Overview: 
Gen 8 NSa firewalls drives strong security with a comprehensive solution encompassing of threat protection, centralized management, reporting and analytics, security and managed service options, Secure Service Edge (SSE) integration, and cyber warranty.
SonicWall latest mid-range next-gen firewalls, Network Security Appliance (NSa) Series offer medium and large enterprises industry-leading threat prevention performance at the lowest total cost of ownership in their class. The firewalls are the cornerstones of the threat protection solution that includes simplified centralized firewall management, Zero Trust enablement, flexible licensing with an option of managed firewall services, and an embedded cyber warranty for risk mitigation.
The Gen 8 firewalls deliver comprehensive security features such as intrusion prevention, VPN, application control, malware analysis, URL filtering, DNS Security, Geo-IP and Bot-net services, protecting the perimeter from advanced threats without becoming a bottleneck.
| Up to 40 Gbps |
Up to 55 Gbps |
Up to 20 Million |
| Threat Prevention Throughput |
Firewall Throughput |
Connections |
Highlights
- Form Factor: 1U Rackable Mounted
- Support for 40G/25G/10G/5G/2.5G/1G ports
- Multi-gigabit Threat and Malware Analysis Throughput
- Superior TLS performance (sessions and throughput)
- Best-in-class price-performance
- Expandable storage
- Advanced DNS Filtering
- Reputation-based Content Filtering Service (CFS 5.0)
- Simplified Centralized SaaS and On-Premises management via Network Security Manager
- Wi-Fi 6 firewall management
- SonicWall Unified Management Support
- Enterprise Internet Edge Ready
- Secure SD-WAN capability
- TLS 1.3 support
- Simplified licensing including Hardware Only, Advanced and Managed Protection Security Suites.
- Powered by SonicWall Capture Labs threat research team
- SonicWall Switch, SonicWave Access Point and Capture Client integration
- Cloud Secure Edge Connector Support
- Embedded Warranty up to USD$200K by Cysurance included in Service Suites
Hardware
Gen 8 NSa Series, built with the latest hardware components, deliver multi-gigabit threat prevention throughput — even for encrypted traffic. Featuring a high port density, the firewall solutions support network and hardware redundancy with high availability and dual power adapters including one for redundancy
Architecture
The Gen 8 NSa Series runs on SonicOS 8, a new operating system that delivers a modern user interface, intuitive workflows and user-first design principles. SonicOS 8 provides multiple features designed to facilitate enterpriselevel workflows. It offers easy policy configuration, zero-touch deployment and flexible management — all of which allow enterprises to improve both their security and operational efficiency.
The NSa Series supports advanced networking features, such as SD-WAN, dynamic routing, layer 4-7 high availability and high-speed VPN functionality. In addition to integrating firewall and switch capabilities, the appliances provide a single-paneof-glass interface to manage both switches and access points.
Threat Protection and Security Services
Built to mitigate the advanced cyberattacks of today and tomorrow, the Gen 8 NSa Series offers access to SonicWall’s advanced firewall security services, allowing you to protect your entire IT infrastructure. Solutions and services such as Cloud Application Security, Capture Advanced Threat Protection (ATP) cloud-based sandboxing, patented Real-Time Deep Memory Inspection (RTDMI™) and Reassembly-Free Deep Packet Inspection (RFDPI) — for all traffic including TLS 1.3 — offer comprehensive gateway protection from most stealthy and dangerous malware, including zero-day and encrypted threats.
Simplified licensing includes Hardware Only, Advanced (APSS) and Managed Protection Security Suite (MPSS) to meet your unique needs. MPSS augments resources with managed services for firewalls.
A Cloud Secure Edge Connector integration provides secure access to their private applications behind the firewalls. Users and devices can adhere to a Zero-Trust framework for application access.
Cyber Warranty
An embedded cyber warranty is offered as part of your security suite to mitigate costs of security breach, meet compliance requirements and promote peace of mind.
Deployments:
The Gen 8 NSa Series has two main deployment options for medium and distributed enterprises:
Internet Edge Deployment
In this standard deployment option, the Gen 8 NSa Series NGFW protects private networks from malicious traffic coming from the internet, allowing you to:
- Deploy a proven NGFW solution with highest performance in its class
- Gain visibility and inspect encrypted traffic, including TLS 1.3, to block evasive threats coming from the Internet — all without compromising performance
- Protect your enterprise with integrated security, including malware analysis, cloud app security, URL filtering and reputation services
- Save space and money with an integrated NGFW solution that includes advanced security and networking capabilities
- Reduce complexity and maximize efficiency using a central management system delivered through an intuitive single-paneof-glass user interface
Medium and Distributed Enterprises
The SonicWall Gen 8 NSa Series supports SD-WAN and can be centrally managed, making it an ideal fit for medium and distributed enterprises. This deployment allows organizations to:
- Future-proof against an ever-changing threat landscape by investing in a NGFW with multi-gigabit threat analysis performance
- Provide direct and secure internet access to distributed branch offices instead of back-hauling through corporate headquarters
- Allow distributed branch offices to securely access internal resources in corporate headquarters or in a public cloud, significantly improving application latency
- Automatically block threats that use encrypted protocols such as TLS 1.3, securing networks from the most advanced attacks.
- Reduce complexity and maximize efficiency using a central management system delivered through an intuitive single pane of glass user interface
- Leverage high port density that includes 40 GbE and 10 GbE connectivity to support a distributed enterprise and wide area networks
Specifications:
Gen 8 NSa Series System Specifications
| Firewall |
NSa 2800 |
NSa 3800 |
NSa 4800 |
NSa 5800 |
| Operating system |
SonicOS 8 |
| Interfaces |
16x1GbE, 3x10G SFP+, 2 USB 3.0, 1 Console, 1 Mgmt. port |
24x1GbE, 10x10G SFP+, 2 USB 3.0, 1 Console, 1 Mgmt. port |
24 * 1GbE Cu, 8*10G SFP+, 1 console (RJ45 to DB9), 2 USB (USB type-A) |
24 * 1GbE Cu, 8*10G SFP+, 1 console (RJ45 to DB9), 2 USB (USB type-A) |
| Storage/(Expansion) |
128 Gb (Up to 512 GB) |
256 Gb (Up to 512 GB) |
256 GB (Up to 1 TB) |
256 GB (Up to 1 TB) |
| Centralized Management |
Network Security Manager (NSM) 3.0 and above, CLI, SSH, Web UI, REST APIs |
| Logical VLAN and tunnel interfaces (maximum) |
256 |
256 |
512 |
512 |
| SAML Single Sign-On Users1 |
40,000 |
40,000 |
50,000 |
50,000 |
| Access points supported (maximum) |
512 |
512 |
512 |
512 |
| Firewall/VPN Performance |
| Firewall inspection throughput2 |
8 Gbps |
12 Gbps |
20 Gbps |
30 Gbps |
| Threat Prevention throughput3 |
6 Gbps |
8 Gbps |
13 Gbps |
24 Gbps |
| Application inspection throughput3 |
7 Gbps |
9 Gbps |
13 Gbps |
24 Gbps |
| IPS throughput2 |
7 Gbps |
8 Gbps |
13 Gbps |
24 Gbps |
| Anti-malware inspection throughput3 |
6 Gbps |
8 Gbps |
13 Gbps |
24 Gbps |
| TLS/SSL inspection and decryption throughput3 |
1.8 Gbps |
3 Gbps |
4.2 Gbps |
8 Gbps |
| IPSec VPN throughput4 |
5.5 Gbps |
8 Gbps |
10 Gbps |
21 Gbps |
| Connections per second |
50,000 |
90,000 |
140,000 |
240,000 |
| Maximum connections (SPI) |
2,000,000 |
3,000,000 |
6M |
8M |
| Maximum connections (DPI) |
1,00,000 |
1,200,000 |
3M |
5M |
| Maximum connections (TLS) |
150,000 |
300,000 |
600K |
750K |
| VPN AND ZTNA |
| Site-to-site VPN tunnels |
2,000 |
3,000 |
4,000 |
6,000 |
| IPSec VPN clients (max) |
50 (1000) |
50 (1000) |
500 (3000) |
2000 (4000) |
| SSL VPN licenses (max) |
2 (500) |
2 (500) |
2(1000) |
2(1500) |
| Encryption/authentication |
AES (128, 192, 256-bit)/MD5, SHA-1, Suite B Cryptography |
| Key exchange |
Diffie Hellman Groups 1, 2, 5, 14v |
| Route-based VPN |
RIP, OSPF, BGP |
| Certificate support |
Verisign, Thawte, Cybertrust, RSA Keon, Entrust and Microsoft CA for SonicWall-to-SonicWall VPN, SCEP |
| VPN features |
Dead Peer Detection, DHCP Over VPN, IPSec NAT Traversal, Redundant VPN Gateway, Route-based VPN |
| Global VPN client platforms supported |
Microsoft® Windows 10 and Windows 11 |
| NetExtender |
Microsoft® Windows 10 and Windows 11, Linux |
| Mobile Connect |
Apple® iOS, Mac OS X, Google® Android™ |
| SonicWall Private Access powered by Cloud Secure Edge5 |
Included in 3&Free Loyalty Program |
| Security Services |
| Deep Packet Inspection services |
Gateway Anti-Virus, Anti-Spyware, Intrusion Prevention, TLS Decryption |
| Content Filtering Service (CFS) |
Reputation-based URL filtering, HTTP URL, HTTPS IP, keyword and content scanning, Comprehensive filtering based on file types such as ActiveX, Java, Cookies for privacy, allow/forbid lists |
| Comprehensive Anti-Spam Service |
Yes |
Yes |
Yes |
Yes |
| Application Visualization |
Yes |
Yes |
Yes |
Yes |
| Application Control |
Yes |
Yes |
Yes |
Yes |
| Capture Advanced Threat Protection |
Yes |
Yes |
Yes |
Yes |
| DNS Security |
Yes |
Yes |
Yes |
Yes |
| Networking |
| IP address assignment |
Static (DHCP, PPPoE, L2TP and PPTP client), Internal DHCP server, DHCP relay |
| NAT modes |
1:1, 1:many, many:1, many:many, flexible NAT (overlapping IPs), PAT, transparent mode |
| Routing protocols4 |
BGP, OSPF, RIPv1/v2, static routes, policy-based routing |
| QoS |
Bandwidth priority, max bandwidth, guaranteed bandwidth, DSCP marking, 802.1e (WMM) |
| Authentication |
LDAP (multiple domains), XAUTH/RADIUS, TACACS+, SAML SSO1, Radius accounting NTLM, internal user database, 2FA, Terminal Services, Citrix, Common Access Card (CAC) |
| Local user database |
1000 |
| VoIP |
Full H323-v1-5, SIP |
| Standards |
TCP/IP, UDP, ICMP, HTTP, HTTPS, IPSec, ISAKMP/IKE, SNMP, DHCP, PPPoE, L2TP, PPTP, RADIUS, IEEE 802.3 |
| Certifications |
IPv6/USGv6 |
| High availability |
Active/Passive with stateful synchronization |
| Hardware |
| Form factor |
1U Rack Mountable |
1U Rack Mountable |
1U Rack Mountable |
1U Rack Mountable |
| Power supply |
90W |
150W |
450W |
450W |
| Maximum power consumption (W) |
52.8 |
102.3 |
110.4 |
119.4 |
| Input power (AC) |
100-240 VAC, 50-60 Hz |
100-240 VAC, 50-60 Hz |
100-240 VAC, 50-60 Hz |
100-240 VAC, 50-60 Hz |
| Total heat dissipation (BTU) |
180.01 |
341 |
377.4 |
407.5 |
| Dimensions (Unit: cm) |
43 x 32.5 x 4.5 Shipping: 57.5 x 47.5 x 18.5 |
43 x 32.5 x 4.5 Shipping: 57.5 x 47.5 x 18.5 |
43 x 46 x 4.5 Shipping: 69.5 x 59.5 x 21 |
43 x 46 x 4.5 Shipping: 69.5 x 59.5 x 21 |
| Weight |
4.6 |
4.6 |
7.4 Kg |
7.4 Kg |
| WEEE weight |
4.8 |
4.8 |
9.3 Kg |
9.3 Kg |
| Shipping weight |
7.2 |
7.2 |
13.2 Kg |
13.2 Kg |
| Environment (Operating/Storage) |
0°C to +40° C / -40°C to +70°C |
| Humidity |
5-95% non-condensing |
| Regulatory |
| Major regulatory compliance |
FCC Class A, ICES Class A, CE (EMC, LVD, RoHS), UL, cUL, Mexico DGN Notice by UL, ANATEL, WEEE, REACH, SCIP, RCM, MIC Terminal, VCCI Class A, KCC/MSIP, BSMI, MTCTE/TEC, CB |
CC Class A, ICES Class A, CE (EMC, LVD, RoHS), UL, cUL, Mexico DGN Notice by UL, ANATEL, WEEE, REACH, SCIP, RCM, VCCI Class A, KCC/ MSIP, BSMI, MTCTE/TEC, CB |
| Regulatory model numbers |
1RK56-11C |
1RK57-122 |
IRK58-123 |
IRK58-123 |
1 SAML Single Sign-On is available with the upcoming SonicOS 8.1, releasing soon.
2 Testing Methodologies: Maximum performance based on RFC 2544 (for firewall). Actual performance may vary depending on network conditions and activated services.
3 Threat Prevention/Gateway AV/Anti-Spyware/IPS throughput measured using industry standard Keysight HTTP performance test tools. Testing done with multiple flows through multiple port pairs. Threat Prevention throughput measured with Gateway AV, Anti-Spyware, IPS and Application Control enabled.
4 VPN throughput measured with UDP traffic using 1418 byte packet size AESGMAC16-256 Encryption adhering to RFC 2544. All specifications, features and availability are subject to change.
5 Included with3-yearbundle