We use this solution ourselves and we also deploy to our clients. It is a capable, general-purpose firewall with VPN tunneling built in, and a lot of web features if you're hosting a website. We are resellers of Sophos and I'm a partner in our company.
President at a tech vendor with 1-10 employees
Very good basic firewall functions with advanced firewall scanning
Pros and Cons
- "Good basic firewall functions with advanced firewall scanning."
- "The solution has email firewall built in with all sorts of functionality, it is an absolutely excellent firewall, the logging is really good, you get great information about what's going on."
- "Updates come out agonizingly slowly, a trickle."
- "The updates come out agonizingly slowly. They just trickle out and when there's a problem with an update it takes a while to sort out."
What is our primary use case?
How has it helped my organization?
We haven't changed our procedures as a result of using this product but maybe the flip side is the case. We haven't had to change our procedure because we have this great tool that keeps the bad guys away.
What is most valuable?
I would say the email for sure and the basic firewall functions are great features. It also has advanced firewall scanning. If you receive a file, you can have it scanned through Sophos. It's a really complete product.
What needs improvement?
Sophos has a very small crew of people who continue to work on enhancing the UTM. At some point, they had actually stopped enhancing it and the word on the street was that they weren't going to enhance it any more because everybody was going to go over to XG, but they found that 50% of their users were still on the UTM and that was five years after they'd come out with the XG line. They decided they were going to rebuild some core parts of XG, and that would take a while. It's been six years and they're still not there. The updates come out agonizingly slowly. They just trickle out and when there's a problem with an update it takes a while to sort out. It's still a viable product but the more they improve XG, the less you have a need to stick with SG.
Buyer's Guide
Sophos UTM
May 2026
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,838 professionals have used our research since 2012.
For how long have I used the solution?
I've been using this solution for 15 years.
What do I think about the stability of the solution?
There are some legacy things that were probably fine back in the day when it was invented in Germany, things like the IPS, the Intrusion Protection engine. It's terrific and it works really well, but it can be a little bit slow. Because of the way that some pieces are built, for example the core for the IPS runs on only core, even if you have a multi-core CPU. 15 years ago that wasn't a big deal because your weak link was going to be your computer. But nowadays, you could have a fast enough computer if they could just let it work with multi-cores. They clearly aren't interested in rewriting large portions of the code because they're going to the XG so all they do is fix it or maybe add a feature that's in the marketplace. Over time, they've been adding more ways to do a VPN tunnel but some things they need haven't been added because it would require a big rewrite and they don't want to go there.
What do I think about the scalability of the solution?
The scalability has worked great for us. Everyone in our company uses it even though some may not know that they're using it. One of our larger clients, with a super computing center and some of the fastest computers in the world, use Sophos, so I would say that it does the job.
How are customer service and support?
Technical support have been very good. They are very knowledgeable but it can take too long to make contact. They're great once you do get hold of them. They've solved every problem we've had.
Which solution did I use previously and why did I switch?
We've tried numerous other solutions. Cisco, and some of the other major ones that were out there, but once we started using this, it was so much better in so many ways, we just dumped all the others.
How was the initial setup?
The initial setup is pretty straightforward. They have a template which takes you through and asks what you want protected. There's still a lot to do after that because there are variations which require more work. For example, if I have clients who need to block certain email addresses, I have to go through and set those up. If I need to allow conversations which require specific ports open in order to get to a particular business or credit card processing, that has to be set up. There is a lot of HIPAA detail in it and it also has credit card compliance things which require a manual set up. The setup requires a knowledge base.
What's my experience with pricing, setup cost, and licensing?
The solution is 100% free. You can just download the software for up to 50 IP addresses. It is a hundred percent free. Throw it on your own machine. Right, it's a native Linux product, a hardened Linux product and it's free for that sort of user.
What other advice do I have?
The solution has email firewall built in with all sorts of functionality, it is an absolutely excellent firewall, the logging is really good, you get great information about what's going on. It does things like GeoIP tracking and you can make decisions based on where people are coming from. It's just really a complete firewall. I would say if you're just starting right now, get the XG. Not that the UPM isn't outstanding, but it's disappearing. You might as well learn the XG. The product still works really well, although it's getting a bit long in the tooth. The sooner that they come out with the XG that can do everything that the UTM does, the faster the rest of the world will make the jump.
I would rate this solution an eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Digital Transformation and Technological Innovation Manager at a educational organization with 501-1,000 employees
Easy to manage with good content filtering and an easy initial setup
Pros and Cons
- "The initial setup is pretty easy."
- "The stability of the product is quite good; we haven't had any issues with bugs or glitches, it doesn't crash or freeze on us, and we trust its reliability."
- "There needs to be some improvement in the IPsec VPN. There is implementation only support. I have version one. I'd be most interested in having IP version two from the protocol."
What is our primary use case?
We primarily use the solution for perimeter security in order to protect content. We also use it for the XG firewall.
What is most valuable?
The content filtering is the solution's most valuable aspect.
The initial setup is pretty easy.
The solution is pretty easy to manage.
What needs improvement?
There needs to be some improvement in the IPsec VPN. There is implementation only support. I have version one. I'd be most interested in having IP version two from the protocol.
For how long have I used the solution?
I've been using the solution for about five years or so at this point.
What do I think about the stability of the solution?
The stability of the product is quite good. We haven't had any issues with bugs or glitches. It doesn't crash or freeze on us. We trust its reliability.
What do I think about the scalability of the solution?
We don't really have scalability in mind right now. I need proof of all that. It's a single device that we have.
We don't plan on increasing usage with this device. In fact, we're considering a switch to Sophos XG.
How are customer service and technical support?
We've never directly worked with Sophos' technical support. We've always dealt with the Sophos partners.
We also don't really have any experience with online community support or documentation.
Which solution did I use previously and why did I switch?
I previously worked with Microsoft BMG. At the time we switched, Sophos was the better option. We needed a solution that was easy to manage and Sophos fit the bill in that sense. Microsoft didn't really offer any support. Sophos also was integrated with a directory and a single sign-on.
We're actually looking at switching to Sophos XG in the near future. The main difference between the two lines of Sophos products is the level of support provided. XG offers more of what we need. We may also eventually move to a Huawei firewall.
How was the initial setup?
The initial implementation is not complex. We found it to be very straightforward. It was easy.
The deployment took approximately one week. It didn't take too long.
We had two people on staff that handle deployment and maintenance.
What about the implementation team?
We had a consultant help us manage the implementation. hey were very good and quite knowledgable. We were satisfied with the assistance they provided to our team.
What's my experience with pricing, setup cost, and licensing?
We pay for the service on a yearly basis. The last time we paid was in June, for a year. At the time, it was about $20,000.
There are no costs above a standard licensing fee.
What other advice do I have?
We're just customers. We don't have a business relationship with Sophos.
I can't remember the exact version of the solution I am currently using, however, I believe it to be around version 9.
It's a good product, and I would recommend it, however, I would advise other potential users to instead maybe consider Sophos XG.
Overall, I would rate the solution at an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Sophos UTM
May 2026
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,838 professionals have used our research since 2012.
Cyber Security Officer at Grupo Vision
Has good quality and functionality
Pros and Cons
- "The most valuable feature is the price. I've been requesting prices all over these years between different solutions like Fortinet, Palo Alto, and Check Point and Sophos has been the cheapest and the best of all of them that I have tried. I have been working with Fortinet, it's a fact that the price is surprisingly better."
- "In terms of quality and functionality, Sophos is very useful and better than the competition."
- "Sophos should improve its ability to check something like bandwidth consumption for users or something more real-time."
What is our primary use case?
Our primary use cases include:
- Remote SSL connection
- Web-filtering
- Web server protection
- WAF application.
- Firewall rules
How has it helped my organization?
We have securely deploy systems accesible only behind encrypted ssl vpn and all user can access without the risk of data exposure.
What is most valuable?
The most valuable feature is the price. I've been requesting prices all over these years between different solutions like Fortinet, Palo Alto, and Check Point and Sophos has been the cheapest and the best of all of them that I have tried. I have been working with Fortinet, it's a fact that the sophos price is surprisingly better.
I have also worked with Check Point and it's not far enough from what Sophos can do. In terms of quality and functionality, Sophos is very useful and better than the competition.
What needs improvement?
Sophos should improve its ability to check something like bandwidth consumption for users or something more real-time.
real time trafic graph most show specific info from user, ip and bandwith, in my personal opinion i have seen better traffic graphs in open source firewalls.
For how long have I used the solution?
I have been using Sophos UTM for six years.
What do I think about the stability of the solution?
It's very stable. In all the time I have been using it, I haven't seen it fail or gets stuck.
What do I think about the scalability of the solution?
Scalability is not a complex issue and is something you can do within 20 minutes. I've been managing three UTMs, one with 50 users, another one with around 150, and the biggest one has 3,000 users.
Which solution did I use previously and why did I switch?
i used PFSense, the capabilities of UTM sophos y very much higher and powerfull.
How was the initial setup?
The initial setup was straightforward. It depends on the rules, but a basic setup can take up to seven to 15 minutes max.
What about the implementation team?
What was our ROI?
Based on cost compare with other vendor who bill per license and OTP users, the ROI have been set as far as 6 moths.
What's my experience with pricing, setup cost, and licensing?
SOphos is the best alternative in features, specifications and lower price.
Which other solutions did I evaluate?
yes i did, Fortinet, Checkpoint, Palo Alto, Meraki.
What other advice do I have?
It's a good solution, I would say to go for it.
I would rate Sophos UTM a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Presales & Implementation Engineer at a tech services company with 11-50 employees
Offers good threat monitoring features
Pros and Cons
- "It is a very good product, and the threat monitoring process is the most valuable feature."
- "Sophos should be more user-friendly, have more dashboards, and an easier implementation."
What is most valuable?
It is a very good product. The threat monitoring process is the most valuable feature.
What needs improvement?
Sophos is good for endpoint security but Trend Micro is better than Sophos. APEX is better than Sophos because it has a friendly, usable dashboard, and the implementation is very easy.
Sophos should be more user-friendly, have more dashboards, and an easier implementation.
What's my experience with pricing, setup cost, and licensing?
It is the cheapest product available. It's good if you have a low budget.
What other advice do I have?
I would rate Sophos UTM a ten out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior System Engineer at a real estate/law firm with 51-200 employees
Easy to manage but five-factor authentication needs improvement
Pros and Cons
- "It is easy to manage."
- "I would recommend Sophos, it is easy besides for the five-factor authentication."
- "The five-factor authentication needs improvement. It needs central management."
What is our primary use case?
We use it for email security, malware protection, IPS, and filtering.
What is most valuable?
It is easy to manage.
What needs improvement?
The five-factor authentication needs improvement.
It needs central management.
For how long have I used the solution?
I have been using Sophos UTM for a few years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
We have around 400 users.
How are customer service and technical support?
We offer certified support.
How was the initial setup?
The initial setup was straightforward. We had a problem with the multi-factor authentication.
What other advice do I have?
I would recommend Sophos, it is easy besides for the five-factor authentication. It is good for my needs.
I would rate it a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
System Administrator Server and Networks at a manufacturing company with 201-500 employees
Provides all of the network security you need in a single modular appliance
Pros and Cons
- "I would recommend UTM over XG because it's easier to manage."
- "It's stable, but the reaction time of the GUI is terrible; however, in my opinion, UTM is more stable than XG."
What is our primary use case?
We mainly use it for web filtration — we have a number of small websites. It's also a VPN — that's filtering, firewalling, and IPS.
Within our organization, there are roughly 250 people using Sophos UTM. Also, we have around 15 XG users.
We plan on using XG for the next few years, but we are going to stop using UTM on our main site.
What needs improvement?
I think the behavior with the zones was a little bit tricky to understand at the beginning of this project. It can be hard to manage at first, but overall, we don't have many problems with this solution.
For how long have I used the solution?
I have been using this solution for one and a half years.
What do I think about the stability of the solution?
It's stable, but the reaction time of the GUI is terrible; however, in my opinion, UTM is more stable than XG.
How are customer service and technical support?
Sometimes, It can be quite a time-consuming process to book a session with Sophos' support.
How was the initial setup?
The initial setup was not straightforward because we had experience with UTM, but not with XG. It's a completely different system.
We had it up and running within one week.
What about the implementation team?
We installed it on our own.
What other advice do I have?
I would recommend UTM over XG because it's easier to manage.
On a scale from one to ten, I would give XG a rating of 6. Conversely, I would give UTM a rating of nine.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Architect at a consultancy with 11-50 employees
Feature rich and provides good security for SMB
Pros and Cons
- "We find all of the features valuable because together they fit the needs of our customers."
- "This is a very good security solution for SMB, so this solution is a good fit for many of our customers."
- "We would like to have unique viewable IDs for rules and in the packet filter logfile, for easier debugging of old log files."
- "We would be happy with fewer new features over the same time, but with more stable updates!"
What is our primary use case?
We primarily use this solution for:
- VLAN separated network
- Proxy / SSL-Interception
- VPN (IPsec and SSL)
- Reverse Proxy / Webserver Security
- Email Security / Mail gateway
- HA (Hot-Standby)
- IPS / ATP
How has it helped my organization?
This is a very good security solution for SMB, so this solution is a good fit for many of our customers.
What is most valuable?
We find all of the features valuable because together they fit the needs of our customers.
What needs improvement?
We would be happy with fewer new features over the same time, but with more stable updates!
We would like to have unique viewable IDs for rules and in the packet filter logfile, for easier debugging of old log files.
Sophos UTM shouldn't die.
For how long have I used the solution?
I have been using this solution for fifteen years.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Network & Hardware Administrator at Nile Projects & Trading Co.
Creates secure IPsec and SSL VPN high availability connections between head office and branches
Pros and Cons
- "It allows me to easily connect with more than forty-five remote sites and more than fifty remote users between IPsec and SSL VPN, applying the web filter and application filter to ensure a secure connection."
- "I would like to see the SD-WAN feature improved."
What is our primary use case?
We use this solution for IPsec & site-to-site SSL VPN.
My environment involves connecting all of our branches with the head office through one Sophos XG 210 device. This is done using IPsec and SSL VPN, after which we apply a web filter, as well as an application filter to ensure that we are getting a secure connection.
How has it helped my organization?
It allows me to easily connect with more than forty-five remote sites and more than fifty remote users between IPsec and SSL VPN, applying the web filter and application filter to ensure a secure connection.
This solution also gives me varieties of VPN policies for good data encryption.
What is most valuable?
The most valuable features of this solution are:
- High Availability between IPsec site tunnels provides a valid continuous connection and ensures we have no downtime affecting our business.
- Log Viewer allows me to monitor all incoming and outgoing traffic, as well as view and block vulnerabilities.
What needs improvement?
I would like to see the SD-WAN feature improved. I want to manage many lines and load-balance them, getting high availability by making SLA tests according to:
- Check interval.
- Failures before inactive.
- Restore link after.
- SD-WAN Rules to control bandwidth, download and upload stream.
For how long have I used the solution?
We have been using this solution for more than four years.
Which solution did I use previously and why did I switch?
I switched to Sophos as it is more reliable.
What's my experience with pricing, setup cost, and licensing?
This solution is less expensive than FortiGate.
Which other solutions did I evaluate?
We did not evaluate other solutions prior to choosing this one.
Disclosure: My company has a business relationship with this vendor other than being a customer. Sophos XG
Owner at Robert Obrinsky Industries, LLC
A powerful and flexible user interface makes remote client support easy
Pros and Cons
- "Configuration troubleshooting is eased by the use of the color-coded, live firewall log."
- "The most valuable feature is the user interface, which is flexible, powerful, and easy to understand."
- "Support for IKEv2 is needed in this solution."
What is our primary use case?
I use this solution in both the home and office, and I am also a reseller of the product. It is used for Unified Threat Management for SMB to Mid-Size companies. It provides VPN solutions for our clients, and it has the absolute best UI in the industry.
How has it helped my organization?
This solution makes remote support of clients extremely easy and flexible. Modifications can be made in minutes. New definitions of network objects, users, groups, etc. can be made from anywhere in the UI.
What is most valuable?
The most valuable feature is the user interface, which is flexible, powerful, and easy to understand. Configuration troubleshooting is eased by the use of the color-coded, live firewall log. Live logs for most features are also available.
What needs improvement?
Support for IKEv2 is needed in this solution. But, the handwriting is on the wall that Sophos will probably stop development in favor of their XG Firewall. No timeframe on that yet though.
Which solution did I use previously and why did I switch?
We have been using this solution since it was the Astaro Security Gateway (/products/sophos-utm-reviews ).
Disclosure: My company has a business relationship with this vendor other than being a customer. I am a reseller of this product, and I also use it in my home and office. It is by far the best firewall/UTM solution I have tested or worked with in my career.
CEO at NG
Offers secure and Scalable Firewall Security
Pros and Cons
- "The features that I've known to be most valuable are both the web security features as well as the web firewall capabilities. As a partner of Sophos firewall, we have some clients and they are using Sophos firewall UTM and we are using it as well."
- "Sophos UTM is a good product for security purposes and maybe if Sophos provided another company option to implement their products then I would say that Sophos UTM is great."
- "The only time we face a problem or issues is when we place a ticket. We have found that response is very slow."
What is our primary use case?
We use this solution for communication endpoint, encryption, and network security. We are focused on providing security software to the small to mid-market enterprises; the essence of our delivery is internet security.
What is most valuable?
The features that I've known to be the most valuable are both the web security features as well as the web firewall capabilities. As a partner of Sophos firewall, we have some clients that are using Sophos firewall UTM and we use it as well.
What needs improvement?
One additional feature that should be included in the next release is
synchronized security, which would enable all the security to work together as a system. Another suggestion is to add advanced threat protection (ATP) to defend against sophisticated Malware. Seeing these additional improvements would be a great thing going forward.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
The product is stable. It's a product that our clients are able to use and enjoy. We haven't had many complaints about the product at all. Internally we haven't experienced any problems.
What do I think about the scalability of the solution?
The scalability is also fine. Currently, we have 20 employees using the product to date and only one employee needed to maintain the product. At the moment we don't have any plans to increase usage in the company. Not now, next year maybe.
How are customer service and technical support?
We train our employee's on technical support. I don't need any outside technical support.
The only time we faced a problem or issue is when we place a ticket. We have found that the response is very slow. That seems to be our biggest problem.
Which solution did I use previously and why did I switch?
We previously used Cyberoam but Sophos acquired Cyberoam. That's why we migrated to Sophos.
How was the initial setup?
The initial setup was done with our engineers, they also set up that server firewall. The setup was straightforward.
What about the implementation team?
The deployment took one month. We're a support base reseller. Our in-house team took care of it. We don't use anyone from the outside, we can deploy the product on our own.
What's my experience with pricing, setup cost, and licensing?
Everything involving pricing and licensing is maintained by our Bangladesh Sophos country managers. The pricing is okay and the licensing is also included in the price.
What other advice do I have?
Sophos UTM is a good product for security purposes and maybe if Sophos provided another company option to implement their products then I would say that Sophos UTM is great.
On a scale of one to ten with 10 being the best, I would give this solution a nine out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Unified Threat Management (UTM)Popular Comparisons
Fortinet FortiGate
WatchGuard Firebox
Check Point Quantum Force (NGFW)
Cisco Meraki MX
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Juniper SRX Series Firewall
KerioControl
Untangle NG Firewall
Stormshield Network Security
Huawei NGFW
Zyxel Unified Security Gateway
Juniper vSRX
Sophos Cyberoam UTM
LANCOM R&S Unified Firewalls
Endian UTM
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, Fortinet FortiGate or Sophos UTM?
- What Is The Biggest Difference Between Sophos UTM and Sophos XG?
- What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
- What Is The Biggest Difference Between Sophos and pfSense?
- Who provides a better antivirus solution: Bitdefender or Sophos?
- What are the biggest differences between Meraki and Sophos? Which one is good for security and SD-WAN?
- What is the biggest difference between Fortinet FortiGate and Sophos UTM?
- When evaluating Unified Threat Management (UTM), what aspect do you think is the most important to look for?
- What UTM solution do you recommend?
- Why is a UTM solution important?















A few observations on an otherwise-accurate review...
The quickest way to get Sophos Support is by submitting a case via MyUTM, SophServ or at secure2.sophos.com/en-us/support/open-a-support-case/describe-issue.aspx. Calling is the slowest way to open a case.
I wonder if Mr. Khan's review doesn't apply to the XG Firewall which is a new Sophos product based on the GUI that Cyberoam developed.
Cheers - Bob