Cloud Security

How SonicWall Cloud Secure Edge Extends Capture ATP Beyond the Firewall

by Sheldon Rezendes, Amelia Foss

Off-Network Should Not Mean Unprotected

For security teams that have invested in SonicWall's next-generation firewall stack, Capture ATP is among the most valued capabilities in the portfolio. Its multi-engine sandbox approach consistently earns top scores in third-party testing and provides on-network users with robust protection against unknown and zero-day file-based threats. However, that protection has always carried an implicit condition: the user must be on the network. 

Although EDR tools do accompany the device and offer a vital last line of defense, detection and response inherently rely on the threat having already reached the endpoint. A more robust approach is to prevent threats from reaching the device in the first place. Blocking a malicious file at the network layer, before it executes, is fundamentally better than detecting and fixing it after the damage is done. 

SonicWall Cloud Secure Edge (CSE) addresses this directly. Through its Secure Internet Access (SIA) capability, CSE extends the same Capture ATP engine that powers your firewall to every device, regardless of where it connects. The inspection point moves from the network edge to the cloud, ensuring that users connecting from home offices, hotel lobbies, or co-working spaces receive the same (and in some cases stronger) layered file protection as those sitting inside the corporate perimeter. 

Capture ATP on the Firewall: A Strong Foundation 

On a SonicWall next-generation firewall, Capture ATP intercepts files passing through the network and submits them for analysis in a cloud-based, multi-engine sandbox. Files that cannot be immediately classified as clean are held while analysis runs in parallel across multiple environments. The result is a verdict: clean, malicious, or unknown. 

This approach is highly effective for traffic that transits the firewall. Content filtering, geo-blocking, botnet protection, and DPI-SSL inspection all operate at the same inspection point, creating a layered security posture for on-network users. 

The limitation is architectural, not technical. The firewall inspects traffic at the network edge. When a user is off-network, that edge is no longer in the path. 

Extending Inspection to the Endpoint with CSE SIA 

CSE's Secure Internet Access capability repositions the inspection point from the network edge to the endpoint itself. The CSE agent proxies outbound web traffic through SonicWall's cloud-delivered security stack, regardless of the user's physical location or network connection. 

This means the same layers of protection available on the firewall (DNS filtering, URL-level inspection, content categorization, geo-blocking, and now Capture ATP file analysis) travel with the user. The security posture does not degrade when a device leaves the office. 

What CSE Adds: Augmenting the On-Firewall Implementation 

Integrating Capture ATP into CSE involved more than just rerouting traffic through the same engine. It was also a chance to introduce features that are only feasible in an agent-based delivery model. 

  • Expanded File Size Limit: 10 MB to 100 MB

The on-firewall Capture ATP implementation applies a 10 MB file size limit for sandboxed analysis. Files larger than this threshold pass through without deep file inspection. In practice, this is a meaningful gap: software installers, archive files, and documents with embedded media frequently exceed 10 MB. CSE raises this ceiling to 100 MB, substantially expanding the population of files eligible for analysis. 

  • File Decompression for Greater Coverage

A significant portion of files delivered over the web are compressed into ZIP archives, gzip-encoded content, and similar container formats. The on-firewall implementation treats these as containers, limiting visibility into their contents. 

CSE performs file decompression prior to analysis, unpacking compressed payloads and submitting the underlying files for inspection individually. Internal benchmarking showed that enabling decompression more than doubled the number of eligible files identified for analysis.  In this case, CSE is not simply matching the firewall's coverage on a larger scale; it is materially expanding it. 

  • Hash-Based Protection for Files Above 100 MB

Even at the expanded 100 MB limit, some files will exceed the threshold for full sandbox analysis. For these, CSE performs hash-based reputation checks against SonicWall's threat intelligence database. This provides an additional layer of protection: known malicious files are blocked based on their signature regardless of size, and the overall coverage gap is significantly reduced. 

  • User-Facing Notifications

CSE surfaces real-time status to the user through the agent. When a file is being submitted for analysis, the user sees an in-app notification. When a verdict is returned and a file is blocked, the user receives a clear explanation. This improves the operational experience without any additional configuration by the administrator. 

  • Throttled Download Handling

Standard file inspection proxies can disrupt the download process during analysis. This may lead to corruption in application-level transfers, like software updates or file sync agents, which require a complete file at a designated path. CSE instead uses connection-preserving throttling, trickling bytes to the application at a controlled rate while analysis runs in parallel. If the file is clean, delivery completes normally. If it is malicious, the socket is terminated. Application compatibility is preserved without sacrificing inspection coverage. 

  • Reduced manual administration

Certificate management is another area where CSE reduces administrative overhead. DPI-SSL inspection on a firewall requires manually generating, deploying, and renewing SSL certificates, a recurring task that carries the risk of silent inspection lapses when certificates expire. CSE automates the full certificate lifecycle. Capture ATP file inspection is similarly straightforward: a single toggle in the management console enrolls all eligible file types, with no per-type configuration required. 

  • 12-Month Analysis Log Retention

CSE retains a full log of analyzed files for 12 months. Each log entry captures file metadata, submission timestamps, analysis verdicts, and disposition outcomes. In the event of a security incident, this record provides the forensic continuity that auditors and IT teams require — without relying on reconstructed data or manual tracking. Retention is automatic and requires no additional configuration.

Layered Defense at the Endpoint: How CSE Works with Endpoint Security 

It's important to differentiate CSE's method of securing remote users from that of endpoint detection and response (EDR) platforms. EDR operates on the device itself, monitoring process behavior, file execution, and system activity to detect and respond to threats that have already landed on the endpoint. It is a powerful and necessary layer of defense. CSE operates earlier in the chain by inspecting files and web traffic before they reach the device. Rather than identifying a malicious file after it executes, CSE aims to prevent it from arriving in the first place. The two capabilities are complementary: CSE reduces the volume of threats that EDR has to contend with, and EDR provides a backstop for anything that gets through. Together, they reflect a defense-in-depth posture that does not rely on any single layer to carry the full burden and provides visibility no one tool can. 

Extending What You Already Trust 

For organizations already running SonicWall next-generation firewalls, CSE SIA is not a departure from an established security strategy but rather an extension of one. The same Capture ATP engine, the same threat intelligence, and the same layered inspection philosophy that protects users on the network now follow them off it.  

Request a demo of Cloud Secure Edge today and extend the same protection your network relies on to every user, everywhere.

Share This Article

An Article By

Sheldon Rezendes

Product Manager

Sheldon Rezendes heads up Cloud Secure Edge's Secure Internet Access from a Product Management perspective. His background includes a variety of roles centered on network, endpoint and platform security. He is passionate about the evolution of security and helping customers through all stages of their cloud journey.   

Amelia Foss

Product Marketing Specialist

Amelia Foss is a Product Marketing Specialist for SonicWall, where she supports the company’s Network Security portfolio and Unified Management solutions. She brings over a decade of cybersecurity marketing experience, having led content development initiatives for both emerging startups and global security brands, including ESET and Axis Communications. She is passionate about making cybersecurity more accessible to broader audiences.

Related Articles

  • Monatliche Firewall-Serviceoption für mehr Einfachheit und Skalierbarkeit
    Read More
  • SonicWall Capture Cloud Platform – 8つの新たな方法で企業を保護
    Read More
  • 最新式のSaaSセキュリティ:クラウドアプリ時代における、電子メールおよびデータ、ユーザーアクセスのセキュリティ
    Read More