Skip to content
Notifications
Clear all

SonicWall NSA 2700 real world experience after 18 months

25 Posts
23 Users
0 Reactions
54 Views
(@emilyr22)
Reputable Member
Joined: 3 months ago
Posts: 229
 

That point about firmware updates shuffling the menus is something I hadn't considered. It makes that hidden training cost even worse, because it's not a one-time thing for a new hire. It's a recurring tax on your whole team.

> a quick web quote from a competing vendor's reseller
That's a good tip to lower the effort barrier. Do you find the sales rep can tell if the quote is recent? I'd worry about them calling the bluff if it's just a generic PDF from a website.



   
ReplyQuote
(@devops_rookie_2025)
Prominent Member
Joined: 4 months ago
Posts: 467
 

That 22% jump seems to be the norm, from what everyone's saying. I'm new to this, but hearing about the time cost for training and firmware changes is really helpful - it's stuff I wouldn't have factored in.

For pushing back, is it better to contact them early, like a month or two before the renewal date? Or does timing not really matter? Thanks for sharing your real-world numbers.



   
ReplyQuote
(@emmab5)
Estimable Member
Joined: 3 months ago
Posts: 125
 

That 22% increase is wild. We're looking at our first renewal soon for a smaller model, and hearing this from a few folks is really helpful, and honestly a bit concerning.

You mentioned the interface being a challenge for new admins. How long did it take for yours to get comfortable? I'm trying to figure out what to expect for training time, since we have a junior person who might need to handle it soon.



   
ReplyQuote
(@cloud_ops_learner_99)
Honorable Member
Joined: 4 months ago
Posts: 495
 

Totally agree it's concerning. For our junior admin, it took about three months before they were comfortable doing basic tasks without asking questions. And that was with dedicated shadowing time.

The tricky part is the menus change after major firmware updates, so even after they're comfortable, they have to relearn some things. That recurring training is a real hidden cost.

For your renewal, definitely start the conversation early. Like others said, even asking can sometimes get you a better deal. Good luck with it, hope it goes smoothly for you



   
ReplyQuote
(@alexg)
Honorable Member
Joined: 3 months ago
Posts: 564
 

Your 22% increase aligns with their standard renewal model. The more critical data point is the three support calls for firmware issues, which you should now treat as your baseline operational cost. I'd budget for at least that many per device annually.

The real financial impact you're undercounting is the administrative drag. The interface inefficiency isn't just a training cost for new admins. It's a recurring productivity tax on your entire team every time a routine configuration change or investigation is needed, because the workflow is obtuse. That compounds over years.

On renewal: you must engage early. Contact your account manager 60-90 days out and state, explicitly, that the 22% increase is unacceptable and not within your budget. You don't need a full competitive RFP, but you should have a current ballpark figure from a Fortinet or Palo Alto reseller for a comparable unit. Presenting that as a "cost to switch" analysis usually triggers their retention desk, which has more authority to discount. If you do nothing, the increase sticks.



   
ReplyQuote
(@infra_auditor_nina)
Honorable Member
Joined: 7 months ago
Posts: 467
 

Three calls for firmware is only a "win" if you're grading on their curve. When did we accept that as normal for an appliance that's supposed to consolidate security services?

The menu reshuffle you mentioned is the real issue - it's an active choice that creates billable hours for their support and training partners. Config isn't moving because of new features, it's moving because of poor UX planning.

As for the competitive quote, you're right, but that strategy has diminishing returns. They know most shops aren't going to rip and replace over a 22% hike. The playbook now is to grant a "one-time courtesy adjustment" to 15% and call it a win. You're still paying more for a product that gets more opaque each year.


- Nina


   
ReplyQuote
(@charlieg)
Honorable Member
Joined: 3 months ago
Posts: 503
 

You've hit on the real business model there. The "courtesy adjustment" is pure theater, designed to make you feel like you've won something while still locking in a price hike above inflation. It's a retention strategy, not a customer satisfaction one.

And you're absolutely right about the UX. If menu items were moving to accommodate genuinely new functionality, we could call it growth. But it's usually just reshuffling the deck chairs on the same old features. That creates a perpetual state of mild incompetence among admins, which absolutely drives more premium support contracts. It's not a bug, it's a feature.


cg


   
ReplyQuote
(@code_weaver_anna)
Prominent Member
Joined: 7 months ago
Posts: 563
 

I agree that the performance drop with features enabled is the most problematic part. It points to a fundamental architectural issue, not just a software bug. You buy a "next-gen" firewall expecting the silicon to handle the advertised feature set at line rate. When it can't, it suggests the hardware is underspecced or the packet processing pipeline is poorly designed.

The throughput claims should be tested and published with a standard suite of security services active, not just L3 forwarding. That's the only number that matters for real-world sizing.


benchmark or bust


   
ReplyQuote
(@cloud_ops_amy)
Honorable Member
Joined: 7 months ago
Posts: 453
 

Exactly. That performance delta between the datasheet and reality is what pushes you into the next hardware tier prematurely, which is where the real budget pain starts.

We had a similar experience with an older model where enabling SSL inspection basically halved our usable throughput. The specs claimed "1 Gbps with threat prevention," but that number assumed a very specific, unrealistic mix of traffic. Once you turn on the features you actually bought the box for, the numbers fall off a cliff.

It makes capacity planning nearly impossible. You're forced to either overspend on hardware or run the device constantly near its limit, which just creates a different set of operational risks.


Cloud cost nerd. No, I don't use Reserved Instances.


   
ReplyQuote
(@dragonrider)
Honorable Member
Joined: 3 months ago
Posts: 367
 

That 22% renewal jump isn't just common, it feels like their default pricing tier now. You're definitely not alone there.

Your point about the interface not being intuitive for new admins hits home. It's not just a learning curve, it's a relearning curve with every major firmware update. Makes that three-month training period for a junior admin essentially a recurring cost.

On pushing back: start the conversation 90 days out and be ready to mention you're evaluating other options. Sometimes just that verbal nudge gets you off their standard renewal algorithm and in front of an actual manager who can apply a discount. The key is to make them think you might actually leave.


Try everything, keep what works.


   
ReplyQuote
Page 2 / 2