Network Security, Products & Services

SonicOS 7.3.3 for GEN7: What MSPs and Channel Partners Need to Know

by Asif Mujtaba

From Generative AI content filtering to default-on credential auditing, SonicOS 7.3.3 gives managed service providers a stronger security baseline and a clearer upsell story.

SonicWall is releasing SonicOS 7.3.3 for GEN7 appliances, which includes a set of changes that directly affect how you manage, protect, and grow your customer base. From a new Generative AI content filtering category to credential security enabled out of the box, SonicOS 7.3.3 is designed to help MSPs and channel partners deliver stronger security with less configuration overhead.

This guide covers every significant change in the release, what it means for your practice, and the specific actions you should take before and after upgrading.

 

What Is New in SonicOS 7.3.3: Feature Summary

 

FeatureWho It AffectsRecommended Action
Generative AI CFS CategoryAll MSPs managing CFS-subscribed customersReview and update CFS policies post-upgrade
Self-Harm, DNS-over-HTTPS (DoH), Low-THC CategoriesEducation, healthcare, and regulated industriesEnable categories relevant to each customer segment
Credential Auditor (on by default)All GEN7 customers are being upgradedSet customer expectations before upgrading
Kosovo Geo-IP ReclassificationAny customer with an active Europe block ruleExplicitly add Kosovo to the Geo-IP policy after the upgrade
DTLS SSL-VPN SupportCustomers with latency complaints on SSL-VPNVerify compatible clients; no config change required
NetExtender 10.3.4 in PortalAll remote-access users

Notify end users about the update prompt in advance

 

MAC-IP Anti-Spoofing (Bridge Mode)Customers using SonicWall in Native Bridge modeEnable during post-upgrade hardening review
Same-Subnet WAN InterfacesCustomers with ISPs using bonded or same-subnet WANsRemove legacy workarounds; validate SD-WAN policies

 

Generative AI Is Now a Dedicated Content Filtering Category

The most significant feature in SonicOS 7.3.3 is the addition of Generative AI as a dedicated Content Filtering Service (CFS) category. Generative AI adoption is accelerating across every segment of your customer base, often faster than IT policies can keep up with. Employees are submitting sensitive data to AI platforms without fully understanding the risk, and many organizations have no visibility into that activity at all.

SonicOS 7.3.3 gives administrators the ability to apply allow, block, or warn policies specifically to Generative AI platforms, including ChatGPT, Microsoft Copilot, and Google Gemini, independently of other content categories. This level of granularity lets you enforce AI usage policies at the network layer without maintaining custom URL lists or manually updating them.

For MSPs, this is a straightforward upsell conversation. Customers in education, healthcare, financial services, and legal already have data governance obligations. The Generative AI CFS category provides a mechanism to enforce those obligations at the firewall, and it is immediately available in the CFS policy editor after upgrading, with no additional configuration required to surface it.

This is also a good time to audit CFS subscriptions across your customer base. Customers who are not subscribed will not have access to the new category.

GEN8 note: The Generative AI CFS category will be available on GEN8 with SonicOS 8.2.2, with general availability targeted for July 21, 2025.

Three Additional CFS Categories in This Release

Alongside Generative AI, SonicOS 7.3.3 introduces three further content filtering categories:

  • Self-Harm: Blocks access to content that promotes or facilitates self-harm. Particularly relevant for education, healthcare, and employee wellbeing programs.
  • DNS-over-HTTPS (DoH): Allows administrators to control or block DoH traffic. This is important because DoH encrypts DNS queries in a way that can bypass traditional CFS enforcement if left unchecked, undermining the effectiveness of other content filtering policies.
  • Low-THC Cannabis Products: Provides granular policy control over this product category separately from existing cannabis content categories, enabling more precise enforcement for regulated industries and educational institutions.

All four new categories, including Generative AI, require an active CFS subscription to access.

Credential Auditor Is Now Turned on by Default for GEN7

Compromised credentials are one of the most common entry points for network breaches, and this risk disproportionately affects the SMB customers that most MSPs manage. Many of those customers have never changed default or factory-set passwords, and a significant number are running credentials that have appeared in third-party data breach databases.

SonicOS 7.3.3 addresses this by enabling Credential Auditor by default on all GEN7 appliances. The feature automatically checks configured administrator and user credentials against known compromised password databases. When a match is found, an alert is generated. No traffic is blocked, and no accounts are locked. Credential Auditor is entirely passive from an operational standpoint, but it surfaces real risk signals that would otherwise go undetected.

What This Means Before You Upgrade

When you upgrade a customer to SonicOS 7.3.3, Credential Auditor will begin running automatically and may generate alerts for existing credentials. This works as designed. Set that expectation with customers before the upgrade and use any flagged credentials as an opportunity to document and remediate. It is a straightforward value-add conversation that demonstrates the security monitoring you are already providing.

Credential Auditor has been the default on GEN8 appliances for some time. SonicOS 7.3.3 introduces the same behavior in GEN7, aligning the security baseline across both generations.

Geo-IP Now Supports Kosovo and South Sudan as Policy Targets

The Geo-IP database has been updated with UI-level policy support for Kosovo and South Sudan, two countries that previously had no individual policy controls.

  • Kosovo: Previously classified under the broader Europe region in the database. Starting with this release, Kosovo is a distinct, selectable entry in the Geo-IP policy editor. This is a critical change for any customer with an existing Europe block rule. Kosovo traffic will no longer be covered by that rule after the database update. Customers who need to continue blocking Kosovo must explicitly add it to their Geo-IP policy after upgrading.
  • South Sudan: Was already recognized at the database level but had no UI selectability. SonicOS 7.3.3 adds it as an explicit policy target for the first time.

This change also applies to GEN6 at the database level. The Kosovo reclassification will take effect automatically on GEN6 after the database update. However, UI-level policy controls for Kosovo and South Sudan are not planned for GEN6. If you manage GEN6 deployments for customers with active Geo-IP policies, review those policies before upgrading. Knowledge Base article SW-KB-GEOIP-001 covers the full behavior breakdown by platform and firmware version.

DTLS Support in SSL-VPN for Lower Latency Remote Access

SonicOS 7.3.3 adds DTLS (Datagram Transport Layer Security) support to the SSL-VPN gateway. DTLS is a UDP-based encrypted tunnel that provides meaningfully lower latency than standard TLS-based SSL-VPN, particularly for real-time applications such as voice calls, video conferencing, and collaboration tools.

When a compatible client connects, DTLS negotiation is automatically initiated. No end-user configuration is required, and TLS fallback is maintained for clients that do not support DTLS. For customers who have raised concerns about call quality or latency over SSL-VPN, this is a direct answer that does not require a platform change.

NetExtender 10.3.4 Is Now Embedded in the SSL-VPN Portal

NetExtender 10.3.4 is now embedded directly in the SonicOS 7.3.3 SSL-VPN portal. Users connecting to the portal will be automatically prompted to update to 10.3.4 if they are running an older version. No separate client distribution is required.

For MSPs managing large remote-access user bases, this eliminates the overhead of coordinating client rollouts and reduces the version mismatch issues that generate unnecessary helpdesk tickets. The update is delivered transparently through the standard portal connection flow. Communicate this to end users in advance to avoid unexpected prompts during business hours.

MAC-IP Anti-Spoofing Now Available in Native Bridge Mode

SonicOS 7.3.3 extends MAC-IP Anti-Spoofing support to Native Bridge (Layer 2) deployments. When enabled, the appliance enforces MAC-to-IP address bindings on bridged interfaces, detecting and blocking ARP spoofing and IP spoofing attacks inline.

This closes a security gap that has existed for customers deploying SonicWall transparently, without re-addressing their network, in retail, branch, and campus environments. It is also directly relevant for financial services and regulated industry customers who require spoofing controls in Layer 2 configurations. If you have customers running SonicWall in bridge mode, enabling this feature should be part of a standard post-upgrade hardening review.

WAN Interfaces on the Same Subnet Are Now Supported

A long-standing deployment limitation has been removed in SonicOS 7.3.3. The platform now supports W0-WAN and X1, or any two wired WAN interfaces, in the same IP subnet. This resolves a common blocker for customers whose ISP provides both WAN handoffs in the same subnet, including bonded circuits and certain ISP handoff types, where workarounds were previously required.

The configuration is now fully supported, including with SD-WAN policies. If you have customers running workarounds for this limitation, this is a good opportunity to clean up those configurations post-upgrade.

Management Interface and Diagnostic Improvements

  • Save/Edit Configuration Banner: Redesigned to be less cluttered and more intuitive, with clearer feedback on pending configuration state. This reduces the risk of administrators accidentally discarding changes, which has been a consistent source of support escalations.
  • Switch Diagnostics for x86 and ARM: Switch diagnostic capabilities are now accessible from the management UI across both x86 and ARM-based GEN7 platforms. Administrators can view link state, MAC address tables, port statistics, and VLAN assignments without CLI access. This closes a gap that previously required out-of-band tools on ARM appliances.

Upgrade Checklist for MSPs

Complete the following steps before and after upgrading customers to SonicOS 7.3.3:

  • Back up the configuration. Always export and save the running configuration before any firmware upgrade.
  • Set expectations on Credential Auditor alerts. Customers upgrading from earlier firmware may receive alerts immediately post-upgrade. This is expected behavior, not an incident.
  • Review Geo-IP policies. Any customer with an active Europe block rule should be informed about the Kosovo reclassification. Check the policy editor after upgrading and add Kosovo explicitly if it is required.
  • Audit CFS subscriptions. The four new categories are only accessible with an active CFS subscription. Use this upgrade cycle to audit and remediate any lapsed subscriptions across your customer base.
  • Communicate the NetExtender update. Users will be prompted to update to NetExtender 10.3.4 on their next portal connection. Notify end users in advance to avoid unexpected prompts.
  • Enable MAC-IP Anti-Spoofing for bridge-mode customers. Add this to your post-upgrade hardening checklist for any customer running SonicWall in Native Bridge mode.

SonicOS 7.3.3 firmware is available through the MySonicWall portal for customers with an active support contract and can be deployed at scale through NSM for centrally managed environments.

Frequently Asked Questions

 

QuestionAnswer
What GEN7 appliances support SonicOS 7.3.3?SonicOS 7.3.3 is available for all GEN7 appliances with an active support contract. Refer to SonicOS 7.3.3 Release Notes for the full supported platform list.
When will Generative AI content filtering be available in GEN8?The Generative AI CFS category will be available on GEN8 with SonicOS 8.2.2, with general availability targeted for July 21, 2025.
Does Credential Auditor block accounts or traffic?No. Credential Auditor is entirely passive. It generates alerts when credentials match known compromised password databases, but does not block accounts, lock users, or interrupt traffic.
Will upgrading to 7.3.3 break existing Geo-IP policies?Customers with an active Europe block rule will need to explicitly add Kosovo to their Geo-IP policy after upgrading, since Kosovo is now a separate entry distinct from the Europe region.
Is a CFS subscription required for the new content categories?Yes. All four new categories (Generative AI, Self-Harm, DNS-over-HTTPS, and Low-THC Cannabis) require an active Content Filtering Service subscription.
Where can I download SonicOS 7.3.3?SonicOS 7.3.3 firmware is available through the MySonicWall portal for customers with an active support contract. It can be deployed at scale through NSM for centrally managed environments.

 

Final Thoughts

SonicOS 7.3.3 is a meaningful release for GEN7, not a cosmetic update. The combination of Generative AI content control, default-on credential auditing, expanded Geo-IP policy coverage, DTLS performance improvements, and security gap closures in Layer 2 environments gives MSPs a solid set of talking points and a genuine opportunity to demonstrate security value to customers.

The features that matter most in practice are those that work without requiring customers to change their behavior. Credential Auditor running silently in the background, Generative AI controls a policy toggle away, and NetExtender updating itself on the next portal login represent exactly the kind of improvements that make managed security tangible and visible.

If you have questions about the release or want to discuss how to position these features for your customers, reach out to your SonicWall channel team or visit support.sonicwall.com.

 

SonicOS 7.3.3 is available now for GEN7 appliances through the MySonicWall portal. A CFS subscription is required to access the new content filtering categories. Refer to the SonicOS 7.3.3 Release Notes for the full list of supported platforms and known issues. Read the in-depth FAQ.

 

Share This Article

An Article By

Asif Mujtaba

Product Manager

Asif Mujtaba is a Product Manager at SonicWall with over a decade of experience in cybersecurity, specializing in product management and technical leadership. He is passionate about driving innovation and delivering secure, scalable solutions that empower organizations to navigate the evolving threat landscape.

Related Articles

  • One Engine Is Never Enough. SonicWall Runs Several.
    Read More
  • Why “Good Enough” Isn’t Enough: Moving from Legacy to Active Protection in 2026
    Read More