Sonicwall Capture Security Appliance 6 Port
Capture Security Appliance 1000
A 6-port on-premises threat analysis appliance built for organizations that can’t send files off-site. RTDMI memory-based inspection, dual 10GbE SFP+ uplinks, and REST API access — engineered to bring cloud-grade Capture ATP sandboxing inside your own data center.
On-premises sandboxing, without the cloud round-trip
01 — OverviewThe SonicWall Capture Security Appliance (CSa) 1000 brings Capture Advanced Threat Protection and sandboxing malware analysis on-site for organizations facing compliance restrictions on sending files to cloud analysis — or that simply want every byte of data to stay inside their own walls.
The CSa 1000 accepts suspicious files forwarded by other SonicWall products — firewalls and email security gateways — and returns rapid, high-confidence verdicts while the customer retains full custody of the file. A REST API extends that same analysis capability to threat intelligence teams, third-party tooling, and any software stack that can call a published API.
Multi-stage detection pipeline
Every submitted file passes through reputation and global-intelligence lookups, static analysis, and SonicWall’s patented Real-Time Deep Memory Inspection (RTDMI) engine, which watches application behavior directly in memory. That lets RTDMI see through obfuscation and encryption techniques that would otherwise slip past conventional network and sandbox analysis, across documents, executables, and archives alike.
Why teams deploy it
- 01 Files never leave the organization’s network for analysis
- 02 Regular intelligence updates synced from Capture ATP’s global cloud dataset
- 03 Role-based admin — separate scanning-history and network-config visibility
- 04 Scheduled reporting by role, with false positive/negative feedback loop
- 05 Hardened OS with Secure Boot and anti-tamper chain of trust
Port & interface layout
02 — ConnectivitySix Gigabit copper ports for LAN-side device connectivity, plus dual 10-Gigabit SFP+ uplinks for high-throughput file ingestion and a dedicated management port isolated from data traffic.
A Copper Ethernet
B Fiber Uplinks
C Management & I/O
Full specifications
03 — Datasheet01 Chassis & Form Factor
02 Interfaces
03 Storage
04 Security & Crypto
05 Power
06 Reliability
07 Analysis Limits
08 Supported VMs
09 Compliance & Emissions
Analysis throughput
04 — PerformanceThroughput scales down as analysis gets deeper — reputation lookups are near-instant, real-world file mix is moderate, and full dynamic RTDMI sandboxing is the most thorough and most resource-intensive stage.
Feature set
05 — CapabilitiesSupported file types
Deployment models
06 — ArchitectureSingle office / single location
Deployed anywhere on the local network that’s IP-reachable by the products submitting files. Firewalls and email security gateways redirect suspicious files to the CSa instead of the cloud.
Distributed enterprise
Multiple branches share one CSa hosted centrally or in a reachable data center, over direct internet access or VPN. Mass rollout is handled via GMS or cloud-based NSM.
REST API gateway
Threat intelligence teams and third-party systems submit files and query results directly via the REST API, with sample code published on SonicWall’s GitHub.
Compatible with TZ, NSa, and SuperMassive series firewalls running SonicOS 6.5.4.6 or later (not supported on SuperMassive 9800 or NSsp 12000), plus Email Security 10.x. Firewalls additionally require UDP access on port 2259.
Ordering information
07 — SKUs| Product | SKU |
|---|---|
| Capture Security Appliance CSa 1000 (appliance only, requires activation) | 02-SSC-2853 |
| CSa 1000 + Intelligence Updates & Support Bundle — 1 Year | 02-SSC-5637 |
| CSa 1000 + Intelligence Updates & Support Bundle — 3 Years | 02-SSC-5638 |
| CSa 1000 + Intelligence Updates & Support Bundle — 5 Years | 02-SSC-5639 |
| Intelligence Updates, Activation & Support — 1 Year | 02-SSC-4712 |
| Intelligence Updates, Activation & Support — 3 Years | 02-SSC-4714 |
| Intelligence Updates, Activation & Support — 5 Years | 02-SSC-4716 |
| REST API Activation — 1 Year | 02-SSC-4706 |
| REST API Activation — 3 Years | 02-SSC-4708 |
| REST API Activation — 5 Years | 02-SSC-4710 |
All devices sending files to the CSa 1000 must have Capture ATP licensed independently. Pricing and availability subject to change without notice.
Request a quote
Tell us about your environment and expected file-submission volume — we’ll come back with appliance pricing, bundle options, and a recommended support term.
