Network Security, Products & Services

Why Do New Firewalls Go Live Before They Are Actually Protected?

by Asif Mujtaba

How SonicOS 8.2.2 Closes the Registration-to-Protection Gap on GEN8 Appliances

There is a quiet gap in almost every firewall deployment, and it rarely appears on anyone's project plan.

An appliance arrives on site. Someone racks it, cables it, brings up the WAN link, and confirms that traffic is flowing. The deployment is declared successful because the visible test succeeded: users can reach the internet, and the phones have stopped ringing. What has not yet happened is the part nobody sees. Gateway Anti-Virus may not be inspecting anything. Intrusion Prevention may be licensed but idle. Botnet Filtering may be switched off.

The firewall is online. It is not yet protecting anyone.

Why Does This Protection Gap Exist in the First Place?

The gap is not caused by carelessness. It is a structural consequence of how firewalls have traditionally been deployed.

  • Licensing and enablement are separate events. A security service can be fully paid for and still be inactive. Purchase does not imply protection, and the distinction is easy to lose track of across an estate of appliances.
  • Deployment pressure favors connectivity over inspection. Connectivity failures are loud and immediate. Inspection failures are silent. When a deployment window is tight, the loud problem wins, and security tuning is deferred to a follow-up task that is often never scheduled.
  • Nothing reports the omission. An appliance with inspection disabled does not raise an alert, fail a health check, or appear in a dashboard as deficient. It simply passes traffic. The omission usually surfaces during an incident review, which is the most expensive possible moment to discover it.

The result is a population of appliances that are registered, licensed, monitored, and materially less protected than their owners believe.

What Security Services Does SonicOS 8.2.2 Enable by Default?

SonicOS 8.2.2 inverts the default. On new GEN8 appliances, the core security services activate automatically at the point of registration, with no manual configuration step required:

  • Gateway Anti-Virus
  • Anti-Spyware
  • Intrusion Prevention
  • Botnet Filtering
  • Geo-IP Filtering

Registration and protection become the same event rather than two events separated by an interval of unknown length. This is a small change in mechanics and a significant change in posture. The question at handover is no longer "were the security services enabled?" but "were any of them deliberately changed?" The second question is far easier to answer, and far easier to audit.

Why Does This Matter More for MSPs and Multi-Site Estates?

For a single site, the gap described above is a manageable risk. For a managed service provider onboarding dozens of sites, it is a recurring one. Every manual enablement step is an opportunity for omission, and the probability of at least one omission approaches certainty as the estate grows. Worse, the omission is not evenly distributed: it concentrates in exactly the deployments that were rushed, performed out of hours, or handled by whoever was available rather than whoever was most experienced.

Deployment FactorTraditional Manual EnablementSonicOS 8.2.2 Secure-by-Default
Manual enablementEach service is switched on by a technician after connectivity is confirmedGateway Anti-Virus, Anti-Spyware, Intrusion Prevention, Botnet Filtering, and Geo-IP Filtering activate at registration
Onboarding speedDeployment time is split between network design and baseline security setupTechnicians spend deployment time on network design and customer-specific policy
Starting postureEvery appliance may begin from a different, undocumented stateEvery appliance begins from the same known posture, so drift is detectable
Audit positionRequires proving a checklist was followed correctly on every occasionProtection enabled by design is easier to demonstrate than a checklist history
Channel riskPartners carry the risk that a shipped appliance went live unprotectedPartners are no longer carrying that risk by default

 

Figure 1: Traditional Manual Enablement vs. SonicOS 8.2.2 Secure-by-Default

Does Enabling Services by Default Replace the Need for Tuning?

It is worth being direct about what this feature does not do. Enabling services by default establishes a sound baseline. It does not replace tuning, and it is not a substitute for understanding the environment. Signature policies, inspection exclusions, bandwidth considerations, and application-specific behavior all still warrant attention from an administrator who knows the network.

Geo-IP Filtering deserves particular mention. The default policy is deliberately conservative, restricted to a small set of high-risk regions, precisely so that it improves posture without disrupting legitimate traffic on day one. Administrators retain complete control and can widen, narrow, or disable the policy to suit the environment. A broadened Geo-IP policy can have side effects worth planning for, including on automated services that contact the appliance from distributed infrastructure.

The intent is not to make decisions on the administrator's behalf. The intent is to ensure that the absence of a decision does not leave an appliance undefended.

 

 

SonicOS_8.2.2_Protection_graphic_v4.png

How Should Organizations Get Started with SonicOS 8.2.2?

For new GEN8 deployments running SonicOS 8.2.2, no action is required. Register the appliance, and the services listed above are active.

For existing estates, the most valuable exercise is a short audit. Confirm which appliances currently have inspection services enabled, and compare that against which appliances are licensed for them. In most estates, the two lists are not identical, and the difference is the gap this feature was built to close.

For upgrade guidance and full feature details, consult the SonicOS 8.2.2 Release Notes and the SonicOS 8.2.2 Frequently Asked Questions on the SonicWall Knowledge Base, or contact your SonicWall representative or partner.

Frequently Asked Questions

QuestionAnswer
Why isn't a newly deployed firewall protecting a network right away?Historically, licensing and enablement have been separate events. A service can be fully paid for and still sit inactive because connectivity failures are loud and inspection failures are silent, so security tuning is often deferred and never revisited.
What security services does SonicOS 8.2.2 enable by default on GEN8 appliances?Gateway Anti-Virus, Anti-Spyware, Intrusion Prevention, Botnet Filtering, and Geo-IP Filtering all activate automatically at registration, with no manual configuration required.
Does enabling services by default replace the need for security tuning?No. It establishes a sound baseline, not a ceiling. Signature policies, inspection exclusions, bandwidth considerations, and application-specific behavior still require attention from an administrator who understands the network.
How conservative is the default Geo-IP Filtering policy?The default policy is restricted to a small set of high-risk regions so that it improves posture without disrupting legitimate traffic on day one. Administrators can widen, narrow, or disable the policy at any time.
What should partners do with firewalls deployed before SonicOS 8.2.2?Run a short audit: confirm which appliances currently have inspection services enabled and compare that list against which appliances are licensed for them. The difference identifies the gap that needs closing.

 

Learn more: 

 

 

Share This Article

An Article By

Asif Mujtaba

Product Manager

Asif Mujtaba is a Product Manager at SonicWall with over a decade of experience in cybersecurity, specializing in product management and technical leadership. He is passionate about driving innovation and delivering secure, scalable solutions that empower organizations to navigate the evolving threat landscape.

Related Articles

  • Why Patching Isn't Enough: Active Cybersecurity Management 2026 | SonicWall
    Read More
  • Beyond the CVE: Why Secure by Design and Automated Patching Are Redefining Protection
    Read More