We use it for email security, malware protection, IPS, and filtering.
Senior System Engineer at a real estate/law firm with 51-200 employees
Easy to manage but five-factor authentication needs improvement
Pros and Cons
- "It is easy to manage."
- "I would recommend Sophos, it is easy besides for the five-factor authentication."
- "The five-factor authentication needs improvement."
- "The five-factor authentication needs improvement. It needs central management."
What is our primary use case?
What is most valuable?
It is easy to manage.
What needs improvement?
The five-factor authentication needs improvement.
It needs central management.
For how long have I used the solution?
I have been using Sophos UTM for a few years.
Buyer's Guide
Sophos UTM
April 2026
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,311 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
We have around 400 users.
How are customer service and support?
We offer certified support.
How was the initial setup?
The initial setup was straightforward. We had a problem with the multi-factor authentication.
What other advice do I have?
I would recommend Sophos, it is easy besides for the five-factor authentication. It is good for my needs.
I would rate it a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
System Administrator Server and Networks at a manufacturing company with 201-500 employees
Provides all of the network security you need in a single modular appliance
Pros and Cons
- "I would recommend UTM over XG because it's easier to manage."
- "I would recommend UTM over XG because it's easier to manage."
- "It's stable, but the reaction time of the GUI is terrible."
- "It's stable, but the reaction time of the GUI is terrible; however, in my opinion, UTM is more stable than XG."
What is our primary use case?
We mainly use it for web filtration — we have a number of small websites. It's also a VPN — that's filtering, firewalling, and IPS.
Within our organization, there are roughly 250 people using Sophos UTM. Also, we have around 15 XG users.
We plan on using XG for the next few years, but we are going to stop using UTM on our main site.
What needs improvement?
I think the behavior with the zones was a little bit tricky to understand at the beginning of this project. It can be hard to manage at first, but overall, we don't have many problems with this solution.
For how long have I used the solution?
I have been using this solution for one and a half years.
What do I think about the stability of the solution?
It's stable, but the reaction time of the GUI is terrible; however, in my opinion, UTM is more stable than XG.
How are customer service and technical support?
Sometimes, It can be quite a time-consuming process to book a session with Sophos' support.
How was the initial setup?
The initial setup was not straightforward because we had experience with UTM, but not with XG. It's a completely different system.
We had it up and running within one week.
What about the implementation team?
We installed it on our own.
What other advice do I have?
I would recommend UTM over XG because it's easier to manage.
On a scale from one to ten, I would give XG a rating of 6. Conversely, I would give UTM a rating of nine.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Sophos UTM
April 2026
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,311 professionals have used our research since 2012.
IT Architect at a consultancy with 11-50 employees
Feature rich and provides good security for SMB
Pros and Cons
- "We find all of the features valuable because together they fit the needs of our customers."
- "This is a very good security solution for SMB, so this solution is a good fit for many of our customers."
- "This is a very good security solution for SMB, so this solution is a good fit for many of our customers."
- "We would like to have unique viewable IDs for rules and in the packet filter logfile, for easier debugging of old log files."
- "We would be happy with fewer new features over the same time, but with more stable updates!"
- "We would be happy with fewer new features over the same time, but with more stable updates!"
What is our primary use case?
We primarily use this solution for:
- VLAN separated network
- Proxy / SSL-Interception
- VPN (IPsec and SSL)
- Reverse Proxy / Webserver Security
- Email Security / Mail gateway
- HA (Hot-Standby)
- IPS / ATP
How has it helped my organization?
This is a very good security solution for SMB, so this solution is a good fit for many of our customers.
What is most valuable?
We find all of the features valuable because together they fit the needs of our customers.
What needs improvement?
We would be happy with fewer new features over the same time, but with more stable updates!
We would like to have unique viewable IDs for rules and in the packet filter logfile, for easier debugging of old log files.
Sophos UTM shouldn't die.
For how long have I used the solution?
I have been using this solution for fifteen years.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Network & Hardware Administrator at Nile Projects & Trading Co.
Creates secure IPsec and SSL VPN high availability connections between head office and branches
Pros and Cons
- "It allows me to easily connect with more than forty-five remote sites and more than fifty remote users between IPsec and SSL VPN, applying the web filter and application filter to ensure a secure connection."
- "It allows me to easily connect with more than forty-five remote sites and more than fifty remote users between IPsec and SSL VPN, applying the web filter and application filter to ensure a secure connection."
- "I would like to see the SD-WAN feature improved."
- "I would like to see the SD-WAN feature improved."
What is our primary use case?
We use this solution for IPsec & site-to-site SSL VPN.
My environment involves connecting all of our branches with the head office through one Sophos XG 210 device. This is done using IPsec and SSL VPN, after which we apply a web filter, as well as an application filter to ensure that we are getting a secure connection.
How has it helped my organization?
It allows me to easily connect with more than forty-five remote sites and more than fifty remote users between IPsec and SSL VPN, applying the web filter and application filter to ensure a secure connection.
This solution also gives me varieties of VPN policies for good data encryption.
What is most valuable?
The most valuable features of this solution are:
- High Availability between IPsec site tunnels provides a valid continuous connection and ensures we have no downtime affecting our business.
- Log Viewer allows me to monitor all incoming and outgoing traffic, as well as view and block vulnerabilities.
What needs improvement?
I would like to see the SD-WAN feature improved. I want to manage many lines and load-balance them, getting high availability by making SLA tests according to:
- Check interval.
- Failures before inactive.
- Restore link after.
- SD-WAN Rules to control bandwidth, download and upload stream.
For how long have I used the solution?
We have been using this solution for more than four years.
Which solution did I use previously and why did I switch?
I switched to Sophos as it is more reliable.
What's my experience with pricing, setup cost, and licensing?
This solution is less expensive than FortiGate.
Which other solutions did I evaluate?
We did not evaluate other solutions prior to choosing this one.
Disclosure: My company has a business relationship with this vendor other than being a customer. Sophos XG
Owner at Robert Obrinsky Industries, LLC
A powerful and flexible user interface makes remote client support easy
Pros and Cons
- "Configuration troubleshooting is eased by the use of the color-coded, live firewall log."
- "The most valuable feature is the user interface, which is flexible, powerful, and easy to understand."
- "The most valuable feature is the user interface, which is flexible, powerful, and easy to understand."
- "Support for IKEv2 is needed in this solution."
- "Support for IKEv2 is needed in this solution."
- "Support for IKEv2 is needed in this solution."
What is our primary use case?
I use this solution in both the home and office, and I am also a reseller of the product. It is used for Unified Threat Management for SMB to Mid-Size companies. It provides VPN solutions for our clients, and it has the absolute best UI in the industry.
How has it helped my organization?
This solution makes remote support of clients extremely easy and flexible. Modifications can be made in minutes. New definitions of network objects, users, groups, etc. can be made from anywhere in the UI.
What is most valuable?
The most valuable feature is the user interface, which is flexible, powerful, and easy to understand. Configuration troubleshooting is eased by the use of the color-coded, live firewall log. Live logs for most features are also available.
What needs improvement?
Support for IKEv2 is needed in this solution. But, the handwriting is on the wall that Sophos will probably stop development in favor of their XG Firewall. No timeframe on that yet though.
Which solution did I use previously and why did I switch?
We have been using this solution since it was the Astaro Security Gateway (/products/sophos-utm-reviews ).
Disclosure: My company has a business relationship with this vendor other than being a customer. I am a reseller of this product, and I also use it in my home and office. It is by far the best firewall/UTM solution I have tested or worked with in my career.
CEO at NG
Offers secure and Scalable Firewall Security
Pros and Cons
- "The features that I've known to be most valuable are both the web security features as well as the web firewall capabilities. As a partner of Sophos firewall, we have some clients and they are using Sophos firewall UTM and we are using it as well."
- "Sophos UTM is a good product for security purposes and maybe if Sophos provided another company option to implement their products then I would say that Sophos UTM is great."
- "The only time we face a problem or issues is when we place a ticket. We have found that response is very slow."
- "The only time we face a problem or issues is when we place a ticket. We have found that response is very slow."
What is our primary use case?
We use this solution for communication endpoint, encryption, and network security. We are focused on providing security software to the small to mid-market enterprises; the essence of our delivery is internet security.
What is most valuable?
The features that I've known to be the most valuable are both the web security features as well as the web firewall capabilities. As a partner of Sophos firewall, we have some clients that are using Sophos firewall UTM and we use it as well.
What needs improvement?
One additional feature that should be included in the next release is
synchronized security, which would enable all the security to work together as a system. Another suggestion is to add advanced threat protection (ATP) to defend against sophisticated Malware. Seeing these additional improvements would be a great thing going forward.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
The product is stable. It's a product that our clients are able to use and enjoy. We haven't had many complaints about the product at all. Internally we haven't experienced any problems.
What do I think about the scalability of the solution?
The scalability is also fine. Currently, we have 20 employees using the product to date and only one employee needed to maintain the product. At the moment we don't have any plans to increase usage in the company. Not now, next year maybe.
How are customer service and technical support?
We train our employee's on technical support. I don't need any outside technical support.
The only time we faced a problem or issue is when we place a ticket. We have found that the response is very slow. That seems to be our biggest problem.
Which solution did I use previously and why did I switch?
We previously used Cyberoam but Sophos acquired Cyberoam. That's why we migrated to Sophos.
How was the initial setup?
The initial setup was done with our engineers, they also set up that server firewall. The setup was straightforward.
What about the implementation team?
The deployment took one month. We're a support base reseller. Our in-house team took care of it. We don't use anyone from the outside, we can deploy the product on our own.
What's my experience with pricing, setup cost, and licensing?
Everything involving pricing and licensing is maintained by our Bangladesh Sophos country managers. The pricing is okay and the licensing is also included in the price.
What other advice do I have?
Sophos UTM is a good product for security purposes and maybe if Sophos provided another company option to implement their products then I would say that Sophos UTM is great.
On a scale of one to ten with 10 being the best, I would give this solution a nine out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Owner at Technologies International
Application layer filtering is a vital feature
Pros and Cons
- "Protected it against malware and allowed us to serve our servers safely."
- "Setup: Getting an exchange server to work behind Sophos is incredibly difficult with rules invoked that are simple numbers (e.g. 9054)."
What is our primary use case?
SMB firewall.
How has it helped my organization?
Protected it against malware and allowed us to serve our servers safely.
What is most valuable?
Application layer filtering.
What needs improvement?
Setup: Getting an exchange server to work behind Sophos is incredibly difficult with rules invoked that are simple numbers (e.g. 9054).
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Pre-sales manager at National Information Technology Company
Has a solid state hard drive and can boot in less than sixty seconds
Pros and Cons
- "Sophos UTM has improved the porting section. It has improved security by seeing the gaps. For example, when you discover that an entry has been using a certain application, with Sophos UTM acting as a Layer 7 firewall, you can block the application, not the port."
- "The IT Admin or IT Security in any organization would like to have Sophos UTM because it is full of all the features you think about for enterprise."
- "With Sophos UTM, there is a general rule in the firewall when the country blocking can block some countries from accessing your data. In the current version, you still need to add it by putting in the IP range. This feature would be helpful for administrators and it gives them the advantage to block stuff in less time."
- "With Sophos UTM, there is a general rule in the firewall when the country blocking can block some countries from accessing your data. In the current version, you still need to add it by putting in the IP range."
What is our primary use case?
We are partners with Palo Alto and several IT certificate vendors, like Sophos. We deploy Sophos UTM for customers.
Internally we use Sophos, but we deploy solutions including both Sophos and Palo Alto Networks to our customers. We are an IT integration company. Our services include the deployment of security appliances.
Our environment includes Sophos UTM for internal use, which means it is protecting the network. It is protecting our environment.
We publish our services like the help desk, mail server, and other servers. Sophos UTM offers us protection for publishing and the VPN.
How has it helped my organization?
When we started with Sophos UTM, we were using Microsoft Threat Management Gateway (TMG) which formed part of the firewall. It's not anymore there, it has been discontinued.
Sophos UTM is an SSD appliance. It has a solid state hard drive and can boot in less than sixty seconds. It is an appliance that has more stability than software solutions. It all depends on which hardware you have installed.
Sophos UTM has improved the porting section. It has improved security by seeing the gaps. For example, when you discover that an entry has been using a certain application, with Sophos UTM acting as a Layer 7 firewall, you can block the application, not the port.
In the application firewall, you can block the next update for Bitcoin or for Facebook. It has settings to block a port or wifi or just block the application and firewall. Sophos UTM will be able to detect the application type and filter network users.
Sophos UTM did help us a lot on the throughput of the internet because at that time we were using ADSL. Now it is fiber, which means we are able to manage the throughput of the firewall by also putting the quality of service first.
For example, we are able to configure 2MB for YouTube or 5MB are guaranteed for the service which is published. In the past, with TMG you had to buy third-party tools that also did not have the same functionality.
Currently, Sophos UTM and XG are helping our customers. The features available in the UTM and XG are a combination of all the firewalls in the market which means all the features.
The IT Admin or IT Security in any organization would like to have Sophos UTM because it is full of all the features you think about for enterprise.
Sophos UTM normally will deploy a batch or an upgrade and add more features, every six to eight months based on the RMD.
What is most valuable?
To be quite honest, from my personal experience all the features of Sophos UTM are useful, which includes publishing templates and the ease of publishing any servicing needs.
From the VPN side, all the VPN protocols are available so you can choose from SSVPN to PPTP to other versions of VPN, and it's easy to deploy within minutes.
The firewall includes very good logging where you can see what's hacking your network. The IDS and IPS settings are based on your reliance and also alerts you if there is an attack.
We're happy with Sophos and we also have an XG version being used for other services, because we are a company that provides services. We have two versions, we have the XG and the latest one.
The Sophos UTM which is the previous version but still being in production is our main firewall for the company.
We happy with all the features, we have no negative comments on any of the features except that the XG has more ability to block based on countries.
On the previous model, the blocking of countries we had a problem with, i.e. if you use the NAT feature, you can't block countries. You have to enter the IP network.
With the XG version, you can just select when you publish via NAT not via WAF. You can select the countries.
That is the only difference between XG and the UTM which we did not really like, but other than that its all cool.
What needs improvement?
There is definitely room for improvement with Sophos UTM. For the SG version of Sophos UTM, they can add blocking of countries in the NAT section, not only in the firewall section.
When you are mapping, they should also add the ability to block countries in that section. That's not available right now. It's only available in the firewall if you want to block incoming traffic.
With Sophos UTM, there is a general rule in the firewall when the country blocking can block some countries from accessing your data. In the current version, you still need to add it by putting in the IP range.
This feature would be helpful for administrators and it gives them the advantage to block stuff in less time.
The web filter needs additional enhancement but that's the point of the XG upgrade. If they're going to continue with the production of the XG, then they will not add the same features to the basic version of Sophos UTM.
For how long have I used the solution?
More than five years.
What do I think about the stability of the solution?
With the ability of the hardware, we haven't experienced any problems with Sophos UTM so far. Neither have our customers.
At the beginning of the XG version, three years back, they had hardware issues. After that Sophos deployed division two, three, and four as hardware appliances.
Sophos fixed the hardware issue for the lower models, i.e. the 525, the XG 125, and the XG 85. All of the larger Sophos UTM models were fine.
Now, all are stable, all are fine. We haven't seen any crash. One of our customers had a DDoS attack. Since he had the proper rules, we did not record any incident.
Sophos UTM blocked the DDoS. Although it is not a dedicated anti-DDoS solution, Sophos UTM has the features.
Sophos UTM is stable. I haven't seen any claims or issue tickets from our customers regarding stability.
What do I think about the scalability of the solution?
Sophos UTM has different aspects. If you have an HA distribution, high availability, you can scale up.
When you go and purchase Sophos UTM, you have to plan and say what the environment is. This planning has to be done before buying. If you buy a small appliance and after two years, you are 50 or 70 employees there are upgrade options.
It should be between you and Sophos. They can give you a free appliance if you subscribe for three years on subscription, for example.
If you have an existing subscription and you want to have HA, this means another device has to be set as redundant. The only downside is that it has to be the same version and the same model.
In my company, we have around 35 loyal customers. These customers have purchased and are redeeming Sophos UTM with us. Altogether, we are 55 employees. Most of them are at the office. Concurrently around 35 others are on site at other clients. We have around 35 servers.
We have the published Sophos UTM on the main server, help desk, share point, etc. We've got around nine published services, plus 10 VPNs running concurrently for our support engineers to connect and work on our internal infrastructure for the allotment servers.
We have 50 Sophos UTM installations at least that are actively browsing, downloading, and being protected by the web filter and other features there.
It depends on the organization, but for us we only require one person to manage this solution, even working remotely at home.
How are customer service and technical support?
We don't have much need to speak with the vendor because we are educated and experienced with Sophos UTM. We are an integrator company.
For our customers, in the beginning, we give them training. After a week we do expect to have some calls because they are not yet educated or they're not yet used to it.
After that, that's it. They already told us if they are ready or not. Sophos' support is better than others because Sophos also can sell endpoint solutions.
If one of our customers has an issue and Sophos did support and send their team for the investigation it could be conflicting.
For example, one of our customers had an endpoint which is an antivirus and they had an issue. We have teams that were actively taking care of the customer based on our relationship with the client and their Sophos UTM device license.
We have no comment on the Sophos UTM support which we have seen at our customer sites because it was only with a government customer.
The customer told us that the Sophos UTM representative mentioned that they wanted to have the vendor take care of this issue.
Other than that, I have had no negative experiences with Sophos' technical support.
How was the initial setup?
The initial setup of Sophos UTM is straightforward for both versions, the XG & UTM. In addition, they both provide a proper manual.
In the beginning, seven years back, Sophos UTM wasn't straightforward for beginners. You had to be already excellent in security. Now, it is very easy because you install the IP address, you log in, and you do the initial setup by routine.
These days its much easier than in the past but not everyone that has a firewall is secured. If you do it properly by choosing the right network, the right topology, and the right firewall rules, Sophos UTM will work.
There are orders for most of the rules. For example, if you put a deny rule below an allow rule, you are not going to have the proper result.
Sophos UTM requires knowledge. It's easy to deploy but also there is a responsibility on the person who is deploying to understand.
You must have the knowledge of security and networking, to make sure that the solution is working properly. Sophos UTM is very easy compared to other vendors somehow.
In our environment, we have defined previously the VLAN rules on our sheets because we had another firewall. In the beginning, we just copied the current rules and then enhanced them slowly so deployment took place quickly.
After fixing the appliance physically on the rack, it took one hour to be up and running and ready based on the rules. If you are a small environment that would take you less than 20 minutes.
It all depends on how many rules you have, how many demands, how many users, and public services. For example: if you have five websites, the main server, and a starter business, you might need more time because you would need to define the rules properly.
It all depends on how complex your environment is. Sophos UTM is easy and straightforward for me and for somebody who is certified on security levels.
What about the implementation team?
We haven't opened a ticket with Sophos for 60 days, but we still have support. All our customers use us as the first level of support, even if they have to chase it.
Sophos UTM comes with a license. We are very aware and updated on Sophos solutions. We have good experience with it.
Although we sell other solutions, we are looking forward to building, selling, and integrating Sophos XG/UTM versus other vendors because of the ease of use.
We are more focused now. Our entire team is certified in Sophos Enterprise, while other vendors would likely still have just one or two members who are certified.
We feel more comfortable using Sophos equipment and solutions.
What was our ROI?
I can't mention anything on ROI because I'm more focused on the technical part. I'm not needed in the financial part. In our company, we have saved bandwidth and lots of network hardware waste.
The Sophos UTM solution did help us because we were depending on a software base from Microsoft. Microsoft is a great company but they are not great for our security. Now they have improved. When you go out and buy something, buy it from the specialists.
For example, if you go for virtualization, VMware is a company that only does virtualization. Go for specialized people. Don't go for people who are doing everything at once.
It's like when you go to a physician or a doctor and you have a problem with certain things. i.e you have a problem with the bones. Go to the doctor that is specialized in the bones, not a general doctor.
What's my experience with pricing, setup cost, and licensing?
The Sophos UTM license is annual or you have a choice for a two or three-year term.
The Sophos UTM licensing is based on if you have an appliance. There are several layers of subscription you can take:
- Sophos UTM Full Guard includes everything but a few features.
- Sophos UTM Full Guard Plus includes all the most used features, i.e Wifi, ITF, ITS, web publishing WAF, etc.
There is a huge price list. The prices in the MENA area (the Middle East and North Africa) is completely different than North America.
The products are completely different in the MENA area from the United States. Each region has its own scheme of pricing based on the VAT and the tax refund.
The price might be different for the people who are in the United States and the UK.
After you select the level of subscription, you pay once.
Which other solutions did I evaluate?
We tried and tested Fortigate from Fortinet. We tested several appliances about six years back. Not Palo Alto at that time, only Fortinet.
We evaluated other open-source Linux software but not appliances. We decided to go with Sophos UTM based on several factors related to the tests we did at that time.
Evaluation is very important so that you can see what are you buying and what you are going to face in the future.
What other advice do I have?
My recommendation is that businesses should go for the XG version, not the SG because the XG version of Sophos offers next-generation firewall support and has more improvements.
Sophos XG is the next generation firewall that is not available on the UTM version. The difference is in the features between the two and how you deploy them.
Sophos XG version covers what is in the SG version plus additional bonuses: the dashboard, the heartbeat between the firewall and the input, etc.
I advise first evaluate, know your network, know your needs, and plan for the upcoming two or three years before you purchase.
Get in touch with the vendors because these days every vendor wants to sell. They are willing to help the customers and willing to show them what they will get.
Make sure you evaluate properly many platforms. Don't just go with one vendor. Go with two or three vendors. Evaluate and then short-list and choose the best for you.
The rating has to have criteria:
- On performance, I would give Sophos UTM a 10 out of 10 rating.
- On price, it is a long discussion because you can get a discounted price if you are an integrator.
- As a user and a customer, I would give Sophos UTM a 9 out of 10 rating.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2026
Product Categories
Unified Threat Management (UTM)Popular Comparisons
Fortinet FortiGate
WatchGuard Firebox
Check Point Quantum Force (NGFW)
Cisco Meraki MX
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Juniper SRX Series Firewall
KerioControl
Untangle NG Firewall
Stormshield Network Security
Huawei NGFW
Zyxel Unified Security Gateway
Juniper vSRX
Sophos Cyberoam UTM
LANCOM R&S Unified Firewalls
Endian UTM
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, Fortinet FortiGate or Sophos UTM?
- What Is The Biggest Difference Between Sophos UTM and Sophos XG?
- What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
- What Is The Biggest Difference Between Sophos and pfSense?
- Who provides a better antivirus solution: Bitdefender or Sophos?
- What are the biggest differences between Meraki and Sophos? Which one is good for security and SD-WAN?
- What is the biggest difference between Fortinet FortiGate and Sophos UTM?
- When evaluating Unified Threat Management (UTM), what aspect do you think is the most important to look for?
- What UTM solution do you recommend?
- Why is a UTM solution important?















A few observations on an otherwise-accurate review...
The quickest way to get Sophos Support is by submitting a case via MyUTM, SophServ or at secure2.sophos.com/en-us/support/open-a-support-case/describe-issue.aspx. Calling is the slowest way to open a case.
I wonder if Mr. Khan's review doesn't apply to the XG Firewall which is a new Sophos product based on the GUI that Cyberoam developed.
Cheers - Bob