Datasheet
Firewall
• Reassembly-Free Deep Packet Inspection
• Deep packet inspection for SSL
• Stateful packet inspection
• TCP reassembly
• Stealth mode
• Common Access Card (CAC) support
• DOS attack protection
• UDP/ICMP/SYN Flood Protection
Intrusion prevention
• Signature-based scanning
• Automatic signature updates
• Outbound threat prevention
• IPS exclusion list
• GeoIP and Reputation-based filtering
• Regular Expression matching
• UDP/ICMP/SYN Flood protection
Anti-Malware
• Stream-based malware scanning
• Gateway anti-virus
• Gateway anti-spyware
• SSL decryption
• Bi-directional inspection
• No file size limitation
• CloudAV threat database
Application control
• Application control
• Application component blocking
• Application bandwidth management
• Custom application signature creation
• Application Trac Visualization
• Data leakage prevention
• Application reporting over NetFlow/IPFIX
• User activity tracking (SSO)
• Comprehensive application signature
database
Web content filtering
• URL filtering
• Anti-proxy technology
• Keyword blocking
• Bandwidth manage CFS rating categories
• Unified policy model with app control
• 56 Content filtering categories
VPN
• IPSec VPN for site-to-site connectivity
• SSL VPN or IPSec client remote access
• Redundant VPN gateway
• Mobile Connect for Apple
®
iOS and
Google
®
Android
™
• Route-based VPN (OSPF, RIP)
Networking
• Dynamic routing
• SonicPoint wireless controller*
• Policy-based routing
• Advanced NAT
• DHCP server
• Bandwidth Management
• Link aggregation
• Port redundancy
• A/P High availability with State Sync
• A/A Clustering
• Inbound/Outbound Load balancing
• L2 Bridge, Wire mode, Tap Mode, NAT
Mode
VoIP
• Advanced QoS
• Bandwidth management
• DPI for VoIP trac
• H.323 gatekeeper and SIP proxy support
Management and monitoring
• Web GUI
• Command line interface (CLI)
• SNMPv2/v3
• O-Box reporting (Scrutinizer)
• Centralized management and reporting
Global Management System policy
management and reporting
• Logging
• Netflow/IPFix Exporting
• App Trac visualization
• LCD management screen
• Centralized policy management
• Single Sign-On (SSO)
• Terminal service/Citrix support
• Solera Networks Forensics integration
SonicOS feature summary
Features
Content/context awareness
Feature Description
User activity tracking
GeoIP country trac
identification
Regular Expression DPI
filtering
User identification and activity are made available through seamless AD/LDAP/Citrix/Terminal
Services SSO integration combined with extensive information obtained through DPI.
Identifies and controls network trac going to or coming from specific countries to either
protect against attacks from known or suspected origins of threat activity, or to investigate
suspicious trac originating from the network.
Prevents data leakage by identifying and controlling content crossing the network through
regular expression matching.
8
*SonicPoint wireless controller available in 9000 series at the time of publication