Skip to content
Notifications
Clear all

SonicWall TZ570 after 12 months - honest review from a mid-market IT manager

1 Posts
1 Users
0 Reactions
1 Views
(@emilyk22)
Estimable Member
Joined: 1 week ago
Posts: 100
Topic starter   [#10224]

Having now managed a fleet of seven SonicWall TZ570 appliances across our regional offices for a full calendar year, I feel I can provide a substantive, operationally-focused review that moves beyond the initial setup phase. Our environment is a classic mid-market hybrid setup, with approximately 300 users, a mix of on-premise servers and cloud SaaS dependencies, and a growing remote workforce. Our primary drivers for selecting the TZ570 were the desire for deep application-layer visibility, robust SD-WAN capabilities for our site interconnects, and a consolidated security stack to reduce point-product complexity.

From a feature-set and performance standpoint, the device largely delivers on its core promises. The comparative analysis I performed against competitors like Fortinet and Palo Alto at the time showed SonicWall as a strong value contender, particularly when factoring in the bundled services for the first year.

* **The Good:**
* **SD-WAN & Path Selection:** The implementation is genuinely intelligent. We have dual ISPs at each site, and the TZ570's ability to dynamically steer Microsoft 365 or VoIP traffic over the optimal path, based on actual latency and packet loss—not just simple load balancing—has measurably improved call quality and reduced user complaints.
* **Gateway Anti-Virus & Intrusion Prevention:** The stack is effective. We've had zero breaches, and the weekly threat prevention reports detail blocked ransomware, command-and-control callbacks, and exploit attempts. The peace of mind here is not trivial.
* **Centralized Management (NSM):** While not without its quirks (covered below), having a single pane of glass for policy deployment, firmware updates, and event correlation across all seven firewalls is a non-negotiable operational necessity for us. Bulk policy push generally works as advertised.

* **The Not-So-Good (The Practical Pitfalls):**
* **Technical Support Experience:** This remains the most significant friction point. While the online knowledge base is extensive, engaging with live support for a complex issue often follows a predictable and frustrating pattern: lengthy hold times, repeated solution re-hashing even after diagnostics are provided, and escalation paths that feel opaque. For a mission-critical security device, this is an area that requires substantial improvement.
* **NSM's Learning Curve & Latency:** The cloud-based NSM portal can feel sluggish at times. Furthermore, certain advanced configurations—like fine-tuning SSL-Inspection policies for specific internal applications—still often require logging directly into the local appliance GUI, which undermines the "centralized" promise. The logic for policy inheritance and object management across groups is not as intuitive as it could be.
* **Renewal Pricing & Model Clarity:** As we approach our 12-month mark, the renewal process for the security services (Gateway AV, IPS, Content Filtering) has been less straightforward than anticipated. The pricing jump from initial purchase to renewal was steeper than projected, and deciphering the exact SKUs needed to maintain equivalent coverage required back-and-forth with our distributor.

**Operational Verdict:** The TZ570 is a capable workhorse appliance whose core security functionality is sound. Its SD-WAN features are standout. However, operational efficiency is hampered by a support structure that can be inefficient and a management platform that, while functional, has room for refinement in usability. For a team with in-house firewall expertise willing to navigate these administrative hurdles, it represents good value. For organizations seeking a "set-and-forget" experience with premium support hand-holding, the total cost of ownership calculations must weigh these operational factors heavily. Our organization will likely renew for another year based on the performance stability, but we are simultaneously initiating a fresh, formal comparative evaluation cycle for the next refresh, with these hands-on experiences firmly in mind.


Support is a product, not a department.


   
Quote