Try our new research platform with insights from 80,000+ expert users
General manager at DotCom, Lda.
Real User
It's a complete firewall covering all layers of protection
Pros and Cons
  • "The three most important features for us are web protection, web server protection, and network protection."
  • "Sophos UTM sometimes falls short in high-availability environments. They used to launch firmware that didn't work very well in a high-availability environment."

What is our primary use case?

Sophos UTM is a complete firewall we use to protect from internet threats and check traffic from our network to the internet. It's a firewall covering all layers of protection.

Sophos has some plugins that run on the cloud, but it's transparent to the end-user. For example, there is something to identify threats on an email system called SenseStorm, which is connected to the Sophos Cloud and identifies new threats then spreads the same pattern to all Sophos installations in real-time. I can say that almost 100 percent of our customer companies who have a file solution use Sophos.

What is most valuable?

The three most important features for us are web protection, web server protection, and network protection.

What needs improvement?

Sophos UTM sometimes falls short in high-availability environments. They used to launch firmware that didn't work very well in a high-availability environment. 

For how long have I used the solution?

I've been using Sophos UTM for the last five years, but we started using Astaro Security Gateway, the predecessor to Sophos UTM, in 2002.

Buyer's Guide
Sophos UTM
June 2025
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,632 professionals have used our research since 2012.

What do I think about the stability of the solution?

Sophos UTM is a strong solution. I give it a 10 out of 10 for stability.

What do I think about the scalability of the solution?

Sophos UTM is scalable.

How was the initial setup?

The initial setup is somewhat tricky. You need to understand networking concepts well, and the company must have good policies for internet access. However, it's not that complicated. I would say it's an intermediate difficulty, but I also have a lot of experience with this solution. It might be challenging for a new technician. We do all the deployment in-house, and it takes about three business days. Our team consists of two technicians and me, the manager. 

What's my experience with pricing, setup cost, and licensing?

Sophos UTM isn't cheap. It's in the middle, so not the cheapest, but not the most expensive. It's average. If you buy the full suite, you don't need to pay for add-ons, but if you buy some partial products, you have to pay to deploy more features.

What other advice do I have?

I rate Sophos UTM 10 out of 10. It's the most reliable solution in the firewall market. Considering the price and quality of the product, Sophos UTM is the best solution.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Director with 11-50 employees
Real User
Secure and stable with an easy initial setup
Pros and Cons
  • "With Sophos, we have not had any incidents this year. The security provided has been good. It has proven to be okay for our needs."
  • "The solution needs to do better at covering mobile devices, although they may have an integrated solution for that purpose."

What is most valuable?

During the pandemic, telework grew, however, so did attacks. There was a higher degree of ransomware and so on. With Sophos, we have not had any incidents this year. The security provided has been good. It has proven to be okay for our needs.

The initial setup is very simple.

The solution is stable.

the scalability is good.

What needs improvement?

The solution needs to do better at covering mobile devices, although they may have an integrated solution for that purpose. 

I don't really know how it behaves when it comes to web server protection. We have no web servers of our own. I don't know how it behaves if we open our servers to the outside. My sense is that the degree of protection must be higher.

For how long have I used the solution?

We haven't used the solution for very long. We've been using it for less than a year at this point. 

What do I think about the stability of the solution?

The stability has been good. There are no bugs or glitches. It doesn't crash or freeze. It's reliable. 

What do I think about the scalability of the solution?

The scalability on offer is quite good. If a company needs to expand, it can do so. 

We are not a big company. We have about 70 or so people. 

How are customer service and support?

Technical support is okay. It is provided by a local company, not Sophos directly.

Which solution did I use previously and why did I switch?

Previously we did not have any integrated solutions. We had an antivirus of one kind, and a firewall of another. It was a good step for us to integrate all these features into one solution.

How was the initial setup?

The initial setup was simple and straightforward. The deployment was fast. It only took about a week or so, maybe less. 

What's my experience with pricing, setup cost, and licensing?

The pricing is reasonable. Of course, the customer would always like it to be lower, however, the quality to price ratio is positive.

Which other solutions did I evaluate?

I'm also aware of Fortinet options, however, they are more expensive if you look at Fortinet vs Sophos. 

What other advice do I have?

We are customers and end-users. We came into the pandemic situation needing a VPN and the one offered by the Sophos behaves quite well. From the point of view of our users, it has been a positive experience.

I don't quite know by heart the version of the solution, however, it's quite recent. It's not the newest one. I saw that the brand new one which came out this year and we don't have that.

I'd rate the solution at an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Sophos UTM
June 2025
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,632 professionals have used our research since 2012.
reviewer1292835 - PeerSpot reviewer
IT Manager at a consultancy with 51-200 employees
Reseller
Stable with good documentation and fair pricing
Pros and Cons
  • "The cost of the solution is very reasonable."
  • "The initial setup may be difficult for those not familiar with the product."

What is our primary use case?

We primarily used the solution to replace Cyberoam. For a client recently, we replaced their old SD device with the latest version, XG 210.

What is most valuable?

At the moment we have deployed the web filtering application as they have their own web servers and their email protection. The web filtering is great. At the moment, we haven't heard any negative feedback from the client.

There is plenty of documentation that can help you check scenarios or different situations that might you have.

The stability is great.

The cost of the solution is very reasonable.

What needs improvement?

I can't recall dealing with any missing features.

Lately, I've dealt more with Fortinet, and haven't focused too much on Sophos.

The initial setup may be difficult for those not familiar with the product.

For how long have I used the solution?

If I recall correctly, I've been dealing with the solution for about five or so years. It's been a while at this point. 

What do I think about the stability of the solution?

The solution is very stable. There are no bugs or glitches. It doesn't crash or freeze. It's reliable. 

What do I think about the scalability of the solution?

We are actually in the process of discussing scaling with a client. We're working on the business planning aspect right now. We're looking at opportunities on how to protect their network, besides just the webserver and the email servers.

How are customer service and technical support?

I haven't made any request for technical support previously. That is due to the fact that even the local authorized distributor here in the Philippines is very helpful in deploying and configuring the product. Therefore, we have no need to contact Sophos directly.

There's also lots of documentation to reference. 

Which solution did I use previously and why did I switch?

Recently, I've used a lot of Fortinet products. 

How was the initial setup?

Although I hadn't done a setup in a while, I quickly recalled the steps taken. If you've handled a setup before, you're likely to find the implementation process rather straightforward. I found I was able to adapt quickly and figure out the necessary configurations.

What's my experience with pricing, setup cost, and licensing?

In terms of licensing, here in the Philippines, we just pay on a yearly basis. The renewal is up for this year in Q3. We are talking now with the distributor where we purchased the hardware for a possible renewal with the client.

Overall, they provide very reasonable pricing.

What other advice do I have?

My company is a reseller of Sophos.

I haven't deployed one of their latest solutions yet. We just had a recent project for a basic firewall, and they were actually 210. That's the last project I had with Sophos.

We are in the process of taking up certification exams for Sophos.

I definitely recommend Sophos. It's one of our top products in the company.

I'd rate the solution at a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
System Analyst at Abbey Mortgage Bank
Real User
Good protection, scalable, easy to setup, and it has good local vendor support
Pros and Cons
  • "The most valuable feature is ransomware protection."
  • "I think that additional metrics features are needed to be able to monitor other areas or to monitor as much as you can, at a fine-grain resolution."

What is our primary use case?

I use this solution for my severs.

How has it helped my organization?

At some point in time, it seemed to be ravaging organizations around us and we couldn't definitely outrightly isolate ourselves from it. While we were attacked, I want to believe that it was solely because there was that in addition to the fact that there are triggers. 

We also know very well that Sophos is proactive in monitoring and protecting against malware and brute-force attacks.

It's one of the things that it is quite good for.

What is most valuable?

The most valuable feature is ransomware protection. It is known for ransomware protection.

In terms of additional features, I'm still getting to understand more about how it works.

What needs improvement?

I'm still exploring the features and I haven't used them in totality. 

I think that additional metrics features are needed to be able to monitor other areas or to monitor as much as you can, at a fine-grain resolution. This would be good. Somewhat similar to what Darktrace can do. 

Proactively understand and using AI intelligence to monitor and see activities that are away from the norm and then proactively see how they can either isolate the quarantine system and inject it back into the system upon validation.

They could explore most of the products in Symantec's and Fresh Services and run from the same file to see what additional feature one is offering.

I would also like it if they could work on the price because it is expensive.

For how long have I used the solution?

I have been using Sophos UTM for approximately three years.

What do I think about the stability of the solution?

I understand that it's had a couple of releases too frequently but I want to believe that it's relatively stable. 

I still believe that in terms of stability, Symantec is better, so this can be improved.

What do I think about the scalability of the solution?

Sophos UTM is quite scalable.

How are customer service and technical support?

I haven't had any reason to contact support directly because I have MacBytes, which happens to be a local vendor that we have been using. It's been pretty good. 

They are very good at supporting us technically when the need arises.  

Which solution did I use previously and why did I switch?

I am currently using Symantec for my own workstations and I use Sophos for my server Endpoint protection.

How was the initial setup?

The initial setup is relatively straightforward.

What's my experience with pricing, setup cost, and licensing?

The prices can be better, they could make it a lot cheaper.

What other advice do I have?

You are on the right track with Sophos UTM, but you should keep up with the trends as they become available.

I would rate Sophos UTM a nine out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
IT Manager at Cartlis
Real User
Stable with an easy initial implementation and a very nice user interface
Pros and Cons
  • "The stability, overall, is excellent. I haven't had a problem in the last two years."
  • "It would be nice if it had basic features, such as DLP (Data Loss Prevention)."

What is most valuable?

The solution's user interface is very user-friendly. It's very easy to navigate.

They have an all-in-one product for small businesses. Basically, I do not want to manage the firewall for four products. I'll take it all in one. It makes everything easier to manage. 

It's really good and it's been working really well over the last few years. 

The initial setup has been very simple and straightforward. 

The stability, overall, is excellent. I haven't had a problem in the last two years.

What needs improvement?

It is a fine product, however, I need more endpoint protection.

They should release a license for more than 50 IPs. As of now I have had some discussion about with management, and we need to do some planning and around that to see if we can change things.

The pricing is too high. There are other options that are less expensive, such as Bitdefender. In fact, Bitdefender is very good, aside from lacking a firewall such as this. Beyond that, it's a very good product with central management on-premises. 

It would be nice if it had basic features, such as DLP (Data Loss Prevention).

For how long have I used the solution?

I've only been using the solution for about two years or so at this point.

What do I think about the stability of the solution?

The stability has been excellent. It doesn't crash or freeze. There are no bugs or glitches. It's very good and very reliable. 

What do I think about the scalability of the solution?

This solution is perfect for small businesses. 

How are customer service and technical support?

I don't have too much experience with technical support. I only recall one case where I had to contact them directly. I recall them being very helpful and responsive. I had a good experience and was satisfied with their level of service. 

Which solution did I use previously and why did I switch?

The solution is being discontinued. Hopefully, whatever they replace it with will be very good for small businesses as well. 

How was the initial setup?

The initial setup was not complex. It was very simple and very straightforward. It was not difficult at all. A company shouldn't have any trouble with the process. Specifically, if you have experience in IT, you will find it very easy to deploy these products.

What other advice do I have?

I am a Sophos customer.

I'm using UTM for home use only. It's only four 50 IPS.

I'd rate the solution at a ten out of ten. Overall, it's worked really really well. Everything from the updates to the signatures has been very helpful for our business. 

I would recommend this product to other users and other organizations. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Technical Manager at Digital World
Real User
Easy to install, scalable, and stable
Pros and Cons
  • "It's a stable solution."
  • "We need to speed up the support."

What is our primary use case?

We use this solution as a firewall, for DCP filtering, applications, and training.

What needs improvement?

We need to speed up the support.

For how long have I used the solution?

We have been using this solution for three years.

What do I think about the stability of the solution?

It's a stable solution.

What do I think about the scalability of the solution?

It is a scalable solution but the only disadvantage is that when we use a proxy, we can bypass Sophos.

We have 50 customers. The maximum number of users in one device is approximately 4,000. It's a large network.

How are customer service and technical support?

The support is okay, but it takes time to connect to the support team.

How was the initial setup?

It is easy to install.

We only require one engineer to deploy and maintain this solution.

What's my experience with pricing, setup cost, and licensing?

The appliance should be purchased and there is a fee for the license.

There is an option for a yearly licensing fee or for three years.

What other advice do I have?

We recommend this solution. We complete between 20 and 30 installations per month.

I would rate Sophos UTM a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Dana Bailes - PeerSpot reviewer
Network Administrator at a manufacturing company with 51-200 employees
Real User
Great web and email filtering with reasonable pricing
Pros and Cons
  • "We've found the technical support to be helpful."
  • "The ease of use could be a bit better."

What is our primary use case?

We primarily use the solution for a number of use cases, including the firewall, web filtering, email filtering, and email encryption. UTM does it all. The only thing that we don't use it for is web application and protection. We don't really have any web servers in-house.

What is most valuable?

The web and email filtering are the two biggest and most valuable aspects of the solution for us.  

The solution overall has just been a good, cost-effective solution for us.

The solution offers a lot of functionality.

The solution scales well.

We've found the technical support to be helpful.

The stability and performance are quite good.

What needs improvement?

The ease of use could be a bit better. It's something they could work on.

The ease of configuration could be improved. It's not as simple as it could be just yet. However, it's kind of the nature of it.

They're kind of difficult to get set up sometimes.

Some of the detail in the web filter and the email filtering could be better outlined in the reporting. It is not as good as the two separate standalone solutions we used previously. However, it does also gives us a lot of other stuff that those two solutions didn't. It's a trade-off.

For how long have I used the solution?

I've been using the solution for the last five years at this point.

What do I think about the stability of the solution?

The stability and performance are good. The solution is reliable. There are no bugs or glitches. It doesn't crash or freeze. It's good.

What do I think about the scalability of the solution?

We've been using the same hardware for five years and it's always had a very good performance. I would say it scales pretty well. We have around 80 users on the solution currently. We've had double that. Actually, until COVID hit, we did have double that, as of a year ago.

How are customer service and technical support?

We've been very happy with Sophos, despite the fact that most of their support is based out of Europe. When you get them on the phone, they're actually very good. Their support is very good. We've been happy with them, and have no concerns about renewing the maintenance.

Which solution did I use previously and why did I switch?

We currently use a few Cusco solutions. We had a SurfControl web filter previously - a standalone server for that. We also had an email filtering package, that was on a separate server by itself. We found that the Sophos UTM did both of those things, and it gave us a firewall, and it saved us money. That's largely why we switched. The downside to Sophos is the reporting wasn't as good, however, everything else was better.

There was nothing wrong with the other solutions that we had other than it would cost us twice as much money to get a lot fewer capabilities. We don't really have the manpower to fully utilize those other solutions in great detail, which is why a simple web filter and email filter that was built into the Sophos solution worked for us. Plus, it does a lot more than that. We could run everything through it. We could - and we may do this - move away from using the Cisco solutions altogether, and just use the two Sophos firewalls. Once we get the XG up and running, we can upgrade the UTM to XG also and have the two XG firewalls in our two locations, and use it for the LAN connection between the locations. I don't know that we'll do that, however, it's definitely something that we can do. It's just a lot of additional capability and flexibility. 

How was the initial setup?

While the configuration can sometimes be tricky, it was pretty much straightforward to initially set everything up. It helped that we had paid support through Sophos, so their technicians helped us get it up and running.

The deployment took a couple of weeks in total. It wasn't too big of a deal.

We don't really have any staff dedicated to deployment and maintenance. I tend to handle those aspects myself.

I've watched a few webinars, even on implementation, and it's just that a lot of the stuff is really different. You need to work on it a bit to get the hang of everything.

What about the implementation team?

We had Sophos directly assist us. They were great at helping us implement everything. We physically got it in place, and then got it up and running, and then finished it off with some assistance from Sophos.

What's my experience with pricing, setup cost, and licensing?

We've found the solution to be cost-effective overall.

Normally we do a three-year license with maintenance on a firewall.

Beyond the standard maintenance fee, the solution doesn't require any other licensing costs.

What other advice do I have?

We are a manufacturing company. We're not a technology company. We don't need to have the very latest state-of-the-art technology, however, we want to try to be close to it. For us, Sophos is perfect.

We also plan to use Sophos XG, however, we haven't implemented it yet. We're hoping it might be easier to configure and set up than UTM.

Our antivirus, actually, was the antivirus that was managed by the UTM. Now they've since retired that capability, and they've gone to endpoint security software being managed in the cloud. Sophos Central can manage all of the Sophos security products, including all the firewalls, the endpoint security. Basically, you end up with one web interface for all of your security stuff. That's actually going to be a big feature, especially moving forward with XG, due to the fact that, if XG detects anything fishy going on, you can shut down individual client networks, and not allow any traffic to go through.

 Our Exchange ActiveSync is actually behind a Cisco firewall. We have a Cisco ASA also.

We use the latest version of the solution.

I'd rate the solution at an eight out of ten. We've largely been satisfied with the product.

As a company, you're looking to get the best solution out there. Once you have something in place, and it's worked well for you, and it hasn't cost you any excess money, you don't need to have too much contact with anyone. I rarely contact Sophos. That's a good indication of how good the product is working for us. If I was looking for something new, or if when maintenance comes up, and we've had hardware that's been in operation for a while, maybe we just need something new. Then you look and see if there's something out there that works better for you. That's basically it. We're not looking for anything new. We've actually been very happy with Sophos. I liked the way that there's a lot of good stuff there.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Senior Network Engineer at a computer software company with 11-50 employees
Real User
Simple to set up, comprehensive, free for home users, and there is lots of support available online
Pros and Cons
  • "Sophos UTM is the simplest of these products to setup."
  • "The logs are not clear, which means that you need an additional piece of software in order to read them clearly."

What is our primary use case?

We are a solution provider and I am the architect of solutions that employ Sophos UTM.

How has it helped my organization?

Sophos was one of the first firewall products that were free, so you can install it at home and test it. Then when you have the experience, you can recommend it to customers.

What is most valuable?

Sophos UTM is the simplest of these products to setup. If you follow the instructions using the wizard, which is just a few steps, then you will have a firewall to protect you and your customer.

What needs improvement?

Sophos UTM is sensitive when it comes to setting up the SSL VPN, with the certificate.

The bandwidth speeds are limited, although this could be because they're doing web filtering. They need to have the time to filter all of the traffic.

The logs are not clear, which means that you need an additional piece of software in order to read them clearly. This is the main issue with Sophos UTM. Essentially, you need to spend time looking through the logs and if you want quicker access then you need to have third-party software.

For how long have I used the solution?

I have been working with Sophos UTM for eight years.

What do I think about the stability of the solution?

This is a stable product. In my experience, I have only seen one case where, after four years, a customer's UTM was completely dead. The motherboard just died.

This customer had a license, so they contacted Sophos and within one week, they had a replacement.

What do I think about the scalability of the solution?

It is easy to scale. You can set up a failover with a second Sophos device, where the second one is available as a backup. You have the option to set up Sophos Lite, which is a small device from Sophos that can link with your main unit.

For example, if you have remote offices, you can have the main Sophos device in your main office, and then all the branch offices connected using the lite model. All of the traffic goes to your main site, and it will provide all the web filtering.

How are customer service and technical support?

The quality of technical support depends on who answers the call. When you reach the proper support person, they are really good and know what they're doing.

There is a lot of information available online, partly because Sophos is the old Cyberoam. Most of the time, I try to solve problems by myself. However, if I can't, I contact Sophos.

How was the initial setup?

I am a certified Sophos architect, so I help to create the solution.

I have never had any trouble setting it up. There are some things that you have to do from the command line, but that's how Sophos and other products work. It is the same with Meraki and FortiGate. 

For the most part, it's straightforward and you just follow the wizard. The questions regard your internet connection, what service you expect Sophos to provide, and of course, the main one is the license because, for home users, it is free.

What's my experience with pricing, setup cost, and licensing?

This product is free for home users. There is a limitation to the number of devices that can be connected, but nobody expects at home that there will be more than 50 devices connected to the firewall.

For business users, if you have the proper license, it will provide full protection not only as a firewall, but will protect your web server, Exchange Server, network, and provider web filtering capabilities. These days, that is really important. You don't want somebody to get in, or when a user clicks a link, they could lose some information.

The more expensive products have better performance. If you have fast broadband then you will need a bigger device, otherwise, it will slightly reduce the speed of your throughput. For example, if you have a gigabit connection with the cheapest model, perhaps a UTM 320, then it will cut the speed by approximately 50% to 500 megabits.

Which other solutions did I evaluate?

We sell the Meraki MX solution to protect some of our customers, and we are resellers of FortiGate as well.

Sophos is easier to set up than Meraki.

When it comes to reading the logs of other devices, it is much easier with Meraki, FortiGate, or even the Sophos XG firewall.

At the moment, all of the firewalls on the market are doing the same thing. Once you buy the license, it will cover everything.

What other advice do I have?

Sophos UTM is a comprehensive product that does the job that it should. They have another product now, called the XG firewall, that covers everything that UTM does not. The best part about this is that you can run the XG firewall on the same hardware where UTM is installed. This means that if you're thinking that Sophos UTM is not good for you, you can always migrate to the XG firewall. That said, I have never had a problem setting up UTM and can't think of a problem that I couldn't solve with it.

Overall, UTM is good, but if you want something better that can handle more complex rules then you can use the XG firewall. My only complaint is that they limit the bandwidth, depending on the model.

The suitability of this product depends on the customer's needs. If they don't need really complicated firewall rules, yet want to protect the network and want really good web filtering, then I recommend using Meraki. If on the other hand, they have a really complicated setup and want better filtering, then Sophos is the better option.

Also, if you have your own web server or mail server on-site, then I recommend Sophos. If instead, you have a normal office network with mail stored in the cloud, then I recommend Meraki.

I would rate this solution a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros sharing their opinions.