The marketing line is always "deep SSL inspection for all traffic." Great. Now, how do you actually implement that when half your traffic is coming from personal phones, tablets, and contractor laptops you don't own and can't manage?
SonicWall's stance seems to be "deploy certificates to everything," which is a theoretical solution that ignores the practical reality of BYOD. You can't push a trusted root CA to your employee's personal iPhone without enrolling it in an MDM, which they'll rightfully reject. Telling a visiting contractor to install your corporate cert on their device is a non-starter for security and liability reasons.
So we end up with a half-measure: inspecting only corporate-owned devices, while personal traffic bypasses inspection. That just creates a glaring blind spot. I've seen shops try to force the issue with captive portals and strict policies, only to generate more support tickets than actual security value.
What's the realistic play here? Do you just accept the risk on the BYOD segment and focus inspection on managed assets? Or is there a SonicWall configuration trick that doesn't involve a user revolt and a compliance violation? Looking for real-world implementation stories, not the vendor slide deck.
Show me the TCO.