This product serves as our current firewall solution, which is a network protection gateway.
Information Technology Security Officer at South African National Accreditation System (sanas)
Quick to install and configure with proactive support, but updates often cause problems
Pros and Cons
- "Definitely, its usability is very good, and it's a very robust firewall."
- "Technical support for Sophos is very good and they have a big presence in South Africa."
- "I think that the main area for improvement is the quality assurance of the updates."
- "Software updates always come with issues. For example, I just upgraded to the next version, 80.5, and it came with VPN issues."
What is our primary use case?
What is most valuable?
This is a very simple solution.
It integrates well with Sophos Endpoint Protection, and we use the two of them to form a holistic security perimeter control.
What needs improvement?
Software updates always come with issues. For example, I just upgraded to the next version, 80.5, and it came with VPN issues. It started dropping my VPN users. So, I had to roll back to before the software update. I think that the main area for improvement is the quality assurance of the updates.
The management console is a little bit rigid.
Scalability can be improved.
I think that it performs a little bit slow when it comes to connectivity, and having the speed increased would be better.
For how long have I used the solution?
We have been using Sophos XG for the past four years.
Buyer's Guide
Sophos Firewall
April 2026
Learn what your peers think about Sophos Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,311 professionals have used our research since 2012.
What do I think about the stability of the solution?
This is a very stable platform. In the four years that we have had it, it's never gone down.
What do I think about the scalability of the solution?
It is not a very scalable product. I would rate the scalability a seven out of ten because where you order it, it comes with prefixed ports. You will only have perhaps two for the WAN, and then maybe four LAN ports, and one console. In this regard, it's not scalable.
When you buy it, you can't change the port configuration. In order to get more ports, you may have to upgrade to a bigger firewall.
We have about 130 accounts for approximately 80 employees.
How are customer service and support?
Technical support for Sophos is very good and they have a big presence in South Africa. It uses something called Sophos Central, where support can fix the problem before you, as the user, actually finds it.
How was the initial setup?
It is a very simple and very quick initial setup and configuration. Because it is a next-generation firewall, it does most of the rule development in the background. You just need to set up the basics and start it up.
What was our ROI?
For what you are buying, it's good value for the money.
What's my experience with pricing, setup cost, and licensing?
Sophos is very good when it comes to pricing. A firewall has a lot of things to look for when you're buying it, including throughput and its features. When we purchased this product, Sophos was the best on the market.
Which other solutions did I evaluate?
In addition to Sophos, we looked at FortiGate, SonicWall, and Cisco. We were looking for a next-generation firewall, and Cisco was out of range because it was too expensive. We settled on Sophos because we already had the endpoint solution in our environment, and the price was very good as well.
What other advice do I have?
Sophos XG is a firewall that I recommend because it's a very simple firewall. It's not complicated, and a LAN expert can just start using it and learn very quickly. Definitely, its usability is very good, and it's a very robust firewall.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior IT Manager at a agriculture with 11-50 employees
A stable, flexible, and easy-to-use solution that works well and comes with a web management portal that can be accessed from anywhere
Pros and Cons
- "It is stable, flexible, and easy to use. It has got a web management portal that can be accessed from anywhere."
- "It is stable, flexible, and easy to use, and it has got a web management portal that can be accessed from anywhere."
- "I would like to have more artificial intelligence in the web monitoring service that comes with it. It should alert us when particular events happen. It has already got some of that. I know that it is more of a service, and Sophos is already looking at it. It is called SIEM."
- "I would like to have more artificial intelligence in the web monitoring service that comes with it. It should alert us when particular events happen."
What is our primary use case?
It can be used as a firewall, SD-WAN enabler, and secure web gateway. You can also use it for unified threat management, email detection, mobile device management, and wireless management. I use it in the cloud and on-premises, and I have its latest version.
What is most valuable?
It is stable, flexible, and easy to use. It has got a web management portal that can be accessed from anywhere.
What needs improvement?
I would like to have more artificial intelligence in the web monitoring service that comes with it. It should alert us when particular events happen. It has already got some of that. I know that it is more of a service, and Sophos is already looking at it. It is called SIEM.
For how long have I used the solution?
I have been using this solution for a few years.
What do I think about the scalability of the solution?
We have roughly 700 users who use this firewall.
How are customer service and technical support?
I have interacted with them a few times. I am very satisfied with their technical support.
Which solution did I use previously and why did I switch?
We were using FortiGate.
How was the initial setup?
It is easy to install. I have done the installation in less than a day.
What about the implementation team?
We did it ourselves. We have two people for its deployment. We have one engineer and one admin.
What's my experience with pricing, setup cost, and licensing?
It is not that expensive compared to the other solutions. It is about the same price range as Fortigate, which we used previously. Licensing is on a yearly basis.
What other advice do I have?
I would recommend this solution. We're very happy with the product. It works very well, and we don't have too many issues.
I would rate Sophos XG a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Sophos Firewall
April 2026
Learn what your peers think about Sophos Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,311 professionals have used our research since 2012.
Network Security Administrator at a comms service provider with 501-1,000 employees
Reasonably-priced and straightforward to set up, but instability has caused problems and customer support should be improved
Pros and Cons
- "The initial setup was straightforward."
- "The initial setup was straightforward."
- "The first area that needs to be improved is customer support."
- "The issue of stability is the reason that I'm trying to move away from using Sophos as our firewall."
What is our primary use case?
We use the Sophos XG firewall as part of our security solution.
What needs improvement?
The first area that needs to be improved is customer support.
If I'm implementing a connection on the DMZ or WAN, I should be able to dive deep into the implementation, specifying what needs to be implemented or not. For example, I should be able to configure specific details for the DMZ, and not have to follow the templates that they provide.
We have had problems with the stability that affected business operations.
For how long have I used the solution?
We have been using Sophos XG for three years.
What do I think about the stability of the solution?
The issue of stability is the reason that I'm trying to move away from using Sophos as our firewall. There were times where Sophos randomly cut some users off of the internet, which adversely affected business operations. It is important because our business relies on throughput and service, like the uptime of e-commerce servers.
What do I think about the scalability of the solution?
Scalability depends on the specifications during the time of order, prior to first implementing the firewall. With respect to my organization, scalability has been okay. It comes down to the amount of money that is spent.
We have 1,200 users in the company.
How are customer service and technical support?
Customer support needs to be improved. The time they take to resolve issues is too long.
How was the initial setup?
The initial setup was straightforward. It took us less than 30 minutes. Normally, it depends on the size of your organization, so for mine, the installation was less than 15 minutes. By 30 minutes I was finished even with the setup and configuration.
What's my experience with pricing, setup cost, and licensing?
For our company, the price was reasonable.
What other advice do I have?
We are now thinking about incorporating the Fortinet next-generation firewall.
My advice for anybody who is considering Sophos is that a business with a lot of throughput and data traffic should look for another firewall.
I would rate this solution a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Analyst at a financial services firm with 11-50 employees
Seamless VPN connection that is easy to manage and reasonably priced
Pros and Cons
- "The most valuable feature is the VPN aspect."
- "During this COVID era, the VPN has really been helpful."
- "In the Firewall, the Intrusion Prevention System can be improved."
- "In the Firewall, the Intrusion Prevention System can be improved."
What is most valuable?
The most valuable feature is the VPN aspect. It has been beneficial for my users who work from home. Connectivity and from a security aspect. The security aspect of this is quite good. It measures up to the standard that I expect.
From a Firewall perspective and then user management, easy to manage and the user experience, profile, are giving me what I am expecting.
During this COVID era, the VPN has really been helpful. We can seamlessly connect to the applications remotely and work from home.
What needs improvement?
In the Firewall, the Intrusion Prevention System can be improved. Now because COVID has come to stay, people tend to work from home, and cybersecurity has been on the high side.
It can improve more on the security aspect of this so that it can combat any major threat or common bug. I am not saying that the security has become compromised, as it is usually active, but they can improve on it.
Local and technical support can be improved.
When firmware updates are complete, there were issues with connectivity and VPN users. Recently, I stopped updating the firmware because I didn't want to obstruct the connectivity of the staff working remotely at different locations.
I have stopped doing any updates until the issue can be addressed.
For how long have I used the solution?
I have been using Sophos XG for approximately 12 months.
What's my experience with pricing, setup cost, and licensing?
When you compare with Barracuda, Sophos is quite a bit cheaper.
With Sophos, you can upgrade on what you need and upgrade as time goes on. I think that it's relatively open, compared to other products.
What other advice do I have?
I would rate this solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Managing Director at FORESEC
Straightforward to set up, stable, and is well-suited to SMB
Pros and Cons
- "Overall, this is a good product and I would recommend it for small to mid-sized customers."
- "Overall, this is a good product and I would recommend it for small to mid-sized customers."
- "The number of ports, especially on the entry-level appliances, should be increased."
- "The number of ports, especially on the entry-level appliances, should be increased."
What is our primary use case?
We are a solution provider and Sophos XG is one of the security products that we implement for our customers. We always provide them with the latest version.
What needs improvement?
The number of ports, especially on the entry-level appliances, should be increased.
The price of adding ports should be reduced to make it more competitive.
The vendor needs to create materials to show the differences between Sophos products and those from other vendors.
Network management needs to be included in the package.
As it is now, it only supports ten multiple users, which is something that should be increased.
For how long have I used the solution?
I have been working with Sophos XG for approximately two years.
What do I think about the stability of the solution?
This solution is stable.
What do I think about the scalability of the solution?
This is a scalable product and we have approximately 150 users.
How are customer service and technical support?
We get our support from the local distributor.
Which solution did I use previously and why did I switch?
Prior to Sophos XG, we used products from Fortinet and Forcepoint.
The Forcepoint product is doing well. We have a different perimeter firewall for our data center that uses it because we use different vendors for different sites.
How was the initial setup?
This is an on-premises appliance and the installation is straightforward. It can be deployed in less than an hour. However, according to the number of users and the number of ports that will be connected, the design may vary. This makes it difficult to estimate the time required to do a full implementation of the product.
What about the implementation team?
We have four people in charge of maintenance, although they do not work exclusively with Sophos. We have another appliance from another vendor. The entire team, including their manager, is about 10 people.
What's my experience with pricing, setup cost, and licensing?
The price is in the mid-range and it is very good for small to medium-sized businesses. One license opens everything.
What other advice do I have?
Overall, this is a good product and I would recommend it for small to mid-sized customers.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
IT Executive at Hotel Maluri Kuala Lumpur
User-friendly and easy to explore with many good features
Pros and Cons
- "The product is very easy to explore. It has a very good layout."
- "Overall, everything about the solution works well; we haven't had any issues at all, the features on offer are great, it has pretty much everything we need, and the solution is very user-friendly."
- "The solution is tied to the US dollar. You need to pay whatever the equivalent is in your own currency, and, if the exchange is bad, it can really add to the cost."
- "The solution is tied to the US dollar. You need to pay whatever the equivalent is in your own currency, and, if the exchange is bad, it can really add to the cost."
What is most valuable?
Overall, everything about the solution works well. We haven't had any issues at all.
The features on offer are great. It has pretty much everything we need.
The solution is very user-friendly.
The product is very easy to explore. It has a very good layout.
What needs improvement?
I need to do a bit more research on the product. I can't think of any features that are missing.
The solution is tied to the US dollar. You need to pay whatever the equivalent is in your own currency, and, if the exchange is bad, it can really add to the cost.
For how long have I used the solution?
We've been using the solution for three years. It hasn't been an extremely long amount of time.
What do I think about the stability of the solution?
The stability is great. We don't have any issues. I haven't come across bugs or glitches. There isn't crashing or freezing. It's reliable.
How are customer service and technical support?
Technical support is quite good. That said, we really haven't had any issues with the product itself.
Which solution did I use previously and why did I switch?
I used to use Fortinet. That was at a different company, however.
How was the initial setup?
The solution is very straightforward to set up. It's not too complex. Sophos Endpoint is similar in that respect. It's easy to implement.
What's my experience with pricing, setup cost, and licensing?
The pricing is a bit expensive. That is mostly due to the US exchange. If the exchange is bad, it's quite an expensive option for us.
What other advice do I have?
We are Sophos customers. We're just end-users.
We also use Sophos Intercept X and Sophos Endpoint as well.
It's a good option. It's easy to explore and to use. Everything is pretty straightforward, especially if you compare it to other firewalls.
Overall, I would rate it at a nine out of ten. We've been very happy with it in general.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CTO at Kingsway Hospitals
The great interface and security are key features
Pros and Cons
- "Good security and a good interface."
- "I've found that the valuable features are the interface and the security, both are really great."
- "Content filtering could be more effective and efficient."
- "The security of the solution could be improved by making it more intuitive and it should have a background reputation service for classification of websites for content filtering."
What is our primary use case?
I'm the CTO of our company and we are customers of Sophos.
What is most valuable?
I've found that the valuable features are the interface and the security, both are really great.
What needs improvement?
The security of the solution could be improved by making it more intuitive and it should have a background reputation service for classification of websites for content filtering. It's a service which defines the type of websites enabling me to do my content filtering in a much more effective and efficient way.
They really need to include some kind of a client app for mobiles so that firewalls and all the metrics can be accessed directly on the phone; some kind of administrative application on the phone, maybe on an iOS or Android.
For how long have I used the solution?
I've been using this solution for over four years.
What do I think about the stability of the solution?
This is a stable solution, it's a nice robust firewall. We love using it.
What do I think about the scalability of the solution?
The solution is scalable, we have around 700 end users and 10 technical people on staff.
How are customer service and technical support?
We are satisfied with the technical support but having said that, we didn't need much support because the menus and all the online documentation is self-explanatory. There was no failure so we didn't have to actually log a call with Sophos.
Which solution did I use previously and why did I switch?
We didn't previously use another solution before implementing Sophos. We chose it by specification and the reputation it has in the market.
How was the initial setup?
The initial setup was a little complex because of the kind of configuration that we were looking at, the way the firewall had to be configured was slightly complex. We carried out the implementation ourselves and it took a maximum two days.
What other advice do I have?
I would recommend this solution but would suggest that before buying any firewall, it's important to assess your expectations and then match it with the specification. You will not be disappointed if you do this.
I would rate this solution a nine out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior IT Consultant - Sophos Architect at ARENTIA S.A.
A powerful and cost-effective web application firewall solution
Pros and Cons
- "The web application firewall reverse proxy is very good."
- "Sophos XG isn't expensive compared to Check Point, but the specs and technical side of Sophos XG are close to Check Point, and the price is lower, so I can do the same complex configurations with Sophos XG that I used to do on Check Point firewalls."
- "Sophos can improve the debugging of the WAPS function."
- "I have a lot of issues with Sophos technical support."
What is our primary use case?
We essentially use Sophos XG to protect our customers. Most of our customers use remote VPN connections. They also use the WAF protection for exposed internet WEB servers.
What is most valuable?
The web application firewall or WAF is very useful. Web application firewalls help keep your servers safe from hackers by scanning activity and identifying probes and attacks.
Using the Web Application Firewall (WAF), also known as reverse proxy, Sophos
UTM lets you protect your webservers from attacks and malicious
behavior like cross-site scripting (XSS), SQL injection, directory
traversal, and other potent attacks against your servers.
You can define external addresses (virtual webservers) which should be
translated into the "real" machines in place of using the DNAT rule(s).
From there, servers can be protected using a variety of patterns and
detection methods.
This function has been completely re-developed in XG, relatively of the UTM-9 version, and it works fine. I protect many internet web servers (IIS) for my customers with this function, due to of a lot of attempted attacks. It's a very useful and relatively simple to implement in Sophos XG.
Obviously, like all security systems, it is not a "fire and forget" configuration. It is necessary to properly analyze the system to be protected, create an appropriate policy and monitor its behavior once activated.
What needs improvement?
I think Sophos XG can improve some annex features. Like in DHCP, we can't make IP reservations in the range. We must reserve out of the range, which is not good. It will not be the same as the DHCP function in a Windows Server. We can't make an IP reservation in the range of the DHCP in the Sophos.
Better in the next release? I hope...
Sophos can also improve the debugging of the WAF function and provide a better resolution in the log, in the attached WEB log. The initial error doesn't appear. You must tail the console log to find the source pattern, cause of the error.
For how long have I used the solution?
I have been using Sophos XG for about tree years.
What do I think about the stability of the solution?
Sophos XG is stable. I don't encounter problems that are typical with broken systems. But bugs in the system exists. Last example, I discovered a bug is in the asymmetric routing implementation. In a specific network configuration, asymmetric routing, with sub-net 25 doesn't work, but mask 24 and mask 26 works!!
But this is just a bug, and Sophos' support is very good to correct quickly, ASAP.
I only had a break function once because of the appliance BIOS. The Sophos support send me a new BIOS very quickly, and the problem was resolved.
How are customer service and technical support?
I have a lot of issues with Sophos technical support. I still have some pending issues that need to be resolved. It's very odd in the beginning because your first contact is with the sub-part of another sub-part of Sophos based in India or Pakistan. It's very odd to have a quick connection with the second level or third level engineer at Sophos in UK.
I have personal contact with some security managers and the sub-part manager of Sophos support. When they don't resolve a problem quickly, I send an email, or I call my contacts Sophos UK, and it happens! They have good reactivity.
Which solution did I use previously and why did I switch?
We start with Sophos UTM-9, the old version of Sophos firewalls, and then we switched to the XG.
How was the initial setup?
The initial setup of the last version of Sophos XG is good. The initialization is very simple, but you must prepare it. You need an Sophos customer account , on the web cell, to declare easy a firewall.
It'll ask for an account, and you can create it in the interface, but it's better to prepare it before in the Sophos site, to have the account ready, for the first initialization of the firewall.
The deployment time depends on the system's complexity, the number of ISPs, the number of sub-nets, WAF functions and VPNs.
It's normally very easy for a little company. A retail company with 20-30 computer-users, and a simple connection to the internet, it'll take about four to six-hours to deploy. If you need to fine-tune it, maybe two hours more. So like eight hours or a day to deploy.
What's my experience with pricing, setup cost, and licensing?
Sophos XG isn't expensive compared to Check Point. Sure, Check Point is the Rolls-Royce of firewalls: It's great, it's fun, technically good tunned, but it's very expensive.
But the specs and technical side of Sophos XG are close to Check Point, and the price is lower. It's better for our customers. I can do the same complex configurations with Sophos XG that I used to do on Check Point firewalls.
Which other solutions did I evaluate?
The main difference between Sophos XG and Check Point is keylogging and working with clouds. Both FortiGate and Watchguard doesn't have in log packet analyzer to do so deeply.
For me personally, Check Point firewall is the best firewall, because the log console is the power key of the firewalls. But Sophos XG is the main challenger of Check Point, I think. You can open the debugging packet analyzer, like a Wireshark, directly in the WEB log console. This function is a powerful tool and must be discovered, because it's very useful for quick debugging.
If I had to rank them, it's Check Point first, second, Sophos XG, and in third with FortiGate and Watchguard. We chose Sophos XG because it's much cheaper than Check Point.
What other advice do I have?
I think it's very important to choose the right appliance first. Implementing a lot of things like VPN, IPS strong protection and WAF functions will stress more the appliance CPU. It depend also with the number of connections and number of users too.
Sophos XG is a lot of fun because you can change the appliance model without changing the configuration. You can back-up the configuration of the old appliance and import into the new appliance without spending hour for migration. It's powerful, and the new system is quickly operational.
Another key is VPN LAN to LAN in SSL, allowing connections to be set up much faster. Is this the end of the old IPSEC protocol? No, but it is a function which increases the versatility of the Sophos XG firewall.
Last, but not least, the virtual appliance works perfectly, in private or public clouds. Very simple to implement, work perfectly.
On a scale from one to ten, I would give Sophos XG a nine.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company has a business relationship with this vendor other than being a customer. ARENTIA S.A. - Sophos Gold Partner
Av. Francisco Sá Carneiro 380
2415-376 Leiria - Portugal
Buyer's Guide
Download our free Sophos Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2026
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Check Point Quantum Force (NGFW)
Cisco Meraki MX
Azure Firewall
Check Point Cloud Firewall (formerly CloudGuard Network Security)
SonicWall TZ
Fortinet FortiGate-VM
Palo Alto Networks VM-Series
Juniper SRX Series Firewall
KerioControl
Buyer's Guide
Download our free Sophos Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos XG 210 vs Fortigate FG 100E
- What Is The Biggest Difference Between Sophos UTM and Sophos XG?
- What is the biggest difference between Sophos XG and FortiGate?
- Which firewall is better and why: Sophos XG 210 or Fortinet FortiGate 100E?
- Which solution do you prefer: Fortinet FortiGate or Sophos XG?
- What are the main differences in features between Sophos XG and FortiGate 80F?
- Which product do you prefer: Sophos XGS 2100 or Fortinet FortiGate 100F?
- Fortinet FortiGate or Sophos XG?
- How does Meraki MX compare with Sophos XG?
- Which firewall to choose for an SMB to prevent malware damage: Cisco Firepower or Sophos XG?














