Sophos XG is very good.
It's very friendly.
The performance is good.
Sophos XG is very good.
It's very friendly.
The performance is good.
The reporting could be improved.
Many other firewalls give you the option to disconnect a user. For example, if an end-user is using too much bandwidth, you could right-click to disconnect this user, but Sophos XG does not support this feature.
Sophos XG does not have the ability to disconnect a user.
I have been using Sophos XG for one and a half years.
We are using the latest version.
The stability of Sophos XG is great!
Sophos XG is scalable.
We have approximately 120 users in our organization who are using this solution.
We have never contacted the technical support for Sophos. Once or twice we called the local support but not for Sophos.
Previously we used Cyberoam. When they announced the end of life we switched to Sophos XG.
It was upgraded because it had reached the end of its life. We only had one option for upgrading to Sophos XG. They gave us the option to upgrade and provided us with the hardware for free.
We migrated from Cyberoam. The migration went very well.
The migration process did not require a lot of configuration.
It took a few days to complete the migration and the testing.
This solution is being managed by myself and a colleague. We are a team of two.
We were able to complete the migration ourselves.
They have different options for the license.
We paid for three years which included the migration and the free hardware.
In most cases, I believe that the licensing is paid yearly.
I don't have any issues with this solution. I would recommend this solution for others who are interested in using it.
I would rate Sophos XG an eight out of ten.
I primarily use the solution as a firewall. It's running on our data centers and all of our offices.
It has a simple GUI, which is good.
The initial setup is pretty simple.
Unfortunately, there are quite a few negatives with them.
Their tech support is not great.
The features on offer are lacking.
Basically what they don't have is proper bandwidth management for multiple WAN ports and multiple WAN ports to multiple VPN WANs. Meaning, if I have it on both sides on both the main side and on the secondary side, two internet connections, I can't bond the two of them together into a single VPN and have bandwidth managed between the two of them.
If I want to go ahead and make a VPN, right now, I have two internet connections on each side. I have to make a failover a group of four VPNs for it to go ahead and failover between them.
You're getting into a lot of rules. It's a lot of extra rules, et cetera, that has to be done. They don't have simple pointing systems where you could go ahead and make rules saying, "Hey, here's the route". They're not fully route-based VPN rules yet. You literally have to take down all the routes all over the place in order to make updates. It's tedious.
Basically, we had the problem where we moved certain ranges from one data center to another data center. It took us about an hour of downtime to do that. We had to go ahead and we had to reset VLANs and we had re-setup all the VPNs in all the different places we reconnected. We don't have two sites, we have 25 sites. It was a lot of work.
I've used the solution for about three years at this point.
It has its bugs and we can't get answers due to the fact that technical support is outsourced. There are some bugs that we keep running into that tech support can't figure out what to do. The bigger problem is the log systems aren't big enough for them to actually capture all the logs that happen.
Technical support is an issue. About six months after we bought it to a year after we bought it, they outsourced all their tech support to India. Literally beforehand, they were an American-based tech support company and they actually had full product knowledge. The Indian-based tech support doesn't have the product knowledge and there was a language barrier. They could speak English, however, they didn't understand us very well.
We were told that they stopped doing outsource and they are rehiring their own internal staff again for tech support. We're hoping that we're going to be able to get better tech support again.
The initial setup is pretty straightforward and simple. It's not overly difficult. I don't consider it to be complex.
We bought it as is. We bought it with four years of support. However, I can't speak to how much it costs.
I'd advise users considering the solution that, if you have quite a bit of sites, it's going to get a lot of work to do, to fix things up. It makes more sense if you have minimal sites.
I'd rate the solution at a six out of ten.
Firewall is not our expertise, but we do sell it as per the requirement of the customer or if they ask for it.
Most of the firewalls are on-prem. What we deliver is the hardware. It is appliance-based.
Sophos firewalls are scalable. They are pretty strong in security. So, when they provide any kind of firewall, they provide all the features such as anti-spam, antivirus, etc.
Its price should be improved. Its features are pretty okay, but the price is the area where we have to fight more. They should do something about the price structure.
It has been a couple of years.
It is stable. Its performance is very good. They have now stopped calling it a firewall. They're calling it a Unified Threat Management (UTM) solution.
It is scalable in the sense that if they are using a small model or a small box of firewall and there is an increase in their network and the number of users, they can move that small box to a bigger model. So, if they are using a firewall and they want to scale it up, they can go to the next model.
Sophos has more than 1,000 customers.
Our clients have a good system of support over here. They have full support. They get support from the distributors, from the partners, and then directly from Sophos.
We are a partner of Sophos and Fortinet. We work with Sophos much more than we work with Fortinet.
If it is a small model and a small network, it takes about two days. You need at least two people for its deployment and maintenance.
Its price should be better. Initially, the clients have to pay for the appliance. Then, they have to pay for the software that is installed on the appliance. Depending on whether they have a one-year, two-year, or three-year license, they just have to renew the license of the software after it expires. They don't have to renew the appliance license. So, they have to pay for the appliance only once, and after that, they just renew the software license. That's all.
I would definitely recommend Sophos to others. I would rate it a nine out of 10.
We primarily use the solution for a firewall. We use it as a security device.
The product is very easy to use. We enjoy the ability for it to fit into our high-level security framework.
It gives us some separation from being on Microsoft tasks. We've got multiple levels of security. We're government contractors. It's great that it's been a separate product that gives us the ability to do the security to a high level without having to resort to needing a big team.
The solution is stable. I've had very few problems with it.
We have found the solution to be scalable.
We're always looking for the best products and the best pricing. Pricing is always a concern for us.
When they do updates, they could handle them a little bit better. We've only had one problem, however, I do prefer when updates come out a bit quicker. We do the patching and updates and different things, however, in terms of the patch and timing and the criticality of it, it could always be better.
We've been using the solution for five or more years at this point. We've used it for a while.
The product is reliable and stable. There are no bugs or glitches. It doesn't crash or freeze.
The product has proven to be scalable. If a company needs to expand it, it can do so.
We have 430 end-users on the product.
We're mostly happy with the technical support. It's better than Microsoft. Any issues we have may simply come down to the SLA.
The initial setup is pretty straightforward, and, over the last six years, it's gotten simpler, especially when it comes to cloud products. A company shouldn't have any issues with the process.
The deployment was very quick. It does not take long.
My team is quite small internally. I have five to seven IT staff. I have many service providers that I outsource a lot of the day-to-day management of the infrastructure to.
Sophos assisted us with training at the outset, which we really appreciated.
We pay annually for the licensing for the overall on-prem solution, however, we also have some Sophos access points at permanent IT sites and different things. I have different Sophos products I may pay a monthly fee for.
We're just customers and end-users.
While this deployment is on-premises, for the cloud, we use Sophos Central.
I'd rate the solution at an eight out of ten. We're pretty pleased with its protection capabilities.
The solution is mostly used for setting up a firewall and policies.
The solution is very easy to understand.
It's simple to set up the firewall and policies. Setting rules is very easy on Sophos as compared to other solutions.
The product offers many great features.
Technical support is very good.
The initial setup is easy.
We have found the solution to be very stable.
A company can easily scale the product if they need to.
When upgrading the firewalls, the process could be easier.
While we do have network control, we don't have network monitoring. If I have 200 nodes and I want to see what's happening, I don't have visibility, especially if people are working remotely.
If we could control roaming users through the firewalls and make it so that it's more of a complete security solution, which we prefer, that would be ideal. If we have to install some clients on these machines, that's fine. The only concern is the DLP. We want to protect our data from being stolen. We'd also like to monitor activities from the perspective of productivity. We want to be able to track and calculate what users are doing on their machines.
I've been using the solution for more than ten years.
Earlier, Sophos was known as Cyberoam, Before that, I use Cyberoam and now this has turned into Sophos.
The stability is very good. It does not crash or freeze. There are no bugs or glitches. the solution is reliable.
The level of scalability depends on the box. We do have the option to scale if we need to.
I have found the technical support to be very helpful and responsive. I am pleased with the level of support I can get. They always provide proper solutions to all issues, whatever we face.
It is not difficult to set up the solution. One ISP, internet service provider, is required, and that is sufficient. If you do have a landline, some switches are available, and we can add to that a firewall. That is secondary. However, the initial requirement is nothing. It is just a plug-and-play setup that is very straightforward.
We had a vendor assist us with the installation.
There's no additional cost for installation. The provider from which we purchased, the vendor, himself arranged all installation and configuration. They helped us. However, even through customer care, a company can ask for assistance.
I'm not providing any services. I'm using the product as a customer only. The company, one day, would like to become a partner, however.
I would recommend the solution to other companies.
I would rate the solution at a seven out of ten, specifically if I compare it to other options on the market. It's pretty good.
We use Sophos Firewall for our environment.
The Sophos Firewall, from our interaction and the way we are using it, is a very effective network security solution that basically protects our infrastructure, identifies any infections or any network security threats that actually may happen within our environment. We also are able to manage our users in terms of bandwidth usage and the allocation of bandwidth, whereby we give our users restricted access for use during working hours and they are supposed to utilize the bandwidth and make sure that we optimize and prioritize the applications able to get the necessary bandwidth. We do use it to manage our bandwidth. We do use it as well to make sure that our environment is secure against any possible threats.
In terms of the Sophos XG Firewall, what really excites us is basically the issue of intrusion detection and the intrusion prevention features. Those are both very, very good.
The issue of sandboxing as well is something that is very useful. It's able to protect our environment quite well.
Email protection is something that we are basically using all the time and it protects our environment which has more than 2000 users.
All of the protection features are great in terms of securing our environment.
Sophos is way ahead of a number of other products in terms of the enhancements and upgrades they offer.
Sophos offers a great centralized dashboard that makes it easy to see what's happening on your network.
The initial setup is very straightforward and the solution is extremely user-friendly.
The documentation is very, very good.
In terms of the product, from the way that we have been utilizing it, we have noticed that the vendor has been able to continuously upgrade and upgrade and update the product with new features. You'd find that all the time a new release has come out, and we're actually happy with that. We don't find it inconvenient that we are constantly upgrading.
I can't think of any downsides in terms of the features on offer.
I'd like the dashboard to be improved. It could be a bit more customizable.
I have about five years of experience with the product.
We are very satisfied with the functionality. We are very satisfied with the way that it is securing our environment. The stability has been excellent.
We have 2,000 users on the solution currently.
The solution is very scalable. We basically started with about 900 users. We went up to about 1,300. As we went up, as our users increased, we also scaled it up in terms of protection. Sophos was able to scale up easily and protect all our end users as well as our environment. It's been great overall.
We do plan to increase usage. Our employee base is about 10,000. We have 2,000 networked employees and we are planning to add another 1,000 users by the end of the year.
The technical support has been great. All of our technical staff have been certified as Sophos administrators. They were able to offer us the training to make sure that all of the support staff are familiar with the functionality of the product. Then, in terms of technical support that we may need, when we call the Sophos team, they are usually very available and they are even able to support us remotely if there is a need to do that. We are extremely satisfied overall.
I also often work with Cisco's ASA Firewall as well as Nagios. We bought Sophos to complement the ASA firewall.
The initial setup was very, very straightforward. You find that we did not even require a lot of external help from the vendor. It's so straightforward. The documentation is quite comprehensive and it takes the user through a step-by-step process, It's very user-friendly.
For the firewall as well as deployment of the end-user, the email protection as well as the sandbox, and the like, it took us approximately three days to finalize everything for our entire environment. We had over a hundred network sites, which are dotted through the city of Harare, therefore, we knew that we had to make sure that deployment was done fully throughout the entire environment.
There was very minimal, minimal assistance from the vendor. The vendor, here and there, would assist if we requested their help. However, you'd find that in most of the installations we did in-house, we didn't need the vendor to do anything. We knew that the installation process was very user-friendly.
The cost of procuring this product is very reasonable and it's very affordable for most organizations.
We're a customer and an end-user.
We use the latest version of the product.
I'd advise those considering the solution that Sophos' security solution is highly synchronized, very secure, and provides comprehensive security. I'd like them to know that it has enhanced and very detailed and sophisticated functionality, which is really easy to use, easy to deploy, and very user-friendly. It is a product that I would highly recommend for any organization that needs to comprehensively secure its infrastructure.
I'd rate the solution at a nine out of ten.
Our primary use case of this solution is for protection and to have better governance for our LAN usage. I've got a lot of people working from outside on the corporate infra and all policy based decisions happen there. The solution is basically a firewall that protects us from various internet threats, but other than that provides controlled and properly managed access using various rules of VPN and other fingerprints of people logging in. I'm the CTO of the company and we are customers of Sophos.
The interface is great and easy to understand. Any firewall engineer who has medium to moderate experience on bylaws, can easily understand the UI. The language presented on various features and the in-built help, is very intuitive. If you have a problem you can figure it out there and then. As a result, there is less probability that we'll call tech support.
The solution really needs some additional features like network access control. If they could incorporate some user profiling and present the analytics of the login user usage patterns, or a typical proper management dashboard to take a decision on the firewall rules, that would be useful. Basically, MI's and the dashboard could be more user friendly. The information is there but the dashboards are not in a graphical format. In short, I'd like to see network access control, user profiling and analytics dashboards. It would make the solution a more competitive product on the market.
I've been using this solution for over four years.
This is a stable solution. I haven't had any firewall crashes or any non-performing rules for over two years. We are a hospital so all the lights of all the devices should be on 24/7, 365 days a year.
We manage and control around 250-300 internal users. There would probably be another 75-100 logging in externally.
This is definitely a scalable solution. The way we've configured it, if a device goes down, it can be shut off and removed from the network for repairs or updates and our second firewall automatically takes the load.
We only used technical support during our initial deployment. After that, we didn't need support because the product was working perfectly well. We trained ourselves on the newer software and we are capable of managing and maintaining our own firewalls. In addition, Sophos provides online documentation which is very user friendly. If you follow the steps you get the result.
I previously used Cisco's firewall ASA and it was extensively implemented in my earlier role. The main reason to migrate to Sophos was due to their aggressiveness in terms of pricing but also the fact that they had features that Cisco did not have.
The initial setup was very straightforward. Deployment took somewhere between six and eight hours.
There's no annual licensing fee. When we purchased the product, it was with a five year agreement bundled in with the product price and the recent rollout is not yet five years old. When we renew, we'll renegotiate. I can't differentiate between the product costs and the licensing costs at this point. We're very lucky that we get one of the best deals in the country in terms of pricing. The Sophos-backed pre-sales and implementation team were very cooperative and collaborative which really helped us make the decision to choose Sophos.
I would definitely recommend this solution but it's only suitable if it fits the needs of the company so I would suggest carrying out some research. Why does the company need a firewall? What rules do they want to deploy on the firewall? Based on the answers to those questions the company can make a call.
I would rate this solution a nine out of 10.
We use the solution as an antivirus gateway and internet gateway.
All the features are effective in enhancing our network security. I am satisfied with the product. The threat intelligence capabilities of the tool are good. It has contributed to reducing our overall security costs by approximately 90%.
I do not get notifications regarding ISP downtime. It would be better if I could get notifications related to the critical errors occurring in Sophos. The product is difficult to use. The administrators must be notified of the errors occurring in the firewall through emails or messages. It will help organizations take proactive measures instead of taking action after the incident happens.
I have been using the solution for one and a half years.
The customer support is weak. The support team is not responsive. The support people do not follow up or call us back.
Negative
The implementation is not difficult. The service providers help install and implement the firewall in our network.
I will recommend the product to others. However, I would not recommend it to organizations that do not have technical people who deal with networks. Overall, I rate the product a seven out of ten.
The antivirus features are valuable.
The price should be cheaper. Xstream must be included in future releases.
I have been using the solution for five years.
I rate the tool’s stability a seven out of ten.
I rate the tool’s scalability a ten out of ten. Our clients are SMBs.
I rate the ease of setup a ten out of ten. The solution is deployed both on-premise and on the cloud. The deployment takes half an hour.
I rate the pricing a six out of ten.
We are distributors. We sell the solution. We have many customers. Overall, I rate the product an eight out of ten.
We use the latest version.
We are very familiar with the solution. It's pretty straightforward, our personnel is properly trained and we use it efficiently. The solution integrates very easily with other brands. I've done VPN tunnels with other brands, and that was fine as well. The solution is quite stable and we don't have any issues with it. The VPN is easy and has good logging, monitoring and notifications.
When compared with Sophos XG, Fortinet lacks the notifications and reporting features.
When it comes to improvements that the vendor can make, we see that the cloud integration for managing all the firewalls is essentially a replacement of the on-prem version we had. It's not mature yet, being still in its infancy stage. That would require some improvement. As I have many firewalls, having the ability to delegate access to use, such as exists with Microsoft CSP or other services, would be a nice feature to see.
Also, as a tech person, I know that executives do not wish to receive complicated reports, so a simplified executive report for executives would be a nice improvement. This would save us from having to explain issues which are beyond the scope of their knowledge.
Sophos XG is basically a mix of UTM9, Check Point and several other technologies. It is essentially a merging of technologies. We've been using it since version UTM9, at which point we switched to Sophos XG..
The solution is quite stable.
The solution is scalable, but an organization should assess in advance its size based needs. Say, for example, a company utilizes the XG 125 version, but grows rapidly. At this point it may need to switch to the 210 version. Yet, switching from one version to another would not really present an issue. One can restore the backup configuration version on the new hardware and be up and running.
Technical support is pretty good, although I did have some issues with its availability during the COVID-19 pandemic, even though this seems to have been a challenge faced by all major support companies. There were delay issues owing to their teleworking, but the support they offer is quite supportive and they have all the necessary documentation. The truth is that I have a need for many cases, although the ones I require have to do with things that are out of my control, such as licensing or the occasion of a new app that failed to show up in the console. I have many sub-sites and I did face a serious issue. Technical support was pretty helpful even though I had to redesign the typology of one of my sites. They actually tried assisting me with the original design and I found them to be quite helpful and to possess a good base of knowledge on the site.
It is important for a person to properly learn the features of any product so that he can optimize its utilization. The setup of the solution is pretty straightforward. What is truly important for a person with only a basic network background is to undergo proper training, so that he may learn about all the features and how to configure them.
For any product a person uses, it is a good idea to do a test run. Sophos allows for its product to be evaluated without any financial commitment. It offers a free virtual machine for home use testing of the features.
At present, Fortinet seems to have a slightly higher rating than Sophos XG, so if it were also to turn out to be more cost effective this would affect my rating of it. The reason is that this factor does have an impact on the decisions reached by CEOs when it comes to cost-benefit analysis.
This said, I rate Sophos XG as a nine out of ten, because we are very happy with it and don't really have any issues. We have actually been replacing Cisco normal routers, not sets, with Sophos and we're very happy with them.

Well done! Happy to see it was easy.
Next step is Synchronize Security with Sophos Endpoint (formely Sophos Central), to block "lateral movement"!
https://www.sophos.com/en-us/l...
https://techvids.sophos.com/wa...
Regards,