by Asif Mujtaba

SonicWall is releasing SonicOS 7.3.3 for GEN7 appliances, which includes a set of changes that directly affect how you manage, protect, and grow your customer base. From a new Generative AI content filtering category to credential security enabled out of the box, SonicOS 7.3.3 is designed to help MSPs and channel partners deliver stronger security with less configuration overhead.
This guide covers every significant change in the release, what it means for your practice, and the specific actions you should take before and after upgrading.
| Feature | Who It Affects | Recommended Action |
| Generative AI CFS Category | All MSPs managing CFS-subscribed customers | Review and update CFS policies post-upgrade |
| Self-Harm, DNS-over-HTTPS (DoH), Low-THC Categories | Education, healthcare, and regulated industries | Enable categories relevant to each customer segment |
| Credential Auditor (on by default) | All GEN7 customers are being upgraded | Set customer expectations before upgrading |
| Kosovo Geo-IP Reclassification | Any customer with an active Europe block rule | Explicitly add Kosovo to the Geo-IP policy after the upgrade |
| DTLS SSL-VPN Support | Customers with latency complaints on SSL-VPN | Verify compatible clients; no config change required |
| NetExtender 10.3.4 in Portal | All remote-access users | Notify end users about the update prompt in advance
|
| MAC-IP Anti-Spoofing (Bridge Mode) | Customers using SonicWall in Native Bridge mode | Enable during post-upgrade hardening review |
| Same-Subnet WAN Interfaces | Customers with ISPs using bonded or same-subnet WANs | Remove legacy workarounds; validate SD-WAN policies |
The most significant feature in SonicOS 7.3.3 is the addition of Generative AI as a dedicated Content Filtering Service (CFS) category. Generative AI adoption is accelerating across every segment of your customer base, often faster than IT policies can keep up with. Employees are submitting sensitive data to AI platforms without fully understanding the risk, and many organizations have no visibility into that activity at all.
SonicOS 7.3.3 gives administrators the ability to apply allow, block, or warn policies specifically to Generative AI platforms, including ChatGPT, Microsoft Copilot, and Google Gemini, independently of other content categories. This level of granularity lets you enforce AI usage policies at the network layer without maintaining custom URL lists or manually updating them.
For MSPs, this is a straightforward upsell conversation. Customers in education, healthcare, financial services, and legal already have data governance obligations. The Generative AI CFS category provides a mechanism to enforce those obligations at the firewall, and it is immediately available in the CFS policy editor after upgrading, with no additional configuration required to surface it.
This is also a good time to audit CFS subscriptions across your customer base. Customers who are not subscribed will not have access to the new category.
GEN8 note: The Generative AI CFS category will be available on GEN8 with SonicOS 8.2.2, with general availability targeted for July 21, 2025.
Alongside Generative AI, SonicOS 7.3.3 introduces three further content filtering categories:
All four new categories, including Generative AI, require an active CFS subscription to access.
Compromised credentials are one of the most common entry points for network breaches, and this risk disproportionately affects the SMB customers that most MSPs manage. Many of those customers have never changed default or factory-set passwords, and a significant number are running credentials that have appeared in third-party data breach databases.
SonicOS 7.3.3 addresses this by enabling Credential Auditor by default on all GEN7 appliances. The feature automatically checks configured administrator and user credentials against known compromised password databases. When a match is found, an alert is generated. No traffic is blocked, and no accounts are locked. Credential Auditor is entirely passive from an operational standpoint, but it surfaces real risk signals that would otherwise go undetected.
When you upgrade a customer to SonicOS 7.3.3, Credential Auditor will begin running automatically and may generate alerts for existing credentials. This works as designed. Set that expectation with customers before the upgrade and use any flagged credentials as an opportunity to document and remediate. It is a straightforward value-add conversation that demonstrates the security monitoring you are already providing.
Credential Auditor has been the default on GEN8 appliances for some time. SonicOS 7.3.3 introduces the same behavior in GEN7, aligning the security baseline across both generations.
The Geo-IP database has been updated with UI-level policy support for Kosovo and South Sudan, two countries that previously had no individual policy controls.
This change also applies to GEN6 at the database level. The Kosovo reclassification will take effect automatically on GEN6 after the database update. However, UI-level policy controls for Kosovo and South Sudan are not planned for GEN6. If you manage GEN6 deployments for customers with active Geo-IP policies, review those policies before upgrading. Knowledge Base article SW-KB-GEOIP-001 covers the full behavior breakdown by platform and firmware version.
SonicOS 7.3.3 adds DTLS (Datagram Transport Layer Security) support to the SSL-VPN gateway. DTLS is a UDP-based encrypted tunnel that provides meaningfully lower latency than standard TLS-based SSL-VPN, particularly for real-time applications such as voice calls, video conferencing, and collaboration tools.
When a compatible client connects, DTLS negotiation is automatically initiated. No end-user configuration is required, and TLS fallback is maintained for clients that do not support DTLS. For customers who have raised concerns about call quality or latency over SSL-VPN, this is a direct answer that does not require a platform change.
NetExtender 10.3.4 is now embedded directly in the SonicOS 7.3.3 SSL-VPN portal. Users connecting to the portal will be automatically prompted to update to 10.3.4 if they are running an older version. No separate client distribution is required.
For MSPs managing large remote-access user bases, this eliminates the overhead of coordinating client rollouts and reduces the version mismatch issues that generate unnecessary helpdesk tickets. The update is delivered transparently through the standard portal connection flow. Communicate this to end users in advance to avoid unexpected prompts during business hours.
SonicOS 7.3.3 extends MAC-IP Anti-Spoofing support to Native Bridge (Layer 2) deployments. When enabled, the appliance enforces MAC-to-IP address bindings on bridged interfaces, detecting and blocking ARP spoofing and IP spoofing attacks inline.
This closes a security gap that has existed for customers deploying SonicWall transparently, without re-addressing their network, in retail, branch, and campus environments. It is also directly relevant for financial services and regulated industry customers who require spoofing controls in Layer 2 configurations. If you have customers running SonicWall in bridge mode, enabling this feature should be part of a standard post-upgrade hardening review.
A long-standing deployment limitation has been removed in SonicOS 7.3.3. The platform now supports W0-WAN and X1, or any two wired WAN interfaces, in the same IP subnet. This resolves a common blocker for customers whose ISP provides both WAN handoffs in the same subnet, including bonded circuits and certain ISP handoff types, where workarounds were previously required.
The configuration is now fully supported, including with SD-WAN policies. If you have customers running workarounds for this limitation, this is a good opportunity to clean up those configurations post-upgrade.
Complete the following steps before and after upgrading customers to SonicOS 7.3.3:
SonicOS 7.3.3 firmware is available through the MySonicWall portal for customers with an active support contract and can be deployed at scale through NSM for centrally managed environments.
| Question | Answer |
| What GEN7 appliances support SonicOS 7.3.3? | SonicOS 7.3.3 is available for all GEN7 appliances with an active support contract. Refer to SonicOS 7.3.3 Release Notes for the full supported platform list. |
| When will Generative AI content filtering be available in GEN8? | The Generative AI CFS category will be available on GEN8 with SonicOS 8.2.2, with general availability targeted for July 21, 2025. |
| Does Credential Auditor block accounts or traffic? | No. Credential Auditor is entirely passive. It generates alerts when credentials match known compromised password databases, but does not block accounts, lock users, or interrupt traffic. |
| Will upgrading to 7.3.3 break existing Geo-IP policies? | Customers with an active Europe block rule will need to explicitly add Kosovo to their Geo-IP policy after upgrading, since Kosovo is now a separate entry distinct from the Europe region. |
| Is a CFS subscription required for the new content categories? | Yes. All four new categories (Generative AI, Self-Harm, DNS-over-HTTPS, and Low-THC Cannabis) require an active Content Filtering Service subscription. |
| Where can I download SonicOS 7.3.3? | SonicOS 7.3.3 firmware is available through the MySonicWall portal for customers with an active support contract. It can be deployed at scale through NSM for centrally managed environments. |
SonicOS 7.3.3 is a meaningful release for GEN7, not a cosmetic update. The combination of Generative AI content control, default-on credential auditing, expanded Geo-IP policy coverage, DTLS performance improvements, and security gap closures in Layer 2 environments gives MSPs a solid set of talking points and a genuine opportunity to demonstrate security value to customers.
The features that matter most in practice are those that work without requiring customers to change their behavior. Credential Auditor running silently in the background, Generative AI controls a policy toggle away, and NetExtender updating itself on the next portal login represent exactly the kind of improvements that make managed security tangible and visible.
If you have questions about the release or want to discuss how to position these features for your customers, reach out to your SonicWall channel team or visit support.sonicwall.com.
SonicOS 7.3.3 is available now for GEN7 appliances through the MySonicWall portal. A CFS subscription is required to access the new content filtering categories. Refer to the SonicOS 7.3.3 Release Notes for the full list of supported platforms and known issues. Read the in-depth FAQ.
Share This Article
An Article By
An Article By
Asif Mujtaba
Product Manager
Asif Mujtaba
Product Manager