SonicWall TZ580 TotalSecure Essential Edition

SonicWall TZ580 Appliance with 1Yr of ESSENTIAL PROTECTION: Essential Protection Security Suite (EPSS) includes - Capture Advanced Threat Protection, Gateway Anti-Virus, Anti-Spyware, Intrusion Prevention, Application Firewall Service, Content Filtering Services, Comprehensive Anti-Spam, 24x7 Support with firmware updates And Cloud Management with 7-Day Alerting, Basic Reporting.
SKU: 03-SSC-9189
£2,360.44
£1,827.93

See configuration tab below.


General
Operating system SonicOS 8
Interfaces 8 x 1GbE, 2 x 10G/5G/2.5G/1G SFP, 1 console (Micro-USB), 1 USB (type-C)
Redundant power Yes
Storage expansion Optional up to 512 Gb
Management Network Security Manager (NSM), CLI, SSH, Web UI, GMS, REST APIs
SAML Single Sign-On (SSO) Users 2500
VLAN interfaces 256
Access points supported (maximum) 32
 
Firewall/VPN Performance
Firewall inspection throughput 4.5 Gbps
Threat Prevention throughput 2.2 Gbps
Application inspection throughput 2.5 Gbps
IPS throughput 2.5 Gbps
Anti-malware inspection throughput 2.2 Gbps
TLS/SSL decryption and inspection throughput 750 Mbps
IPSec VPN throughput 2.2 Gbps
Connections per second 20000
Maximum connections (SPI) 1 400 000
Maximum connections (DPI) 500 000
Maximum connections (TLS) 60 000
VPN
Site-to-site VPN tunnels 250
IPSec VPN clients (maximum) 10 (500)
SSL VPN licenses (maximum) 2 (200)
Encryption/authentication AES (128, 192, 256-bit)/MD5, SHA-256, SHA-384, Suite B Cryptography
Key exchange Diffie Hellman Groups 1, 2, 5, 14v
Route-based VPN RIP, OSPF, BGP
Certificate support Verisign, Thawte, Cybertrust, RSA Keon, Entrust and Microsoft CA for SonicWall-toSonicWall VPN, SCEP
VPN features Dead Peer Detection, DHCP Over VPN, IPSec NAT Traversal, Redundant VPN Gateway, Route-based VPN
Global VPN client platforms supported Microsoft® Windows 10/11
NetExtender Microsoft® Windows 10/11, Linux
Mobile Connect Apple® iOS, Mac OS X, Google® Android™
 
Security Services (with subscription APSS or MPSS)
Deep Packet Inspection services Gateway Anti-Virus, Anti-Spyware, Intrusion Prevention, TLS Decryption
Content Filtering Service (CFS) HTTP URL, HTTPS IP, keyword and content scanning, Comprehensive filtering based on file types such as ActiveX, Java, Cookies for privacy, allow/forbid lists
Comprehensive Anti-Spam Service Yes
Application Visualization Yes
Application Control Yes
Capture Advanced Threat Protection Yes
Advanced DNS Filtering Yes
 
Networking
IP address assignment Static, (DHCP, PPPoE, L2TP and PPTP client), Internal DHCP server, DHCP relay
NAT modes 1:1, 1:many, many:1, many:many, flexible NAT (overlapping IPs), PAT, transparent mode
Routing protocols BGP4, OSPF, RIPv1/v2, static routes, policy-based routing
QoS Bandwidth priority, max bandwidth, guaranteed bandwidth, DSCP marking, 802.1e (WMM)
Authentication LDAP (multiple domains), XAUTH/RADIUS,TACACS+, SAML SSO1, Radius accounting NTLM, internal user database, 2FA, Terminal Services, Citrix, Common Access Card (CAC)
Local user database 1000
VoIP Full H.323v1-5, SIP
Standards TCP/IP, UDP, ICMP, HTTP, HTTPS, IPSec, ISAKMP/IKE, SNMP, DHCP, PPPoE, L2TP, PPTP, RADIUS, IEEE 802.3
Certifications IPv6
Certifications pending FIPS 140-2 (with Suite B) Level 2, IPv6 (Phase 2), ICSA Network Firewall, ICSA Anti-virus, Common Criteria NDPP (Firewall and IPS)
High availability Active/Standby with stateful synchronization
 
Hardware
Form factor Desktop
Power supply 12V/1.34A
Maximum power consumption (W) 15.6
Input power 100 - 240 VAC, 50-60 Hz
Total heat dissipation 56.74
Dimensions 3.5 x 13 x 19 (cm)
Shipping 7.2 x 22.8 x 23 (cm)
Weight 0.97 kg
WEEE weight 1.42 kg
Shipping weight 1.93 kg
MTBF (years) 30.7
Environment (Operating/Storage) 0°to 40°/-40°C / -40° to 70° C
Humidity 5-95% non-condensing
 
Regulatory
Regulatory model numbers APL70-11D
Major regulatory compliance FCC Class B, ICES Class B, CE (EMC, LVD, RoHS), UL, cUL, Mexico DGN Notice by UL, ANATEL, WEEE, REACH, SCIP, RCM, MIC Terminal, VCCI Class B, KCC/MSIP, BSMI, MTCTE/TEC, CB
Essential Protection Service Suite
Complete network security, content filtering, application control, CaptureATP, gateway anti-virus, anti-spam, 24x7 support in a single integrated package.

The SonicOS architecture is at the core of SonicWall physical and virtual firewalls including the TZ, NSa, NSv and NSsp Series. SonicOS leverages our patented, single-pass, lowlatency, Reassembly-Free Deep Packet Inspection® (RFDPI) and patent-pending Real-Time Deep Memory Inspection™ (RTDMI) technologies to deliver industry-validated high security effectiveness, SD-WAN, real-time visualization, high-speed virtual private networking (VPN) and other robust security features.

Through a combination of cloud-based and on-box technologies we deliver protection to our firewalls that’s been validated by independent third party testing for its extremely high security effectiveness. Unknown threats are sent to SonicWall’s cloud-based Capture Advanced Threat Protection (ATP) multiengine sandbox for analysis. Enhancing Capture ATP is our RTDMI™ technology. The RTDMI engine detects and blocks malware and zero-day threats by inspecting directly in memory. RTDMI technology is precise, minimizes false positives, and identifies and mitigates sophisticated attacks where the malware’s weaponry is exposed for less than 100 nanoseconds.

At a Glance
  1. Complete network security solution
    All security licences included.
  2. Capture ATP
    Multi-engine network sandbox to prevent zero-day threats. See Capture Advanced Threat Protection Service (CATPS).
  3. Gateway anti-virus and anti-spyware protection
    Including DPI-SSL and RFDPI.
  4. Cutting-edge IPS technology
    Protects against worms, trojans, software vulnerabilities and other intrusions by scanning all network traffic for malicious or anomalous patterns.
  5. Application intelligence and control
    Set of granular, application-specific policies providing application classification and policy enforcement to help administrators control and manage both business and non-business related applications.
  6. Content filtering
    Enforce internet use policies and control internal access to inappropriate, unproductive and potentially illegal web content with comprehensive content filtering. See Content Filtering Service (CFS).
  7. Network Topology View
    Display hosts, access-points in the network based on device name, mac address and IP Address.
  8. 24x7 support with firmware updates and hardware replacement
    Including firmware updates and hardware replacement protects your business and your SonicWall investment.
Remote Configuration & Setup

When you purchase a new firewall, SonicWall support does not cover initial configuration.  We can help you fill this gap by offering the optional add-on, “Remote Configuration & Support” when you purchase any of SonicWall TZ and NSa firewalls or from the Secure Mobile Access product sets. 

Our experienced technicians will guide you through the installation and configuration process during an initial telephone consultation, regardless of your level of experience or skill.  All we require is access to the appliance over the internet and a contact phone number for your on-site engineer. The service is for a maximum of 2 hours - additional time can be purchased by prior agreement.

 

The Process

  1. Remember to tick the “REMOTE CONFIGURATION?” checkbox (above) before adding the device to the basket.  Once you’ve completed the purchase, we will contact you to book a scheduled telephone appointment with one of our engineers*.
  2. You will need to ensure that the appliance is available remotely on HTTPS.**
  3. Our engineer will contact you during the scheduled appointment (please provide a valid telephone number) to guide you through the installation and configuration process.
  4. Our service is tailored for any skill level so if you require additional support (or for more advanced configuration assistance), you can request an additional appointment.
  5. Once we are satisfied that your appliance is up and running, we will provide details of the network configuration, including setup and login details for your records.
  6. You can also expect a post-installation health check to ensure that your appliance is functioning at optimum levels.
  7. If you already have your network configuration planned out, we will implement it accordingly. If you do not have these details, we can advise on best practices, network setups, ranges and policies to ensure the most secure and flexible configuration. Full details will be provided at the end of the process.

 

* For multiple appliances, you will need to book a session for each installation.

** Although we can advise you on how to enable this, it is your responsibility to perform the required gateway/router changes. You may need to contact your connectivity provider. By default, the device is available on HTTPS. 

 

Need a proforma invoice?

You can checkout using the purchase order option. For higher value orders (those totalling above £7000) please contact us directly for the best pricing for your requirements.

Need a quote? Have a question?

Fill out the form below and we'll get back to you as soon as possible.