We have only been using it for a short while but it's definitely given us a level of protection at the edge device. We're not at the moment using the Capture endpoint stuff, but we are also looking at that product as well, which actually allows you to run Capture for the client. We use another product for our endpoint solution at the moment.
The reporting that you get from it is the most valuable feature. You can see it via the appliance itself, and also via the MySonicWall account for the registered device. You are able to select the file if it's malicious, and you can select it in the reporting and see what triggered it, and things like that. I found that to be quite useful.
Also, the ability to be able to actually turn it on and off based on the requirements on the firewall in which you can actually just have it turned on for everyone or you can turn it on based on users, exclusion lists, and things like that.