SonicOS 8 Release Notes

Version 8.0.1-8017

May 2025

Compatibility and Installation Notes

  • Most popular browsers are supported, but Google Chrome is preferred for the real-time graphics display on the Dashboard.
  • A MySonicWall account is required.

The platform-specific version for this unified release is the same:

Platform Firmware Version
TZ80 8.0.1-8017
NSa 2800 8.0.1-8017

The TZ80 must be licensed before it can be configured or used.

The TZ80 must always be connected to the Internet. It cannot be used in a closed network environment.

Beginning with SonicOS 8.0.0, these SonicPoint devices will no longer be supported:

  • SonicPoint-N
  • SonicPoint-NDR
  • SonicPoint-Ni/Ne
  • SonicPoint-ACe/ACi/N2

What's New

  • SonicOS 8.0.1 adds support for the NSa 2800.
  • SonicOS 8.0.1 includes in-product migration where you can import settings from your:
    • SonicWall SOHO/SOHOW security appliance to your new SonicWall TZ80.
    • SonicWall NSa 2600 or NSa 2700 security appliance to your new NSa 2800.
  • For more information, refer to the SonicOS 8 Migration Requirements Reference Guide.

  • Beginning with SonicOS 8.0.0, support for the security protocols WEP and TKIP has been deprecated.

This maintenance release provides fixes for previously reported issues

Resolved Issues

Issue ID Issue Description
GEN8-1740 TZ80 only: When the X4 port is connected to a Dell Force10 switch or another SonicWall firewall in Auto Negotiate mode, the remote port is negotiated as 1G Half Duplex.
GEN8-5152 TLS displayed as Disabled when a LDAP server is automatically added, and displays an error if you try to manually enable TLS.
GEN8-6497 The Setup Wizard displays Failure: "failed to finish auto-configuration" on the summary page. After clicking OK, it will proceed, and the Setup Wizard settings are saved and take effect.
GEN8-6581 TZ80 only: The license expiration time is inconsistent with MySonicWall due to the time zone difference (+/- 12 hours).
GEN8-6748 When adding a network object 0.0.0.0/8, the firewall does not display the correct net mask when saved.
GEN8-6761 User login authentication redirection starting from HTTPS URLs is not working in Chrome and Microsoft Edge browser versions 129.0.x.x and 130.0.x.x.
GEN8-6817 A newly added local user may not be seen until a refresh is done.
GEN8-6833 TZ80 only: The Wireless Clients Configure button is always grayed out on the Access Point Monitor.
GEN8-6864 TZ80 only: After the TZ80 starts up, the following error is displayed: License Manager Unavailable. The firewall can no longer communicate with the Licensing Server (LM/License Manager). Please restore.
GEN8-7799 SonicWall SSL VPN Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
GEN8-7800 SonicWall SSL VPN Authentication Bypass Vulnerability
GEN8-7801 SonicWall SSH Management Server-Side Request Forgery Vulnerability
GEN8-7824 When a large number of VPN security associations are present in a Stateful High Availability environment, some IKE security associations may not be cleaned up on the secondary device if the synchronization fails.

Known Issues

Issue ID Issue Description
GEN8-6938 After Cloud Edge Security (Cloud Edge Security) Tunnels are down, it takes a longer time (about 8 minutes) to get the WireGuard Session Disconnect Log even after Cloud Edge Security status shows "down" status.
GEN8-7902 NSa 2800 only: Flow control may not function as expected when the link speed of a port is configured as Forced (e.g., 1G Full Duplex,100M Full Duplex).
GEN8-8036 NSa 2800 only: The auto-update feature is not automatically installing the downloaded firmware on firewalls in a High Availability configuration when one of firewalls is offline.
GEN8-8050 When the 10G SFP+ port is connected with copper twinax cable, after disabling the 10G port using firewall web management interface, the actual link is still available in the peer device.
GEN8-8125 Logging out multiple selected guest users may not function as expected.
GEN8-8154 The expired IPsec Signature Authority of IKEv2 VPN is not deleted on an idle firewall in a High Availability configuration.
GEN8-8216 NSa 2800 only: When importing settings from SonicWall GEN 7 appliances, if there is a L3 LAG or port redundancy created between interfaces that translate to SFP vs. non-SFP, then that L3 LAG or port redundancy will not be created. The settings in general will be imported without any issues. There will be a WARNING displayed in the console logs regarding not creating the L3 LAG and port redundancy.
GEN8-8528 The DNS Security > DNS Report > Host page displays the same host names for multiple IP addresses listed on this page.
GEN8-8721 The console displays the error message snwl_mv_cpss_lacp_port_tcam_flood_block: src port 15 dst port 10 cpssDxChVirtualTcamRuleWrite FAILED when adding a link aggregation group on the Switching > Link Aggregation page.
GEN8-8749 The search fails when searching for a LDAP user with a Qualified Login Name with the error "qualified-name" is not a reasonable value.
GEN8-8798 NSa 2800 only: A firewall cannot be detected by the SonicExpress Setup Guide when using an iPhone with an USB connection to the firewall.
GEN8-9022 The console displays cpss failure "initTcamMgr: cpssDxChVirtualTcamCreate tcam id 3 FAILED rc = [4] while the firewall starts up.