SONICWALL NSA 3600

With lowest latency and most concurrent connections in its class, the SonicWALL™ Network Security Appliance (NSA) 4600 Next-Generation Firewall (NGFW) provides enterprise-class features and uncompromising performance to secure growing medium-sized organization.

£2,895.69 (ex. VAT)

Compare

Description

The SonicWALL Network Security Appliance (NSA) Series offers excellent security and performance for emerging small and mid-size organizations. Based on the same architecture as the flagship SuperMassive Series next-generation firewall (NGFW) platforms, the NSA Series offers the ease of use and high value that emerging institutions require.

Next-generation security
The NSA Series combines Reassembly-Free Deep Packet Inspection2 (RFDPI) single-pass threat prevention engine with a powerful, scalable multi-core architecture. By combining on-the-fly SSL decryption and inspection, an intrusion prevention system (IPS) with sophisticated anti-evasion technology and a network-based malware protection system that leverages the power of the cloud, the NSA Series provides next-generation threat protection . It offers ultralow latency and among the highest number of concurrent connections and connections-per-second rates in its class .

As many as 24 specialized security cores spread the network’s load evenly, so you won’t find your performance lessening when you are exposed to heavy traffic conditions or malicious content.
RFDPI technology scans every byte.

The NSA Series uses the high-performance RFDPI technology to look at all traffic and examine every byte of every packet, regardless of port or protocol, to detect and block threats before they ever enter the network . The patented RFDPI engine helps eliminate the protection-for-performance trade-off and offers an intrusion prevention system (IPS) that features sophisticated anti-evasion technology.

Simplified structure and low costs
The NSA Series makes it easy to configure, deploy and maintain your security solutions. Quick, easy setup, excellent power efficiency and a simple, intuitive design help lower the cost of ownership.

Technical Info

Datasheet

Please see the manufacturers datasheet below for detailed information on this product and the full range of SonicWall NSA series Firewall products.

SonicWall Network Security Appliance (NSA) Firewall Series Datasheet.

 

Product Comparison – SonicWall NSA Series

Legend: S — Standard,  O — Optional,  N — Not Available

_productName NSA 6600 NSA 5600 NSA 4600 NSA 3600 NSA 2650
TotalSecure Firewall Overview
Deep Packet Inspection Firewall
TotalSecure Firewall Overview
S S S S S
Stateful Packet Inspection Firewall
TotalSecure Firewall Overview
S S S S S
Unlimited File Size Protection
TotalSecure Firewall Overview
S S S S S
Protocols Scanned
TotalSecure Firewall Overview
S S S S S
Threat Prevention Services Available
Application Intelligence and Control
Threat Prevention Services Available
S S S S S
Intrusion Prevention Service
Threat Prevention Services Available
S S S S S
Gateway Anti-Virus and Anti-Spyware
Threat Prevention Services Available
S S S S S
Content & URL Filtering (CFS)
Threat Prevention Services Available
S S S S S
SSL Inspection (DPI SSL)
Threat Prevention Services Available
S S S S S
Content Filtering Client (CFC)1
Threat Prevention Services Available
O O O O O
Analyzer Reporting1
Threat Prevention Services Available
O O O O O
Capture Advance Threat Protection1
Threat Prevention Services Available
O O O O O
Enforced Client Anti-Virus and Anti-Spyware (McAfee®)1
Threat Prevention Services Available
O O O O O
24×7 Support
Threat Prevention Services Available
S S S S S
Firewall General
Interfaces
Firewall General
4 x 10-GbE SFP+,
8 x 1-GbE SFP,
8 x 1-GbE,
1 GbE Management,
1 Console
2 x 10-GbE SFP+,
4 x 1-GbE SFP,
12 x 1-GbE,
1 GbE Management,
1 Console
2 x 10-GbE SFP+,
4 x 1-GbE SFP,
12 x 1-GbE,
1 GbE Management,
1 Console
2 x 10-GbE SFP+,
4 x 1-GbE SFP,
12 x 1-GbE,
1 GbE Management,
1 Console
4 x 2.5-GbE SFP,
4 x 2.5-GbE,
12 x 1-GbE,
1 GbE Management,
1 Console
Management
Firewall General
CLI, SSH, GUI, GMS CLI, SSH, GUI, GMS CLI, SSH, GUI, GMS CLI, SSH, GUI, GMS CLI, SSH, GUI, GMS
Nodes Supported
Firewall General
Unrestricted Unrestricted Unrestricted Unrestricted Unrestricted
Site-to-Site VPN Tunnels
Firewall General
6,000 4,000 3,000 1,000 1,000
IPSec VPN Clients (Maximum)
Firewall General
2,000 (6,000) 2,000 (4,000) 500 (3,000) 50 (1,000) 50 (1,000)
SSL VPN NetExtender Clients (Maximum)
Firewall General
2 (1,500) 2 (1,000) 2 (500) 2 (350) 2 (350)
VLAN Interfaces
Firewall General
500 400 256 256 256
Wireless Controller
Firewall General
S S S S S
WWAN Failover (4G/LTE)
Firewall General
S S S S S
Network Switch Management
Firewall General
S S S S S
Firewall/VPN Performance
Firewall Inspection Throughput2
Firewall/VPN Performance
12 Gbps 9 Gbps 6 Gbps 3.4 Gbps 3 Gbps
Full DPI Throughput (GAV/GAS/IPS)3
Firewall/VPN Performance
3 Gbps 1.6 Gbps 800 Mbps 500 Mbps 600 Mbps
Application Inspection Throughput3
Firewall/VPN Performance
4.5 Gbps 3 Gbps 2 Gbps 1.1 Gbps 1.4 Gbps
IPS Throughput3
Firewall/VPN Performance
4.5 Gbps 3 Gbps 2 Gbps 1.1 Gbps 1.4 Gbps
Anti-Malware Inspection Throughput3
Firewall/VPN Performance
3 Gbps 1.7 Gbps 1.1 Gbps 600 Mbps 600 Mbps
IMIX Throughput
Firewall/VPN Performance
3.5 Gbps 2.4 Gbps 1.6 Gbps 900 Mbps 700 Mbps
SSL DPI Throughput3
Firewall/VPN Performance
1.3 Gbps 800 Mbps 500 Mbps 300 Mbps 300 Mbps
VPN Throughput4
Firewall/VPN Performance
5 Gbps 4.5 Gbps 3 Gbps 1.5 Gbps 1.5 Gbps
Latency
Firewall/VPN Performance
16 ?s 24 ?s 17 ?s 38 ?s 38 ?s
Maximum SPI Connections
Firewall/VPN Performance
1.5M 1.5M 1M 750K 1M
Maximum DPI Connections
Firewall/VPN Performance
1M 1M 500K 375K 500K
Default/Maximum Connections (DPI SSL)5
Firewall/VPN Performance
6,000/10,500 4,000/8,500 3,000/4,500 2,000/2,750 12,000/13,500
New Connections/Sec
Firewall/VPN Performance
90,000 60,000 40,000 20,000 15,000
Features
Logging and Reporting
Features
Analyzer, Local Log, Syslog Analyzer, Local Log, Syslog Analyzer, Local Log, Syslog Analyzer, Local Log, Syslog Analyzer, Local Log, Syslog
Network Traffic Visualization
Features
S S S S S
Netflow/IPFIX Reporting
Features
S S S S S
SNMP
Features
S S S S S
Authentication
Features
LDAP (multiple domains), XAUTH/RADIUS, SSO, Novell, Terminal Services, Citrix LDAP (multiple domains), XAUTH/RADIUS, SSO, Novell, Terminal Services, Citrix LDAP (multiple domains), XAUTH/RADIUS, SSO, Novell, Terminal Services, Citrix LDAP (multiple domains), XAUTH/RADIUS, SSO, Novell, Terminal Services, Citrix LDAP (multiple domains), XAUTH/RADIUS, SSO, Novell, Terminal Services, Citrix
Dynamic Routing
Features
BGP, OSPF, RIP BGP, OSPF, RIP BGP, OSPF, RIP BGP, OSPF, RIP BGP, OSPF, RIP
Single Sign-on (SSO)
Features
S S S S S
Voice over IP (VoIP) Security
Features
S S S S S
PortShield Security
Features
S S S S S
Port Aggregation
Features
S S S S S
Link Redundancy
Features
S S S S S
Policy-based Routing
Features
S S S S S
Route-based VPN
Features
S S S S S
Dynamic Bandwidth Management
Features
S S S S S
Stateful High Availability
Features
S S S O O
Multi-WAN
Features
S S S S S
Load Balancing
Features
S S S S S
Object-based Management
Features
S S S S S
Policy-based NAT
Features
S S S S S
IKEv2 VPN
Features
S S S S S
TLS/SSL/SSH Decryption and Inspection
Features
S S S S S
SSL Control
Features
S S S S S
Auto-provision VPN
Features
S S S S S
Active/Active Cluster
Features
S S S S S
Terminal Services Authentication/Citrix Support
Features
S S S S S
Biometric Authentication
Features
S S S S S
DNS Proxy
Features
S S S S S
Harware Failover
Features
Active/Passive with State Sync, Active/Active DPI with State Sync, Active/Active Clustering Active/Passive with State Sync, Active/Active DPI with State Sync, Active/Active Clustering Active/Passive with State Sync, Active/Active Clustering Active/Passive with State Sync, Active/Active Clustering Active/Passive with State Sync
  1. Services must be purchased separately.
  2. Testing Methodologies: Maximum performance based on RFC 2544 (for firewall). Actual performance may vary depending on network conditions and activated services.
  3. Full DPI/Gateway AV/Anti-Spyware/IPS throughput measured using industry standard Spirent WebAvalanche HTTP performance test and Ixia test tools. Testing done with multiple flows through multiple port pairs.
  4. VPN throughput measured using UDP traffic at 1280 byte packet size adhering to RFC 2544.
  5. For every 125,000 DPI connections reduced, the number of available DPI SSL connections increases by 750.