Try our new research platform with insights from 80,000+ expert users
reviewer1223154 - PeerSpot reviewer
IT Architect at a consultancy with 11-50 employees
Real User
Nov 11, 2019
Feature rich and provides good security for SMB
Pros and Cons
  • "We find all of the features valuable because together they fit the needs of our customers."
  • "We would like to have unique viewable IDs for rules and in the packet filter logfile, for easier debugging of old log files."

What is our primary use case?

We primarily use this solution for:

  • VLAN separated network
  • Proxy / SSL-Interception
  • VPN (IPsec and SSL)
  • Reverse Proxy / Webserver Security
  • Email Security / Mail gateway
  • HA (Hot-Standby)
  • IPS / ATP

How has it helped my organization?

This is a very good security solution for SMB, so this solution is a good fit for many of our customers.

What is most valuable?

We find all of the features valuable because together they fit the needs of our customers.

What needs improvement?

We would be happy with fewer new features over the same time, but with more stable updates!

We would like to have unique viewable IDs for rules and in the packet filter logfile, for easier debugging of old log files.

Sophos UTM shouldn't die.

Buyer's Guide
Sophos UTM
January 2026
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.

For how long have I used the solution?

I have been using this solution for fifteen years.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
PeerSpot user
Network & Hardware Administrator at a financial services firm with 1,001-5,000 employees
Real User
Top 20
Aug 5, 2019
Creates secure IPsec and SSL VPN high availability connections between head office and branches
Pros and Cons
  • "It allows me to easily connect with more than forty-five remote sites and more than fifty remote users between IPsec and SSL VPN, applying the web filter and application filter to ensure a secure connection."
  • "I would like to see the SD-WAN feature improved."

What is our primary use case?

We use this solution for IPsec & site-to-site SSL VPN.

My environment involves connecting all of our branches with the head office through one Sophos XG 210 device. This is done using IPsec and SSL VPN, after which we apply a web filter, as well as an application filter to ensure that we are getting a secure connection.

How has it helped my organization?

It allows me to easily connect with more than forty-five remote sites and more than fifty remote users between IPsec and SSL VPN, applying the web filter and application filter to ensure a secure connection.

This solution also gives me varieties of VPN policies for good data encryption.

What is most valuable?

The most valuable features of this solution are:

  • High Availability between IPsec site tunnels provides a valid continuous connection and ensures we have no downtime affecting our business.
  • Log Viewer allows me to monitor all incoming and outgoing traffic, as well as view and block vulnerabilities.

What needs improvement?

I would like to see the SD-WAN feature improved. I want to manage many lines and load-balance them, getting high availability by making SLA tests according to:

  1. Check interval.
  2. Failures before inactive.
  3. Restore link after.
  4. SD-WAN Rules to control bandwidth, download and upload stream.

For how long have I used the solution?

We have been using this solution for more than four years.

Which solution did I use previously and why did I switch?

I switched to Sophos as it is more reliable.

What's my experience with pricing, setup cost, and licensing?

This solution is less expensive than FortiGate. 

Which other solutions did I evaluate?

We did not evaluate other solutions prior to choosing this one.

Disclosure: My company has a business relationship with this vendor other than being a customer. Sophos XG
PeerSpot user
Buyer's Guide
Sophos UTM
January 2026
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
it_user1104651 - PeerSpot reviewer
Owner with 11-50 employees
Real User
May 31, 2019
A powerful and flexible user interface makes remote client support easy
Pros and Cons
  • "Configuration troubleshooting is eased by the use of the color-coded, live firewall log."
  • "Support for IKEv2 is needed in this solution."

What is our primary use case?

I use this solution in both the home and office, and I am also a reseller of the product. It is used for Unified Threat Management for SMB to Mid-Size companies. It provides VPN solutions for our clients, and it has the absolute best UI in the industry.

How has it helped my organization?

This solution makes remote support of clients extremely easy and flexible. Modifications can be made in minutes. New definitions of network objects, users, groups, etc. can be made from anywhere in the UI.

What is most valuable?

The most valuable feature is the user interface, which is flexible, powerful, and easy to understand. Configuration troubleshooting is eased by the use of the color-coded, live firewall log. Live logs for most features are also available.

What needs improvement?

Support for IKEv2 is needed in this solution. But, the handwriting is on the wall that Sophos will probably stop development in favor of their XG Firewall. No timeframe on that yet though.

Which solution did I use previously and why did I switch?

We have been using this solution since it was the Astaro Security Gateway (/products/sophos-utm-reviews ).

Disclosure: My company has a business relationship with this vendor other than being a customer. I am a reseller of this product, and I also use it in my home and office. It is by far the best firewall/UTM solution I have tested or worked with in my career.
PeerSpot user
CEO at a comms service provider with 201-500 employees
Real User
Apr 16, 2019
Offers secure and Scalable Firewall Security
Pros and Cons
  • "The features that I've known to be most valuable are both the web security features as well as the web firewall capabilities. As a partner of Sophos firewall, we have some clients and they are using Sophos firewall UTM and we are using it as well."
  • "The only time we face a problem or issues is when we place a ticket. We have found that response is very slow."

What is our primary use case?

We use this solution for communication endpoint, encryption, and network security. We are focused on providing security software to the small to mid-market enterprises; the essence of our delivery is internet security.

What is most valuable?

The features that I've known to be the most valuable are both the web security features as well as the web firewall capabilities. As a partner of Sophos firewall, we have some clients that are using Sophos firewall UTM and we use it as well.

What needs improvement?

One additional feature that should be included in the next release is
synchronized security, which would enable all the security to work together as a system. Another suggestion is to add advanced threat protection (ATP) to defend against sophisticated Malware. Seeing these additional improvements would be a great thing going forward.  

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

The product is stable. It's a product that our clients are able to use and enjoy. We haven't had many complaints about the product at all. Internally we haven't experienced any problems. 

What do I think about the scalability of the solution?

The scalability is also fine. Currently, we have 20 employees using the product to date and only one employee needed to maintain the product. At the moment we don't have any plans to increase usage in the company. Not now, next year maybe.

How are customer service and technical support?

We train our employee's on technical support. I don't need any outside technical support.

The only time we faced a problem or issue is when we place a ticket. We have found that the response is very slow. That seems to be our biggest problem.

Which solution did I use previously and why did I switch?

We previously used Cyberoam but Sophos acquired Cyberoam. That's why we migrated to Sophos.

How was the initial setup?

The initial setup was done with our engineers, they also set up that server firewall. The setup was straightforward.

What about the implementation team?

The deployment took one month. We're a support base reseller. Our in-house team took care of it. We don't use anyone from the outside, we can deploy the product on our own.

What's my experience with pricing, setup cost, and licensing?

Everything involving pricing and licensing is maintained by our Bangladesh Sophos country managers. The pricing is okay and the licensing is also included in the price.

What other advice do I have?

Sophos UTM is a good product for security purposes and maybe if Sophos provided another company option to implement their products then I would say that Sophos UTM is great.

On a scale of one to ten with 10 being the best, I would give this solution a nine out of 10. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Bob Alfson - PeerSpot reviewer
Bob AlfsonSophos Certified UTM Architect, Sophos Certified XG Engineer at a reseller with 1-10 employees
User

A few observations on an otherwise-accurate review...

The quickest way to get Sophos Support is by submitting a case via MyUTM, SophServ or at secure2.sophos.com/en-us/support/open-a-support-case/describe-issue.aspx. Calling is the slowest way to open a case.

I wonder if Mr. Khan's review doesn't apply to the XG Firewall which is a new Sophos product based on the GUI that Cyberoam developed.

Cheers - Bob

Owner with 11-50 employees
Real User
Apr 10, 2019
Application layer filtering is a vital feature

What is our primary use case?

SMB firewall.

How has it helped my organization?

Protected it against malware and allowed us to serve our servers safely.

What is most valuable?

Application layer filtering.

What needs improvement?

Setup: Getting an exchange server to work behind Sophos is incredibly difficult with rules invoked that are simple numbers (e.g. 9054).

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
IT Specialist at a financial services firm with 201-500 employees
Real User
Top 20
Feb 19, 2019
Sophos SUM allows us to manage over 50 devices from a central management console

What is our primary use case?

  • Network border protection for clients and internal company
  • It is used for small to medium-sized businesses and networks.

How has it helped my organization?

Sophos SG has provided us with the tools to protect our networks, detect malicious activity, and customize security to our clients' needs.

What is most valuable?

  • Sophos UTM Manager (SUM): It allows us to manage over 50 Sophos UTM devices from a central management console. 
  • Creating rules, exceptions, and managing most features from SUM, and pushing to all or a section of devices as needed.

What needs improvement?

  • SUM cannot manage app control
  • Improve app control system as a whole
  • Extend support for SG until XG has improved significantly.

For how long have I used the solution?

Three to five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
IT Security Specialist at a tech services company with 11-50 employees
Reseller
Jan 20, 2019
It is a good source for IDS and IPS
Pros and Cons
  • "The most valuable feature is the IPS. It also protects us from malware."
  • "The solution could be improved by adding cloud soundboxing."

What is our primary use case?

Our primary use case of this solution is IDS and IPS. We also use it for application availability. 

What is most valuable?

The most valuable feature is the IPS. It also protects us from malware. 

What needs improvement?

The solution could be improved by adding cloud soundboxing.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

The stability is OK. 

What do I think about the scalability of the solution?

The scalability is not something I have experience with because our organization is pretty lean.

How is customer service and technical support?

I have not used technical support. 

How was the initial setup?

It was easy to set up and quite straightforward.

What other advice do I have?

When considering a new solution, I always make sure that there is good technical support. Also, the pricing is an important aspect.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Bob Alfson - PeerSpot reviewer
Bob AlfsonSophos Certified UTM Architect, Sophos Certified XG Engineer at a reseller with 1-10 employees
User

Sophos UTM has offered cloud sandboxing for several years. Sandstorm matured in 2017 and now would be a valuable addition to your company's security.

PeerSpot user
Info Sec Consultant at a consultancy with 1-10 employees
Real User
Top 5
Jan 16, 2019
Allows our client to use cross-region AWS VPCs to connect remote dev offices
Pros and Cons
  • "UTM 9 brings along IPSec as well as iPhone and iPad support. This seems small but it’s useful."
  • "We didn’t find any issues but I know there have been some in the last few years."

What is our primary use case?

A client wanted to trial Sophos UTM 9 before deploying it into a production environment because, historically, Sophos has not had the best of reputations in AWS. The client had used Sophos in other environments, hence they wanted to stick to what they know.

How has it helped my organization?

The solution allows the client to use cross-region AWS VPCs to connect remote dev offices.

What is most valuable?

Classic defence in depth, with layered features. 

  • SPI (stateful packet inspection)
  • IPS
  • WAF 
  • VPN capability with built-in load balancer

Nothing out of the ordinary these days, but the fact Sophos has such a big name and good support was a big plus for the client who already had a relationship with Sophos support. Also, auto-scaling of UTM workers using EC2 is a nice and handy feature.

UTM 9 brings along IPSec as well as iPhone and iPad support. This seems small but it’s useful. 
Finally, Cold Standby CloudFormation script to one node, with persistent info in S3, is a convenient feature.

What's my experience with pricing, setup cost, and licensing?

We procured this solution via the AWS Marketplace because of BYOL (bring your own licence). That was the driving force behind the choice. In addition, they had test and production environments in AWS already so it was easy to get a sign-off.

What other advice do I have?

We didn’t find any issues but I know there have been some in the last few years. I can’t comment about Sophos on AWS previously but they seem fine now. There were no problems for our client so all I can comment on is the experience they had. I think it’s taken a little while for Sophos to get experience in solving problems with their product in the AWS environment, but they do seem to go the extra mile.

This solution rates an eight out of ten, based on our experience. Support was good. You will always find problems with installations so it does hinge on support.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2026
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros sharing their opinions.