by Asif Mujtaba

There is a quiet gap in almost every firewall deployment, and it rarely appears on anyone's project plan.
An appliance arrives on site. Someone racks it, cables it, brings up the WAN link, and confirms that traffic is flowing. The deployment is declared successful because the visible test succeeded: users can reach the internet, and the phones have stopped ringing. What has not yet happened is the part nobody sees. Gateway Anti-Virus may not be inspecting anything. Intrusion Prevention may be licensed but idle. Botnet Filtering may be switched off.
The firewall is online. It is not yet protecting anyone.
The gap is not caused by carelessness. It is a structural consequence of how firewalls have traditionally been deployed.
The result is a population of appliances that are registered, licensed, monitored, and materially less protected than their owners believe.
SonicOS 8.2.2 inverts the default. On new GEN8 appliances, the core security services activate automatically at the point of registration, with no manual configuration step required:
Registration and protection become the same event rather than two events separated by an interval of unknown length. This is a small change in mechanics and a significant change in posture. The question at handover is no longer "were the security services enabled?" but "were any of them deliberately changed?" The second question is far easier to answer, and far easier to audit.
For a single site, the gap described above is a manageable risk. For a managed service provider onboarding dozens of sites, it is a recurring one. Every manual enablement step is an opportunity for omission, and the probability of at least one omission approaches certainty as the estate grows. Worse, the omission is not evenly distributed: it concentrates in exactly the deployments that were rushed, performed out of hours, or handled by whoever was available rather than whoever was most experienced.
| Deployment Factor | Traditional Manual Enablement | SonicOS 8.2.2 Secure-by-Default |
| Manual enablement | Each service is switched on by a technician after connectivity is confirmed | Gateway Anti-Virus, Anti-Spyware, Intrusion Prevention, Botnet Filtering, and Geo-IP Filtering activate at registration |
| Onboarding speed | Deployment time is split between network design and baseline security setup | Technicians spend deployment time on network design and customer-specific policy |
| Starting posture | Every appliance may begin from a different, undocumented state | Every appliance begins from the same known posture, so drift is detectable |
| Audit position | Requires proving a checklist was followed correctly on every occasion | Protection enabled by design is easier to demonstrate than a checklist history |
| Channel risk | Partners carry the risk that a shipped appliance went live unprotected | Partners are no longer carrying that risk by default |
Figure 1: Traditional Manual Enablement vs. SonicOS 8.2.2 Secure-by-Default
It is worth being direct about what this feature does not do. Enabling services by default establishes a sound baseline. It does not replace tuning, and it is not a substitute for understanding the environment. Signature policies, inspection exclusions, bandwidth considerations, and application-specific behavior all still warrant attention from an administrator who knows the network.
Geo-IP Filtering deserves particular mention. The default policy is deliberately conservative, restricted to a small set of high-risk regions, precisely so that it improves posture without disrupting legitimate traffic on day one. Administrators retain complete control and can widen, narrow, or disable the policy to suit the environment. A broadened Geo-IP policy can have side effects worth planning for, including on automated services that contact the appliance from distributed infrastructure.
The intent is not to make decisions on the administrator's behalf. The intent is to ensure that the absence of a decision does not leave an appliance undefended.
For new GEN8 deployments running SonicOS 8.2.2, no action is required. Register the appliance, and the services listed above are active.
For existing estates, the most valuable exercise is a short audit. Confirm which appliances currently have inspection services enabled, and compare that against which appliances are licensed for them. In most estates, the two lists are not identical, and the difference is the gap this feature was built to close.
For upgrade guidance and full feature details, consult the SonicOS 8.2.2 Release Notes and the SonicOS 8.2.2 Frequently Asked Questions on the SonicWall Knowledge Base, or contact your SonicWall representative or partner.
Frequently Asked Questions
| Question | Answer |
| Why isn't a newly deployed firewall protecting a network right away? | Historically, licensing and enablement have been separate events. A service can be fully paid for and still sit inactive because connectivity failures are loud and inspection failures are silent, so security tuning is often deferred and never revisited. |
| What security services does SonicOS 8.2.2 enable by default on GEN8 appliances? | Gateway Anti-Virus, Anti-Spyware, Intrusion Prevention, Botnet Filtering, and Geo-IP Filtering all activate automatically at registration, with no manual configuration required. |
| Does enabling services by default replace the need for security tuning? | No. It establishes a sound baseline, not a ceiling. Signature policies, inspection exclusions, bandwidth considerations, and application-specific behavior still require attention from an administrator who understands the network. |
| How conservative is the default Geo-IP Filtering policy? | The default policy is restricted to a small set of high-risk regions so that it improves posture without disrupting legitimate traffic on day one. Administrators can widen, narrow, or disable the policy at any time. |
| What should partners do with firewalls deployed before SonicOS 8.2.2? | Run a short audit: confirm which appliances currently have inspection services enabled and compare that list against which appliances are licensed for them. The difference identifies the gap that needs closing. |
Share This Article
An Article By
An Article By
Asif Mujtaba
Product Manager
Asif Mujtaba
Product Manager