SonicOS 8 Release Notes

Version 8.0.2-8011

August 2025

The platform-specific version for this unified release is the same:

Platform Firmware Version
TZ80 8.0.2-8011
TZ380 8.0.2-8011
TZ480 8.0.2-8011
TZ680 8.0.2-8011
NSa 2800 8.0.2-8011
NSa 3800 8.0.2-8011

This maintenance release provides fixes for previously reported issues.

Resolved Issues

Issue ID Issue Description
GEN8-6768 The Cloud Secure Edge (CSE) connector fails to automatically recover after an extended internet outage.
GEN8-8050 When connecting to the 10G SFP+ port using a copper twinaxial cable, and disabling the 10G port in the management interface, the link is still active in the peer device.
GEN8-8721 The console displays the error message snwl_mv_cpss_lacp_port_tcam_flood_block: src port 15 dst port 10 cpssDxChVirtualTcamRuleWrite FAILED when adding a link aggregation group on the Switching > Link Aggregation page.
GEN8-8798 NSa 2800 only: A NSa 2800 firewall cannot be detected by the SonicExpress Setup Guide when using an iPhone connected to the firewall using an USB cable.
GEN8-9022 The console displays the error message initTcamMgr: cpssDxChVirtualTcamCreate tcam id 3 FAILED rc = [4] during firewall boot up
GEN8-9768 Unable to add a FQDN Address object to an Address group that is part of a NAT policy.
GEN8-9794 Local users members of SonicWall Administrators group are logged out after 2 minutes while actively working in the management interface when Open user's login status window in the same window rather than in a popup is enabled.
GEN8-9814 The error Account Already in Use is displayed when a NetExtender user tries to connect to SSL VPN when the SSL VPN session was not removed when two-factor authentication (TFA) failed.
GEN8-9825

A new SonicWall firewall DPI-SSL CA certificate has been added and will require to be distributed if in-use.

GEN8-9831 A Remote Reset error is displayed when performing a firewall firmware upgrade using Network Security Manager (NSM) for firewalls with High Availability Stateful Synchronization enabled.
GEN8-9857 Syslog data sent from the firewall is incomplete when SSO is enabled and the zone is configured to be a trusted zone.
GEN8-9866 A failure message is displayed when the reset counters are clicked in the routing rules.
GEN8-9877

Upgrading the firmware to SonicOS 8.0.2 on firewalls configured for in High Availability and managed by NSM:

The fix included in the latest SonicOS 8.0.2 release allows upgrading the firmware on firewalls configured for High Availability from SonicOS 8.1.0 to a higher firmware version.

To upgrade the firmware to 8.0.2:

  1. Disable High Availability Stateful Synchronization on the High Availability Active firewall.
  2. Restart both of the firewalls configured for High Availability.
  3. After the firewalls come up, check and ensure High Availability Stateful Synchronization is disabled on both firewalls.
  4. Perform the firmware upgrade.
  5. After both the High Availability firewalls are upgraded to SonicOS 8.1.0, enable High Availability Stateful Synchronization.

After the firewalls are upgraded to SonicOS 8.1.0, the next firmware upgrade to a higher version of SonicOS can be performed directly using NSM without having to perform these steps.

Known Issues

Issue ID Issue Description
GEN8-8692 NSa 3800 only: Flow control does not work well on the NSa 3800 when link speed of the port is configured as Forced (for example: 1G Full Duplex or 100M Full Duplex).
GEN8-9970 The X1 egress rate is not displayed on the Monitor > Real-Time Charts > System Monitor > Interface Usage page.
GEN8-10311

Before registering the firewall, if Enable Logging to Secondary Storage is selected, then the logs that should be visible on Monitor > Logs > System Log are not displayed and an error message is displayed instead.

Register the firewall on the License page.

GEN8-10323 Sometimes traffic fails after High Availability failover when the High Availability Virtual MAC and Override Virtual MAC are both enabled.
GEN8-10453

When the firmware auto update feature is enabled on firewalls configured for High Availability, if the new firmware auto download on the High Availability active firewall is slow and takes more than 45 seconds to complete, the downloaded firmware cannot be synced to the High Availability idle firewall, and the auto install will not complete as expected.

If your firewall is configured for High Availability, the active firewall auto-downloaded a new firmware, and the firmware does not synchronize to the standby firewall:

  1. Delete the uploaded firmware on the active firewall which has been auto-downloaded.
  2. On active firewall:
    1. Manually upload the new firmware.

      It will be synced to the standby firewall.

    2. Upgrade the firmware using the manually uploaded firmware.

      The standby firewall will restart first, then the active firewall will restart with the new firmware.

Additional References

GEN8-10036