Datasheet

Firewall
• Reassembly-Free Deep Packet Inspection
• Deep packet inspection for SSL
• Stateful packet inspection
• TCP reassembly
• Stealth mode
• Common Access Card (CAC) support
• DOS attack protection
• UDP/ICMP/SYN flood protection
Intrusion prevention
• Signature-based scanning
• Automatic signature updates
• Outbound threat prevention
• IPS exclusion list
• GeoIP and reputation-based filtering
• Regular expression matching
Anti-malware
• Stream-based malware scanning
• Gateway anti-virus
• Gateway anti-spyware
• SSL decryption
• Bi-directional inspection
• No file size limitation
• CloudAV threat database
Application control
• Application control
• Application component blocking
• Application bandwidth management
• Custom application signature creation
• Application trac visualization
• Data leakage prevention
• Application reporting over NetFlow/IPFIX
• User activity tracking (SSO)
• Comprehensive application signature
database
Web content filtering
• URL filtering
• Anti-proxy technology
• Keyword blocking
• Bandwidth manage CFS rating categories
• Unified policy model with app control
• 56 Content filtering categories
VPN
• IPSec VPN for site-to-site connectivity
• SSL VPN or IPSec client remote access
• Redundant VPN gateway
• Mobile Connect for iOS and Android
• Route-based VPN (OSPF, RIP)
Networking
• Dynamic routing
• SonicPoint wireless controller
• Policy-based routing
• Advanced NAT
• DHCP server
• Bandwidth management
• Link aggregation
• Port redundancy
• A/P high availability with state sync
• A/A clustering
• Inbound/outbound load balancing
• L2 bridge, wire mode, tap mode, NAT mode
VoIP
• Advanced QoS
• Bandwidth management
• DPI for VoIP trac
• H.323 gatekeeper and SIP proxy support
Management and monitoring
• Web GUI
• Command line interface (CLI)
• SNMPv2/v3
• O-box reporting (Scrutinizer)
• Centralized management and reporting
• Logging
• Netflow/IPFix exporting
• App trac visualization
• Centralized policy management
• Single Sign-On (SSO)
• Terminal service/Citrix support
• Solera Networks Forensics integration
SonicOS feature summary
Features
Content/context awareness
Feature Description
User activity tracking
GeoIP country trac
identification
Regular Expression DPI
filtering
User identification and activity are made available through seamless AD/LDAP/Citrix/Terminal
Services SSO integration combined with extensive information obtained through DPI.
Identifies and controls network trac going to or coming from specific countries to either
protect against attacks from known or suspected origins of threat activity, or to investigate
suspicious trac originating from the network.
Prevents data leakage by identifying and controlling content crossing the network through
regular expression matching.
11