Sonicwall Network Security Appliance (Nsa) Series
Total Page:16
File Type:pdf, Size:1020Kb
SonicWall Network Security appliance (NSa) series Industry-validated security effectiveness and performance for mid-sized networks, distributed enterprises and data centers The SonicWall Network Security sophisticated attacks where the appliance (NSa) series provides malware’s weaponry is exposed for less organizations that range in scale from than 100 nanoseconds. In combination, mid-sized networks to distributed SonicWall’s patented* single-pass enterprises and data centers with Reassembly-Free Deep Packet advanced threat prevention in a high- Inspection (RFDPI) engine examines performance security platform. Utilizing every byte of every packet, inspecting Benefits: innovative deep learning technologies in both inbound and outbound traffic on • Superior threat prevention the SonicWall Capture Cloud Platform, the firewall. By leveraging the SonicWall and performance the NSa series delivers the automated Capture Cloud Platform in addition to • Patent-pending real-time deep real-time breach detection and on-box capabilities including intrusion memory inspection technology prevention organizations need. prevention, anti-malware and web/URL filtering, the NSa series blocks even the • Patented reassembly-free deep packet inspection technology Cutting-edge threat prevention with most insidious threats at the gateway. superior performance • On-box and cloud-based threat Further, SonicWall firewalls provide prevention Today’s network threats are highly complete protection by performing evasive and increasingly difficult to • TLS/SSL decryption and inspection full decryption and inspection of TLS/ identify using traditional methods of SSL and SSH encrypted connections • Industry-validated security detection. Staying ahead of sophisticated effectiveness regardless of port or protocol. The attacks requires a more modern firewall looks deep inside every packet • Multi-core hardware architecture approach that heavily leverages security (the header and data) searching for intelligence in the cloud. Without that • Dedicated Capture Labs threat protocol non-compliance, threats, cloud intelligence, gateway security research team zero-days, intrusions, and even defined solutions can’t keep pace with today’s Network control and flexibility criteria. The deep packet inspection complex threats. NSa series next- engine detects and prevents hidden • Secure SD-WAN generation firewalls (NGFWs) integrate attacks that leverage cryptography, • Powerful SonicOS operating two advanced security technologies to blocks encrypted malware downloads, system deliver cutting-edge threat prevention ceases the spread of infections, and that keeps your network one step ahead. • Application intelligence and control thwarts command and control (C&C) Enhancing SonicWall’s multi-engine • Network segmentation with VLANs communications and data exfiltration. Capture Advanced Threat Protection Inclusion and exclusion rules allow total • High-speed wireless security (ATP) service is our patent-pending control to customize which traffic is Real-Time Deep Memory Inspection Easy deployment, setup and subjected to decryption and inspection (RTDMI™) technology. The RTDMI ongoing management based on specific organizational engine proactively detects and blocks • Zero-Touch Deployment compliance and/or legal requirements. mass market, zero-day threats and • Cloud-based and on-premises unknown malware by inspecting When organizations activate deep packet centralized management directly in memory. Because of the inspection functions such as IPS, anti- • Scalable line of firewalls real-time architecture, SonicWall RTDMI virus, anti-spyware, TLS/SSL decryption/ • Low total cost of ownership technology is precise, minimizes false inspection and others on their firewalls, positives, and identifies and mitigates *U.S. Patents 7,310,815; 7,600,257; 7,738,380; 7,835,361; 7,991,723 network performance often slows down, while non-essential applications are Easy deployment, setup and sometimes dramatically. NSa series bandwidth-limited. Real-time monitoring ongoing management firewalls, however, feature a multi-core and visualization provides a graphical Like all SonicWall firewalls, the NSa hardware architecture that utilizes representation of applications, users and series tightly integrates key security, specialized security microprocessors. bandwidth usage for granular insight connectivity and flexibility technologies Combined with our RTDMI and RFDPI into traffic across the network. into a single, comprehensive solution. engines, this unique design eliminates This includes SonicWave wireless the performance degradation networks For distributed organizations requiring access points and the SonicWall WAN experience with other firewalls. advanced flexibility in their network design, the SD-WAN technology in Acceleration (WXA) series, both of Network control and flexibility SonicOS is a perfect complement to NSa which are automatically detected firewalls deployed at the headquarters and provisioned by the managing At the core of the NSa series is SonicOS, or at remote and branch sites. Instead NSa firewall. Consolidating multiple SonicWall’s feature-rich operating of relying on more expensive legacy capabilities eliminates the need to system. SonicOS provides organizations technologies such as MPLS and T1, purchase and install point products that with the network control and flexibility organizations using SD-WAN can don’t always work well together. This they require through application choose lower-cost public Internet reduces the effort it takes to deploy the intelligence and control, real-time services while continuing to achieve a solution into the network and configure visualization, an intrusion prevention high level of application availability and it, saving both time and money. system (IPS) featuring sophisticated predictable performance. anti-evasion technology, high-speed Cloud-based centralized management, virtual private networking (VPN) and Built into every NSa series firewall is a reporting, licensing and analytics are other robust security features. wireless access controller that enables handled through the SonicWall Capture organizations to extend the network Security Center. A key component of the Using application intelligence and perimeter securely through the use of Capture Security Center is Zero-Touch control, network administrators can wireless technology. Together, SonicWall Deployment. This cloud-based feature identify and categorize productive firewalls and SonicWave 802.11ac simplifies and speeds the deployment applications from those that are Wave 2 wireless access points create and provisioning of SonicWall firewalls unproductive or potentially dangerous, a wireless network security solution at remote and branch office locations. and control that traffic through powerful that combines industry-leading next- Together, the simplified deployment application-level policies on both a per- generation firewall technology with and setup along with the ease of user and a per-group basis (along with high-speed wireless for enterprise-class management enable organizations to schedules and exception lists). Business- network security and performance lower their total cost of ownership and critical applications can be prioritized across the wireless network. realize a high return on investment. and allocated more bandwidth Secure, High-speed Wireless Combine an NSa series next-generation firewall with a SonicWall SonicWave 802.11ac Wave 2 wireless access point to create a high-speed wireless network security solution. NSa series firewalls and SonicWave access points both feature 2.5 GbE ports that enable multi-gigabit wireless throughput offered in Wave 2 wireless technology. The firewall scans all wireless traffic coming into and going out of the network using deep packet inspection technology and then removes harmful threats such as malware and intrusions, even over encrypted connections. Additional security and control capabilities such as content filtering, application control and intelligence and Capture Advanced Threat Protection can be run on the wireless network to provide added layers of protection. 4 x 2.5GbE 1 x 2.5GbE 4 x 2.5GbE ports SFP ports Bi-directional scanning SonicWall NSa 5650 SonicWall SonicWave 432i 2 Capture Cloud Platform on the appliance protect against wide In addition to providing threat classes of attacks, covering tens of prevention, the Capture Cloud Platform SonicWall's Capture Cloud Platform thousands of individual threats. In offers single pane of glass management delivers cloud-based threat prevention addition to the countermeasures on and administrators can easily create and network management plus reporting the appliance, NSa firewalls also have both real-time and historical reports on and analytics for organizations of any continuous access to the Capture Cloud network activity. size. The platform consolidates threat Platform database which extends the intelligence gathered from multiple onboard signature intelligence with tens sources including our award-winning of millions of signatures. multi-engine network sandboxing service, Capture Advanced Threat Protection, as well as more than 1 million SonicWall sensors located around the globe. If data coming into the network is found to contain previously-unseen malicious code, SonicWall’s dedicated, in-house Capture Labs threat research team develops signatures that are stored in the Capture Cloud Platform database and deployed to customer firewalls for up-to-date protection. New