Sonicwall Capture Security Appliance 6 Port

SonicWall Capture Security Appliance CSa 1000 — Datasheet & Specifications
On-Prem ATP Sandbox SKU 02-SSC-2853 1U Rackmount FIPS 140-2 Pending

Capture Security Appliance 1000

A 6-port on-premises threat analysis appliance built for organizations that can’t send files off-site. RTDMI memory-based inspection, dual 10GbE SFP+ uplinks, and REST API access — engineered to bring cloud-grade Capture ATP sandboxing inside your own data center.

6
1GbE RJ-45 Ports
2
10GbE SFP+ Slots
12K
Files/Hr Lookup
2×1TB
SSD RAID 1
100MB
Max File Size
AES-NI
Crypto Accel.
Fig. 01 — Front PanelCSa 1000
6× 1GbE RJ-45 2× 10GbE SFP+ X0 MGMT USB / Console 2× 960GB SSD (RAID1) Dual PSU (Hot-swap) LCD + Controls CSa 1000 Status LEDs — Power 1/2, Alarm, Test, Disk Activity PWR1 · PWR2 · ALARM · TEST · DISK
1U · 17.0 × 16.5 × 1.75 in18.3 lbs

On-premises sandboxing, without the cloud round-trip

The SonicWall Capture Security Appliance (CSa) 1000 brings Capture Advanced Threat Protection and sandboxing malware analysis on-site for organizations facing compliance restrictions on sending files to cloud analysis — or that simply want every byte of data to stay inside their own walls.

The CSa 1000 accepts suspicious files forwarded by other SonicWall products — firewalls and email security gateways — and returns rapid, high-confidence verdicts while the customer retains full custody of the file. A REST API extends that same analysis capability to threat intelligence teams, third-party tooling, and any software stack that can call a published API.

Multi-stage detection pipeline

Every submitted file passes through reputation and global-intelligence lookups, static analysis, and SonicWall’s patented Real-Time Deep Memory Inspection (RTDMI) engine, which watches application behavior directly in memory. That lets RTDMI see through obfuscation and encryption techniques that would otherwise slip past conventional network and sandbox analysis, across documents, executables, and archives alike.

Combined with Block Until Verdict, connected SonicWall firewalls can hold a suspicious download at the gateway until the CSa 1000 returns a verdict — the same inline protection normally reserved for the cloud-delivered Capture ATP service.

Why teams deploy it

  • 01 Files never leave the organization’s network for analysis
  • 02 Regular intelligence updates synced from Capture ATP’s global cloud dataset
  • 03 Role-based admin — separate scanning-history and network-config visibility
  • 04 Scheduled reporting by role, with false positive/negative feedback loop
  • 05 Hardened OS with Secure Boot and anti-tamper chain of trust

Port & interface layout

Six Gigabit copper ports for LAN-side device connectivity, plus dual 10-Gigabit SFP+ uplinks for high-throughput file ingestion and a dedicated management port isolated from data traffic.

A Copper Ethernet

Ports6 × RJ-45
Speed10/100/1000Base-T
RoleLAN / device-facing

B Fiber Uplinks

Ports2 × SFP+
Speed10GBase-X (10 Gigabit)
RoleHigh-throughput uplink

C Management & I/O

Dedicated Mgmt1 × RJ-45 (X0)
USB2 × USB
Console1 × RS-232

Full specifications

01 Chassis & Form Factor

Form factor1U rackmount
Dimensions17.0×16.5×1.75 in
Weight18.3 lbs (8.3 kg)
Expansion slots2 total

02 Interfaces

Ethernet6 × RJ-45 GbE
Fiber2 × 10Gb SFP+
USB / Console2 USB / 1 console
Dedicated mgmtYes (X0)

03 Storage

Capacity2 × 1TB SSD
RAIDRAID 1
RetentionUnrestricted*
*limited byavailable storage

04 Security & Crypto

Encryption accel.AES-NI
TPMYes
Secure bootYes, chain of trust
CertificationFIPS 140-2 pending

05 Power

SupplyDual, hot-swap
Input rating100–240 VAC, 1.79A
Consumption114 W
Heat dissipation389 BTU

06 Reliability

MTBF (@25°C)129,601 hrs
Non-op shock110g, 2msec
Operating temp0–40°C
Cooling3 × fans

07 Analysis Limits

Max file size100 MB
Archive scan depth3 levels
REST APIYes
Devices supported~250 recommended

08 Supported VMs

Windows7, 32/64-bit & up
Linux64-bit

09 Compliance & Emissions

EnvironmentalWEEE, EU/China RoHS
EmissionsFCC, CE, ICES, VCCI
SafetyTUV/GS, UL, CB, CCC

Analysis throughput

Throughput scales down as analysis gets deeper — reputation lookups are near-instant, real-world file mix is moderate, and full dynamic RTDMI sandboxing is the most thorough and most resource-intensive stage.

Reputation & Global Threat Lookup12,000 files/hr
Real-World File Mix2,500 files/hr
Dynamic Analysis (RTDMI)300 files/hr
Throughput is dependent on network connectivity, file types, and compression levels — figures may vary from published rates.

Feature set

Reputation & global verdict lookup (configurable)
Static + dynamic analysis via RTDMI
Whitelist / blacklist by hash or domain
Configurable scheduled reporting
Role-based administration
HTTPS / SSH management, dedicated or in-band
SSH console access
Logging and alerting
False positive/negative reporting with auto-list updates
Direct or VPN connectivity, IP-addressable
Closed network operation
REST API for file submission & analysis

Supported file types

.exe.dll.sys.scr .doc / .docx.xls / .xlsx.ppt / .pptx .pdf.jar.apk.dmg .rar.7z.zip.gz / .bz2 / .xz .elf.dylib.ocx / .cpl / .drv

Deployment models

MODEL 01

Single office / single location

Deployed anywhere on the local network that’s IP-reachable by the products submitting files. Firewalls and email security gateways redirect suspicious files to the CSa instead of the cloud.

MODEL 02

Distributed enterprise

Multiple branches share one CSa hosted centrally or in a reachable data center, over direct internet access or VPN. Mass rollout is handled via GMS or cloud-based NSM.

MODEL 03

REST API gateway

Threat intelligence teams and third-party systems submit files and query results directly via the REST API, with sample code published on SonicWall’s GitHub.

Compatible with TZ, NSa, and SuperMassive series firewalls running SonicOS 6.5.4.6 or later (not supported on SuperMassive 9800 or NSsp 12000), plus Email Security 10.x. Firewalls additionally require UDP access on port 2259.

Ordering information

ProductSKU
Capture Security Appliance CSa 1000 (appliance only, requires activation)02-SSC-2853
CSa 1000 + Intelligence Updates & Support Bundle — 1 Year02-SSC-5637
CSa 1000 + Intelligence Updates & Support Bundle — 3 Years02-SSC-5638
CSa 1000 + Intelligence Updates & Support Bundle — 5 Years02-SSC-5639
Intelligence Updates, Activation & Support — 1 Year02-SSC-4712
Intelligence Updates, Activation & Support — 3 Years02-SSC-4714
Intelligence Updates, Activation & Support — 5 Years02-SSC-4716
REST API Activation — 1 Year02-SSC-4706
REST API Activation — 3 Years02-SSC-4708
REST API Activation — 5 Years02-SSC-4710

All devices sending files to the CSa 1000 must have Capture ATP licensed independently. Pricing and availability subject to change without notice.

Request a quote

Tell us about your environment and expected file-submission volume — we’ll come back with appliance pricing, bundle options, and a recommended support term.

Product SonicWall CSa 1000
Base SKU 02-SSC-2853
Lead time Confirmed at quote
Requires Capture ATP license on submitting devices
No purchase obligation. Responses typically within 1 business day.

Similar Posts