The SonicWALL®
E-Class Network Security Appliance (NSA) Series provides Next-Generation Firewall protection
and advanced application control for the most demanding networks.
Deep Packet Inspection Engine - capable of configurable, high-performance scanning across all ports including Web traffic, email, file transfers, Windows services and DNS.
ICSA-Certified Stateful Packet Inspection Firewall (Pending) - ensuring industry-standard integrity and validity for each connection, packet, source and destination.
Comprehensive Security - including Comprehensive Anti-Spam Service, Gateway Anti-Virus, Anti-Spyware, Intrusion and Prevention Service, Enforced Client Anti-Virus and Content Filtering Service (Premium Business Edition).
SSL and IPSec VPN Clients – provide remote and mobile employees with secure remote access to resources on the corporate LAN from virtually any location.
SonicWALL PortShield - provides the flexibility to configure port level security for the LAN, delivering protection not only from the WAN and DMZ, but also between devices inside the LAN.
Voice and Video over IP - offers high-performance standards-based security for voice (audio), streaming video and other latency-sensitive media over IP-based networks.
| Firewall Overview | NSA E8510 | NSA E8500 | NSA E7500 | NSA E6500 | NSA E5500 |
|---|---|---|---|---|---|
| Deep Packet Inspection Firewall | O | O | O | O | O |
| Stateful Packet Inspection Firewall | S | S | S | S | S |
| Unlimited File Size Protection | S | S | S | S | S |
| Protocols Scanned | 50+ | ||||
| ICSA Firewall Certified | Pending | Pending | S | S | S |
| Security Services Included | NSA E8510 | NSA E8500 | NSA E7500 | NSA E6500 | NSA E5500 |
| Application Intelligence and Control1 | O | O | O | O | O |
| Intrusion Prevention Service1 | O | O | O | O | O |
| Gateway Anti-Virus and Anti-Spyware1 | O | O | O | O | O |
| Enforced Client Anti-Virus and Anti-Spyware1 | O | O | O | O | O |
| Content & URL Filtering (CFS)1 | O | O | O | O | O |
| ViewPoint Reporting1 | O | O | O | O | O |
| Comprehensive Anti-Spam Service1 | O | O | O | O | O |
| SSL Inspection (DPI SSL)1 | S | S | O | O | O |
| E-Class 24x7 Support | Required | ||||
| Firewall General | NSA E8510 | NSA E8500 | NSA E7500 | NSA E6500 | NSA E5500 |
| Interfaces | 2 SFP+ 10 GbE, 4 GbE, 1 HA, 2 USB | 4 GbE, 4 SFP, 1 HA, 2 USB | 4 GbE, 4 SFP, 1 HA, 2 USB | 8 GbE, 1 HA, 2 USB | 8 GbE, 1 HA, 2 USB |
| Management | CLI, SSH, GUI, GMS | ||||
| Certifications | VPNC | VPNC | EAL4+, FIPS 140-2, VPNC, ICSA Firewall 4.1 | EAL4+, FIPS 140-2 , VPNC , ICSA Firewall 4.1 | EAL4+, FIPS 140-2 , VPNC, ICSA Firewall 4.1 |
| Nodes Supported | Unrestricted | ||||
| RAM | 4 GB | 4 GB | 2 GB | 1 GB | 1 GB |
| Flash Memory | 512 MB | ||||
| Visual Information Display (LCD Display) | S | S | S | S | S |
| Site-to-Site VPN Tunnels | 10000 | 10000 | 10000 | 6000 | 4000 |
| Global VPN Clients (Maximum) | 2,000 (10,000) | 2,000 (10,000) | 2,000 (10,000) | 2,000 (6,000) | 2,000 (4,000) |
| SSL VPN NetExtender Clients (Maximum) | 2 (50) | ||||
| Virtual Assist Technicians (Maximum) | 1 (25) | ||||
| Unique Malware Threats Blocked | 1,000,000+ | ||||
| VLAN Interfaces | 512 | 512 | 512 | 256 | 256 |
| SonicPoints Supported (Maximum) | 128 | 128 | 128 | 128 | 96 |
| Firewall/VPN Performance | NSA E8510 | NSA E8500 | NSA E7500 | NSA E6500 | NSA E5500 |
| Stateful Throughput2 | 8.0 Gbps | 8.0 Gbps | 5.6 Gbps | 5.0 Gbps | 3.9 Gbps |
| Full DPI Performance3 | 2.2 Gbps | 2.2 Gbps | 1.7 Gbps | 1.59 Gbps | 850 Mbps |
| Gateway Anti-Virus Throughput3 | 2.25 Gbps | 2.25 Gbps | 1.84 Gbps | 1.69 Gbps | 1.0 Gbps |
| Intrusion Prevention Throughput3 | 3.7 Gbps | 3.7 Gbps | 2.58 Gbps | 2.3 Gbps | 2.0 Gbps |
| IMIX Performance3 | 2.0 Gbps | 2.0 Gbps | 1.6 Gbps | 1.4 Gbps | 1.1 Gbps |
| 3DES/AES VPN Throughput4 | 4.0 Gbps | 4.0 Gbps | 3.0 Gbps | 2.7 Gbps | 1.7 Gbps |
| Maximum Connections5 | 1500000 | 1500000 | 1500000 | 1000000 | 750000 |
| Maximum DPI Connections | 1250000 | 1250000 | 1000000 | 600000 | 500000 |
| New Connections/Sec | 80000 | 80000 | 25000 | 20000 | 15000 |
| Features | NSA E8510 | NSA E8500 | NSA E7500 | NSA E6500 | NSA E5500 |
| Logging | ViewPoint, Local Log, Syslog | ||||
| Network Traffic Visualization | S | S | S | S | S |
| Netflow/IPFIX Reporting | S | S | S | S | S |
| SNMP | S | S | S | S | S |
| Authentication | XAUTH/ RADIUS, Active Directory, SSO, LDAP, Terminal Services, Citrix, Internal User Database | ||||
| Dynamic Routing | OSPF, RIP | ||||
| Single Sign-on (SSO) | S | S | S | S | S |
| Voice over IP (VoIP) Security | S | S | S | S | S |
| Interface to Interface Scanning | S | S | S | S | S |
| PortShield Security | S | S | S | S | S |
| Port Aggregation | S | S | S | S | S |
| Link Redundancy | S | S | S | S | S |
| Policy-based Routing | S | S | S | S | S |
| Route-based VPN | S | S | S | S | S |
| Dynamic Bandwidth Management | S | S | S | S | S |
| 802.11n Wireless Support via SonicPoints | S | S | S | S | S |
| Integrated Wireless Switch & Controller | S | S | S | S | S |
| Layer 2 Wireless Bridging | S | S | S | S | S |
| Stateful High Availability | S | S | S | S | S |
| Multi-WAN | S | S | S | S | S |
| Load Balancing | S | S | S | S | S |
| Object-based Management | S | S | S | S | S |
| Policy-based NAT | S | S | S | S | S |
| Inbound Load Balancing | S | S | S | S | S |
| IKEv2 VPN | S | S | S | S | S |
| Active/Active UTM | S | S | S | S | S |
| Terminal Services Authentication/Citrix Support | S | S | S | S | S |
| Onboard Quality of Service (QoS) | S | S | S | S | S |
| SSL Control | S | S | S | S | S |
| IPv6 | S | S | S | S | S |
| Failover | NSA E8510 | NSA E8500 | NSA E7500 | NSA E6500 | NSA E5500 |
| Hardware Failover | Active/Passive with State Sync, Active/Active DPI with State Sync | ||||
| Multi-WAN Failover | S | S | S | S | S |
| Automated Failover/Failback | S | S | S | S | S |
| Analog Modem Failover | S | S | S | S | S |
| 3G Cellular Modem Failover6 | S | S | S | S | S |
Services must be purchased separately.
Testing Methodologies: Maximum performance based on RFC 2544 (for firewall). Actual performance may vary depending on network conditions and activated services.
DPI/Gateway AV/Anti-Spyware/IPS throughput measured using industry standard Spirent WebAvalanche HTTP performance test and Ixia test tools. Testing done with multiple flows through multiple port pairs.
VPN throughput measured using UDP traffic at 1280 byte packet size adhering to RFC 2544.
Actual maximum connection counts are lower when UTM services are enabled.
USB 3G card and modem are not included.
|
|
|