SonicWall NSv 270
Earn 1,620 points when you buy me!
Earn 1,620 points when you buy me!
SonicWall Network Security virtual (NSv) series brings SonicWall’s industry leading Next-Generation Firewall (NGFW) capabilities to protect your workloads in the cloud from threats, with automated, real-time breach detection and protection. Manage consistent security policies centrally from a single pane of glass across cloud and on-prem environments.
-Leverage Real-Time Deep Memory Inspection (RTDMITM) & Reassembly-Free Deep Packet Inspection (RFDPI®).
-Stop zero-day threats with Capture ATP multi-engine sandboxing.
-Block viruses, spyware, malware, intrusions, encrypted threats, malicious apps and websites.
-Gain VPN and network segmentation capability.
-Attain platform support across hybrid and multi-cloud environments.
-Secure workloads on Amazon Web Services (AWS) and Microsoft Azure.
-Appropriately scale and right-size your infrastructure.
-Help adhere to compliance standards and policies.
-Gain complete visibility and control of traffic across multiple regions and availability zones.
-Attain cost benefit and efficiency by shifting from CAPEX to OPEX model.
-Secure workloads on VMware ESXi, Microsoft Hyper-V and KVM.
-Prevent threats with complete visibility into intra-host communication between virtual machines.
-Ensure appropriate application of security policies throughout the virtual environment.
-Prevent unauthorized takeover of virtual systems.
-Stop unauthorized access to protected data assets.
-Block malicious and intrusive actions, such as spreading malware, executing operating system commands, file system browsing and C&C communication.
-Prevent service disruption of any part or of the entire virtual ecosystem.
-Group similar interfaces, and apply the same policies across them.
-Strictly control access to critical internal resources.
-Automatically restrict segmentation based upon dynamic criteria, such as identity, geo-IP and the security stature of mobile endpoints.
-Effortlessly integrate multi-gigabit network switching into security enforcement policy.
-Deploy over a wide variety of virtualized and cloud platforms for various private and public cloud security use cases.
-Ensure system resiliency, service reliability and regulatory conformance.
-Easily adapt to service-level changes, and ensure VMs and their application workloads and data assets are available, as well as secure.
-Enhance system scalability, operational agility, provisioning speed, management simplicity and cost reduction.
Operating System | SonicOSX 7.0 |
Supported Hypervisors | VMware ESXi, Microsoft Hyper-V, KVM |
Supported Public Cloud Platforms | AWS*, Azure* |
Licensing | BYOL, PAYG |
SSO Users | 500 |
Firewall Inspection Throughput | 6 Gbps |
Application Inspection Throughput | N/A |
IPS Throughput | 4 Gbps |
Anti-Malware Inspection Throughput | N/A |
VPN Throughput | 1.4 Gbps |
Maximum Connections | 225,000 |
Site-to-Site VPN Tunnels | 75 |
IPSec VPN Clients (Maximum) | 50 (1000) |
SSL VPN Clients Included | 2 |
SSL VPN Clients Maximum | 100 |
Firewall Inspection Throughput | 6 Gbps |
Threat Prevention Throughput | 1.6 Gbps |
IPS Throughput | 4 Gbps |
TLS/SSL DPI Throughput | 800 Mbps |
VPN Throughput | 1.4 Gbps |
Connections per second | 13,760 |
Maximum connections (SPI) | 225,000 |
Maximum connections (DPI) | 125,000 |
TLS/SSL DPI Connections | 8,000 |
Site-to-Site VPN Tunnels | 75 |
IPSec VPN Clients (Max) | 50 (1,000) |
SSL VPN Clients Included | 2 |
SSL VPN Clients Maximum | 100 |
Encryption/Authentication | DES, 3DES, AES (128, 192, 256-bit)/MD5, SHA-1, Suite B, Common Access Card (CAC) |
Key Exchange | Diffie Hellman Groups 1, 2, 5, 14v |
Route-Based VPN | RIP, OSPF, BGP |
IP Address Assignment | Static, DHCP, internal DHCP server, DHCP relay |
NAT Modes | 1:1, many:1, 1:many, flexible NAT (overlapping IPs), PAT |
Logical VLAN and Tunnel Interfaces (Max) | 128 |
Routing Protocols | BGP, OSPF, RIPv1/v2, static routes, policy-based routing |
QoS | Bandwidth priority, max bandwidth, guaranteed bandwidth, DSCP marking, 802.1p |
Authentication | XAUTH/RADIUS, Active Directory, SSO, LDAP, Novell, internal user database, Terminal Services, Citrix |
Local User Database | 250 |
|
|
|
Global control over | Centralized control of IPv6 visibility Globally disabling IPv6 traffic processing Disabling default VPN policies, configuration screens, and autogenerated rules |
Login and user security | User lockout based on login attempts by IP address range User lockout from CLI Force password change on the first login Two-factor authentication (TOTP) support Guest user policy zero-touch portal support Guest service IPv6 support TACACS+ accounting support Quota control for all users Dynamic botnet HTTP authentication |
Networking and system | SD-WAN support DNS security / DNS sinkhole support FQDN over TCP DNS FQDN address objects for NAT DHCPv6 relay IPv6 addressing mode for H.323 VoIP application layer gateway Multiple control plane (CP) core support HTTP/HTTPS redirection with data plane offload IP helper offload to data plane Firmware backup on local storage High availability encryption High availability firmware upload support Policy based routing optimization of static and dynamic routes Performance/throughput improvements Watchdog feature to monitor firewall health Enhanced scalability for advanced routing over VPN numbered tunnel interfaces Update H.323 libraries based on OSS Noklava v10.5.0 ASN.1 compiler Task thread priority updates SSLVPN and bookmark on Data Plane |
Security services | Capture ATP block until verdict granular control Capture ATP friendly filename display for non-HTTP protocols CFS blocking of individual YouTube videos Support HTTPS content filtering and DPI-SSL together Next gen anti-virus (SentinelOne) and DPI-SSL enforcement Wan DDOS protection performance enhancement |
Policies / objects | Access rule enhancements App based routing Dynamic address objects CFS policy exclusion Policy based HTTPS content filter objects URI list groups support in content filter objects CFS custom header insertion for HTTP requests UUID for rules and objects UUID for CFS policies Source MAC override for NAT policies |
DPI-SSL / DPI-SSH | DPI-SSL dynamic cloud based white list DPI-SSH blocking of SSH port forwarding DPI-SSH blocking of X11 forwarding SSL decryption port preservation in packet mirror / packet capture DPI-SSL granular control per zone Access rules based DPI-SSL control DPI-SSL client block or allow expired CA certificates TLS certificate status request extension Support for local CRL Enhanced DPI-SSL certificate verification Support for ECDSA-related ciphers OpenSSL LTS release support for federal certification |
Logging, monitoring and reporting | Ability to verify that DPI was performed on a specific packet Filename and URI logging for app control Logon records displayed for administrator Configuration auditing Logging of NAT mapping for TCP connections FTP support for log automation Capture Security Center (CSC) reporting & analytics support for NSv Capture ATP logging of email sender/ recipient Capture threat assessment client enhancements (SWARM v3) Function to reset the SFR (SWARM) statistical data Option to select output language for SonicFlow report |
API | SonicOS API phase 1 SonicOS API authentication support SonicOS API phase 2 LHM RESTful API |
SonicOS web management UI | SonicOS global search Usability improvements for content pages Per user client side UI preferences storage Pin friendly name to SonicOS web management screens Refactored SonicOS web interface layout |
SonicWall NSv 800 Virtual Appliance TotalSecure Advanced Edition (1-year) | ESXI SKU:01-SSC-6101 HYPER-V SKU:02-SSC-1429 AZURE SKU:02-SSC-0889 AWS SKU:02-SSC-0914 KVM SKU:02-SSC-3533 |
SonicWall NSv 800 Virtual Appliance TotalSecure Advanced Edition (3-year) | ESXI SKU:01-SSC-6102 HYPER-V SKU:02-SSC-1428 AZURE SKU:02-SSC-0891 AWS SKU:02-SSC-0913 KVM SKU:02-SSC-3538 |