Get uncompromising high-performance firewall protection
Get uncompromising high-performance firewall protection
Now your business can deliver deep security to detect and block the most sophisticated threats before they can enter your network with the SonicWall SuperMassive 9000 Series next-generation firewall (NGFW). With Capture Advanced Threat Protection, a cloud-based network sandbox, organizations can examine suspicious files and code in an isolated environment to stop never before seen threats such as zero-day attacks. Plus, you can minimize latency for every connection on your network and gracefully handle traffic spikes even on the most demanding enterprise networks using a scalable, high-density, multi-core, high-performance firewall architecture. At the same time, you can save rack space and lower power and cooling costs with this elegant, one-rack unit appliance.
Get the ultra-low latency and high performance that large enterprises demand. The SuperMassive 9000 combines the patented1 Reassembly-Free Deep Packet Inspection (RFDPI) engine with a powerful, multi-core high-performance firewall architecture that operates at multi-gigabit speeds in a compact, power-efficient design.
Protection against today’s emerging threats
SuperMassive 9000 firewalls with RFDPI empower you to block millions of sophisticated threats at the gateway before they enter your network — regardless of port, protocol or file size — with advanced anti-malware, intrusion prevention, TLS/SSL decryption and inspection, and application control.
Easy monitoring and control of application traffic
Identify productive and unproductive application traffic in real time, and control that traffic through powerful application-level policies on both a per-user and a per-group basis (along with schedules and exception lists). SuperMassive 9000 firewalls seamlessly integrate with authentication servers to help you enforce acceptable-use policies, identify custom applications, better manage bandwidth and enhance productivity.
Centralized and unified management
Easily consolidate management of SonicWall security appliances —including the SuperMassive 9000 Series — with the Global Management System (GMS). Reduce administrative and troubleshooting complexities with a unified, secure and extensible platform. Govern all operational aspects of your security infrastructure, including centralized policy management and enforcement, real-time event monitoring, analytics and reporting, and more. A single GMS instance can scale to thousands of distributed enterprise firewalls. Gain agility and ensure compliance when deploying firewall policies with GMS workflow automation. Manage network security by business processes and service levels rather than on a device-by-device basis.
- U.S. Patent 7,310,815 - A method and apparatus for data stream analysis and blocking.
Advanced Gateway Security Suite (AGSS)
Leverage SonicWall Advanced Gateway Security Suite (AGSS) to deliver a multi-engine sandbox, powerful anti‐virus, anti‐spyware, intrusion prevention, content filtering, as well as application intelligence and control services. An upgrade over CGSS, this package features Capture Advanced Threat Protection (ATP), a multi-engine sandbox that runs and inspects suspicious files, programs and code in an isolated cloud-based environment. Available on select SuperMassive 9000 series models.
Comprehensive Gateway Security Suite (CGSS)
Get the most from your high-performance firewall with the SonicWall Comprehensive Security Suite (CGSS) subscription. CGSS includes gateway anti-virus, anti-spyware, intrusion prevention, application intelligence and control service, content/URL filtering and 24x7 support. Combine security, productivity and support in a single solution with a low cost of ownership and greater ROI compared with buying each of the services individually.
Capture Advanced Threat Protection
The cloud-based SonicWall Capture Advanced Threat Protection Service scans a broad range of files to detect advanced threats, analyzes them in a multi-engine sandbox, blocks them prior to a security verdict, and rapidly deploys remediation signatures. The result is higher security effectiveness, faster response times and a lower total cost of ownership. Available on select SuperMassive 9000 series models.
Gateway security services
Enable your business firewall to provide real-time network threat prevention with SonicWall gateway anti-virus, anti-spyware, intrusion prevention, and application intelligence and control. Block the latest blended threats, including viruses, spyware, worms, Trojans, software vulnerabilities and other malicious code. Also, guarantee bandwidth prioritization and ensure maximum network security and productivity with the granular control and real-time visualization of application intelligence and control.
Gain a cost-effective, easy-to-manage way to enforce protection and productivity policies, and block inappropriate, unproductive and dangerous web content in educational, business or government environments. SonicWall Content Filtering Service lets you control access to websites based on rating, IP address, URL and more. You get the ideal combination of control and flexibility to ensure the highest levels of protection and productivity, which you can configure and control from your business firewall, eliminating the need for a costly, dedicated filtering solution. Extend enforcement of your internal policies to devices located outside the firewall perimeter by blocking unwanted internet content with the Content Filtering Client.
Content Filtering Client
Extend the enforcement of web policies in IT-issued devices outside the network perimeter. Although it doesn’t require a firewall, it can be optionally coupled with SonicWall Content Filtering Service as an ideal combination to keep students and employees off of dangerous or non-productive websites by switching to cloud-enforced policies even when they are using roaming devices.
Enjoy easy-to-use web-based traffic analytics and reporting, along with real-time and historical insights into the health, performance and security of your network. SonicWall Analyzer supports SonicWall firewalls and secure remote access devices, while leveraging application traffic analytics for security event reports. Get a complete solution that combines off-box application traffic analytics with granular statistical data generated by SonicWall firewalls.
Keep your security infrastructure current and react swiftly to any problem that may occur. If you need advanced technical support and the additional benefits of ongoing software and firmware updates, SonicWall 24x7 support gives you an around-the clock service that includes:
- Telephone and web-based support 24x7
- Direct access to a team of highly trained senior support engineers
- Advance exchange hardware replacement in the event of failure
- Access to Electronic support tools
TotalSecure hardware & services bundle
Enjoy the convenience and affordability of deploying your firewall as a SonicWall TotalSecure solution. This combines the hardware and all the services needed for comprehensive network protection from viruses, spyware, worms, Trojans, key loggers and more — before they enter your network — and without the complexity of building your own security package.
Provide your enterprise network with uncompromising deep security, with SonicWall SuperMassive 9000 Series Next-Generation Firewalls:
SonicWall SuperMassive 9800
Offers deep security to enterprises with:
- 40 Gbps of firewall throughput
- 24 Gbps of application inspection with intrusion prevention
- 10 Gbps of malware protection
SonicWall SuperMassive 9600
Give your enterprise network:
- 20 Gbps of high-performance business firewall throughput
- 5 Gbps of malware protection
- 11.5 Gbps of application inspection with intrusion prevention
SonicWall SuperMassive 9400
Provide your enterprise network with:
- 20 Gbps of high-performance firewall throughput
- 4.5 Gbps of malware protection
- 10 Gbps of application inspection with intrusion prevention
SonicWall SuperMassive 9200
Add deep security to your enterprise network with:
- 15 Gbps of high-performance firewall throughput
- 3.5 Gbps of malware protection
- 5 Gbps of application inspection with intrusion prevention
Legend: S — Standard, O — Optional, N — Not available
|TotalSecure Firewall Overview||9800||9600||9400||9200|
|Deep Packet Inspection Firewall||S||S||S||S|
|Stateful Packet Inspection Firewall||S||S||S||S|
|Unlimited File Size Protection||S||S||S||S|
|Threat Prevention Services Available||9800||9600||9400||9200|
|Application Intelligence and Control||S||S||S||S|
|Intrusion Prevention Service||S||S||S||S|
|Gateway Anti-Virus and Anti-Spyware||S||S||S||S|
|Content & URL Filtering (CFS)||S||S||S||S|
|SSL Inspection (DPI SSL)||S||S||S||S|
|Content Filtering Client (CFC)1||O||O||O||O|
|Capture Advance Threat Protection1||O||O||O||O|
|Enforced Client Anti-Virus and Anti-Spyware (McAfee® or Kaspersky®)||O||O||O||O|
|Interfaces||4x10GbE SFP+, 12x1GbE SFP, 8x1GbE, 1GbE Management, 1 Console||4x10GbE SFP+, 8x1GbE SFP, 8x1GbE, 1GbE Management, 1 Console||4x10GbE SFP+, 8x1GbE SFP, 1GbE Management, 1 Console|
|Management||CLI, SSH, GUI, GMS|
|Visual Information Display (LCD Display)||S||S||S||S|
|Site-to-Site VPN Tunnels||25000||10000|
|Global VPN Clients (Maximum)||2000(10000)||2000(10000)||2000(6000)||2000(4000)|
|SSL VPN NetExtender Clients (Maximum)||2 (3000)|
|SonicPoints Wireless Controller||N||S||S||S|
|WWAN Failover (4G/LTE)||N||N||N||N|
|Network Switch Management||N||S||S||S|
|Firewall Inspection Throughput2||40 Gbps||20 Gbps||20 Gbps||15 Gbps|
|Full DPI Performance (GAV/GAS/IPS)|| ||4.5 Gbps||4.4 Gbps||3 Gbps|
|Application Inspection Throughput||24 Gbps||11.5 Gbps||10 Gbps||5 Gbps|
|IPS Throughput||24 Gbps||11.5 Gbps||10 Gbps||5 Gbps|
|Anti-Malware Inspection Throughput||10 Gbps||5.0 Gbps||4.5 Gbps||3.5 Gbps|
|IMIX performance||9 Gbps||5.5 Gbps||5.5 Gbps||4.4 Gbps|
|SSL DPI Performance||5 Gbps||2.0 Gbps||2.0 Gbps||1.0 Gbps|
|VPN Throughput4||18 Gbps||11.5 Gbps||10 Gbps||5 Gbps|
|Maximum DPI Connections||2.5M||1.25M||1.0M||1.0M|
|SSL DPI Connections||48000||12000||10000||8000|
|Logging||Analyzer, Local Log, Syslog|
|Network Traffic Visualization||S||S||S||S|
|Authentication||XAUTH/ RADIUS, Active Directory, SSO, LDAP, Terminal Services6, Citrix6, Internal User Database|
|Dynamic Routing||BGP, OSPF, RIP|
|Single Sign-on (SSO)||S||S||S||S|
|Voice over IP (VoIP) Security||S||S||S||S|
|Interface to Interface Scanning||S||S||S||S|
|Dynamic Bandwidth Management||S||S||S||S|
|Stateful High Availability||S||S||S||S|
|Inbound Load Balancing||S||S||S||S|
|Terminal Services Authentication/Citrix Support||N||S||S||S|
|TLS/SL/SSH decryption and inspection||S||S||S||S|
|SSL Control for IPv6||S||S||S||S|
|Hardware Failover||Active/Passive with State Sync, Active/Active DPI with State Sync|
Legend: S — Standard, O — Optional, N — Not available
1 Services must be purchased separately.
2 Testing Methodologies: Maximum performance based on RFC 2544 (for firewall). Actual performance may vary depending on network conditions and activated services.
3 Full DPI/Gateway AV/Anti-Spyware/IPS throughput measured using industry standard Spirent WebAvalanche HTTP performance test and Ixia test tools. Testing done with multiple flows through multiple port pairs.
4 VPN throughput measured using UDP traffic at 1280 byte packet size adhering to RFC 2544.
5 Actual maximum connection counts are lower when services are enabled.
6 Not supported on SuperMassive 9800
Support Docs, Notes and Guides