I use it for one of our universities in Palestine. It's an Arabic university and there were about more than 10,000 students. So, our user base ranges from 1 to 10,000. I use it as the main firewall. I use it for High Availability (HA). That's the main use case why we use Sophos XG. We do intend to keep using it.
Firewall Engineer at a marketing services firm with 1-10 employees
Offers good security for SMBs
Pros and Cons
- "As a security solution, it's a very good security solution."
- "They should improve the hardware. If they can do that, it will be a very good product."
- "I decided that it is not very good for enterprise networks."
What is our primary use case?
What is most valuable?
As a security solution, it's a very good security solution.
What needs improvement?
Some features are not available on the graphical interface. So you need to return to the command line to solve some issues that are faced by the customer. I used it for enterprise networks, I decided that it is not very good for enterprise networks. There is some issue with its hardware. I have faced two problems and that were resolved by Sophos earlier. They changed the appliance. In other products, I have not seen such problems in the hardware. So I think that the hardware is not heavy duty. You can say it's not heavy duty like other vendors. The performance is not as it says on the datasheet. They should improve the hardware. If they can do that, it would be a very good product.
For how long have I used the solution?
I am using the appliance from XG 110. We use versions 105 TO 370. I use more than one product for small to medium size businesses. We also use Intercept X firewalls. We deploy Sophos XG on-premise.
Buyer's Guide
Sophos Firewall
August 2026
Learn what your peers think about Sophos Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,924 professionals have used our research since 2012.
What do I think about the scalability of the solution?
It is scalable for some things. It can have an extendable host. The appliance can be customized for more than one connection point. You can put it in the same fibre and DSL connection.
How are customer service and support?
They have proper support in the technical point of view, and their English language is not clear. You know that they are not native English speakers. That's one of the things that I faced. But they have very good knowledge.
How was the initial setup?
The installation of Sophos is very easy and straightforward.
What's my experience with pricing, setup cost, and licensing?
It's not very expensive.
What other advice do I have?
I recommend it for small to medium businesses, not for enterprise businesses. I'll rate it 8 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Network Team Lead at a manufacturing company with 5,001-10,000 employees
It is user friendly and reliable, but it needs granular control over the traffic
Pros and Cons
- "It is very user friendly and easy to manage from the administrative point of view. It is good, reliable, and easy to implement."
- "It is a very basic and entry-level firewall. It doesn't give very granular control over the traffic. It should have more granular control over the traffic. This feature should be there similar to Palo Alto and Cisco. It should have such advanced features."
What is most valuable?
It is very user friendly and easy to manage from the administrative point of view. It is good, reliable, and easy to implement.
What needs improvement?
It is a very basic and entry-level firewall. It doesn't give very granular control over the traffic. It should have more granular control over the traffic. This feature should be there similar to Palo Alto and Cisco. It should have such advanced features.
For how long have I used the solution?
I have been using Sophos XG for the last two years. We are using the latest version.
What do I think about the stability of the solution?
Its stability and reliability are fine.
What do I think about the scalability of the solution?
If you want to have multiple firewall rules, it has this type of scalability. When I compare it with some other products, such as Palo Alto, I can't find similar scalability in Sophos XG. In Palo Alto, we can have rules based on applications or app IDs, and we can create multiple rules for a single ID. We can create a single user or single IP, but such options are not there in Sophos XG. Granular level scalability should be there in Sophos, and they should do better.
How are customer service and technical support?
I appreciate their support. Their support is good.
Which solution did I use previously and why did I switch?
I also use Palo Alto. Palo Alto provides application IDs, which is a very powerful feature. Sophos XG is a very normal next-generation firewall with URL filtering, application filtering, and all such features. It is not something extraordinary. It is a very normal next-generation firewall.
How was the initial setup?
The initial setup is straightforward. It is a single day task to do the initial configuration and move the traffic over there. The firewall hardening, of course, will take some time depending upon the traffic, but the initial setup is a single day task.
What other advice do I have?
It is a normal firewall. All the basic features are there. However, it is not as advanced as some of the other solutions, such as Palo Alto. As we have more security threats, we need more granular control, but these features are not available in Sophos XG.
I would rate Sophos XG a five out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Sophos Firewall
August 2026
Learn what your peers think about Sophos Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,924 professionals have used our research since 2012.
Networking Engineer at a comms service provider with 1,001-5,000 employees
Easy to set up, good support, and the display of bandwidth usage statistics is interesting. There is a drill down menu showing bandwidth usage for each application. Easy to configure e-mail rules.
Pros and Cons
- "What we found valuable is the way they deal with emails, as well as the way the bandwidth usage is shown."
- "Sophos XG is stable and we have no problems with it."
- "We are having challenges when using Zoom with Sophos XG deployed."
What is our primary use case?
Right now, we are using this product as a perimeter firewall just to deal with emails and to protect servers, as well as other equipment that is on the network.
What is most valuable?
What we found valuable is the way they deal with emails, as well as the way the bandwidth usage is shown. I find this information to be very interesting.
What needs improvement?
We are having challenges with social media because ever since this issue of COVID-19 came into existence, the idea of using online discussions has become relevant. Before this, they were not made the priority because they were not considered to be important. Now, we've discovered that we need to use a lot of these online applications.
We are having challenges when using Zoom with Sophos XG deployed. Our wireless network is not stable through the connection. More work needs to be done there, since the FW is doubling up as a wireless controller.
I would like to see improvements made to the display and visibility. I'm also using Sophos XG firewall as our wireless controller, but as it is now, I can't see my access points on the firewall. My wish is to see the Wireless network and reports also on this firewall cum- controller.
For how long have I used the solution?
We have been using Sophos XG for almost three years.
What do I think about the stability of the solution?
Sophos XG is stable and we have no problems with it.
What do I think about the scalability of the solution?
I think there is a limitation on the issue of scalability, and it is related to the interfaces that we bought. Right now, all of the employees are using it. The traffic that passes through it covers close to 2,000 users.
For us, our bandwidth is growing so we may have to scale further, in terms of the hardware networking components.
How are customer service and technical support?
We are constantly in touch with the distributor in Zimbabwe and they are excellent.
Which solution did I use previously and why did I switch?
Prior to Sophos XG, we were using Cyberoam for our firewall. We switched because Cyberoam was acquired by Sophos.
How was the initial setup?
The initial setup is very simple. It takes perhaps an hour to complete, which included importing rules from Cyberoam.
What about the implementation team?
We completed some certifications for using this product, but for the implementation, we were assisted by IDSS. In some instances, we are doing the maintenance on our own. When we have a challenge, on a case-by-case basis, we might contact the vendor and may require them to come in and assist.
What's my experience with pricing, setup cost, and licensing?
The issue of a recurring license is a hassle because every year, we have to subscribe. It causes us problems in our organization.
What other advice do I have?
We are expanding and setting up a new data center, and I want to put a new firewall in. We have an interest in diversifying, in terms of vendors, so that we do not create a single point of failure in case one product fails. Ideally, we want to have different products.
This is a product that I can recommend for anybody who is looking for a firewall.
I would rate this solution a eight point six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director, Middle East, East India & SAARC at DMX Technologies
Good support, easy to set up, and the VPN helps ensure secure connections for people working remotely
Pros and Cons
- "The feature that we find most valuable is the VPN, which ensures that people working remotely have a secure connection."
- "We feel that the GUI can be improved a bit because it has a lot of information and looks a bit outdated."
What is our primary use case?
We are using this product as the firewall for our head office, so any connections going outside of the office go through it. We are also using VPN clients and especially during the lockdown, it was very helpful.
What is most valuable?
The feature that we find most valuable is the VPN, which ensures that people working remotely have a secure connection.
The email security and other security-related features are useful.
What needs improvement?
We feel that the GUI can be improved a bit because it has a lot of information and looks a bit outdated.
Nowadays, you hear a lot about next-generation firewalls, so some additional features can be added from an EI perspective. Products like FortiGate, for example, have a lot of features apart from the basic firewall.
We would like to see integration with existing IPAM and IDAM products.
In the future, I would like to see new kinds of automations, as well as the inclusion of artificial intelligence-related features. A lot of other firewalls already have these now.
For how long have I used the solution?
I have been using Sophos XG for approximately three years.
What do I think about the stability of the solution?
We have not had many issues, perhaps two or three of them, when using Sophos XG.
What do I think about the scalability of the solution?
Scalability-wise, they have different models. With the requirements that we have, this firewall did a good job. It's still doing a good job in terms of performance. For a larger enterprise with a higher number of users, they can recommend other models.
Currently, we have approximately 100 users.
How are customer service and technical support?
We have received good support. For the small number of issues that we have had, we received help from IT. This included assistance with configuring some additional policies. Whenever we reached out to them, they were very prompt in terms of responding to us.
Which solution did I use previously and why did I switch?
Prior to Sophos XG, we were using a firewall by Palo Alto. The major reason we began looking for a different one was that the support was not very good. The firewall was pretty decent but whenever we wanted some help, it was a bit difficult to reach out to them. To summarize, it was not very prompt.
How was the initial setup?
The initial setup was simple. Within one to two hours, we were done. This was not just the installation, but the complete configuration.
What about the implementation team?
We performed the deployment with the Sophos team guiding us over the phone. It was not complex. There was one person from Sophos who was coordinating it, and it was done by our internal IT manager.
What other advice do I have?
For the most part, I can say that we plan to continue using this product. However, we would like to see if they have come up with new models and what additional features have they been incorporating. With cybersecurity, I know there have been a lot of threats of late, so we would like to see some new technologies or new features being incorporated.
This is a product that I can recommend. My advice for anybody who is implementing it is to first try to understand what the major use cases are. People need to know that there are quite a few options, such as Fortinet, and all of them have different advantages. Sophos fits perfectly for a smaller group of users, with perhaps between a hundred and two hundred people. For larger enterprises, I recommend that they implement Fortinet or Check Point.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chef IT at a healthcare company with 51-200 employees
Stable, with an intuitive and user-friendly dashboard
Pros and Cons
- "This solution does everything and anything a firewall can do."
- "The dashboard is intuitive and user-friendly."
- "There is an area that is very specific to our setup, where working tools you cannot easily establish a VPN between two internal networks."
What is our primary use case?
This solution does everything and anything a firewall can do.
What is most valuable?
I am tempted to say that all of the features are valuable.
When you choose a firewall you have to make a strategic decision, much more than a tactical one. We decided that everything we use within it, goes through and it's got protection.
The dashboard is intuitive and user-friendly.
What needs improvement?
Training on the devices is an area that needs improvement. Their training mechanisms are not perfect, and this is where you lose a good appreciation of the product.
The documentation for implementation is not good. For example, when you look up the details on a firewall rule to validate it, the details are not there.
If you click on the help file, they say a zone is an area where you can define specific logical network areas. This is where they stop, with nothing more. If you want to go further into the concept of it, which you know there is, you have nothing. Then you have to revert to the internet and go onto newsgroups to try to see if anybody has had your type of experience. Then you find someone, they explain it to you then say, "Oh, it only makes sense". So, then when you want to implement this, it's much easier at that time. So, that's the best-case scenario that I can explain.
There is an area that is very specific to our setup, where working tools you cannot easily establish a VPN between two internal networks.
When you want to establish a VPN with different wizards, they assume that you're always going through your internet link.
If you want to create, with the zero-trust concept, which is where you don't trust anybody or any device, you want to make sure that everything on your network is segmented and everything is relative, depending on its flexibility, behind its firewall or a firewall segment. At some points, you might want to establish VPNs between certain network segments.
Since you cannot establish VPN tunnels from the Sophos interfaces, plus if you are doing something that's going through the internet, then you lose flexibility.
Currently, let's say we have a factory V-LAN and you don't want anybody within the factory V-LAN to be able to connect to another unless it is to a specific V-LAN, and you want to use VPN technology, you can't do it because you can't establish the connection again between two internal interfaces.
For how long have I used the solution?
I have been working with Sophos XG for six years.
What do I think about the stability of the solution?
It's a stable product.
What do I think about the scalability of the solution?
In regards to scalability, it's difficult to ascertain at this time because we haven't scaled it necessarily.
The use cases that we have are very particular, and we're not in a mode of having scaled it yet. We have approximately 100 users in our organization who are using Sophos XG.
How are customer service and technical support?
Their support, we have a mixed review of it. It's good, but where it's bad, is because they're an international company that relies on many different continents to be able to get the support at different levels.
When we get into the people that are from India, that's where the support becomes not as efficient as we would want it to be. They have different rules of operating under and they don't show themselves to be flexible. Whereas where I am, currently I'm in Canada. When I speak to the support people within Canada, they're much more flexible when it comes to trying to follow us up on what we're trying to do and get the thing working. They're more flexible.
How was the initial setup?
It was a combination of 75 percent straightforward and 25 percent complicated.
What's my experience with pricing, setup cost, and licensing?
It's approximately $6,000 for each device. We have three devices and it was somewhere around $18,000.
What other advice do I have?
I would recommend Sophos XG to others who are interested in using it.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Systems Infrastructure Manager at a comms service provider with 1,001-5,000 employees
Local support and good training, but the wireless controller and scalability can be better
Pros and Cons
- "I like the firewall, inbound, and outbound modules the most. The VPN feature also works well. It is very easy to configure rules in Sophos XG. We have got local service here in Zimbabwe from Sophos, which is something that I like a lot. We have got good local support, and they come on-site when we have any challenges. Sophos provides a lot of good training all around Zimbabwe. They are quite dominant here, similar to other solutions like Fortinet or WatchGuard."
- "We have got local service here in Zimbabwe from Sophos, which is something that I like a lot."
- "When you are using it as a controller for the wireless access points, it doesn't perform well. It is not suitable for the public cloud. It is more suitable for enterprise data. It is not really the equipment for cloud data centers. I am looking for a data center firewall."
What is our primary use case?
I am using it for unified management.
What is most valuable?
I like the firewall, inbound, and outbound modules the most. The VPN feature also works well. It is very easy to configure rules in Sophos XG.
We have got local service here in Zimbabwe from Sophos, which is something that I like a lot. We have got good local support, and they come on-site when we have any challenges.
Sophos provides a lot of good training all around Zimbabwe. They are quite dominant here, similar to other solutions like Fortinet or WatchGuard.
What needs improvement?
When you are using it as a controller for the wireless access points, it doesn't perform well.
It is not suitable for the public cloud. It is more suitable for enterprise data. It is not really the equipment for cloud data centers. I am looking for a data center firewall.
For how long have I used the solution?
I have been using Sophos XG for more than five years. I started with Cyberoam, which was bought by Sophos.
What do I think about the stability of the solution?
It is stable. I have managed to secure my network. It has been good so far.
What do I think about the scalability of the solution?
It is not so scalable. If you want to upgrade, you have to buy another appliance. I don't see so much scalability. You can only change a port from 1 gigabit to 10 gigabits. There are other solutions like Fortinet that are more scalable.
How are customer service and technical support?
Their support is good. We get local support from them.
How was the initial setup?
The initial setup is straightforward. The deployment took two days.
What's my experience with pricing, setup cost, and licensing?
The pricing is flexible. Sophos looks at a country's economy and offers flexible pricing. This is how they have managed to penetrate the market.
What other advice do I have?
I would definitely recommend it. It has good support and training.
I would rate Sophos XG a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
CTO at Kingsway Hospitals
A great UI with very intuitive features; comprehensive documentation ensuring issues are easily resolved
Pros and Cons
- "Great interface and in-built help is very intuitive."
- "The interface is great and easy to understand, and the language presented on various features and the in-built help is very intuitive so if you have a problem you can figure it out there and then, resulting in less probability that we'll call tech support."
- "Lacking network access control, user profiling and analytics dashboards."
- "The solution really needs some additional features like network access control."
What is our primary use case?
Our primary use case of this solution is for protection and to have better governance for our LAN usage. I've got a lot of people working from outside on the corporate infra and all policy based decisions happen there. The solution is basically a firewall that protects us from various internet threats, but other than that provides controlled and properly managed access using various rules of VPN and other fingerprints of people logging in. I'm the CTO of the company and we are customers of Sophos.
What is most valuable?
The interface is great and easy to understand. Any firewall engineer who has medium to moderate experience on bylaws, can easily understand the UI. The language presented on various features and the in-built help, is very intuitive. If you have a problem you can figure it out there and then. As a result, there is less probability that we'll call tech support.
What needs improvement?
The solution really needs some additional features like network access control. If they could incorporate some user profiling and present the analytics of the login user usage patterns, or a typical proper management dashboard to take a decision on the firewall rules, that would be useful. Basically, MI's and the dashboard could be more user friendly. The information is there but the dashboards are not in a graphical format. In short, I'd like to see network access control, user profiling and analytics dashboards. It would make the solution a more competitive product on the market.
For how long have I used the solution?
I've been using this solution for over four years.
What do I think about the stability of the solution?
This is a stable solution. I haven't had any firewall crashes or any non-performing rules for over two years. We are a hospital so all the lights of all the devices should be on 24/7, 365 days a year.
We manage and control around 250-300 internal users. There would probably be another 75-100 logging in externally.
What do I think about the scalability of the solution?
This is definitely a scalable solution. The way we've configured it, if a device goes down, it can be shut off and removed from the network for repairs or updates and our second firewall automatically takes the load.
How are customer service and technical support?
We only used technical support during our initial deployment. After that, we didn't need support because the product was working perfectly well. We trained ourselves on the newer software and we are capable of managing and maintaining our own firewalls. In addition, Sophos provides online documentation which is very user friendly. If you follow the steps you get the result.
Which solution did I use previously and why did I switch?
I previously used Cisco's firewall ASA and it was extensively implemented in my earlier role. The main reason to migrate to Sophos was due to their aggressiveness in terms of pricing but also the fact that they had features that Cisco did not have.
How was the initial setup?
The initial setup was very straightforward. Deployment took somewhere between six and eight hours.
What's my experience with pricing, setup cost, and licensing?
There's no annual licensing fee. When we purchased the product, it was with a five year agreement bundled in with the product price and the recent rollout is not yet five years old. When we renew, we'll renegotiate. I can't differentiate between the product costs and the licensing costs at this point. We're very lucky that we get one of the best deals in the country in terms of pricing. The Sophos-backed pre-sales and implementation team were very cooperative and collaborative which really helped us make the decision to choose Sophos.
What other advice do I have?
I would definitely recommend this solution but it's only suitable if it fits the needs of the company so I would suggest carrying out some research. Why does the company need a firewall? What rules do they want to deploy on the firewall? Based on the answers to those questions the company can make a call.
I would rate this solution a nine out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at a logistics company with 201-500 employees
Has rules and intelligence to scan all vulnerabilities in our network
Pros and Cons
- "The most effective feature in enhancing our network security is the threat intelligence capability."
- "The technical support could be improved as it is currently not competent and pretty slow."
What is our primary use case?
We use Sophos XGS primarily for VPN and security with clients and supplies.
How has it helped my organization?
Sophos XGS has some rules and intelligence to scan all vulnerabilities in our network.
What is most valuable?
The most effective feature in enhancing our network security is the threat intelligence capability.
What needs improvement?
The technical support could be improved as it is currently not competent and pretty slow.
For how long have I used the solution?
I have been working with Sophos XGS for three years.
How are customer service and support?
The technical support is rated three out of ten, indicating it needs significant improvement.
How would you rate customer service and support?
Negative
What's my experience with pricing, setup cost, and licensing?
The pricing of Sophos XGS is okay. It is approximately two thousand and a half per year.
What other advice do I have?
I would rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head Of IT at Misr Cement Qena
A cost-effective solution to control the network and for web browsing
Pros and Cons
- "It increases productivity in our company. Everything is protected."
- "Deployment could be easier."
What is our primary use case?
We use the solution to control the network and for web browsing. It provides threat protection.
What is most valuable?
It increases productivity in our company. Everything is protected.
What needs improvement?
Deployment could be easier.
For how long have I used the solution?
I have been using Sophos XGS for three years.
How are customer service and support?
I have the company we bought from Cisco, which provides technical support. If anything goes wrong, we call them for any help and support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
With Cisco, You have to buy everything separately and request many options. It's preferable to get a full bundle like Sophos offers. Sophos includes everything in one package, and any additional features are less expensive than Cisco.
It is 20% more expensive than Sophos.
How was the initial setup?
The initial setup is difficult. You need to take a course to learn how to deploy Sophos. With training and hands-on experience, it’s manageable now, but setting up Sophos for the first time was time-consuming. Deploying the security and configuring the network took a lot of effort initially, but the process becomes much easier once that's done.
What other advice do I have?
Overall, I rate the solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Used for website blocking, application blocking, and site-to-site VPN
Pros and Cons
- "Compared to other products, Sophos XGS is a user-friendly solution."
- "It would be useful if Sophos XGS included DDNS-based features."
What is our primary use case?
We use Sophos XGS mostly for website blocking, application blocking, and site-to-site VPN.
What is most valuable?
Compared to other products, Sophos XGS is a user-friendly solution.
What needs improvement?
It would be useful if Sophos XGS included DDNS-based features.
For how long have I used the solution?
I have been using Sophos XGS for four years.
What do I think about the stability of the solution?
I rate the solution an eight out of ten for stability.
What do I think about the scalability of the solution?
Sophos XGS is a scalable solution. We have more than 50 users in our organization.
How are customer service and support?
Sophos XGS provides good technical support. The support team has good knowledge of troubleshooting and fixing our issues.
How was the initial setup?
The solution’s initial setup is complex.
What about the implementation team?
We implemented the solution through an in-house team. The solution’s deployment takes half an hour to one hour.
What's my experience with pricing, setup cost, and licensing?
Sophos XGS is a cost-effective solution.
What other advice do I have?
I would recommend Sophos XGS to other users because it is more cost-effective than other products.
Overall, I rate the solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Sophos Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Cisco Secure Firewall
Netgate pfSense
OPNsense
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Check Point Harmony SASE (formerly Perimeter 81)
Cisco Meraki MX
Check Point Quantum Force (NGFW)
Azure Firewall
Palo Alto Networks VM-Series
Fortinet FortiGate-VM
Juniper SRX Series Firewall
SonicWall TZ
Buyer's Guide
Download our free Sophos Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos XG 210 vs Fortigate FG 100E
- What Is The Biggest Difference Between Sophos UTM and Sophos XG?
- What is the biggest difference between Sophos XG and FortiGate?
- Which firewall is better and why: Sophos XG 210 or Fortinet FortiGate 100E?
- Which solution do you prefer: Fortinet FortiGate or Sophos XG?
- What are the main differences in features between Sophos XG and FortiGate 80F?
- Which product do you prefer: Sophos XGS 2100 or Fortinet FortiGate 100F?
- Fortinet FortiGate or Sophos XG?
- How does Meraki MX compare with Sophos XG?
- Which firewall to choose for an SMB to prevent malware damage: Cisco Firepower or Sophos XG?












