by Asif Mujtaba

SonicWall is pleased to announce the general availability of SonicOS 8.2.2 for GEN8 hardware appliances and the new NSv virtual firewall lineup. This release delivers essential security enhancements, operational improvements, and expanded platform capacity, reinforcing SonicWall's commitment to simplifying firewall management while strengthening defenses against evolving threats.
SonicOS 8.2.2 introduces major features designed to reduce deployment friction, improve visibility, and enhance the user experience across all GEN8 platforms.

Figure 1: SonicOS 8.2.2 Feature Highlights
Every new GEN8 appliance now automatically enables Gateway Anti-Virus, Anti-Spyware, Intrusion Prevention, Botnet Filtering, and Geo-IP Filtering at registration, with no manual configuration required. This secure-by-default posture eliminates a common security gap in SMB and branch deployments, ensuring every registered firewall is protected from day one.
SonicOS 8.2.2 now supports automated SSL/TLS certificate issuance and renewal via Let's Encrypt (ACME v2 protocol). The firewall requests, installs, and automatically renews certificates before expiry with zero administrator intervention, reducing the operational burden of certificate management across hundreds of appliances.
Remote access users can now use TOTP-based two-factor authentication when connecting via Global VPN Client 5.0.0.2008. Support for industry-standard authenticator applications, including Google Authenticator and Microsoft Authenticator, makes MFA enforcement straightforward without requiring a separate authentication platform.
Administrators can now import SHA-256 hash lists from threat intelligence feeds, up to 500,000 entries, directly onto the firewall. Files matching a known malicious hash are blocked in transit and logged for audit, providing security and MSP teams with an additional layer of enforcement alongside endpoint tools.
Passwords for administrators and local users are now stored using one-way cryptographic hashing (bcrypt) rather than reversible encryption. Configuration backups no longer expose recoverable credentials, significantly improving resilience against extraction attacks.
The TZ80 entry-level appliance now supports up to ten concurrent SSL VPN users, and NSv instances now support up to 500 groups, giving growing organizations more headroom before requiring a hardware upgrade.
Based on direct customer feedback, SonicOS 8.2.2 delivers a series of usability refinements that make day-to-day administration faster and less error prone. Add, Edit, and Delete controls are now consistently placed across all rule and policy pages. App Control sorting has been refined to persist user selections. VPN tunnel status now updates in real time. Log entries link directly to signature settings for faster troubleshooting. These improvements align with NSM 4.3 terminology and navigation, creating a consistent experience across centralized and local management.
The maximum number of supported SD-WAN sites on GEN8 hardware has been increased, enabling larger branch deployments from a single hub. Additionally, three new NSv virtual firewall sizes, Small (2 vCPU, 2 GB), Medium (4 vCPU, 8 GB), and Large (8 vCPU, 16 GB), complement the existing NSv XS. All three deliver the complete GEN8 security stack and support VMware, Hyper-V, KVM, Proxmox, AWS, and Azure, allowing customers to right-size firewall capacity to actual workload requirements.

Figure 2: SonicOS 8.2.2 New NSv Virtual Firewall Sizing
SonicOS 8.2.2 is available today for all GEN8 hardware and NSv instances. For upgrade guidance, feature details, and complete release notes, visit the SonicWall Knowledge Base. To discuss how SonicOS 8.2.2 can strengthen your organization's security posture, contact your SonicWall representative or partner today.
SonicOS 8.2.2: Secure by Default. Simple to Manage
Contact your SonicWall representative or partner today to discuss how SonicOS 8.2.2 can strengthen your organization's security posture. |
| Question | Answer |
| What is new in SonicOS 8.2.2? | SonicOS 8.2.2 introduces major features spanning security, management, and platform capacity, including security services enabled by default, native Let's Encrypt certificate automation, two-factor authentication for Global VPN Client, intelligence-driven threat blocking, bcrypt credential hashing, expanded platform capacity, usability refinements, increased SD-WAN site support, and three new NSv virtual firewall sizes. |
| Are security services enabled automatically on new GEN8 appliances? | Yes. Gateway Anti-Virus, Anti-Spyware, Intrusion Prevention, Botnet Filtering, and Geo-IP Filtering all activate automatically at registration, with no manual configuration required. |
| How does SonicOS 8.2.2 simplify SSL/TLS certificate management? | SonicOS 8.2.2 adds native support for Let's Encrypt via the ACME v2 protocol. The firewall requests, installs, and automatically renews certificates before expiry, with zero administrator intervention. |
| What are the new NSv virtual firewall sizes? | Small (2 vCPU, 2 GB), Medium (4 vCPU, 8 GB), and Large (8 vCPU, 16 GB) join the existing NSv XS. All three deliver the complete GEN8 security stack and run on VMware, Hyper-V, KVM, Proxmox, AWS, and Azure. |
| Is SonicOS 8.2.2 available now? | Yes. SonicOS 8.2.2 is generally available today for all GEN8 hardware appliances and NSv instances. |
For upgrade guidance, feature details, and complete release notes, visit the SonicWall Knowledge Base at sonicwall.com/support.
Share This Article
An Article By
An Article By
Asif Mujtaba
Product Manager
Asif Mujtaba
Product Manager