The SonicWall NSA 3700 delivers high-performance security for mid-sized networks and distributed enterprises. With multi-gigabit throughput, advanced threat protection, SD-WAN, and Zero-Touch Deployment, it ensures robust cybersecurity with deep packet inspection, VPN, and seamless cloud management. Ideal for organisations seeking scalable, reliable, and cost-effective network protection.

SonicWall Network Security Manager Essential - For NSA 3700
Whether you’re protecting a small business, a distributed enterprise, multiple businesses, or a closed network, your network security can get overwhelmed by operational disarrays, unseen risks and regulatory demands. Historically, efficient firewall management practices have mostly relied on dependable systems and operation control measures. However, frequent errors, misconfigurations and perhaps even violations of those controls remain to be constant challenges for wellrun Security Operation Centers (SOCs).
SonicWall Network Security Manager (NSM), a multi-tenant centralized firewall manager, allows you to centrally manage all firewall operations error-free by adhering to auditable workflows. Reporting and Analytics¹,² give single-pane visibility and lets you monitor and uncover threats by unifying and correlating logs across all firewalls.
NSM also helps you stay compliant as it provides full audit trails of every configuration change and granular reporting. The solution scales to any size organization that manages networks with up to thousands of firewall devices deployed across many locations. NSM does it all with less effort and time.
Be in control: Orchestrate firewall operations from one place
NSM offers you everything you need for a unified firewall management system. It empowers you with tenant-level visibility, group-based device control and unlimited scale to centrally manage and provision your SonicWall network security operations. These include deploying and managing all firewall devices, device groups and tenants, synchronizing and enforcing consistent security policies across your environments with flexible local controls and monitoring everything from one dynamic dashboard with detailed reports and analytics. NSM enables you to manage all from a single user-friendly console that can be accessed from any location using any browser-enabled device.
Be more effective: Work smarter and take security actions faster with less effort
NSM is a productivity management tool that enables you to work smarter and take security actions faster with less effort. Its design is guided by business processes and grounded on the principle of simplifying and, in some cases, automating workflows to achieve better security coordination. Also, it helps reduce the complexity, time and overhead of performing every-day security operations and administration tasks.
Be more aware: investigate hidden risks with active monitoring, reporting and analytics
NSM interactive dashboard provides real-time monitoring and reporting and analytics data. The information helps you troubleshoot problems, investigate risks and take smart security policy actions for a more adaptive security posture.
Feature Comparison
Feature
Essential
Advanced
Management
Reporting
7 Days
365 Days
Analytics
License: |

8x5 Support for NSa 3700 Series
A SonicWall support license provides telephone and web-based support, unlimited software/firmware updates and upgrades, and hardware replacement for units which have faults.
SonicWall support agreements provide technical assistance during the license coverage hours. A SonicWall technical specialist will work remotely with you to diagnose and identify software and hardware not performing to documented specifications. Support also includes general assistance regarding use and implementation on a limited basis.
SonicWall’s support offerings do not include step-by-step installation or configuration of products or services. If you need installation or configuration assistance, please contact us for a quote.
Support agreements provide for replacement of failing hardware (not applicable to the NSv series) returned to a SonicWall factory. The replacement product may be new, or like-new. In the event of product obsolescence, SonicWall reserves the right to replace failing product with a product of like or better features and functionality.
Includes 8x5 telephone, email and web-based support, software and firmware updates, advance exchange hardware replacement, access to electronic support tools and moderated discussion groups.
License: |

SonicWall Analytics Software (SYSLOG) For NSA 3700
SonicWall Analytics transforms firewall traffic data into actionable insights across users, applications and networks to help mitigate security risks with greater precision and speed - all through a single interface.
Built using high-performance architecture, the analytic engine enriches a massive amount of raw data across thousands of firewall nodes at scale to give stakeholders complete visibility and security transparency via an executive dashboard.
Analytics creates visual and knowledge representations of the data datasets by using various forms of semantic graphs and time-use charts and tables to help reduce data silos and analyst fatigue
With added drill-down capabilities, security responders can investigate and zero in on critical data points to expose hidden risks for early intervention as well as take evidence-backed policy actions against risky user activities as they unfold in the discovery process.
With comprehensive visibility and control, security analysts see everything everywhere to become better risk managers while responders can focus their valuable time and effort on orchestrating rapid response actions across applications and users that matter most instead of reacting to every event. Analytics scales and performs at cloud-agility and -elasticity to meet even the most demanding enterprise requirements.
License: |

HA Conversion License to Standalone Unit for NSa 3700 Series
The SonicWall Network Security Appliance (NSa) 3700 next-generation firewall (NGFW) offers medium to large sized enterprises industry-leading performance at the lowest total cost of ownership in its class.
High Availability (HA) is a redundancy design that allows two identical SonicWall firewalls running the Management Service to be configured to provide a reliable, continuous connection to the public Internet. One SonicWall firewall is configured as the Primary unit, and an identical SonicWall firewall is configured as the Secondary unit. If the Primary firewall fails, the Secondary firewall takes over to secure a reliable connection between the protected network and the Internet. Two firewalls configured in this way are also known as a High Availability Pair (HA Pair).
High Availability provides a way to share SonicWall licenses between two SonicWall firewalls when one is acting as a high-availability system for the other. Both firewalls must be the same SonicWall model.
Converts NSa 3700 HA unit to the basic standalone appliance (no services).

SonicWall Network Security Manager Advanced - For NSA 3700
Whether you’re protecting a small business, a distributed enterprise, multiple businesses, or a closed network, your network security can get overwhelmed by operational disarrays, unseen risks and regulatory demands. Historically, efficient firewall management practices have mostly relied on dependable systems and operation control measures. However, frequent errors, misconfigurations and perhaps even violations of those controls remain to be constant challenges for wellrun Security Operation Centers (SOCs).
SonicWall Network Security Manager (NSM), a multi-tenant centralized firewall manager, allows you to centrally manage all firewall operations error-free by adhering to auditable workflows. Reporting and Analytics¹,² give single-pane visibility and lets you monitor and uncover threats by unifying and correlating logs across all firewalls.
NSM also helps you stay compliant as it provides full audit trails of every configuration change and granular reporting. The solution scales to any size organization that manages networks with up to thousands of firewall devices deployed across many locations. NSM does it all with less effort and time.
Be in control: Orchestrate firewall operations from one place
NSM offers you everything you need for a unified firewall management system. It empowers you with tenant-level visibility, group-based device control and unlimited scale to centrally manage and provision your SonicWall network security operations. These include deploying and managing all firewall devices, device groups and tenants, synchronizing and enforcing consistent security policies across your environments with flexible local controls and monitoring everything from one dynamic dashboard with detailed reports and analytics. NSM enables you to manage all from a single user-friendly console that can be accessed from any location using any browser-enabled device.
Be more effective: Work smarter and take security actions faster with less effort
NSM is a productivity management tool that enables you to work smarter and take security actions faster with less effort. Its design is guided by business processes and grounded on the principle of simplifying and, in some cases, automating workflows to achieve better security coordination. Also, it helps reduce the complexity, time and overhead of performing every-day security operations and administration tasks.
Be more aware: investigate hidden risks with active monitoring, reporting and analytics
NSM interactive dashboard provides real-time monitoring and reporting and analytics data. The information helps you troubleshoot problems, investigate risks and take smart security policy actions for a more adaptive security posture.
Feature Comparison
Feature
Essential
Advanced
Management
Reporting
7 Days
365 Days
Analytics
License: |

SonicWall Gateway Anti-Malware, Intrusion Prevention
and Application Control for NSa 3700 Series
Enabling the security services on the firewall is an essential part of the firewall configuration.
Gateway Anti-Virus
Integrates a high performance Real-Time Virus Scanning Engine and dynamically updated signature database to deliver continuous protection from malicious virus threats at the gateway.
Intrusion Prevention
Integrates a high-performance Deep Packet Inspection architecture and dynamically updated signature database to deliver complete network protection from application exploits, worms and malicious traffic.
Anti-Spyware
SonicWall firewalls provide an innovative multi-layered anti-malware strategy consisting of a patented Reassembly-Free Deep Packet Inspection anti-malware solution
License: |

Content Filtering Service for NSa 3700 Series
Educational institutions, businesses and government agencies assume substantial risks when they provide students and employees IT-issued computers that can be used to access the Internet, even when the device is behind the firewall perimeter where organizational web use policies are enforced. This is particularly true when those connections are used to access sites containing information or images that are inappropriate, dangerous or even illegal. These sites may also be infected with malware that can be inadvertently downloaded and then used to steal confidential information.
Schools, in particular, have a responsibility to protect students from inappropriate and harmful web content. For businesses and government agencies, providing employees with uncontrolled web access can result in non-productive web surfing, creating tremendous losses in productivity, not to mention the potential for legal liability.
CFS running on SonicWall Unified Threat Management and next generation firewalls (NGFWs) is a powerful protection and productivity solution that delivers unequaled content filtering enforcement for educational institutions, businesses, libraries and government agencies. Using SonicWall CFS, organizations have control over the websites students and employees can access using their IT-issued computer behind the firewall. SonicWall CFS compares requested websites against a massive database in the cloud containing millions of rated URLs, IP addresses and websites. CFS provides administrators with the tools to create and apply policies that allow or deny access to sites based on individual or group identity, or by time of day, for over 56 pre-defined categories. CFS also dynamically caches website ratings locally on the SonicWall firewall for nearinstantaneous response times.
For laptops that are used outside the firewall perimeter, the SonicWall Content Filtering Client addresses safety, security and productivity concerns by extending the controls to block harmful and unproductive web content. The client is automatically deployed and provisioned through a SonicWall firewall. In addition to providing IT administrators the tools to control web-based access for roaming devices, the Content Filtering Client can be configured to automatically switch enforcement to the internal policy once the device reconnects to the network firewall. The client is managed and monitored using a powerful policy and reporting engine in the cloud that is accessed seamlessly from the firewall interface. In the event an outdated client attempts to connect to the internal network to access the Internet, the connection is denied and the user receives a message with steps for remediation.
Highlights
Best in-class protection
Granular content filtering controls
Dynamically updated rating architecture
Application traffic analytics
Easy-to-use web-based management
High-performance web caching and rating architecture
IP-based HTTPS content filtering
Scalable, cost-effective solution
Content Filtering Client for roaming devices
License: |

SonicWall Comprehensive AntiSpam Service for NSa 3700
With nearly 80% of email classified as junk (spam, phishing and virus-laden messages), allowing such distracting and dangerous traffic into your network can grind your business communications and organizational productivity to a halt. Removing this junk email at the gateway optimizes network efficiency, and enhances email and employee productivity.
SonicWall Comprehensive Anti-Spam Service (CASS) offers small- to mediumsized businesses comprehensive protection from spam and viruses, with instant deployment over existing SonicWall firewalls. CASS speeds deployment, eases administration and reduces overhead by consolidating solutions, providing one-click anti-spam services, with advanced configuration in just 10 minutes.
CASS offers complete inbound anti-spam, antiphishing, anti-malware protection and features, SonicWall Capture Threat Network IP Reputation, Advanced Content Management, Denial of Service prevention, full quarantine and customizable per-user junk summaries. Outperforming RBL filtering, CASS offers >99% effectiveness against spam, dropping >80% of spam at the gateway, while utilizing advanced anti-spam techniques like Adversarial Bayesian™ filtering using advanced detection techniques like Adversarial Bayesian and machine-learning filtering.
Stop spam, phishing and virus attacks using multiple proven, patented techniques
including reputation checks that check not only a message’s sender IP reputation, but also the reputation of its content, structure, links, images, attachments. Advanced techniques are also used to analyze email content, such as adversarial Bayesian filtering, image analysis and gibberish detection to uncover hidden known threats, and new threats. The cloud-based design utilizes these advanced anti-spam techniques without impacting firewall processing and overall network throughput.
Real-time threat information via the SonicWall Capture Threat Network
collects and analyzes information from industry threat lists and also performs rigorous testing and evaluation of millions of emails every day, establishing reputation scores for senders and content and identifying new threats in real-time to deliver the most accurate and upto-date protection against new spam attacks while also ensuring delivery of good email.
SonicWall Capture Cloud
leverages SonicWall Capture Threat Network technology to deliver cloud-based antivirus and anti-spyware protection.
Flexible junk email routing
categorises junk messages as spam, likely spam, phishing, likely phishing, virus and likely virus. Messages in each category can be rejected, tagged and delivered, sent to the user’s Junk Box, or deleted, for complete control and compliance with corporate and regulatory requirements.
License: |

Essential Protection Service Suite for NSa 3700
Complete network security, content filtering, application control, CaptureATP, gateway anti-virus, anti-spam, 24x7 support, cloud management and reporting in a single integrated package.
The SonicOS architecture is at the core of SonicWall physical and virtual firewalls including the TZ, NSa, NSv and NSsp Series. SonicOS leverages our patented, single-pass, lowlatency, Reassembly-Free Deep Packet Inspection® (RFDPI) and patent-pending Real-Time Deep Memory Inspection™ (RTDMI) technologies to deliver industry-validated high security effectiveness, SD-WAN, real-time visualization, high-speed virtual private networking (VPN) and other robust security features.
Through a combination of cloud-based and on-box technologies we deliver protection to our firewalls that's been validated by independent third party testing for its extremely high security effectiveness. Unknown threats are sent to SonicWall's cloud-based Capture Advanced Threat Protection (ATP) multiengine sandbox for analysis. Enhancing Capture ATP is our RTDMI™ technology.
The RTDMI engine detects and blocks malware and zero-day threats by inspecting directly in memory. RTDMI technology is precise, minimizes false positives, and identifies and mitigates sophisticated attacks where the malware’s weaponry is exposed for less than 100 nanoseconds.
Essential Protection Service Suite (EPSS) includes - Capture Advanced Threat Protection, Gateway Anti-Virus, Anti-Spyware, Intrusion Prevention, Application Firewall Service, Content Filtering Services, Comprehensive Anti-Spam and 24x7 Support with firmware.
Benefits
Complete network security solution
All service licences included.
Capture ATP
To protect customers against the increasing dangers of zero-day threats, SonicWall Capture Advanced Threat Protection Service — a cloud-based service available with SonicWall firewalls — detects and and can block advanced threats at the gateway until verdict.
This service is the only advanced threat-detection offering that combines multi-layer sandboxing, including full system emulation and virtualization techniques, to analyze suspicious code behavior. This powerful combination detects more threats than single-engine sandbox solutions, which are compute environment specific and susceptible to evasion.
Gateway anti-virus and anti-spyware protection
DPI-SSL extends SonicWall's patented Reassembly-Free Deep Packet Inspection® (RFDPI) technology to allow inspection of encrypted HTTPS traffic and other SSL-based traffic. It provides additional security, application control, and data leakage prevention for analysing encrypted traffic.
The RFDPI engine is not limited by file size or the amount of concurrent traffic it can scan (unlike other scanning engines). By working at the application layer, RFDPI protects against hidden application vulnerabilities that may be inadvertently letting attackers in through an unknown back door.
Cutting-edge IPS technology
Protects against worms, trojans, software vulnerabilities and other intrusions by scanning all network traffic for malicious or anomalous patterns.
Application intelligence and control
Set of granular, application-specific policies providing application classification and policy enforcement to help administrators control and manage both business and non-business related applications.
Content filtering
CFS running on SonicWall Unified Threat Management and next generation firewalls (NGFWs) is a powerful protection and productivity solution that delivers unequaled content filtering enforcement for educational institutions, businesses, libraries and government agencies. Using SonicWall CFS, organizations have control over the websites students and employees can access using their IT-issued computer behind the firewall.
SonicWall CFS compares requested websites against a massive database in the cloud containing millions of rated URLs, IP addresses and websites. CFS provides administrators with the tools to create and apply policies that allow or deny access to sites based on individual or group identity, or by time of day, for over 56 pre-defined categories. CFS also dynamically caches website ratings locally on the SonicWall firewall for nearinstantaneous response times.
Network Topology View
Display hosts, access-points in the network based on device name, mac address and IP Address.
24x7 support with firmware updates and hardware replacement
Including firmware updates and hardware replacement protects your business and your SonicWall investment.
Management and reporting
Manage and view reports on firewalls via cloud through Network Security Manager tile of Capture Security Center.
SonicWall Capture Security Centre is easy with true Single-Sign-On (SSO) and Single-Pane-of-Glass (SPOG) architecture. Watch over your entire security ecosystem with a scalable management solution. Included as part of all AGSS subscriptions.
Capture Security Center (CSC) gives you everything you need for comprehensive management, accessible from a single function packed interface. It touches everything, including analytics and reporting for networks, endpoint and cloud security, risk meters and asset management.
Security Suite Comparison Chart
Feature
Essential
Advanced
Premier
Gateway Anti-Virus, Intrusion Prevention,
Application Control
Content Filtering Service
Anti-Spam
24x7 Support
Network Visibility
Capture ATP (Multi-Engine) Sandboxing
RTDMI Technology
Basic DNS Security
Cloud Management
Cloud based Reporting - 7 Days
Advanced Cloud Analytics - Virtual, 365 Days Reporting
Advanced DNS Security
Firewall System Check Tool
Cloud App Security Starter Pack
Capture Client Starter Pack
Premier Support
- Part of bundle
- Not available with the bundle, but can be purchased separately
- Not supported with the bundle
License: |

Advanced Protection Service Suite for NSa 3700
Complete network security, content filtering, application control, CaptureATP, gateway anti-virus, anti-spam, 24x7 support, cloud management and reporting in a single integrated package.
The SonicOS architecture is at the core of SonicWall physical and virtual firewalls including the TZ, NSa, NSv and NSsp Series. SonicOS leverages our patented, single-pass, lowlatency, Reassembly-Free Deep Packet Inspection® (RFDPI) and patent-pending Real-Time Deep Memory Inspection™ (RTDMI) technologies to deliver industry-validated high security effectiveness, SD-WAN, real-time visualization, high-speed virtual private networking (VPN) and other robust security features.
Through a combination of cloud-based and on-box technologies we deliver protection to our firewalls that's been validated by independent third party testing for its extremely high security effectiveness. Unknown threats are sent to SonicWall's cloud-based Capture Advanced Threat Protection (ATP) multiengine sandbox for analysis. Enhancing Capture ATP is our RTDMI™ technology.
The RTDMI engine detects and blocks malware and zero-day threats by inspecting directly in memory. RTDMI technology is precise, minimizes false positives, and identifies and mitigates sophisticated attacks where the malware’s weaponry is exposed for less than 100 nanoseconds.
Advanced Protection Service Suite (APSS) includes - Capture Advanced Threat Protection, Gateway Anti-Virus, Anti-Spyware, Intrusion Prevention, Application Firewall Service, Content Filtering Services, Comprehensive Anti-Spam, NSM Essential with Management & 7-Day Reporting and 24x7 Support with firmware.
Benefits
Complete network security solution
All service licences included.
Capture ATP
To protect customers against the increasing dangers of zero-day threats, SonicWall Capture Advanced Threat Protection Service — a cloud-based service available with SonicWall firewalls — detects and and can block advanced threats at the gateway until verdict.
This service is the only advanced threat-detection offering that combines multi-layer sandboxing, including full system emulation and virtualization techniques, to analyze suspicious code behavior. This powerful combination detects more threats than single-engine sandbox solutions, which are compute environment specific and susceptible to evasion.
Gateway anti-virus and anti-spyware protection
DPI-SSL extends SonicWall's patented Reassembly-Free Deep Packet Inspection® (RFDPI) technology to allow inspection of encrypted HTTPS traffic and other SSL-based traffic. It provides additional security, application control, and data leakage prevention for analysing encrypted traffic.
The RFDPI engine is not limited by file size or the amount of concurrent traffic it can scan (unlike other scanning engines). By working at the application layer, RFDPI protects against hidden application vulnerabilities that may be inadvertently letting attackers in through an unknown back door.
Cutting-edge IPS technology
Protects against worms, trojans, software vulnerabilities and other intrusions by scanning all network traffic for malicious or anomalous patterns.
Application intelligence and control
Set of granular, application-specific policies providing application classification and policy enforcement to help administrators control and manage both business and non-business related applications.
Content filtering
CFS running on SonicWall Unified Threat Management and next generation firewalls (NGFWs) is a powerful protection and productivity solution that delivers unequaled content filtering enforcement for educational institutions, businesses, libraries and government agencies. Using SonicWall CFS, organizations have control over the websites students and employees can access using their IT-issued computer behind the firewall.
SonicWall CFS compares requested websites against a massive database in the cloud containing millions of rated URLs, IP addresses and websites. CFS provides administrators with the tools to create and apply policies that allow or deny access to sites based on individual or group identity, or by time of day, for over 56 pre-defined categories. CFS also dynamically caches website ratings locally on the SonicWall firewall for nearinstantaneous response times.
Network Topology View
Display hosts, access-points in the network based on device name, mac address and IP Address.
24x7 support with firmware updates and hardware replacement
Including firmware updates and hardware replacement protects your business and your SonicWall investment.
Management and reporting
Manage and view reports on firewalls via cloud through Network Security Manager tile of Capture Security Center.
SonicWall Capture Security Centre is easy with true Single-Sign-On (SSO) and Single-Pane-of-Glass (SPOG) architecture. Watch over your entire security ecosystem with a scalable management solution. Included as part of all AGSS subscriptions.
Capture Security Center (CSC) gives you everything you need for comprehensive management, accessible from a single function packed interface. It touches everything, including analytics and reporting for networks, endpoint and cloud security, risk meters and asset management.
Security Suite Comparison Chart
Feature
Essential
Advanced
Premier
Gateway Anti-Virus, Intrusion Prevention,
Application Control
Content Filtering Service
Anti-Spam
24x7 Support
Network Visibility
Capture ATP (Multi-Engine) Sandboxing
RTDMI Technology
Basic DNS Security
Cloud Management
Cloud based Reporting - 7 Days
Advanced Cloud Analytics - Virtual, 365 Days Reporting
Advanced DNS Security
Firewall System Check Tool
Cloud App Security Starter Pack
Capture Client Starter Pack
Premier Support
- Part of bundle
- Not available with the bundle, but can be purchased separately
- Not supported with the bundle
License: |

Stateful HA Upgrade for NSa 3700 Series
The SonicWall Network Security Appliance (NSa) 3700 next-generation firewall (NGFW) offers medium to large sized enterprises industry-leading performance at the lowest total cost of ownership in its class.
High Availability (HA) is a redundancy design that allows two identical SonicWall firewalls running the Management Service to be configured to provide a reliable, continuous connection to the public Internet. One SonicWall firewall is configured as the Primary unit, and an identical SonicWall firewall is configured as the Secondary unit. If the Primary firewall fails, the Secondary firewall takes over to secure a reliable connection between the protected network and the Internet. Two firewalls configured in this way are also known as a High Availability Pair (HA Pair).
High Availability provides a way to share SonicWall licenses between two SonicWall firewalls when one is acting as a high-availability system for the other. Both firewalls must be the same SonicWall model.
Upgrades the NSa 3700 to support active / passive with statesync for seemless failover between two NSa 3700.



