Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Senior IT Consultant at a tech services company with 51-200 employees
Consultant
Great security and logging.

What is most valuable?

Great security and logging. Easy GUI.

What needs improvement?

It really needs to update IPSec to enable IKEv2.

For how long have I used the solution?

Two years.

What was my experience with deployment of the solution?

No.

Buyer's Guide
Sophos UTM
June 2025
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,632 professionals have used our research since 2012.

What do I think about the stability of the solution?

No.

What do I think about the scalability of the solution?

No.

How are customer service and support?

Customer Service:

Customer service is great and responds really fast.

Technical Support:

Technical support might be a bit better and there are not enough easily accessible guides.

Which solution did I use previously and why did I switch?

Previously used the OpenSource pfSense which works great, but Sophos adds the little extra that is needed in security.

How was the initial setup?

Straightforward.

What about the implementation team?

In-house.

Which other solutions did I evaluate?

I evaluated pfSense, and still go with pfSense where IPSec to AzurePack services are needed because Sophos does not support IKEv2.

What other advice do I have?

At first I did not like Sophos UTM but after second setup and config I liked it a lot and now recommend it to all my customers. It has great security features, and together with Sophos Endpoint Protection it works perfectly.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
IT and Data Security Manager at a tech services company
Consultant
An Excellent Product, easy to understand for an experienced engineer

The Sophos UTM products helped us manage and a global network of more than 20 sites. 

Their ability to firewall, filter and monitor network traffic and provide VPN connectivity really helped us day to day with such a complex network.

We chose the product initially because the user interface was simple to understand and made sense without requiring a long training course for an experienced network engineer to utilise. 

Central Management is made easy with the Sophos UTM Manager which allows you to set configurations, see patch status and pull reports from all your estate.

While the product was originally with Astaro the low end (1xx) units had serious reliability issues and support was extremely challenging to engage with. However, once Sophos took over their world class technical support teams soon brought responsiveness up to the level I would expect from a premium product. And the newer hardware is much better quality.

The ability to have either software, hardware or virtual appliances allows excellent freedom of choice.

High Availability is easy to configure and works really well, with options to have either active \ active or active \ passive depending on your needs and budget.

The fact you can use the full product for Free at home is a wonderful idea for engineers to become more familiar with the product and keep their skills up to date.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Sophos UTM
June 2025
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,632 professionals have used our research since 2012.
PeerSpot user
Senior Technical Consultant with 51-200 employees
MSP
Sophos UTM vs. Fortinet FortiGate

I have used both Sophos and Fortinet products in production and I have found the Sophos UTM appliances (hardware and virtual) to be a better fit most of the time -- with a few caveats which I will touch on below. In both instances, the transition from TMG will be mostly straightforward. The main hang-ups will be with the VIP/load balancing and SSL. For some reason that completely escapes me, both of these vendors make getting valid certificates onto their boxes unnecessarily difficult -- the Fortinet appliances more so than the Sophos UTM appliances. At one point a Fortinet engineer had to write an entire manual on how to get an SSL certificate uploaded successfully on the 4.x firmware.

Sophos: The one feature that is missing (and this makes some amount of sense) from the Sophos appliance is BITS caching for updates. Other than that, Sophos offers a full replacement for TMG on UTM9. The XG platform also offers a replacement for the TMG; however, some of the rumblings about upcoming releases suggests that Sophos is going to give XG the Apple iOS treatment and "streamline" the interface...potentially cutting out/hiding some functionality. On the effectiveness of the NGFW, Sophos is mostly good but has a few issues blocking all pieces of an application. For instance, we had to build custom blocking rules for OpenVPN (the vpn was being used to bypass the content filter) because the default Application Control wasn't effectively blocking the application.

Fortinet: If it wasn't for Fortinet's terrible tech support we would still be deploying Fortigates exclusively. So perhaps that answers your last question right upfront. FortiWeb is not absolutely required for what you are proposing; however, the FortiWeb does make the transition from TMG much easier as the FortiWeb is purpose-built to do what you are requiring. Related, the AD-integration used with Fortinet is one of the strongest implementations we have used: The SSO agents ability to poll data from the DCs without an agent allows the use of SSO with non-Windows machines that are bound to AD, which we have used extensively at both educational institutions and shops running CentOS. Transitioning to Fortinet is relatively simple: The UI makes a lot more sense than it did in the old 4.x releases, the firewall rules are straight-forward, and the reverse proxy settings are well-documented.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user326337 - PeerSpot reviewer
it_user326337Customer Success Manager at PeerSpot
Real User

Mark, how has your experience with Firewall security been since this past January?

See all 5 comments
PeerSpot user
Technical Consultant at a tech services company
Consultant
It's provided us with unified threat management as well as comprehensive lists of reports, although we can't currently run 2.4 Ghz and 5 Ghz bands simultaneously.

What is most valuable?

  • Firewall
  • Intrusion Prevention
  • Web Filtering
  • SMTP Proxy
  • Red (VPN Appliance Box for remote sites)

How has it helped my organization?

The product has provided us with unified threat management as well as comprehensive list of reports.

What needs improvement?

Their new product range which is the new SG Series UTMs, especially the wireless versions, should at least include two radios for 2.4 Ghz and 5 Ghz bands. Currently we can only run one or the other, but not both.

For how long have I used the solution?

I've used it for around 18 months.

What was my experience with deployment of the solution?

No at this stage.

What do I think about the stability of the solution?

Only thing we have noticed as of late was that their firmware updates break something else that was working in a previous version. Only noticing this on some customers though not all customers.

How are customer service and technical support?

They're great.

Which solution did I use previously and why did I switch?

I’ve used other products like NetboxBlue, SonicWALL in my previous roles. We chose the Sophos UTM because of pricing, rich feature set and the fact that it can be either a Virtual App or Hardware Appliance.

How was the initial setup?

The initial setup was very straightforward. It was done through a wizard and there not much needed doing while setting up the UTM.

What about the implementation team?

We are a reseller so we use the same product that we sell to our customers. That’s how much we love the product.

Disclosure: My company has a business relationship with this vendor other than being a customer. We're a Sophos Gold Partner.
PeerSpot user
PeerSpot user
Senior Expert for Microsoft infrastructure at a computer software company with 51-200 employees
Vendor
It provides firewall, proxy, and VPN in one solution, but be prepared to follow the Zeroeth Rule during implementation.

What is most valuable?

  • SSL VPN
  • HTML5 VPN portal
  • Application control
  • Reverse proxy
  • Web filtering

How has it helped my organization?

We used several vendor products before UTM, and now it is all in one box - firewall, proxy, and VPN. Sophos is much easier to manage and configure.

What needs improvement?

Every product has room for improvement.

For how long have I used the solution?

I have used it for three years actively with several projects utilizing UTM.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

We don't have direct contact with Sophos support so I can’t rate the level of customer service and technical support properly.

Which solution did I use previously and why did I switch?

I did. Sophos UTM is far more easier to configure and it is very intuitive with configuration.

How was the initial setup?

Setup is easy and straightforward. It is a browser based tool, so you can access it from every location, and with different operating systems.

What about the implementation team?

We did it in-house.

What other advice do I have?

I have some technical advice, but generally, always prepare steps to implement Sophos UTM and test your implementation before using it in production environment.

The Zeroeth Rule:

Start with a hostname that is an FQDN resolvable in public DNS to your public IP. If you didn't do that, start over with a factory reset; it will save you hours of frustration.

  1. Whenever something seems strange, always check the Intrusion Prevention, Application Control and Firewall logs
  2. In general, a packet arriving at an interface is handled only by one of the following, in order, DNATs first, then VPNs and proxies and, finally, manual routes and manual Firewall rules, which are considered only if the automatic Routes and rules coming before hadn't already handled the traffic
  3. Never create a Host/Network definition bound to a specific interface. Always leave all definitions with 'Interface
  4. When creating DNATs for traffic arriving from the internet, in "Going to:" always use the "(Address)" object created by WebAdmin when the interface or the Additional Address was defined. Using a regular Host object will cause the DNAT to fail as the packets won't qualify for the traffic selector.
  5. In NAT rules, it is a good habit to leave a field blank when not making a change. In the case of a service with a single destination port, this makes no difference. In the case of a service with multiple ports, or a Group, repeating the service makes the NAT rule ineffective.
  6. There are only four reasons to sync users from AD to the ASG/UTM:
    • The user should be able to log on to a Remote Access VPN that uses certificates to authenticate the user
    • Email Protection is enabled and the user should receive Quarantine Reports and be able to manage personal black/whitelists and/or use Email Encryption/Signing
    • You want to do Reporting by Department for Web Protection (and I consider it a bug to require this when doing AD-SSO)
    • You want to use the Authentication Agent to populate "username (User Network)" objects
    • There's no other reason to sync users to WebAdmin - certainly not with AD-SSO
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user243894 - PeerSpot reviewer
Systems Engineer at Base-2 ICT Services Ltd
Consultant
The reliability of the equipment makes it possible to provide stable connections but IPSEC site-to-site VPN connectivity needs to be improved.

What is most valuable?

  • Reliability
  • Usability
  • Number of features that fully cover goals
  • Perfect support
  • Possibility to get “under the hood”

How has it helped my organization?

The Sophos solution provides a branch to head office distributed network for a construction company across New Zealand, and the reliability of the equipment makes it possible to provide stable connections and is easy to implement and support.

What needs improvement?

Would be great if it would be possible to improve IPSEC site-to-site VPN connectivity over slow/unstable internet connections.

For how long have I used the solution?

This particular configuration has been in use for about two and a half years.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

Very rare cases of appliance lost admin password or web-service hangs.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

Since I’m an engineer, I probably cannot evaluate this aspect, however as far as I know equipment order and upgrade was always fine

Technical Support:

4.99 out of 5 – support is very helpful, only once there were misunderstanding about licensing and number of supported Sophos WAPs and that was resolved promptly and fully.

Which solution did I use previously and why did I switch?

For this project, the Sophos infrastructure has been planned and deployed from the start and there has been no need to change it

How was the initial setup?

It's logically straightforward and the transparent interface made possible a quick deployment. However, a little time was needed to get familiarized with the interface.

What about the implementation team?

It was implemented in house.

What other advice do I have?

Nothing is perfect, but with Sophos those are really small – sometimes it is incorrect firmware upgrade paths, or rare log in problems (device forgetting admin password). All those though can be fixed, there is plenty information in the Internet and support is usually awesome. Also, you need to plan the solution and costs involved, while having in mind potential growth of users/connections; e.g. creating virtual appliances and allocating resources (RAM, CPU, NICs) minding potential workload.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user243894 - PeerSpot reviewer
it_user243894Systems Engineer at Base-2 ICT Services Ltd
Consultant

Hi PatrikS, it was ASG120, had to reset it connecting via com port and using monitor connected to the unit.

See all 3 comments
it_user241089 - PeerSpot reviewer
IT Security & Audit Manager at a tech services company with 51-200 employees
Consultant
It is full of options, but the web filtering engine needs to be improved.

What is most valuable?

They are all valuable, but the most valuable is the uplink balancing. This is very useful when dealing with more than one ISP, and the wireless capability for our guests.

How has it helped my organization?

It's scalable and easy to manage.

What needs improvement?

The web filtering engine needs to be improved as, sometimes, the service hangs for a while and restarts randomly. Alas, there was an issue with authorizing Lync traffic but it's all good now.

For how long have I used the solution?

I've used it for eight years.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

Rarely.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

It's good.

Technical Support:

It's acceptable because sometimes there are delays with answering our requests. We are using the regular support, so we don't have the ability to contact Sophos directly.

Which solution did I use previously and why did I switch?

We did, and we switched due to the costs and the functionalities.

How was the initial setup?

It was very easy.

What about the implementation team?

We used a vendor team to implement it.

What other advice do I have?

It's a nice product that is full of interesting options.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Niraj Kumar Sinha - PeerSpot reviewer
Niraj Kumar SinhaLead Network and Security Management at a logistics company
Real User

Had done POC for 2 months but can't able to justify as per our prospect.

it_user230352 - PeerSpot reviewer
Support Engineer at a tech services company with 51-200 employees
Consultant
RED appliances and APs make a difference, however, performance is suffering under high traffic usage.

Valuable Features

I think the RED appliances and APs make a difference, and add value to Sophos. Also, it is easy to configure, robust and is a stable appliance. The licensing is great, because you don't have to pay the same license fee for a standby appliance.

Improvements to My Organization

Actually, we were not used to firewalls in our organization, but I was working at a distributor previously so I had a chance to do many demos. The customers like its GUI because it's easy to manage and RED takes attention of the customer which has distributed locations like shops, cafes, fast food stores etc.

Room for Improvement

They should have more powerful appliances. The appliances throughput and performance is suffering under high traffic usage. Also, I think they need better appliances for enterprise and high end customers.

Use of Solution

I've used it for one year.

Deployment Issues

Because we have local laws about logging, we had to get permission to develop a logging mechanism. Also, we had lots of requests to improve URL filtering categories.

Stability Issues

I had an issue with transparent mode in a demo, but mostly it is a very stable appliance and software.

Scalability Issues

Sophos has a sizing guide which is a great during the planning phase in ensuring you are getting the sizing right. I have used it many times when I preparing customer demands. I haven't had any problems yet.

Customer Service and Technical Support

Customer Service:

I was working with Sophos' Germany office, and they always supported me. It was really great working with them.

Technical Support:

They're 6/10. I had many cases, but they don't like to do a remote session immediately. To be honest, I have worked with better support teams from other vendors,.

Initial Setup

It is very easy.

Implementation Team

I implemented it but got help from the vendor when I got stuck wit something. They are great.

Other Advice

It is great solution for customers who have small, branch offices. I would advise you get Sophos for distributed locations (with RED and APs).

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user197961 - PeerSpot reviewer
it_user197961Network Solutions Engineer at a tech services company
Consultant

I agree with Patrik. Specially SG series devices running on Sophos UTM 9.3 are amazingly performing devices. If they are correctly sized and scoped, I gurantee they match even out perform many of their competition. They offer 360 degree Security peace of mind. Still though, my favaroutes are WatchGuard M series UTMs for SMBs.
Regards,
Serhat

See all 2 comments
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros sharing their opinions.