This article covers some of the basic FAQ'S related to SonicWall NSv XS
Q: What is SonicWall NSv XS?
SonicWall NSv XS is SonicWall's entry-level Gen 8 virtual firewall — a single-core Next-Generation Firewall (NGFW) purpose-built for SOHO (Small Office/Home Office) and micro-SMB environments. It delivers enterprise-grade threat protection at an accessible price point
Q: How many virtual CPUs (vCPUs) does NSv XS support?
NSv XS is a single-core virtual firewall, supporting 1 vCPU. This single-core design reduces VM resource consumption and simplifies deployment for environments without dedicated IT staff.
Q: What are the minimum hardware requirements?
NSv XS requires a minimum of 2 GB RAM and 32 GB of storage. It runs as a lightweight VM on supported hypervisors.
Q: What are the throughput specifications for NSv XS?
NSv XS delivers the following throughput:
Q: How many VPN policies and tunnels does NSv XS support?
NSv XS supports 25 site-to-site VPN policies
Q: How many logical interfaces does NSv XS support?
NSv XS supports up to 128 logical VLAN/tunnel interfaces.
Q: Which hypervisors are supported by NSv XS?
NSv XS supports the following hypervisors:
Q: Is NSv XS available on public cloud platforms?
Yes. NSv XS is available on:
Q: When NSv XS will be available in AWS and Azure Marketplace?
NSv XS is expected to be available from the week of May 4th, subject to approvals from AWS and Azure Marketplace.
Q: What makes Proxmox support significant?
NSv XS is the first Gen 8 virtual firewall to offer native Proxmox support. This provides budget-conscious IT teams running the free, open-source Proxmox hypervisor with a full Gen 8 security option — something many competitors do not offer at this price tier.
Q: What threat protection technologies does NSv XS include?
NSv XS includes:
Q: Does NSv XS inspect encrypted (TLS) traffic?
Yes. NSv XS performs full TLS 1.3 and SSL/SSH deep inspection, eliminating blind spots in encrypted traffic — including east-west traffic between cloud workloads that cloud-native security groups cannot inspect.
Q: What networking and connectivity features are included?
NSv XS includes:
Q1: How is NSv XS managed?
NSv XS is managed via NSM (Network Security Manager)/Unified Management, SonicWall's centralised cloud management console. NSM provides a single pane of glass for all sites and workloads, including multi-tenant architecture for MSPs.
Q: Does NSv XS support zero-touch deployment?
Yes. NSv XS supports zero-touch provisioning allowing branch offices to go live without a technician on-site. Unlike a physical firewall, NSv requires manual registration before it can be managed by NSM via zero-touch provisioning.
Note: Before registration, NSv operates in an unlicensed mode without an associated serial number (SN), whereas a physical firewall has an embedded SN in its factory default state. When NSv is in an unlicensed state, none of the core functions are operational. Features such as VPN, management, and traffic pass-through are not available. Only limited functions like DNS configuration, basic administrative settings, and logging/diagnostics are accessible.
Q: What management and reporting tools are included?
NSv XS includes:
Q: What are the available subscription tiers for NSv XS?
NSv XS is offered in three annual subscription tiers:
Q:What is the cyber warranty included with NSv XS?
NSv XS includes an embedded Cysurance cyber warranty at no additional cost — up to $100K with the APSS tier and up to $200K with MPSS. This provides customers and auditors with financial assurance in the event of a breach. No competitor at this price point offers equivalent financial backing.
Q: Is PAYG (Pay As You Go) available?
Yes. On AWS, NSv XS is available as PAYG, meaning there is no upfront commitment and customers pay only for actual usage. This is particularly beneficial for DevOps, lab, or proof-of-concept environments.
Q: How does NSv XS address cloud security blind spots?
Cloud-native security groups define allow/deny rules but perform no traffic inspection — encrypted lateral movement between cloud workloads goes completely unseen. NSv XS deploys natively within the cloud boundary (AWS/Azure), inspecting east-west traffic using full TLS 1.3 decryption and RTDMI sandboxing.
Q: How does NSv XS support branch office deployments?
NSv XS runs as a VM on branch server infrastructure (VMware, Hyper-V, KVM, or Proxmox), eliminating the need to ship, stage, or replace hardware at each site. Zero-touch deployment and optional MPSS with SonicSentry NOC enable branches to go live with no local IT expertise required.
Q: What distinguishes NSv XS from competing entry-level virtual firewalls?
NSv XS offers three primary differentiators:
Q: Why should MSPs consider NSv XS?
NSv XS acts as a margin multiplier for MSPs — enabling more customer sites to be served from the same headcount. MPSS bundled with SonicSentry NOC creates a recurring managed firewall revenue stream. The $200K embedded cyber warranty serves as a competitive differentiator when presenting to prospective clients.
Q: What is the default mode in Gen 8?
Now, Global/Classic mode is the default modein Gen 8 NSv. SonicWall recommends staying in Classic mode.
Q: What are the features not supported in PolicyMode?
SAML Support, CSE Connector and anythingbeyond SonicOS 7.3.2
Q: Compared to TZ, What are the features not available in NSv XS?
Q: How to switch modes: Classic to Policy and Vice-versa?
Q: Is there a trial License available?
Yes, Trial License is available for NSv XS
Q: Can we delete interfaces from NSv XS?
SonicWall does not recommend deleting interfaces in NSv.
Q: Does NSv work in Closed Network?
NSv XS will not work in Closed Network. NSv S, M & L will be supported in Closed Network 8.2.2 Release.
Q: What are the NSM versions supported?
NSM 4.0.0 --> NSv XS
Q: Can users upgrade to newer generation of NSv from older generation without reboot or with seamless upgrade?
No, currently this is not supported.
Q: Can firmware upgrades be done via NSM?
Yes
Q: Does Microsoft Azure support Active/Standby High Availability without using Azure Load balancer?
NSv supports Layer 3 High Availability in Active/Standby Mode
Q: Does Azure Active/Standby HA solution support settings/configuration synchronizing?
Yes. Azure Active/Standby HA solution supports settings synchronization.
Q: Does Azure Active/Standby HA solution support Stateful synchronization
Yes, It is supported
Q: Is Availability zone settings supported on NSv Azure cloud deployments?
Yes. It is supported on standalone and HA deployments using ARM templates.
Q: Is HA supported for NSv AWS?
HA is not supported in NSv deployment in AWS. It is supported only in Azure
Q: Is migration of licenses possible from BYOL to PAYG and vice versa?
No. It is not possible to migrate the licenses
Q: Like TZ80, Gen 8 NSv won't work without an active subscription, correct?
Yes