Sonicos 7 0 and Services Datasheet
Sonicos 7 0 and Services Datasheet
Sonicos 7 0 and Services Datasheet
The SonicOS architecture is at the core of SonicWall physical to our firewalls that’s been validated by independent third-
and virtual firewalls including the TZ, NSa, NSv and NSsp party testing for its extremely high security effectiveness.
Series. SonicOS leverages our patented, single-pass, Unknown threats are sent to SonicWall’s cloud-based
low-latency, Reassembly-Free Deep Packet Inspection® Capture Advanced Threat Protection (ATP) multiengine
(RFDPI) and patented Real-Time Deep Memory Inspection™ sandbox for analysis. Enhancing Capture ATP is our
(RTDMI) technologies to deliver industry-validated high RTDMI™ technology. The RTDMI engine detects and blocks
security effectiveness, SD-WAN, real-time visualization, malware and zero-day threats by inspecting directly in
high-speed virtual private networking (VPN) and other robust memory. RTDMI technology is precise, minimizes false
security features. positives, and identifies and mitigates sophisticated attacks
Our vision for securing networks in today’s continually- where the malware’s weaponry is exposed for less than
Streaming Data
Classified Malware
PDF RANSOMWARE
Locky
Email
RANSOMWARE BLOCK
Data File WannaCry
101001001010 Artifact 1
TROJAN
010100101101
Artifact 2 MACHINE Spartan
LEARNING
010010100100
101001010010
Artifact 3
110101010010
Deep Learning UNKNOWN
010100100010
Artifact 4 Algorithms CLOUD CAPTURE
101100100101
SANDBOX
A Hypervisor
Endpoint
A B C D B Emulation
C Virtualization
D RTDMI
DATASHEET
In combination, our RFDPI engine examines every byte Security Service Bundles
of every packet, inspecting both inbound and outbound SonicWall security services turns firewall into a complete
traffic directly on the firewall. By leveraging Capture ATP security solution. The security services is offered in
with RTDMI technology in the SonicWall Capture Cloud three subscription bundles – Threat, Essential and
Platform in addition to on-box capabilities including Advanced Protection. (i) SonicWall Threat Protection
intrusion prevention, anti-malware and web/URL filtering, our Service Suite includes basic security services needed
next-generation firewalls stop malware, ransomware and to ensure that the network is protected from threats
other threats at the gateway. in a cost-effective bundle. (ii) SonicWall Essential
The introduction of the SonicOS 7.1.1 operating system (OS) Protection Service Suite provides all essential security
further catapults Gen 7 firewall features and functionality services needed to protect against known & unknown
to the next level. In addition to featuring advanced security, threats. (iii) SonicWall Advanced Protection Service
simplified policy management, and critical networking Suite offers advanced security to extend the security of
and management capabilities for distributed enterprises your network with cloud essential security services.
with next-gen SD-Branches and small- to medium-sized
businesses, SonicOS 7.1.1 adds new or enhanced features
around Wi-Fi 6 support, DNS security, reputation-
based content filtering, and Network Access Control
(NAC) integration.
RTDMI Technology
DNS Security
Cloud Management
Part of the bundle Not available with the bundle, but can be purchased separately
Enhanced Dashboard
Feature Description
DNS security Uses the Domain Name System to block malicious websites or applications and to filter out harmful or
inappropriate content.
Network Access Control (NAC) Provides network access control for SonicWall customers by integrating with Aruba ClearPass. This architecture
integration will turn static security into contextual security to provide more flexible and advanced security protection.
Wi-Fi 6 support Integrate and manage Wi-Fi 6 SonicWave access points.
Secondary storage enhancements Support packet capture, TSR, and threat correlation data in storage. Save the following logs to storage: threat logs,
audit logs, app flow, pcap.
Token-based registrations A string that will replace MySonicWall username and password in the bootstrap file used for the NSv bootstrapping
process to automate mass deployments with basic configuration and licensing info.
NSv bootstrapping Simplify mass NSv deployments; support on VMware, Hyper-V, AWS, and Azure; simplify product registrations
using token-based licensing; INIT file includes basic configuration to get the instance ready with minimal
configuration.
Enhanced Dashboard Dashboard with actionable alerts.
"Enhanced Device view with display of User can now find out from the UI home tab, about the real-time status of front panel, back-panel and storage
Front-View,Back-View and Storage module usage statistics. Giving you similar experience as if you are physically in front of the hardware.
Stats of the hardware"
Real-time System usage and User can now view real-time system usage of Core and Bandwidth in the network.
bandwidth usage
Summarized traffic distribution Traffic distribution usage on user's firewall with real-time update of most used application.
Summary of top users Summary of top users based on allowed or blocked sessions; by data sent and received.
Summary of Observed threats Real-time threat summary of threats seen within customer's network like virus, zero-day malware, spyware,
vulnerabilities and risky applications.
Services Summary Real-time status of enabled or disabled security services like IPS, GAV, Anti-Spyware, Capture ATP or DPI-SSL.
Insights on infected hosts Displaying the total number of infected host machines in the network in real-time.
Insights on critical attacks Displaying the total number of mission-critical attacks in the network in real-time.
Insights on encrypted traffic Displaying the total number of encrypted traffic in the network in real-time.
Summary of top applications Displaying the top applications used in the network with additional options of sorting by sessions, bytes,
access-rule blocks, virus,spyware and intrusions.
Summary of top addresses Displaying the top address objects used in the network with additional options of sorting by sessions, bytes,
access-rule blocks, virus, spyware and intrusions.
Summary of top users Displaying the top users used in the network with additional options of sorting by sessions, bytes, access-rule
blocks, virus, spyware and intrusions.
Summary of top website ratings Displays the top website ratings by session.
Summary of top country statistics Displaying the top country statistics by session, dropped traffic, bytes sent or received.
Summary of real-time threat Displaying top threats with separate statistics for Virus, Intrusions, Spyware and Botnet by sessions.
Enhanced Access Point Snapshot Displaying statistics on Access Point status in the network and Client associations real-time statistics
Access Point Traffic Rate Provides real-time bandwidth usage by access-points.
WiFi Client Report Provides real-time Wi-Fi client report based on OS type, frequency and top client chart
Real-Time WiFi Client Monitor Determines the host machine, OS type, frequency, Access-Point info and data transfer.
Insights to Capture ATP verdicts Displays verdicts given for File analysis by Capture ATP.
Insights to FileTypes Displays the type of files based on Capture-ATP report.
Insights to Destination Address Displays the top destinations being used by malicious files.
Malware Analysis statistics Displays in-depth statistics on dynamic vs static malware analysis per file.
Location based zero-day Attack Displays attack origin by countries.
Origin Analysis
Capture ATP statistics Displays insights to total files submitted, dynamically analyzed files, malicious files and average processing time
using Capture ATP.
Network Topology View Topology View displaying hosts, access-points connected in user's network based on device name, mac-address
and IP Address
API Driven Management Management of the firewall is API-driven
SDWAN Wizard Wizard to automatically configure SDWAN Policy on the firewall
Notification Center New notification center with summary of threats, event logs and system alert.
Improved Online Help Online help with links to technical documentation on each and every model.
SDWAN Monitoring Displays SD-WAN Performance probes and top connections.
Enhanced Packet Monitor Utility Packet Monitor enhanced to include access rule, NAT Rule and route information.
Storage Device Configuration Configuration support of storage modules including extended modules. Module usage statistics.
Content/context Awareness
Feature Description
User activity tracking User identification and activity are made available through seamless AD/LDAP/Citrix/Terminal Services SSO
integration combined with extensive information obtained through DPI.
GeoIP country traffic identification Identifies and controls network traffic going to or coming from specific countries to either protect against attacks
from known or suspected origins of threat activity, or to investigate suspicious traffic originating from the network.
Ability to create custom country and Botnet lists to override an incorrect country or Botnet tag associated with an
IP address. Eliminates unwanted filtering of IP addresses due to misclassification.
Regular expression matching Prevents data leakage by identifying and controlling content crossing the network through regular
and filtering expression matching.
Intrusion Prevention1
Feature Description
Countermeasure-based protection Tightly integrated intrusion prevention system (IPS) leverages signatures and other countermeasures to scan
packet payloads for vulnerabilities and exploits, covering a broad spectrum of attacks and vulnerabilities.
Automatic signature updates The SonicWall Threat Research Team continuously researches and deploys updates to an extensive list of IPS
countermeasures that covers more than 50 attack categories. The new updates take immediate effect without any
reboot or service interruption required.
Intra-zone IPS protection Bolsters internal security by segmenting the network into multiple security zones with intrusion prevention,
preventing threats from propagating across the zone boundaries.
Botnet command and control (CnC) Identifies and blocks command and control traffic originating from bots on the local network to IPs and domains
detection and blocking that are identified as propagating malware or are known CnC points.
Protocol abuse/anomaly Identifies and blocks attacks that abuse protocols as they attempt to sneak past the IPS.
Zero-day protection Protects the network against zero-day attacks with constant updates against the latest exploit methods and
techniques that cover thousands of individual exploits.
Anti-evasion technology Extensive stream normalization, decoding and other techniques ensure that threats do not enter the network
undetected by utilizing evasion techniques in Layers 2-7.
Threat Prevention1
Feature Description
Gateway anti-malware The RFDPI engine scans all inbound, outbound and intra-zone traffic for viruses, Trojans, key loggers and other
malware in files of unlimited length and size across all ports and TCP streams.
Capture Cloud malware protection A continuously updated database of tens of millions of threat signatures resides in the SonicWall cloud servers
and is referenced to augment the capabilities of the onboard signature database, providing RFDPI with extensive
coverage of threats.
Around-the-clock security updates New threat updates are automatically pushed to firewalls in the field with active security services, and take effect
immediately without reboots or interruptions.
Bi-directional raw TCP inspection The RFDPI engine scans raw TCP streams on any port and bi-directionally to detect and prevent both inbound and
outbound threats.
Extensive protocol support Identifies common protocols such as HTTP/S, FTP, SMTP, SMBv1/v2 and others, which do not send data in raw TCP.
Decodes payloads for malware inspection, even if they do not run on standard, well-known ports.
Advanced Security
Feature Description
Network visibility It provides granular network visibility of network topology along with host info
Cloud management Manage firewalls via cloud through Network Security Manager tile of Capture Security Center
Cloud-based reporting Includes seven day cloud-based reporting
1
Requires added subscription
About SonicWall
SonicWall delivers stable, scalable, seamless cybersecurity for the hyper-distributed era and a work reality where everyone
is remote, mobile and unsecure. By knowing the unknown, providing real-time visibility and enabling breakthrough economics,
SonicWall closes the cybersecurity business gap for enterprises, governments and SMBs worldwide. For more information, visit
www.sonicwall.com.
SonicWall, Inc.
1033 McCarthy Boulevard | Milpitas, CA 95035
Refer to our website for additional information.
www.sonicwall.com
Datasheet-SonicOS7andServices-JK-9883