The SonicWALL® E-Class Network Security Appliance (NSA) Series is an industry first—using a re-assembly free deep packet inspection engine in combination with multi-core specialized security microprocessors to deliver gateway anti-virus, anti-spyware and intrusion prevention at high-speed so you don’t have to sacrifice network performance.
Features of NSA E5500
Deep Packet Inspection & Multi-Threat Protection
» Fully integrated deep packet inspection firewall, including gateway anti-virus, anti-spyware, intrusion prevention, and application firewall for perimeter and internal protection
» Application Firewall feature-set for Application inspection and control
» Automated and Dynamic Security Updates
Powerful Performance
» High-performance 8-core Multi-Core Architecture
» 2.0 Gbps Stateful Packet Inspection Firewall
1
» 1.5 Gbps 3DES and AES VPN Throughput
1
» 400 Mbps Full Unified Threat Management (UTM) Inspection
» Eight (8) 10/100/1000 Copper Gigabit Ethernet interfaces
Enterprise Networking & Complete Business Continuity
» Business application prioritization & QoS
» Highly Redundant Hardware - Fans
» Stateful Hardware Failover, ISP Failover, and WAN Redundancy
» Integrated Server Load Balancing Feature-set
Integration & Simplified Maanaagement
» Integrated Network Security Policy and Management
» Next-Generation Streamlined GUI
» Powerful Wizards - Set-up, Firewall Policies, VPN, NAT
» Front panel controls and LCD display provides easy network deployment and integration
Deployment Flexibility
» Data Center, Campus and Department Network Applications
» Transparent L2 Bridge Mode
» Integrated Wireless Switch Deployment
Flexible, Customizable Deployment Options:
Central-site Gateway: Deployed as a Central-site Gateway the NSA Series provides a high-speed scalable platform, providing network segmentation and security using VLAN’s and security zones. Redundancy features include WAN Load balancing, ISP fail-over and stateful high availability.
Layer 2 Bridge: Mode Layer 2 bridge mode provides inline intrusion detection and prevention, adds an additional level of zone-based security to network segments or business units and simplifies layered security. Additionally, this enables administrators to limit access to sensitive data by specific business unit or database server.
Multi-layer Protection:
Remote Site Protection: The E-Class NSA Series incorporates ultra-high performance Virtual Private Networks (VPNs) that easily scales to thousands of end points and branch offices. Innovative SonicWALL Clean VPN™ technology prevents vulnerabilities and malicious code by decontaminating traffic before it enters the corporate network, in real time and without user intervention.
Gateway Protection: Easily integrated into existing environments, E-Class NSAs centralize gateway-level protection across all incoming and outgoing applications, files and content-based traffic, while controlling bandwidth and applications, without significantly impacting performance or scalability.
Internal Protection: The highly-configurable E-Class NSA Series extends protection over the internal network by inspecting traffic over LAN interfaces and VLANs. Specifically designed for LAN network threats, the E-Class NSA Series monitors and responds to internally spreading malware, denial of service attacks, exploited software vulnerabilities, confidential documents, policy violations and network misuse.
Desktop and Server Protection: In addition to network and gateway based protection, the E-Class NSA Series provides additional end point protection for workstations and servers through an enforced anti-virus and antispyware client with advanced heuristics. This enforced client solution delivers network access control by restricting Internet access on end points that do not have the latest signature or engine updates. When enforcement is enabled on the appliance, each end point is directed to download the enforced anti-virus and anti-spyware client without any administrator intervention, automating the deployment of end point security.
Centralized Policy Management: The SonicWALL Global Management System (GMS) provides flexible, powerful and intuitive tools to centrally manage E-Class NSA configurations across distributed enterprises, view real-time monitoring metrics and integrate policy and compliance reporting.
Technical Specification for NSA E5500:
| Features |
| Nodes Supported | Unrestricted |
| SonicOS Version | SonicOS Enhanced 5.0 |
| Stateful Throughput* | 2 Gbps |
| GAV Performance | 750 Mbps |
| IPS Performance | 550 Mbps |
| UTM Throughput | 400 Mbps |
| Connections | 700,000 (Max) |
| Denial of Service Attack Prevention | 22 classes of DoS, DDoS and scanning attacks |
| SonicPoints Supported | 96 |
| VPN |
| 3DES/AES Throughput* | 1.5 Gbps |
| Encryption | DES, 3DES, AES (128, 192, 256-bit), MD5, SHA-1 |
| Site-to-Site Performance | 4,000 |
| Licenses | 2,000 (4,000) |
| Key Exchange | IKE, IKEv2, Manual Key, PKI (X.509) |
| L2TP/IPsec | Yes |
| Certificate Support | Verisign, Thawte, Cybertrust, RSA Keon, Entrust, and Microsoft CA for SonicWALL-to-SonicWALL VPN |
| Redundant VPN Gateway | Yes |
| Global VPN Client Platforms Supported | Microsoft® Windows 2000, Windows XP, Microsoft® Vista 32-bit |
| Networking |
| IP Address Assignment | Static, (DHCP, PPPoE, L2TP and PPTP client), Internal DHCP server, DHCP relay |
| NAT Modes | 1:1, 1:many, many:1, many:many, flexible NAT (overlapping IPs), PAT, transparent mode |
| Policy-based Routing | OSPF, RIPv1/v2, static routes, policy-based routing, Multicast |
| QoS | Bandwidth priority. maximum bandwidth, guaranteed bandwidth, DSCP marking, 802.1p |
| Authentication | XAUTH/RADIUS, Active Directory, SSO, LDAP, internal user database |
| User Database | 1,500 |
| VoIP | Full H.323v1-5, SIP, gatekeeper support, outbound bandwidth management, VoIP over WLAN, deep inspection security, full interoperability with most VoIP gateway and communications devices |
| System |
| Standards | TCP/IP, UDP, ICMP, HTTP, HTTPS, IPSec, ISAKMP/IKE, SNMP, DHCP, PPPoE, L2TP, PPTP, RADIUS |
| Management and Monitoring | Web GUI (HTTP, HTTPS), Command Line (SSH, Console), SNMP v2: Global management with SonicWALL GMS |
| Logging and Reporting | ViewPoint, Local Log and Syslog |
| Load Balancing | Yes, (Outgoing with percent-based, round robin and spill-over) (Incoming with round robin, random distribution, sticky IP, block remap and symmetrical remap |
| High Availability | Active/Passive with State Sync |
| Hardware |
| Interfaces | (8) 10/100/1000 Copper Gigabit Ports, 1Gbe HA Interface, 1 Console Interface, 2 USB (Future Use) |
| Memory | 1 GB |
| Flash Memory | 512 MB Compact Flash |
| Power Supply | Single 250W ATX Power Supplies |
| Max Power Consumption | 81 W |
| Total Heat Dissipation | 276 BTU |
| Certifications (Pending) | ICSA Firewall 4.1 |
| Dimensions | 17 x 16.75 x 1.75 in/43.18 x 42.54 x 4.44 cm |
| Weight | 15.00 lbs/ 6.80 kg |
| Major Regulatory Compliance | FCC Class A, CES Class A, CE, C-Tick, VCCI, Compliance MIC, UL, cUL, TUV/GS, CB, NOM, RoHS, WEEE |
| Environment | 40-105° F, 5-40° C |
1Firewall and VPN throughput measured using UPD traffi c adhering to RFC 2544.
2Gateway AV/Anti-Spyware/IPS throughput measured using industry standard Spirent WebAvalanche HTTP Performance test.
SonicWALL TotalSecure
SonicWALL® TotalSecure delivers the convenience of all-in-one network protection by combining gateway anti-virus, anti-spyware intrusion prevention, content filtering, firmware updates and 24X7 support onto a high-performance deep packet inspection firewall, creating a powerful, single security solution. Even before new threats begin to spread, TotalSecure solutions are automatically updated with signatures that stop attacks before they can enter the network, ensuring around-the-clock protection. TotalSecure provides complete network security against threats including viruses, spyware, worms, Trojans and more, yet it is simple to install and manage.
Convenient Security Package
SonicWALL TotalSecure removes the complexity associated with choosing between a host of point products and add-on services by integrating comprehensive network security in a convenient and affordable package. Every TotalSecure solution includes:
• Gateway Anti-Virus, Anti-Spyware and Intrusion Prevention Service subscription (1 year)
• Application Intelligence subscription included on TZ 210, NSA and E-Class NSA Series (1 year)
• Content Filtering Service subscription - Standard Edition on TZ 180 Series and Premium Business Edition on TZ 100, TZ 200, TZ 210, NSA and E-Class NSA Series (1 year)
• 24x7 Support subscription (1 year)
• ViewPoint reporting software
• SonicWALL deep packet inspection network security appliance (wired and wireless options)
Tangible Results
SonicWALL TotalSecure makes it easy to:
• Eliminate viruses, worms and Trojans
• Block spyware, adware, keyloggers, malicious mobile code (MMC) and other dangerous applications
• Protect networks against intrusions from hackers and bots
• Filter access to unproductive, inappropriate and illegal objectionable content
• Restrict recreational file-sharing, multimedia streaming and downloading from peer-to-peer applications
• Implement comprehensive security measures with a single installation
• View reports on threats and activities
• Securely access your office network from a remote location