SonicWall NSa 2800 Next-Generation Firewall

Highlights
- Form Factor: 1U Rackable Mounted
- Multi-gigabit Threat and Malware Analysis Throughput
- Superior TLS performance (sessions and throughput)
- Best-in-class price-performance
- Expandable storage
- Advanced DNS Filtering
- Reputation-based Content Filtering Service (CFS 5.0)
- Simplified Centralized SaaS and On-Premises management via Network Security Manager
- Wi-Fi 6 firewall management
- SonicPlatform Support
- Enterprise Internet Edge Ready
- Secure SD-WAN capability
- TLS 1.3 support
- Flexible licensing including Hardware Only, Essential, Advanced and Managed Protection Security Service
- Powered by SonicWall Capture Labs threat research team
- SonicWall Switch, SonicWave Access Point and Capture Client integration
- Cloud Secure Edge Connector Support
- Embedded Warranty up to USD$200K by Cysurance included in Service Suites
|
FIREWALL GENERAL |
|
|
NSa 2800 SERIES |
NSa 3800 SERIES |
||
|
Firewall inspection throughput |
8 Gbps |
12 Gbps |
||||
|
Threat Prevention throughput |
6 Gbps |
8 Gbps |
||||
|
Application inspection throughput |
7 Gbps |
9 Gbps |
||||
|
IPS throughput2 |
7 Gbps |
8 Gbps |
||||
|
Anti-malware inspection throughput |
6 Gbps |
8 Gbps |
||||
|
TLS/SSL inspection and decryption throughput |
1.8 Gbps |
3 Gbps |
||||
|
IPSec VPN throughput |
5.5 Gbps |
8 Gbps |
||||
|
Connections per second |
50,000 |
90,000 |
||||
|
Maximum connections (SPI) |
2,000,000 |
3,000,000 |
||||
|
Maximum connections (DPI) |
1,00,000 |
1,200,000 |
||||
|
Maximum connections (TLS) |
150,000 |
300,000 |
||||
|
VPN AND ZTNA |
||||||
|
Site-to-site VPN tunnels |
2,000 |
3,000 |
||||
|
IPSec VPN clients (max) |
10 (1000) |
50 (1000) |
||||
|
SSL VPN licenses (max) |
2 (500) |
2 (500) |
||||
|
Encryption/authentication |
DES, 3DES, AES (128, 192, 256-bit)/MD5, SHA-1, Suite B Cryptography |
|||||
|
Key exchange |
Diffie Hellman Groups 1, 2, 5, 14v |
|||||
|
Route-based VPN |
RIP, OSPF, BGP |
|||||
|
Certificate support |
Verisign, Thawte, Cybertrust, RSA Keon, Entrust and Microsoft CA for SonicWall-to-SonicWall VPN, SCEP |
|||||
|
VPN features |
Dead Peer Detection, DHCP Over VPN, IPSec NAT Traversal, Redundant VPN Gateway, Route-based VPN |
|||||
|
Global VPN client platforms supported |
Microsoft® Windows 10 and Windows 11 |
|||||
|
NetExtender |
Microsoft® Windows 10 and Windows 11, Linux |
|||||
|
Mobile Connect |
Apple® iOS, Mac OS X, Google® Android™ |
|||||
|
SonicWall Private Access powered by Cloud Secure Edge5 |
Included in 3&Free Loyalty Program |
|||||
|
SECURITY SERVICES |
||||||
|
Deep Packet Inspection services |
Gateway Anti-Virus, Anti-Spyware, Intrusion Prevention, TLS Decryption |
|||||
|
Content Filtering Service (CFS) |
Reputation-based URL filtering, HTTP URL, HTTPS IP, keyword and content scanning, Comprehensive filtering based on file types such as ActiveX, Java, Cookies for privacy, allow/forbid lists |
|||||
|
Comprehensive Anti-Spam Service |
Yes |
Yes |
||||
|
Application Visualization |
Yes |
Yes |
||||
|
Application Control |
Yes |
Yes |
||||
|
Capture Advanced Threat Protection |
Yes |
Yes |
||||
|
DNS Security |
Yes |
Yes |
||||
|
NETWORKING |
||||||
|
IP address assignment |
Static (DHCP, PPPoE, L2TP and PPTP client), Internal DHCP server, DHCP relay |
|||||
|
NAT modes |
1:1, 1:many, many:1, many:many, flexible NAT (overlapping IPs), PAT, transparent mode |
|||||
|
Routing protocols4 |
BGP, OSPF, RIPv1/v2, static routes, policy-based routing |
|||||
|
QoS |
Bandwidth priority, max bandwidth, guaranteed bandwidth, DSCP marking, 802.1e (WMM) |
|||||
|
Authentication |
LDAP (multiple domains), XAUTH/RADIUS, TACACS+, SAML SSO1, Radius accounting NTLM, internal user database, 2FA, Terminal Services, Citrix, Common Access Card (CAC) |
|||||
|
Local user database |
1000 |
|||||
|
VoIP |
Full H323-v1-5, SIP |
|||||
|
Standards |
TCP/IP, UDP, ICMP, HTTP, HTTPS, IPSec, ISAKMP/IKE, SNMP, DHCP, PPPoE, L2TP, PPTP, RADIUS, IEEE 802.3 |
|||||
|
Certifications |
Pending: IPv6 |
|||||
|
High availability |
Active/Passive with stateful synchronization |
|||||
