SonicWall NSM.
One console to manage every SonicWall firewall you run.
SonicWall Network Security Manager (NSM) is the centralized firewall management platform for your full SonicWall estate,
covering zero-touch deployment, policy management, and real-time threat visibility. Basic management is included with
active SonicWall firewall support at no added charge, with paid tiers adding extended reporting and log analytics for
teams that need deeper visibility.
Expert Pre-Sales AdviceCertified reps reply in 1 hour.
Config & Managed ServicesSkip the setup. We'll do it.
POs · Tax-Exempt · Net 30Welcomed for Corp, Edu, & Gov.
Same-Day ShippingOrder by 3pm EST, ships today.
Features and Deployment
NSM at a Glance
NSM Essential vs. NSM Advanced
NSM Essential is the right choice for teams that need centralized policy management and
up to 7 days of reporting. NSM Advanced includes everything in Essential and adds 365
days of compliance-grade reporting and up to 30 days of log analytics for threat
investigation. Both tiers cover unlimited firewall scale in the cloud version. A
firewall's basic management console access through NSM SaaS is included at no charge
with active SonicWall support subscriptions.
Cloud (SaaS) Deployment
NSM SaaS requires no infrastructure. It runs as a multi-tenant cloud service accessible
from any browser-enabled device. Unlimited scale supports hundreds of firewalls per
tenant. Zero-touch deployment provisions new firewalls without an on-site technician.
Multi-device firmware upgrades let administrators update an entire fleet from the group
management view. High Availability is built into the SaaS service.
On-Premises Deployment
NSM on-premises runs as a virtual appliance on VMware ESXi, Microsoft Hyper-V, KVM, and
Microsoft Azure. It is licensed per node with a 5-node base license and stackable add-on
packs. Closed network support allows managed firewalls to be licensed and patched
without contacting SonicWall's license servers, making it suitable for air-gapped and
classified environments. IP-based admin access restrictions add an extra layer of
control over who can reach the management plane.
Compliance and Security Operations
NSM generates audit-ready compliance reports across the managed firewall fleet with
customizable data sets. Policy templates and configuration workflows enforce consistent
security baselines and flag deviations before they become incidents. AI-driven insights
surface configuration gaps and recommend hardening actions without requiring manual
policy review. Two-factor authentication is enforced through the Capture Security Center
portal for SaaS, and through Google or Microsoft Authenticator for on-premises.
Migrating from GMS to NSM?
Our team can assess your current GMS node count and firewall models, map them to the right
NSM tier, and walk you through the migration. Firewalls remain online and managed
throughout. Most migrations from GMS to NSM complete without service interruption to managed
firewalls.
SonicWall Network Security Manager (NSM) is the centralized firewall
management platform for the SonicWall product line. It provides zero-touch
deployment, policy management, real-time monitoring, AI-driven configuration
insights, and compliance reporting for SonicWall Gen 6 and Gen 7 firewalls. It
replaces SonicWall GMS, which reached end of sale on October 1, 2025.
NSM Essential provides full firewall management capabilities and up
to 7 days of reporting. NSM Advanced includes everything in Essential and adds 365
days of compliance-grade reporting and up to 30 days of log analytics for threat
investigation and forensic review. Both tiers support unlimited firewall scale in
the SaaS version.
Basic NSM SaaS management, including the centralized console and
alerting, is included at no additional cost for firewalls with active SonicWall
support subscriptions. The paid NSM Essential and Advanced tiers unlock extended
reporting, log analytics, and additional operational features.
Yes. The SonicWall TZ80 is a subscription-based model that requires
an NSM-linked service subscription to operate. Without an active service
subscription such as Secure Connect, Advanced Protection Security Suite (APSS), or
Managed Protection Security Suite (MPSS), the TZ80 will not function.
NSM on-premises runs as a virtual appliance on VMware ESXi, Microsoft
Hyper-V, KVM, and Microsoft Azure. It is licensed on a node basis with a 5-node base
license and add-on node packs. Closed network support allows NSM on-premises to
manage air-gapped firewall deployments without connecting to SonicWall license
servers.
NSM supports SonicWall Gen 6 firewalls running SonicOS firmware 6.5.x
or higher, and all Gen 7 firewalls running SonicOSX 7.0 or higher. Supported
hardware includes the NSsp, NSa, TZ, and SOHO series. NSM also manages SonicWall
switches and wireless access points that are connected to managed firewalls.
Not sure which NSM tier fits your environment?
Tell us your firewall count, firmware generations, whether you need cloud or on-premises
management, and how many days of reporting your compliance requirements call for. A
SonicWall-certified engineer will recommend the right NSM tier within one business hour.