DPI-SSL Overview

Deep Packet Inspection of Secure Socket Layer (DPI-SSL) extends SonicWall’s Deep Packet Inspection technology to allow for the inspection of encrypted HTTPS traffic and other SSL-based traffic. The SSL traffic is decrypted transparently, scanned for threats and then re-encrypted and sent along to its destination if no threats or vulnerabilities are found.

DPI-SSL provides additional security, application control, and data leakage prevention for analyzing encrypted HTTPS and other SSL-based traffic. DPI-SSL supports:

The following security services and features are capable of utilizing DPI-SSL:

DPI-SSL has two main deployment scenarios:

The DPI-SSL feature is available in SonicOS Enhanced 5.6. The following table shows which platforms support DPI-SSL and the maximum number of concurrent connections on which the appliance can perform DPI-SSL inspection.

 

Platforms That Support DPI-SSL

Hardware Model

Max Concurrent DPI-SSL Connections

SOHO

100

NSA 220/220W

100

NSA 240

100

NSA 250M/250MW

100

NSA 2400MX

50

NSA 2400

250

NSA 3500

250

NSA 4500

350

NSA 5000

1000

E-Class NSA E5500

2000

E-Class NSA E6500

3000

E-Class NSA E7500

8000

E-Class NSA E8500

8000

E-Class NSA E8510

8000