
For security teams that have invested in SonicWall's next-generation firewall stack, Capture ATP is among the most valued capabilities in the portfolio. Its multi-engine sandbox approach consistently earns top scores in third-party testing and provides on-network users with robust protection against unknown and zero-day file-based threats. However, that protection has always carried an implicit condition: the user must be on the network.
Although EDR tools do accompany the device and offer a vital last line of defense, detection and response inherently rely on the threat having already reached the endpoint. A more robust approach is to prevent threats from reaching the device in the first place. Blocking a malicious file at the network layer, before it executes, is fundamentally better than detecting and fixing it after the damage is done.
SonicWall Cloud Secure Edge (CSE) addresses this directly. Through its Secure Internet Access (SIA) capability, CSE extends the same Capture ATP engine that powers your firewall to every device, regardless of where it connects. The inspection point moves from the network edge to the cloud, ensuring that users connecting from home offices, hotel lobbies, or co-working spaces receive the same (and in some cases stronger) layered file protection as those sitting inside the corporate perimeter.
On a SonicWall next-generation firewall, Capture ATP intercepts files passing through the network and submits them for analysis in a cloud-based, multi-engine sandbox. Files that cannot be immediately classified as clean are held while analysis runs in parallel across multiple environments. The result is a verdict: clean, malicious, or unknown.
This approach is highly effective for traffic that transits the firewall. Content filtering, geo-blocking, botnet protection, and DPI-SSL inspection all operate at the same inspection point, creating a layered security posture for on-network users.
The limitation is architectural, not technical. The firewall inspects traffic at the network edge. When a user is off-network, that edge is no longer in the path.
CSE's Secure Internet Access capability repositions the inspection point from the network edge to the endpoint itself. The CSE agent proxies outbound web traffic through SonicWall's cloud-delivered security stack, regardless of the user's physical location or network connection.
This means the same layers of protection available on the firewall (DNS filtering, URL-level inspection, content categorization, geo-blocking, and now Capture ATP file analysis) travel with the user. The security posture does not degrade when a device leaves the office.
Integrating Capture ATP into CSE involved more than just rerouting traffic through the same engine. It was also a chance to introduce features that are only feasible in an agent-based delivery model.
The on-firewall Capture ATP implementation applies a 10 MB file size limit for sandboxed analysis. Files larger than this threshold pass through without deep file inspection. In practice, this is a meaningful gap: software installers, archive files, and documents with embedded media frequently exceed 10 MB. CSE raises this ceiling to 100 MB, substantially expanding the population of files eligible for analysis.
A significant portion of files delivered over the web are compressed into ZIP archives, gzip-encoded content, and similar container formats. The on-firewall implementation treats these as containers, limiting visibility into their contents.
CSE performs file decompression prior to analysis, unpacking compressed payloads and submitting the underlying files for inspection individually. Internal benchmarking showed that enabling decompression more than doubled the number of eligible files identified for analysis. In this case, CSE is not simply matching the firewall's coverage on a larger scale; it is materially expanding it.
Even at the expanded 100 MB limit, some files will exceed the threshold for full sandbox analysis. For these, CSE performs hash-based reputation checks against SonicWall's threat intelligence database. This provides an additional layer of protection: known malicious files are blocked based on their signature regardless of size, and the overall coverage gap is significantly reduced.
CSE surfaces real-time status to the user through the agent. When a file is being submitted for analysis, the user sees an in-app notification. When a verdict is returned and a file is blocked, the user receives a clear explanation. This improves the operational experience without any additional configuration by the administrator.
Standard file inspection proxies can disrupt the download process during analysis. This may lead to corruption in application-level transfers, like software updates or file sync agents, which require a complete file at a designated path. CSE instead uses connection-preserving throttling, trickling bytes to the application at a controlled rate while analysis runs in parallel. If the file is clean, delivery completes normally. If it is malicious, the socket is terminated. Application compatibility is preserved without sacrificing inspection coverage.
Certificate management is another area where CSE reduces administrative overhead. DPI-SSL inspection on a firewall requires manually generating, deploying, and renewing SSL certificates, a recurring task that carries the risk of silent inspection lapses when certificates expire. CSE automates the full certificate lifecycle. Capture ATP file inspection is similarly straightforward: a single toggle in the management console enrolls all eligible file types, with no per-type configuration required.
CSE retains a full log of analyzed files for 12 months. Each log entry captures file metadata, submission timestamps, analysis verdicts, and disposition outcomes. In the event of a security incident, this record provides the forensic continuity that auditors and IT teams require — without relying on reconstructed data or manual tracking. Retention is automatic and requires no additional configuration.
It's important to differentiate CSE's method of securing remote users from that of endpoint detection and response (EDR) platforms. EDR operates on the device itself, monitoring process behavior, file execution, and system activity to detect and respond to threats that have already landed on the endpoint. It is a powerful and necessary layer of defense. CSE operates earlier in the chain by inspecting files and web traffic before they reach the device. Rather than identifying a malicious file after it executes, CSE aims to prevent it from arriving in the first place. The two capabilities are complementary: CSE reduces the volume of threats that EDR has to contend with, and EDR provides a backstop for anything that gets through. Together, they reflect a defense-in-depth posture that does not rely on any single layer to carry the full burden and provides visibility no one tool can.
For organizations already running SonicWall next-generation firewalls, CSE SIA is not a departure from an established security strategy but rather an extension of one. The same Capture ATP engine, the same threat intelligence, and the same layered inspection philosophy that protects users on the network now follow them off it.
Request a demo of Cloud Secure Edge today and extend the same protection your network relies on to every user, everywhere.
Share This Article

An Article By
An Article By
Sheldon Rezendes
Product Manager
Sheldon Rezendes
Product Manager
Sheldon Rezendes heads up Cloud Secure Edge's Secure Internet Access from a Product Management perspective. His background includes a variety of roles centered on network, endpoint and platform security. He is passionate about the evolution of security and helping customers through all stages of their cloud journey.

Amelia Foss
Product Marketing Specialist
Amelia Foss
Product Marketing Specialist