Sophos XG is a firewall and we use it to create networking rules.
IT Architect at a consultancy with 11-50 employees
Lacking security, poor search tool, but stable
Pros and Cons
- "The performance of Sophos XG is generally good and it is stable."
- "The security of Sophos XG could be improved."
What is our primary use case?
What needs improvement?
The security of Sophos XG could be improved.
Sophos wants to move all things to the cloud, including access to the end-user PCs and data from the cloud. What will be easier to hack for a customer with an outdated firewall, or the Sophos cloud could get hacked which has all the access and information from customers. With my experience, it's not a question of if they will hack it, but a question of when they will do it. I'm not happy with the direction Sophos is going on.
We have problems with the use of the user interface. You have a poor search engine for objects via which you can write new rules. You have to start at the beginning of the whole object name. With the Sophos UTM, you can start with a pattern, with part of the whole word. In Sophos UTM it will list you all the hits with parts of what you type, and that does not happen on the Sophos XG.
For how long have I used the solution?
I have been using Sophos XG for approximately 10 years.
What do I think about the stability of the solution?
The performance of Sophos XG is generally good and it is stable.
Buyer's Guide
Sophos Firewall
May 2026
Learn what your peers think about Sophos Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,838 professionals have used our research since 2012.
What do I think about the scalability of the solution?
I have found the scalability of Sophos XG the same as Sophos XG.
We have approximately 10 clients using this solution.
How are customer service and support?
Since Sophos XG moved the support from London to somewhere in the world, such as India, it's a little bit longer to receive a fast response. They are knowledgeable but they are slow to make decisions. For example, we had a firewall and the hardware was defect. It was really clear, but we had to have a long discussion for them to be able to send us the new firewall. It took one or two weeks until the supporter was able to talk to someone who can make the decision. This is too long, this process could be streamlined.
How was the initial setup?
The initial setup is straightforward . As long as you buy the appliances from Sophos, it works very well. However, in some cases, we have to use our own servers because they have more power and more network bandwidth.
What about the implementation team?
The amount of users needed for the implementation and maintenance depends on the size of the customer's infrastructure.
What's my experience with pricing, setup cost, and licensing?
There is a license required to use this solution and my customers pay for it annually.
What other advice do I have?
I am not amazed by this solution.
I rate Sophos XG a four out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
CIO at a tech services company with 11-50 employees
Useful VPN, helpful vendor implementation, and quick support
Pros and Cons
- "One of the most valuable features is the VPN."
- "Sophos XG is a very good solution, and it's cheaper than most of the other vendors."
- "Sophos XG should improve on the GDPR features involving data protection and encryption. Security regarding data protection is important."
What is our primary use case?
We use Sophos XG to protect our perimeter network and internet access.
What is most valuable?
One of the most valuable features is the VPN.
What needs improvement?
Sophos XG should improve on the GDPR features involving data protection and encryption. Security regarding data protection is important.
For how long have I used the solution?
I have been using Sophos XG since they bought Astaro, and it has been for approximately 15 years.
What do I think about the stability of the solution?
Sophos XG is stable. We've been using it for a long time. We had a lot of proposals from other vendors, but we decided to stick with Sophos.
What do I think about the scalability of the solution?
We have found Sophos XG to be scalable.
We have approximately 150 people using the solution which includes people that do not know they are using it, collaborators, and administrators that work on it.
How are customer service and support?
We had to use support a few times and the answers we received were straightforward and in a timely manner.
Which solution did I use previously and why did I switch?
We were using other solutions previously. However, Sophos bought the companies that created them. We kept using the same solution but the name has changed.
How was the initial setup?
The implementation of Sophos XG is not as straightforward as we would expect in the latest versions.
What about the implementation team?
We used a company to do the implementation of Sophos XG. The process did not take very long, it took them approximately two weeks. It did not seem that difficult. Our experience with the vendor's support was very good.
We have a team of four that work on the Sophos XG for maintenance. They are not working on it full-time but they are all skilled to intervene if needed, and the first line of support for the solution.
What's my experience with pricing, setup cost, and licensing?
Sophos XG is a very good solution, and it's cheaper than most of the other vendors. It is really affordable.
We are on a three-year license to use the solution.
Which other solutions did I evaluate?
I have evaluated other solutions, such as Check Point.
What other advice do I have?
My advice to those wanting to implement this solution would be training is required for the implementation.
I rate Sophos XG an eight out of ten.
I'm aware that there are other solutions that are probably better than Sophos XG, such as Check Point. However, I still find that it's a very good solution for small to mid-size companies.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Sophos Firewall
May 2026
Learn what your peers think about Sophos Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,838 professionals have used our research since 2012.
Network Engineer at Spectrum Engineering Consortium Ltd.
Reliable and flexible for small and large companies, but has some feature issues to resolve
Pros and Cons
- "Sophos XG Firewall is very usable, very easy to install, and very user friendly."
- "We are facing some problems on this firmware version, version 18, that require improvement. We want to improve the email security because it doesn't give proper security with the data protection. Also, our clients are facing some problems where most of the sites which they're accessing are getting blocked. I want to improve those sites, that email security, and the data protection on the Firmware version 18."
- "We are facing some problems on this firmware version, version 18, that require improvement."
What is our primary use case?
You can use Sophos XG in small or large companies. In a small company we are using it as a router and firewall. In larger company, like in the Bangladesh government, they are using Sophos Firewall in various sites, including the Bangladesh Navy. Many of the sites are using Sophos Firewall as a router and firewall and also for security purposes.
How has it helped my organization?
Sophos XG Firewall is for security purposes and we are also using it as a router. Wherever we are deploying it as a router we are mapping and also port forwarding. More clients take it as a router and also a firewall.
What is most valuable?
Sophos XG Firewall is very usable, very easy to install, and very user friendly.
The features that I have found most valuable are the infiltration prevention and data protection. We provide immune security. There are also many features on the VPN. We provide a social VPN. We deployed so many features.
What needs improvement?
We are facing some problems on this firmware version, version 18, that require improvement. We want to improve the email security because it doesn't give proper security with the data protection. Also, our clients are facing some problems where most of the sites which they're accessing are getting blocked. I want to improve those sites, that email security, and the data protection on the Firmware version 18. Also, sometimes it gets frozen and we cannot access it. After we shut it down and restart, then it's perfect. That's a point that we want to improve.
In the next release, I want them to please improve version 18 so that it has more features and is more user friendly and it should have a VRF option.
For how long have I used the solution?
We are using Sophos XG for five years.
What do I think about the stability of the solution?
Sophos XG is stable.
Maintenance, once it is established on the network, requires about two to three people dedicated to Sophos Firewall. We have to give about two to three days monthly.
What do I think about the scalability of the solution?
Scalability is good.
We have about a thousand or more users and have plans to increase usage of this product.
How are customer service and support?
The Sophos support team is good now.
How was the initial setup?
Initial setup is easy. It took about one hour to do the initial setup.
What about the implementation team?
I am an implementer so I deployed it by myself.
What's my experience with pricing, setup cost, and licensing?
Sophos XG is on a subscription basis. We can take a one year or two year subscription.
What other advice do I have?
On a scale of one to ten, I will give Sophos XG a seven.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Gerente de Atendimento na Introduce at a tech services company with 11-50 employees
Robust and feature-rich solution.
Pros and Cons
- "The features that I have found most valuable are first the Web Filter and the Web Application Firewall SD-Wan on Version 18. Additionally, RED Tunnels allows a Sophos vital to speak to another Sophos vital in headquarters."
- "On the security side it makes everything much more secure, especially for the users, because they can't surf the web without some kind of protection for safety and control, and we are alerted if somebody is trying to access strange websites or something the company does not allow."
- "The main problem with Sophos XG today is that it doesn't have a feature where you actually know the quality of an international link, which would allow us to we know if the link is operational or not. We need more information. It's losing packets on the network. It's high latency. So, we need more information to know if the link is really bad or really good, and today, we will only know if it's working and this just isn't enough."
What is our primary use case?
We use and implement Sophos XG for our customers for border security, just to make sure that nobody gets in and that everybody who tries to get out will have some kind of filter or protection.
How has it helped my organization?
I can say that it has not exactly improved how our the organization functions, but on the security side it makes everything much more secure, especially for the users. They can't surf the web without some kind of protection for safety and control, and we are alerted if somebody is trying to access some strange websites or trying to access something the company does not allow.
What is most valuable?
The features that I have found most valuable are first the Web Filter and the Web Application Firewall SD-Wan on Version 18. Additionally, RED Tunnels allows a Sophos vital to speak to another Sophos vital in headquarters.
What needs improvement?
The main problem with Sophos XG today is that it doesn't have a feature where you actually know the quality of an international link, which would allow us to we know if the link is operational or not. We need more information. It's losing packets on the network. It's high latency. So, we need more information to know if the link is really bad or really good, and today, we only know if it's working and this just isn't enough.
For how long have I used the solution?
I have been using Sophos XG for about six, seven years.
What do I think about the stability of the solution?
Sophos XG is really robust because of all the implementations you currently have active. We don't have problems on the hardware or a bug on the software or anything like that. It's really, really rare. Most of the problems are from requests for our customers asking to make a particular website available for some parts of the company and things like this. Just some little configurations on the web filter.
What do I think about the scalability of the solution?
We actually do studies to already know before implementation which firewall will be able to handle all the operations. It is really rare to need to change the firewall or to miss a configuration and put in equipment that can't handle the network. We have never had a case where we had to replace a hardware because it couldn't handle the network. It has always been easy to make a survey to get the right equipment for the right amount of people, and every time we need to make a new implementation we have the study making scalability easy, because each hardware is for a specific customer.
How are customer service and support?
If I were to rate support from zero to 10, I would say about six or seven. The Portuguese Support is really bad. It's really not good. Every time you have an issue that's a little bit more complex, it's better to speak to the Global Support than the Latin American Support.
How was the initial setup?
Today the initial setup is simple since we have been using it for a long time and have implemented it for several customers. So now it is really easy for us.
What about the implementation team?
We are the resellers.
What other advice do I have?
My advice to anyone considering Sophos XG is that it has a good cost-benefit. Let's just put it that it does the job right.
On a scale of one to ten, I would say Sophos XG is a nine.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior IT Security Engineer at a financial services firm with 5,001-10,000 employees
Good filtering and application control features, but the bandwidth could be more effective
Pros and Cons
- "Some of the most valuable features are filtering and application control. The DDoS detection also shows traffic jamming and traffic shaping."
- "This solution could be improved with more effective bandwidth. I found that when I enable DDoS detection for our clients, bandwidth is reduced. If DDoS detection is disabled, the bandwidth will be high, but it isn't secure. We recommend that customers enable DDoS detection, but if they need high bandwidth, we recommend Palo Alto and FortiGate instead of Sophos."
What is our primary use case?
We provide Sophos XG to customers. We work at deploying this solution from scratch to the customer, from unboxing, racking, or stacking, and doing licensing and upgrades for the box. Then we establish the process and security profiles that the customer requires.
This solution is deployed on-prem.
What is most valuable?
Some of the most valuable features are filtering and application control. The DDoS detection also shows traffic jamming and traffic shaping.
What needs improvement?
This solution could be improved with more effective bandwidth. I found that when I enable DDoS detection for our clients, bandwidth is reduced. If DDoS detection is disabled, the bandwidth will be high, but it isn't secure. We recommend that customers enable DDoS detection, but if they need high bandwidth, we recommend Palo Alto and FortiGate instead of Sophos.
For how long have I used the solution?
I have been using Sophos XG for about six months.
What do I think about the stability of the solution?
This solution is not as stable as other products. In terms of stability, our number one recommendation is Palo Alto, number two is FortiGate, and number three is Sophos.
What do I think about the scalability of the solution?
Sophos is scalable, but not enough.
How are customer service and support?
Sophos technical support is effective.
How was the initial setup?
The installation takes two days. It is easy to deploy, and not as complicated as Palo Alto or FortiGate. We make it in our company labs and, for deployment and maintenance, we recommend one or two people.
What about the implementation team?
We provide and implement this solution for customers.
What's my experience with pricing, setup cost, and licensing?
The licensing for Sophos XG is based on the number of users, so I get the module from the sizing of the customer.
Which other solutions did I evaluate?
We also recommend that customers use FortiGate and Palo Alto, since these solutions are more stable and have more effective bandwidth.
What other advice do I have?
I rate Sophos XG a seven out of ten. I would recommend it to others, based on their needs, but the stability could be better.
We have five to seven customers who are using Sophos XG.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Owner at InternetWorld Solutions Sdn Bhd
Functionality is straightforward, but tech support could be improved
Pros and Cons
- "In terms of the functionality, I think it's pretty straightforward; it's easy to pick up and it's also user-friendly."
- "Support could be improved."
- "The principal tech support is not very present in Malaysia."
What is our primary use case?
The firewall is used to maintain security. Basically, it's used to make sure that our clients' corporate network is secure. We want to make sure that their email is scanned, protected, and so on.
What is most valuable?
In terms of the functionality, I think it's pretty straightforward. It's easy to pick up. It's also user-friendly.
What needs improvement?
Support could be improved.
For how long have I used the solution?
I have been selling Sophos XG for two years. It is deployed on-premise.
What do I think about the scalability of the solution?
When it comes to scalability, of course we can upgrade. A lot of firewalls don't allow upgrades. An upgrade would mean changing the box. For our customers, a lot of the functions of the firewall don't reduce. We just need to make sure they enable the security, and then make sure it's giving the protection to the client.
For scalability when it comes to the server, I can add the RAM, the hard disc, and the CPU to boost up the performance.
How are customer service and support?
The principal tech support is not very present in Malaysia. We are relying on the distributor. Most of the technical things we can handle on our own, like when it comes to setup. When it comes to the issues related to product hardware or software bugs, we will reach out to them. But the response is from the distributor.
The support could be a bit better.
How was the initial setup?
Installation for each version, like Fortinet and Next Generation Firewall, is simple. Based on how familiar we are with the client, it can take a day or two.
We only need one or two people for deployment.
What's my experience with pricing, setup cost, and licensing?
For every firewall, you will need to pay the license for the following year. If they don't pay for the license renewal, they basically won't get the support from Sophos.
What other advice do I have?
They do have their own integration, so I don't really have much to comment about Sophos because we basically just maintain the Sophos Firewall that we supply. We don't do a lot of fancy design work.
We are currently still evaluating the solution.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
Head of Operations at Intersect Technologies
Easy to deploy at customer locations and it is priced well
Pros and Cons
- "Using Sophos endpoint and the firewall, synchronized security is easy."
- "I would recommend Sophos XG because it is easy to deploy at customer locations and it is priced well."
- "LAN inbound and outbound traffic requires more control and an additional stop."
What is our primary use case?
We use Sophos XG with medical institutions and corporate banks that we work with. There are approximately 20 employees working with this product in our company.
What is most valuable?
Being centralized, Sophos provides us threat protection there. Even with standalone, we are able to provide the Sophos firewall. Having an internal dashboard and a single dashboard with some endpoints is also valuable. By using Sophos endpoint and the firewall, synchronized security is easy.
What needs improvement?
I would like to see improvement with service and support. LAN inbound and outbound traffic requires more control and an additional stop.
For how long have I used the solution?
We have been using Sophos XG for almost 10 years. We are partners with Sophos.
What do I think about the stability of the solution?
Stability and performance is good.
What do I think about the scalability of the solution?
The solution is easy to scale.
How are customer service and support?
There is no maintenance required with Sophos XG because it is a cloud product.
Which solution did I use previously and why did I switch?
Previously I was using Cyberoam and Fortinet. We switched because there was a lot of hardware, and the performance was not satisfactory. We were experiencing space concerns with the hardware, the dual processor, and even the single processor. This also meant that synchronized security was not there as well.
How was the initial setup?
The initial set up of the solution was simple. It took about 20 minutes.
What about the implementation team?
We implemented the software on our own.
What's my experience with pricing, setup cost, and licensing?
The price is cheaper compared to others.
What other advice do I have?
I would recommend Sophos XG because it is easy to deploy at customer locations and it is priced well. I would rate this product a 10 out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
IT Support Engineer at odak bilisim
Easy port configuration, scalable, but policies could improve
Pros and Cons
- "I have found configuring the ports to be easier in Sophos XG compared to the other devices."
- "The stability and performance are quite good, and we haven't seen any problems."
- "Sophos XG could improve the policies, they are a bit confusing when creating them. There are many options that make it confusing and it could be simplified."
What is our primary use case?
We use Sophos XG for network security as a firewall for our company.
What is most valuable?
I have found configuring the ports to be easier in Sophos XG compared to the other devices.
What needs improvement?
Sophos XG could improve the policies, they are a bit confusing when creating them. There are many options that make it confusing and it could be simplified.
For how long have I used the solution?
I have been using Sophos XG for approximately two years.
What do I think about the stability of the solution?
The Stability and performance are quite good. We haven't seen any problems.
What do I think about the scalability of the solution?
The solution is scalable.
I would rate the scalability of Sophos XG an eight out of ten.
We have approximately 10 people using this solution in my organization.
My customers are using this solution on a daily basis.
How are customer service and support?
I have contacted support once or twice to receive some clarification. I had a good experience.
Which solution did I use previously and why did I switch?
I have used other solutions preciously and FortiGate's user interface is much easier to use when compared to Palo Alto and Sophos. Additionally, in Palo Alto, assigning the ports are more user-friendly.
How was the initial setup?
The installation is straightforward.
What about the implementation team?
I did the implementation of Sophos XG myself and it took approximately 20 minutes.
There is no maintenance is required for this solution.
Our networking team is approximately 10 people that use the solution.
What's my experience with pricing, setup cost, and licensing?
The Palo Alto solution is expensive and the FortiGate is less expensive than Palo Alto. The Sophos XG would be priced in the middle of the two.
There are some fees but you can purchase a bundle package.
What other advice do I have?
My advice to those wanting to use this solution is if you don't have experience, don't use it.
I would recommend this solution to others.
I rate Sophos XG a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Chief-Information-Technology-Officer at ABIG
Good Protection, scales well, and is easy to setup
Pros and Cons
- "Web publishing is important, as well as the importance of the antivirus patch."
- "Once we started using Sophos XG, the number of threats dropped dramatically."
- "Our clients use Karios, and while it integrates well with it, the integration could be improved."
What is our primary use case?
We use this solution for VPN, client VPN, malware filtering, and antivirus scanning.
How has it helped my organization?
It has definitely improved the way our organization functions. Previously only using free tools, and once we started using Sophos XG, the number of threats dropped dramatically. We had a lot of threats to our network, but they have dramatically decreased since we started using this solution.
What is most valuable?
All of the features in Sophos XG are valuable.
Web publishing is important, as well as the importance of the antivirus patch.
The firewall is also essential, and the VPN.
What needs improvement?
Our clients use Karios, and while it integrates well with it, the integration could be improved.
For how long have I used the solution?
I have been using Sophos XG for three years.
We are using the XG version.
What do I think about the stability of the solution?
We encountered an issue with the hardware when we first purchased this solution. We called Sophos, who replaced the device, and we have not had any issues since.
What do I think about the scalability of the solution?
We have no issues with the scalability of Sophos XG.
In our organization, we have 150 users, and all are required to maintain this solution.
We don't have plans to increase the usage at this time.
How are customer service and support?
We have not really used technical support. If we have an issue, we resolve it ourselves.
Which solution did I use previously and why did I switch?
Previously, we were using older versions of Microsoft. We used it for almost 10 years before switching to Sophos.
How was the initial setup?
The initial setup was easy.
We completed the installation ourselves. I took a maximum of two weeks.
What was our ROI?
I have not calculated our ROI.
What's my experience with pricing, setup cost, and licensing?
We have a three-year license.
What other advice do I have?
I am the Chief IT Officer. I don't have all of the technical details of this product. We have technical staff who use this solution for their daily routines and activities.
It's a very good product. I would rate Sophos XG an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
System Integrator IT Manager at Tecnimex S.r.l.
Integrates well with other Sophos solutions, efficient, and is reasonably priced
Pros and Cons
- "Sophos began with a basic version and evolved into something more efficient in terms of performance."
- "It integrates well with other Sophos products, such as the Sophos Firewall, Sophos Endpoint, and other features in a cloud platform, to help the customer better manage security on their site."
- "I would like to have a more efficient login process."
- "Technical support is always an issue, not just with Sophos but also with other brands. It is extremely difficult to interact with support within the time frame that the customer expects."
What is our primary use case?
This solution is used by both us and our customers.
What is most valuable?
As this product has recently changed, we are learning about the features of Sophos XG one step at a time.
Sophos began with a basic version and evolved into something more efficient in terms of performance.
It integrates well with other Sophos products, such as the Sophos Firewall, Sophos Endpoint, and other features in a cloud platform, to help the customer better manage security on their site.
What needs improvement?
I would like to have a more efficient logging process & real time analisys. The logging, expecially with EDR subscription, is something that needs improvement.
I would like to see email management improved to have more features and options for integrating with other solutions, expecially cloud based.
For how long have I used the solution?
We started working with Sophos XG when it was known as Astaro AG. I have been working with this solution for more than 10 years.
How are customer service and support?
Technical support is always an issue, not just with Sophos but also with other brands. It is extremely difficult to interact with support within the time frame that the customer expects.
In general, it takes more time to solve a problem, and better independent actions are required.
How was the initial setup?
The initial setup can be difficult. You should be familiar with Sophos or have prior knowledge of it, as it requires concepts from older versions of Sophos, the Sophos SG, the Cyberoam environment, and everything that has recently been introduced.
It is better to have some training before using this solution.
What's my experience with pricing, setup cost, and licensing?
The price is reasonable in my opinion.
Which other solutions did I evaluate?
I began looking into Fortinet solutions simply to compare some features.
What other advice do I have?
I would always recommend conducting a thorough analysis before deciding on a solution because Sophos may have some oversight for some of the tasks. It is beneficial to examine the environment that the Sophos product will be used, considering the integration with other features.
I would rate Sophos XG an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Buyer's Guide
Download our free Sophos Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Check Point Quantum Force (NGFW)
Cisco Meraki MX
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Azure Firewall
Palo Alto Networks VM-Series
Fortinet FortiGate-VM
SonicWall TZ
Juniper SRX Series Firewall
KerioControl
Buyer's Guide
Download our free Sophos Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos XG 210 vs Fortigate FG 100E
- What Is The Biggest Difference Between Sophos UTM and Sophos XG?
- What is the biggest difference between Sophos XG and FortiGate?
- Which firewall is better and why: Sophos XG 210 or Fortinet FortiGate 100E?
- Which solution do you prefer: Fortinet FortiGate or Sophos XG?
- What are the main differences in features between Sophos XG and FortiGate 80F?
- Which product do you prefer: Sophos XGS 2100 or Fortinet FortiGate 100F?
- Fortinet FortiGate or Sophos XG?
- How does Meraki MX compare with Sophos XG?
- Which firewall to choose for an SMB to prevent malware damage: Cisco Firepower or Sophos XG?













