TZ Series
Gen 7 next-generation firewalls and SD-Branch for SMBs and branch offices.
SonicWall TZ Series (Gen 7) delivers enterprise-grade next-generation firewall protection for SMBs and branch offices in an integrated SD-Branch platform — combining firewalling, SD-WAN, wireless, and switching. Powered by SonicOS 7 with Reassembly-Free Deep Packet Inspection and Capture ATP cloud sandboxing, it brings advanced threat prevention to the edge. Faltrox deploys, configures, and manages it as part of a secure network.
Overview
What TZ Series is
The SonicWall TZ Series is the small-business and branch tier of the Gen 7 firewall line, but it is more than a firewall: it is an integrated SD-Branch platform that unifies next-generation firewalling with SD-WAN, wireless, and switching, so a small site gets a complete, consolidated security-and-connectivity stack from one vendor and one console.
It runs SonicOS 7 with Reassembly-Free Deep Packet Inspection (RFDPI) — inspecting every byte of every packet across all ports without proxying or buffering — and integrates with the Capture ATP cloud sandbox and its patented Real-Time Deep Memory Inspection (RTDMI) to catch evasive and unknown threats. It includes intrusion prevention, anti-malware, content and application control, and TLS inspection. Managed through the Capture Security Center or Network Security Manager, it brings enterprise protection to the edge. Faltrox deploys the appliances, builds the policy, and operates them as managed branch defence.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
SMBs & Branches
Enterprise-grade next-generation firewall protection sized for SMBs and branch offices.
SD-Branch Platform
Unifies firewalling, SD-WAN, wireless, and switching in one integrated platform.
Deep Packet Inspection
RFDPI inspects every byte of every packet across all ports without proxying.
Unknown Threats
Capture ATP cloud sandbox with RTDMI catches evasive and never-before-seen threats.
TLS Inspection
Inspects encrypted traffic so threats cannot hide inside TLS.
Full Threat Prevention
Intrusion prevention, anti-malware, and content and application control at the edge.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Deploy
A compact Gen 7 appliance is placed at the branch and onboarded to Capture Security Center or Network Security Manager.
- 02
Inspect
RFDPI inspects every byte of every packet across all ports, including TLS-decrypted traffic, without proxying or buffering.
- 03
Detonate
Suspicious files route to the Capture ATP cloud sandbox, where RTDMI forces malware to expose its weaponry in memory.
- 04
Consolidate
SD-WAN, wireless, and switching are managed from the same SD-Branch platform as the firewall.
- 05
Operate
Faltrox builds the policy, maintains SonicOS, and monitors the appliances as managed branch defence.
Capabilities
Key capabilities
Reassembly-Free Deep Packet Inspection
Inspects every byte of every packet across all ports without proxying or buffering, at low latency.
Capture ATP Sandbox
Cloud sandbox with patented RTDMI catches evasive, fileless, and never-before-seen threats.
Integrated SD-Branch
Unifies firewalling, SD-WAN, secure wireless, and switching in one platform.
Intrusion Prevention
Blocks exploits and known attacks inline at the branch edge.
Anti-Malware & Content Control
Gateway anti-malware, content filtering, and application control reduce attack surface.
TLS/SSL Inspection
Decrypts and inspects encrypted traffic so threats cannot hide in TLS.
SonicOS 7
A modern operating system with a redesigned interface and expanded connectivity.
Centralised Management
Managed through Capture Security Center or Network Security Manager.
Works with
Part of the platform
SonicWall products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes SonicWall TZ Series for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What makes the TZ Series more than a firewall?
It is an integrated SD-Branch platform — it unifies next-generation firewalling with SD-WAN, secure wireless, and switching, so a branch gets a complete, consolidated security-and-connectivity stack from one vendor and one management console rather than several separate products.
02What is RFDPI?
Reassembly-Free Deep Packet Inspection — SonicWall’s inspection engine that examines every byte of every packet across all ports without proxying or buffering, so it inspects at low latency without the performance penalty of store-and-forward approaches. It is the core of SonicWall threat prevention.
03How does it catch unknown and evasive threats?
Suspicious files route to the Capture ATP cloud sandbox, which uses patented Real-Time Deep Memory Inspection (RTDMI) to force malware to reveal its weaponry in memory — catching evasive, fileless, and never-before-seen threats that traditional sandboxes miss.
04Does it inspect encrypted traffic?
Yes — it decrypts and inspects TLS/SSL traffic so threats cannot hide inside encryption, which is essential now that most traffic is encrypted. Faltrox configures the decryption policy for your environment.
05How does Faltrox operate it?
We deploy the appliances, build the firewall, IPS, and content policy, enable Capture ATP, maintain SonicOS, and monitor them — delivering managed branch firewalling and SD-Branch rather than hardware you configure yourself.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us