SonicWall’s SMA 100 series is now End of Sale and End of Support, which turns a quiet renewal conversation into a migration project for every South African partner with an installed base. Secure remote access does not get replaced by another appliance here. It becomes a different access model, and the difference matters because compromised remote-access credentials remain one of the largest single causes of breaches. This covers what changed, how zero trust access differs from a VPN in practice, and how to plan the migration without breaking anyone’s Monday.
What has changed with SonicWall SMA?
The SMA 100 series, covering the 210, 410 and 500v, is End of Sale and End of Support. SonicWall states this on its own remote access product pages and is directing customers toward a trade-in path to Cloud Secure Edge.
End of Support is the part that should move a secure remote access conversation up the priority list. An appliance that terminates remote access and no longer receives security updates is a poor thing to leave facing the internet. In early September 2026 a critical, actively exploited vulnerability affecting SMA1000 was reported, which is a useful reminder that remote-access gateways are among the most heavily targeted assets on any network.
The SMA 1000 series remains current, covering the 6210, 7210 and 8200v, scaling to 20,000 concurrent connections. So there is still an appliance path for organisations that need one. The question is whether an appliance is the right answer for a client whose applications have mostly moved to cloud.
What is zero trust network access?
Zero trust network access grants a user access to specific applications rather than to a network. A VPN authenticates the user once and then places their device on the corporate network, where it can reach whatever the network routing and firewall rules allow.
The distinction becomes concrete during an incident. When VPN credentials are stolen, the attacker inherits network-level access and can move laterally toward whatever else is reachable. Under a zero trust model those same credentials reach only the applications explicitly assigned to that user, and the device posture is re-evaluated rather than trusted for the life of the session.
SonicWall’s current offering is Cloud Secure Edge, built on its Banyan Security acquisition, with two components. Secure Private Access delivers the zero trust application access. Secure Internet Access covers the cloud access security broker and secure web gateway functions.
Barracuda’s equivalents are Barracuda SecureEdge, its SASE platform combining zero trust access, firewall as a service, web security and secure SD-WAN, alongside Barracuda CloudGen Access, which remains a separate current product rather than having been folded into SecureEdge.
Why does secure remote access keep failing in practice?
Because credentials alone are enough to use it. SonicWall’s 2026 Cyber Protect Report found that more than 48% of breaches in 2025 involved compromised VPN credentials.
That figure explains the industry’s direction of travel better than any product roadmap. A VPN’s security rests almost entirely on the strength of a password and whatever multi-factor authentication sits in front of it. Once through, the model assumes trust.
The same report put average breach detection at 181 days. An attacker with working VPN credentials and six months of unexamined access is not a hypothetical scenario, it is the modal South African breach. Our guide to security operations centres covers the monitoring side of closing that gap, and you can speak to our team about partner enablement if you are planning a migration across several clients.
How should a partner plan an SMA migration?
Start with an inventory of what the appliance is actually doing, because it is rarely only remote access. SMA deployments accumulate. Bookmarks for internal web applications, RDP and SSH access for IT staff, file share access, third-party contractor logins that nobody has reviewed in three years.
Map each of those to an application rather than to a network segment, because that mapping is the migration work. It is also where the security benefit comes from, since most estates discover users with reachability far beyond anything their role requires.
Sequence the cutover by user group and keep the appliance running in parallel during the transition. IT staff first, because they can diagnose their own problems. Then a friendly department. Then everyone else. Contractors and third parties last, because their access is the least documented and generates the most surprises.
Budget for the licence model change as well. Appliance plus support becomes per-user subscription, which usually reads better as an MSP recurring-revenue line but lands differently on a client’s capital budget. Have that conversation before the quote, not after.
PLANNING SMA MIGRATIONS ACROSS YOUR CLIENT BASE?
We help South African partners scope zero trust access projects and size them properly before the quote goes out.
Start my partner enquiry
Does zero trust access replace the firewall?
No. Zero trust access governs how users reach applications. The firewall still handles segmentation, inspection, threat prevention and everything arriving from outside that is not an authenticated user session.
SonicWall’s Gen 8 firewall line, launched in August 2025 and running SonicOS 8, was positioned explicitly at MSPs and MSSPs with zero trust capability built in. The TZ Gen 8 range covers the TZ280 through TZ680, with the NSa Gen 8 range covering the 2800 through 5800. Gen 7 models remain listed alongside them.
For a partner the practical point is that these are complementary line items, not competing ones. A client migrating off SMA still needs the firewall, and a Gen 8 refresh often sits naturally in the same project.
What should you check before quoting a client?
Check what the SMA appliance is really being used for, including the access paths nobody documented. Check whether the client’s applications are on-premises, in cloud, or split, because a heavily on-premises estate changes the design. Check the identity provider, since zero trust access depends on it far more than a VPN does, and a client on a weak identity foundation needs that fixed first.
Check concurrency honestly. Licensing by named user costs differently from an appliance sized for peak concurrent sessions, and the two numbers are rarely close.
Then get the third-party access list in front of someone who can make decisions about it. Every migration surfaces accounts belonging to suppliers who finished the engagement years ago, and those accounts are exactly the ones that turn up in breach reports.
MOVING CLIENTS OFF END OF LIFE REMOTE ACCESS?
Loophold distributes SonicWall and Barracuda to South African partners, with the training and enablement behind the migration.
Become a Loophold partner




