End of Support for HTTP-Based Signature Downloads Through a Proxy Server

Overview

From 30 September 2026, SonicWall will no longer accept HTTP for signature and licence downloads through a proxy server. Firewalls still using the HTTP method after this date will stop receiving security signature updates. To remain protected, upgrade to SonicOS 7.3.0 or later (Gen7) or SonicOS 8.2.0 or later (Gen8), where the same feature runs over HTTPS on port 443, and confirm your proxy and firewall permit outbound TCP 443 to SonicWall License Manager.

SonicWall firewalls deployed in closed network environments, where all outbound traffic is forced through a gateway web proxy, or where SonicOS Web Proxy forwarding is configured, can download security service signatures and synchronize licenses through that proxy server. This capability is configured under Policy | Security Services | Summary and has been available since SonicOS 5.8.

Historically this traffic was carried over HTTP. SonicWall is retiring that transport.

Note: On 30 September 2026, SonicWall License Manager will stop accepting HTTP requests for signature and licence downloads. Only HTTPS on TCP port 443 will be accepted after that date.

What happens if no action is taken

A firewall still using the HTTP method after 30 September 2026 will continue to pass traffic and will continue to enforce the signatures already loaded on the appliance. However:

  • Gateway Anti-Virus, Intrusion Prevention, Anti-Spyware, Application Control, Botnet Filter and Geo-IP signature updates will fail.
  • Licence synchronisation and appliance registration through the proxy will fail.
  • Protection against newly discovered threats will not be applied, and the gap widens with every day that passes.

In other words, the firewall does not go offline, but its threat protection stops advancing. SonicWall strongly recommends completing the change well before the cutoff date.

Cause

Unencrypted HTTP does not protect update traffic in transit and is inconsistent with the encrypted transport used everywhere else between the appliance and SonicWall cloud services. Retiring it:

  • removes plaintext security-related traffic from the network, which many compliance frameworks and cyber-insurance assessments now require;
  • protects the integrity of update metadata against observation or interference by an on-path attacker; and
  • aligns signature delivery with the encrypted transport already used for all other SonicWall cloud communication.

SonicOS 7.3.0 (released July 2025) and SonicOS 8.2.0 introduced the replacement: signature download via proxy now uses HTTPS over port 443, ensuring secure transmission of update files in proxy environments. The feature name, the configuration screen and the configuration workflow are unchanged, only the transport is now encrypted.

Are you affected?

Check both conditions below. You are affected only if both are true.

Check

How to verify

1. Is the proxy method in use?

In SonicOS, navigate to Policy | Security Services | Summary and look at the “Signature downloads through a proxy server” section. If “Download Signatures through a Proxy Server” is enabled, the proxy method is in use.

2. Is the firmware below the required version?

Navigate to Device | Settings | Firmware and Settings (or check the Dashboard). Gen7 firewalls must be on SonicOS 7.3.0 or later. Gen8 firewalls must be on SonicOS 8.2.0 or later.

  • Both true — action required. Follow the resolution steps below before 30 September 2026.
  • Proxy option disabled — no action required. Your firewall connects directly to SonicWall over HTTPS and is unaffected.
  • Already on 7.3.0+ / 8.2.0+ with the proxy option enabled — no action required. Your signature downloads already use HTTPS. Confirm your proxy permits outbound TCP 443 (step 4 below).

Resolution

 

Step 1 — Record your current proxy configuration

Before upgrading, note the existing values so they can be verified afterwards:

  • Proxy Server Name or IP Address
  • Proxy Server Port
  • Whether “This Proxy Server requires Authentication” is enabled, and the username used

Export a current configuration backup from Device | Settings | Firmware and Settings before making any change.

Step 2 — Upgrade the firmware

  1. Sign in to MySonicWall and download the appropriate firmware for your platform: SonicOS 7.3.0 or later for Gen7 firewalls or SonicOS 8.2.0 or later for Gen8 firewalls.
  2. SonicWall recommends the latest available 7.3.x or 8.2.x maintenance build rather than the minimum version, so that a second maintenance window is not required shortly afterwards.
  3. Review the release notes for your target version before upgrading. Note in particular for SonicOS 7.3.0: downgrading to 7.0.x, 7.1.x or 7.2.x is not supported; upgrading NSv from 7.0.1 requires a fresh installation.
  4. Upload and apply the firmware under Device > Settings > Firmware and Settings, then reboot into the new build.
  5. If the firewall is part of a High Availability pair, follow the standard HA upgrade procedure and confirm both units report the same firmware version afterwards. Where the primary unit still uses a legacy password policy, align the password policy across both units before synchronising.

Step 3 — Verify the proxy settings survived the upgrade

  1. Navigate to Policy | Security Services | Summary.
  2. In the “Signature downloads through a proxy server” section, confirm “Download Signatures through a Proxy Server” is still enabled.
  3. Confirm the Proxy Server Name or IP Address and Proxy Server Port match the values recorded in step 1.
  4. If “This Proxy Server requires Authentication” is enabled, re-enter the proxy password. Leaving the password field empty preserves the stored value.
  5. Click Accept.
    Note: No new or different setting needs to be enabled. HTTPS is used automatically on supported firmware.

Step 4 — Permit outbound HTTPS to SonicWall License Manager

This is the most common cause of failure after upgrading. Environments that previously only needed port 80 for this traffic must now allow port 443.

  • On the proxy server, and on any upstream firewall or egress filter, permit outbound TCP port 443 to the SonicWall License Manager destinations.
  • If the proxy server performs TLS inspection or SSL interception, either add a bypass for the SonicWall License Manager destinations, or ensure the proxy presents a certificate chain the firewall trusts. TLS interception without a trusted chain will cause the download to fail.
  • If the proxy enforces URL or category filtering, confirm the SonicWall update and licensing destinations are allowlisted.
  • Confirm outbound DNS resolution for the SonicWall licensing and update hostnames is working from the firewall.
    If you are unsure which destinations to allowlist, contact SonicWall Technical Support and reference this article.

Step 5 — Verify signature downloads are working

  1. Navigate to Device | Settings | Licenses and click Synchronize. The licence list should refresh without error.
  2. Navigate to Band confirm the signature database timestamps for Gateway Anti-Virus, Intrusion Prevention and Anti-Spyware have advanced to a current date.
  3. Check the event log for signature update or licensing failures. A clean log with a recent successful update confirms the change is complete.
  4. Re-check the signature timestamps 24 hours later to confirm scheduled updates are also succeeding, not only the manual synchronisation.

If your firewall cannot be upgraded

Gen6 and earlier platforms cannot run SonicOS 7.3.0 or 8.2.0 and therefore cannot use the HTTPS proxy method. These appliances will stop receiving signature updates through a proxy after 30 September 2026.

The supported path is to migrate to a currently supported Gen7 or Gen8 appliance. Check your platform’s status on the SonicWall Product Life Cycle Tables, then contact your SonicWall partner or account team to plan the migration.

Because the cutoff date is fixed, SonicWall recommends starting this conversation immediately rather than waiting for the deadline.

Frequently asked questions

  • Will my firewall stop working on 30 September 2026?
    No. The firewall continues to pass traffic and continues to enforce the signatures already installed. What stops is the delivery of new signature updates and licence synchronisation through the proxy, so protection against newly discovered threats will no longer be applied.
  • Is SonicWall removing the ability to download signatures through a proxy?
    No. The proxy method remains fully supported and is still the recommended approach for closed network environments. Only the unencrypted HTTP transport is being retired. The configuration screen and workflow are unchanged.
  • Do I need to change any setting inside SonicOS after upgrading?
    No. On SonicOS 7.3.0 or later and 8.2.0 or later, HTTPS is used automatically. You only need to confirm your existing proxy settings are intact and that outbound TCP 443 is permitted.
  • My proxy only allows port 80 for this traffic. What do I do?
    Outbound TCP 443 to the SonicWall License Manager destinations must be permitted for the supported method to work. If your policy cannot allow this, contact SonicWall Technical Support to review alternatives for your environment.
  • My proxy performs SSL inspection. Will that break signature downloads?
    It can. Either bypass TLS inspection for the SonicWall License Manager destinations, or ensure the certificate chain presented by the proxy is trusted by the firewall.
  • Can the 30 September 2026 date be extended for my organisation?
    The change is enforced centrally in SonicWall License Manager and is not configurable per customer. If you have a constraint that makes the date unachievable, raise a case with SonicWall Technical Support as early as possible so it can be reviewed.
  • Does this affect Capture Client, Email Security, SMA or Cloud Secure Edge?
    No. This change applies specifically to firewall security-service signature and licence downloads through the SonicOS proxy server feature.
  • Which firmware version should I target?
    SonicOS 7.3.0 and 8.2.0 are the minimum supported versions. SonicWall recommends the latest available 7.3.x or 8.2.x maintenance build so that you receive current security fixes at the same time.
  • How do I confirm the change worked?
    Synchronize licenses under Device | Settings | Licenses, then confirm the signature database timestamps under Policy > Security Services > Summary have advanced to a current date. Re-check 24 hours later to confirm scheduled updates are succeeding.

Related information

  • Previous Alert
    Last Time Buy Announcement SonicWall NSv 270, NSv 470 and NSv 870 Virtual Firewall Appliances
    Read More
  • Next Alert
    MySonicWall And Unified Management Scheduled Maintenance – Oct 9-10, 2026
    Read More