: $1,378.00
Our Price: $1,033.00
Advanced Gateway Security Suite for TZ300 Series (4 Years)
#01-SSC-1433
List Price: $1,917.00
Our Price: $1,437.00
Advanced Gateway Security Suite for TZ300 Series (5 Years)
#01-SSC-1434
List Price: $2,296.00
Our Price: $1,722.00
Comprehensive Gateway Security Suite
CGSS includes Gateway Anti-Virus, Anti-Spyware and Intrusion Prevention Service, Content Filtering Service and 24x7 Support - Learn more
Comprehensive Gateway Security Suite for TZ300 Series (1 Year)
#01-SSC-0638
List Price: $399.00
Our Price: $312.00
Comprehensive Gateway Security Suite for TZ300 Series (2 Years)
#01-SSC-0639
List Price: $599.00
Our Price: $468.00
Comprehensive Gateway Security Suite for TZ300 Series (3 Years)
#01-SSC-0640
List Price: $779.00
Our Price: $608.00
Comprehensive Gateway Security Suite for TZ300 Series (4 Years)
#01-SSC-0641
List Price: $1,119.00
Our Price: $873.00
Comprehensive Gateway Security Suite for TZ300 Series (5 Years)
#01-SSC-0642
List Price: $1,299.00
Our Price: $1014.00
Gateway Anti-Malware, Intrusion Prevention and Application Control
Gateway Anti-Malware, Intrusion Prevention and Application Control for the TZ300 Series (1 Year)
#01-SSC-0602
List Price: $212.00
Our Price: $160.00
Gateway Anti-Malware, Intrusion Prevention and Application Control for the TZ300 Series (2 Years)
#01-SSC-0603
List Price: $297.00
Our Price: $223.00
Gateway Anti-Malware, Intrusion Prevention and Application Control for the TZ300 Series (3 Years)
#01-SSC-0604
List Price: $434.00
Our Price: $326.00
Gateway Anti-Malware, Intrusion Prevention and Application Control for the TZ300 Series (4 Years)
#01-SSC-0605
List Price: $553.00
Our Price: $415.00
Gateway Anti-Malware, Intrusion Prevention and Application Control for the TZ300 Series (5 Years)
#01-SSC-0606
List Price: $691.00
Our Price: $519.00
Comprehensive Anti-Spam Service
The SonicWALL Comprehensive Anti-Spam Service delivers advanced spam protection at the gateway. Simply activate the service and stop spam before it enters your network. The Comprehensive Anti-Spam Service is recommended for up to 250 users.
Comprehensive Anti-Spam Service for TZ300 Series (1 Year)
#01-SSC-0632
List Price: $277.00
Our Price: $208.00
Comprehensive Anti-Spam Service for TZ300 Series (2 Years)
#01-SSC-0633
List Price: $471.00
Our Price: $354.00
Comprehensive Anti-Spam Service for TZ300 Series (3 Years)
#01-SSC-0634
List Price: $665.00
Our Price: $499.00
Comprehensive Anti-Spam Service for TZ300 Series (4 Years)
#01-SSC-0635
List Price: $887.00
Our Price: $666.00
Comprehensive Anti-Spam Service for TZ300 Series (5 Years)
#01-SSC-0636
List Price: $1,109.00
Our Price: $832.00
Capture Advanced Threat Protection for TZ300 Series
Note: Requires purchase of Gateway Anti-Virus, Anti-Spyware, Intrusion Prevention and Application Firewall Service (GAV)
Capture Advanced Threat Protection for TZ300 (1 Year)
#01-SSC-1435
List Price: $249.00
Our Price: $186.95
Capture Advanced Threat Protection for TZ300 (2 Years)
#01-SSC-1436
List Price: $424.00
Our Price: $318.95
Capture Advanced Threat Protection for TZ300 (3 Years)
#01-SSC-1437
List Price: $598.00
Our Price: $448.95
Capture Advanced Threat Protection for TZ300 (4 Years)
#01-SSC-1438
List Price: $797.00
Our Price: $597.95
Capture Advanced Threat Protection for TZ300 (5 Years)
#01-SSC-1439
List Price: $996.00
Our Price: $747.95
Content Filtering Service
Content Filtering Service Premium Business Edition for TZ300 Series (1 Year)
#01-SSC-0608
List Price: $270.00
Our Price: $203.00
Content Filtering Service Premium Business Edition for TZ300 Series (2 Years)
#01-SSC-0609
List Price: $406.00
Our Price: $305.00
Content Filtering Service Premium Business Edition for TZ300 Series (3 Years)
#01-SSC-0610
List Price: $487.00
Our Price: $366.00
Content Filtering Service Premium Business Edition for TZ300 Series (4 Years)
#01-SSC-0611
List Price: $650.00
Our Price: $488.00
Content Filtering Service Premium Business Edition for TZ300 Series (5 Years)
#01-SSC-0612
List Price: $812.00
Our Price: $610.00
SonicWALL Analyzer Reporting Software
SonicWALL Analyzer is an easy to use web-based traffic analytics and reporting tool that provides real-time and historical insight into the health, performance and security of the network. Learn more!
SonicWALL Analyzer Reporting Software For SOHO, TZ1xx, TZ2xx, TZ3xx, TZ4xx Series
#01-SSC-3378
List Price: $125.00
Our Price: $93.00
Remote Installation Bundles - TZ Series
Western NRG’s Remote Installation Bundle is a turnkey configuration and installation offering that can be purchased with your SonicWALL network security appliance that provides professional configuration by a team of SonicWALL Certified engineers. Learn more!
Remote Installation Bundle for a SonicWALL TZ300 Appliance
*Service provided by Western NRG.
#WNRG-INSTALL-TZ300-BDL
Our Price: $595.00
Dynamic Support 24x7
Dynamic Support 24x7 for the TZ300 Series (1 Year)
#01-SSC-0620
List Price: $212.00
Our Price: $160.00
Dynamic Support 24x7 for the TZ300 Series (2 Years)
#01-SSC-0621
List Price: $297.00
Our Price: $223.00
Dynamic Support 24x7 for the TZ300 Series (3 Years)
#01-SSC-0622
List Price: $434.00
Our Price: $326.00
Dynamic Support 24x7 for the TZ300 Series (4 Years)
#01-SSC-0623
List Price: $553.00
Our Price: $415.00
Dynamic Support 24x7 for the TZ300 Series (5 Years)
#01-SSC-0624
List Price: $691.00
Our Price: $519.00
Standard Support (8x5)
Standard Support (8x5) for the TZ300 Series (1 Year)
#01-SSC-0614
List Price: $129.00
Our Price: $97.00
Standard Support (8x5) for the TZ300 Series (2 Years)
#01-SSC-0615
List Price: $219.00
Our Price: $164.00
Standard Support (8x5) for the TZ300 Series (3 Years)
#01-SSC-0616
List Price: $309.00
Our Price: $232.00
Standard Support (8x5) for the TZ300 Series (4 Years)
#01-SSC-0617
List Price: $412.00
Our Price: $310.00
Standard Support (8x5) for the TZ300 Series (5 Years)
#01-SSC-0618
List Price: $516.00
Our Price: $387.00
UTM SSL VPN Licenses
UTM SSL-VPN 1 User License
#01-SSC-8629
List Price: $50.00
Our Price: $40.00
UTM SSL-VPN 5 User Licenses
#01-SSC-8630
List Price: $215.00
Our Price: $172.00
UTM SSL-VPN 10 User Licenses
#01-SSC-8631
List Price: $345.00
Our Price: $276.00
UTM SSL-VPN 25 User Licenses
#01-SSC-8632
List Price: $450.00
Our Price: $360.00
Global VPN Client for Windows
Global VPN Client for Windows - 1 License
#01-SSC-5310
List Price: $50.00
Our Price: $40.00
Global VPN Client for Windows - 5 Licenses
#01-SSC-5316
List Price: $215.00
Our Price: $172.00
Content Filtering Client
Content Filtering Client - 10 Users (1 Year)
#01-SSC-1252
List Price: $95.00
Our Price: $71.00
Content Filtering Client - 10 Users (2 Years)
#01-SSC-1253
List Price: $162.00
Our Price: $121.00
Content Filtering Client - 10 Users (3 Years)
#01-SSC-1254
List Price: $228.00
Our Price: $171.00
Content Filtering Client - 25 Users (1 Year)
#01-SSC-1225
List Price: $213.00
Our Price: $159.00
Content Filtering Client - 25 Users (2 Years)
#01-SSC-1226
List Price: $361.00
Our Price: $270.00
Content Filtering Client - 25 Users (3 Years)
#01-SSC-1227
List Price: $510.00
Our Price: $382.00
Content Filtering Client - 50 Users (1 Year)
#01-SSC-1228
List Price: $400.00
Our Price: $300.00
Content Filtering Client - 50 Users (2 Years)
#01-SSC-1229
List Price: $680.00
Our Price: $510.00
Content Filtering Client - 50 Users (3 Years)
#01-SSC-1230
List Price: $960.00
Our Price: $720.00
Content Filtering Client - 100 Users (1 Year)
#01-SSC-1231
List Price: $750.00
Our Price: $562.00
Content Filtering Client - 100 Users (2 Years)
#01-SSC-1232
List Price: $1,275.00
Our Price: $956.00
Content Filtering Client - 100 Users (3 Years)
#01-SSC-1233
List Price: $1,800.00
Our Price: $1,350.00
Enforced Client Anti-Virus & Anti-Spyware
SonicWALL Enforced Client Anti-Virus and Anti-Spyware solution provides comprehensive virus, spyware and desktop firewall protection for desktops and laptops using a single integrated client. Learn More
Enforced Client Anti-Virus & Anti-Spyware 5 License Subscription (1 Year)
#01-SSC-2743
List Price: $165.00
Our Price: $123.00
Enforced Client Anti-Virus & Anti-Spyware 10 License Subscription (1 Year)
#01-SSC-2740
List Price: $325.00
Our Price: $243.00
Enforced Client Anti-Virus & Anti-Spyware 25 License Subscription (1 Year)
#01-SSC-2745
List Price: $813.00
Our Price: $609.00
Enforced Client Anti-Virus & Anti-Spyware 50 License Subscription (1 Year)
#01-SSC-2741
List Price: $1,625.00
Our Price: $1,218.00
Rackmounts and Replacement Power Supplies
TZ300 Rackmount Kit
#01-SSC-0742
List Price: $325.00
Our Price: $260.00
TZ400, TZ300, TZ SOHO Series Field Replacement Power Supply
#01-SSC-0709
Our Price: $35.00