We use the product for traffic and security control.
Manager at RSPL LIMITED
Identifies the threat and publishes the information across all endpoints and firewalls
Pros and Cons
- "We currently have multiple clients, and many users are working remotely. We need antivirus protection to guard against malware introduced from public networks. One of the most beneficial features of Sophos XG is its integration with Sophos Central. If any file is detected as malicious on any endpoint or firewall, Sophos Central immediately identifies the threat and publishes the information across all endpoints and firewalls. If a single system gets infected, the threat is communicated and addressed across the entire network, including all sites and remote users."
- "One drawback I've noticed with Sophos XG is that sometimes, the platform can become unresponsive. I've observed that it occasionally hangs, causing traffic to get stuck. During these times, users cannot access the internet or any services routed through the Sophos Firewall. This issue happens randomly and isn't something we've encountered with other firewalls like FortiGate, which we used in the past."
What is our primary use case?
What is most valuable?
We currently have multiple clients, and many users are working remotely. We need antivirus protection to guard against malware introduced from public networks. One of the most beneficial features of Sophos XG is its integration with Sophos Central. If any file is detected as malicious on any endpoint or firewall, Sophos Central immediately identifies the threat and publishes the information across all endpoints and firewalls. If a single system gets infected, the threat is communicated and addressed across the entire network, including all sites and remote users.
What needs improvement?
One drawback I've noticed with Sophos XG is that sometimes, the platform can become unresponsive. I've observed that it occasionally hangs, causing traffic to get stuck. During these times, users cannot access the internet or any services routed through the Sophos Firewall. This issue happens randomly and isn't something we've encountered with other firewalls like FortiGate, which we used in the past.
Dealing with licensing has been a big challenge for us. Despite our efforts to resolve issues through our sales contact, we've faced limitations. After confirming our purchase orders, we had to escalate the issue. We were ready to extend our licenses for two or three months.
For how long have I used the solution?
I have been working with the product for a year.
Buyer's Guide
Sophos XG
April 2025

Learn what your peers think about Sophos XG. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,604 professionals have used our research since 2012.
How are customer service and support?
We haven't seen any major issues with customer support from Sophos. We have faced some problems, but we understand that the support team can sometimes be unresponsive.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
When comparing FortiGate to Sophos XG, I would say that if I'm working on large-scale asset monitoring and security purposes, especially if I have a data center that requires firewall security, then FortiGate would be my choice. It's faster and more responsive than Sophos XG support.
How was the initial setup?
The tool's deployment takes two to three hours to complete. It doesn't require any maintenance. You would need one engineer to handle one application.
What was our ROI?
I can say there has been some return on investment. It's good, but I would still say it's higher by about 10-15 percent compared to other market products with similar configurations.
What's my experience with pricing, setup cost, and licensing?
The tool's pricing and licensing are very complex. As a developing company, we need approvals from management to make a purchase, which can take time. We asked Sophos XG to renew our current firewall license for one or two months while we plan to accommodate our increasing IT assets.
What other advice do I have?
I rate the overall product an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

IT Manager at Saknafta Egypt
Easy to set up with good content blocking and good stability
Pros and Cons
- "Content blocking for websites is the most valuable aspect of the solution."
What is our primary use case?
I primarily use the solution for managing my firewall. I'm managing my internet and my laptops in my company. I'm a personal domain controller. I'm tasked with blocking some websites with it and I'm managing my updates through it. I'm basically controlling the flow of the internet through it.
How has it helped my organization?
I block a lot of sites. I'm controlling the flow of the internet directed to Office 365 so that people can use it easily and fluently. They can upload and send emails easily without hassle and without accessing the internet. I'm also controlling Teams, Zoom, and other stuff for chatting online. Without this solution, I would have no control.
What is most valuable?
Content blocking for websites is the most valuable aspect of the solution. A lot of employees always want to use Facebook and other non-work-related sites. I'm always blocking that.
The initial setup is easy.
The stability is good.
Scaling is not an issue.
What needs improvement?
The reporting needs to be much better. Sometimes I have a lot of trouble understanding what they mean.
Sometimes it misses websites. For example, websites the users shouldn't be able to enter, or sometimes these websites are not shown in this log viewer. It's just occasional misses here and there.
Technical support could be more responsive and quicker in getting to a solution.
For how long have I used the solution?
I've been using the solution for at least three years now.
What do I think about the stability of the solution?
I have found the stability to be very good. There have been no hiccups, no restarts, nothing like that. It doesn't hang and there are barely any bugs.
What do I think about the scalability of the solution?
It's my understanding that they have a solution called RED, and I can upgrade it with another one to make a VPN between them. I haven't tried it yet. I'm looking at it as I have another office. I want to research scaling and have the offices together. From what I have seen, it will be easy.
Right now, we have about 50 users and 10 VPNs. That includes everyone from financial and procurement managers to the CEO, chairman, and HR department, and other operations staff.
We don't have any plans to increase users right now as we haven't increased in population, in employees number. That said, I use it a lot every day. I have to manage my firewalls through it.
How are customer service and support?
In my experience, technical support takes a while to get things done. In the past, I stuck with them for a while. It took about three weeks to serve us up a solution. I don't remember what the problem was as it was a long time ago. It might have been something about the subscription or something like that. What I do remember is it took a very long time.
Which solution did I use previously and why did I switch?
I had a previous firewall, and I just swapped it out. I didn't have to change anything about my network. We previously used a firewall called MikroTik.
With MikroTik, its GUI was very bad. It's very old. Everything was manual. There were no tutorials and it was open-source. You had to search for yourself and do everything yourself. There was no support even from the company.
How was the initial setup?
It was really easy for me, to be honest. The initial setup is very straightforward and simple. It's not overly complex. I had a firewall before that, so I knew what to expect. The implementation was done by a company that I bought this from. They installed it for me. It took about an hour and a half, or something like that.
I can't recall how many staff covered deployment. The deployment happened three years ago now.
What about the implementation team?
I didn't need the assistance of an integrator or reseller.
What was our ROI?
The solution has saved me a lot of time and enhanced my workflow for my company. It enhanced employees' work time and enhanced the internet connectivity for emails. On top of that, there was no downtime with the internet. That was the basic ROI we've seen.
What's my experience with pricing, setup cost, and licensing?
The subscription for this product is yearly. The last time I bought it two years ago it was about $2,000. There's just a subscription fee. There aren't any other costs.
Which other solutions did I evaluate?
I also looked at Fortinet, however, from my research, I was told that Sophos had better reporting. With Fortinet, you have to buy a server to handle reporting. With Sophos, this is unnecessary.
What other advice do I have?
I'm a customer and an end-user.
I'd rate the solution at an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Sophos XG
April 2025

Learn what your peers think about Sophos XG. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,604 professionals have used our research since 2012.
Head of ICT Infrastructure and Security at City of Harare
Easy to set up with great protection features and excellent documentation
Pros and Cons
- "The initial setup is very straightforward and the solution is extremely user-friendly."
- "I'd like the dashboard to be improved. It could be a bit more customizable."
What is our primary use case?
We use Sophos Firewall for our environment.
The Sophos Firewall, from our interaction and the way we are using it, is a very effective network security solution that basically protects our infrastructure, identifies any infections or any network security threats that actually may happen within our environment. We also are able to manage our users in terms of bandwidth usage and the allocation of bandwidth, whereby we give our users restricted access for use during working hours and they are supposed to utilize the bandwidth and make sure that we optimize and prioritize the applications able to get the necessary bandwidth. We do use it to manage our bandwidth. We do use it as well to make sure that our environment is secure against any possible threats.
What is most valuable?
In terms of the Sophos XG Firewall, what really excites us is basically the issue of intrusion detection and the intrusion prevention features. Those are both very, very good.
The issue of sandboxing as well is something that is very useful. It's able to protect our environment quite well.
Email protection is something that we are basically using all the time and it protects our environment which has more than 2000 users.
All of the protection features are great in terms of securing our environment.
Sophos is way ahead of a number of other products in terms of the enhancements and upgrades they offer.
Sophos offers a great centralized dashboard that makes it easy to see what's happening on your network.
The initial setup is very straightforward and the solution is extremely user-friendly.
The documentation is very, very good.
What needs improvement?
In terms of the product, from the way that we have been utilizing it, we have noticed that the vendor has been able to continuously upgrade and upgrade and update the product with new features. You'd find that all the time a new release has come out, and we're actually happy with that. We don't find it inconvenient that we are constantly upgrading.
I can't think of any downsides in terms of the features on offer.
I'd like the dashboard to be improved. It could be a bit more customizable.
For how long have I used the solution?
I have about five years of experience with the product.
What do I think about the stability of the solution?
We are very satisfied with the functionality. We are very satisfied with the way that it is securing our environment. The stability has been excellent.
What do I think about the scalability of the solution?
We have 2,000 users on the solution currently.
The solution is very scalable. We basically started with about 900 users. We went up to about 1,300. As we went up, as our users increased, we also scaled it up in terms of protection. Sophos was able to scale up easily and protect all our end users as well as our environment. It's been great overall.
We do plan to increase usage. Our employee base is about 10,000. We have 2,000 networked employees and we are planning to add another 1,000 users by the end of the year.
How are customer service and technical support?
The technical support has been great. All of our technical staff have been certified as Sophos administrators. They were able to offer us the training to make sure that all of the support staff are familiar with the functionality of the product. Then, in terms of technical support that we may need, when we call the Sophos team, they are usually very available and they are even able to support us remotely if there is a need to do that. We are extremely satisfied overall.
Which solution did I use previously and why did I switch?
I also often work with Cisco's ASA Firewall as well as Nagios. We bought Sophos to complement the ASA firewall.
How was the initial setup?
The initial setup was very, very straightforward. You find that we did not even require a lot of external help from the vendor. It's so straightforward. The documentation is quite comprehensive and it takes the user through a step-by-step process, It's very user-friendly.
For the firewall as well as deployment of the end-user, the email protection as well as the sandbox, and the like, it took us approximately three days to finalize everything for our entire environment. We had over a hundred network sites, which are dotted through the city of Harare, therefore, we knew that we had to make sure that deployment was done fully throughout the entire environment.
What about the implementation team?
There was very minimal, minimal assistance from the vendor. The vendor, here and there, would assist if we requested their help. However, you'd find that in most of the installations we did in-house, we didn't need the vendor to do anything. We knew that the installation process was very user-friendly.
What's my experience with pricing, setup cost, and licensing?
The cost of procuring this product is very reasonable and it's very affordable for most organizations.
What other advice do I have?
We're a customer and an end-user.
We use the latest version of the product.
I'd advise those considering the solution that Sophos' security solution is highly synchronized, very secure, and provides comprehensive security. I'd like them to know that it has enhanced and very detailed and sophisticated functionality, which is really easy to use, easy to deploy, and very user-friendly. It is a product that I would highly recommend for any organization that needs to comprehensively secure its infrastructure.
I'd rate the solution at a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
it officer at a government with 1,001-5,000 employees
Offers intuitive interface but needs licensing improvement
Pros and Cons
- "The user interface of Sophos XG enhances our administrative tasks because it is intuitive and easy to navigate."
- "I am struggling with the licensing model of Sophos XG because we don't have a license. Our licenses expired and we're not supposed to renew the licenses at this time."
What is our primary use case?
We don't have remote workers, so Sophos XG is only used for our in-house applications and users within the same building. For remote access, we use the Sophos free firewall home edition to connect to the Sophos XG 450, so there was no problem when the license was still activated. We experienced problems currently since the license is no longer activated.
What is most valuable?
The user interface of Sophos XG enhances our administrative tasks because it is intuitive and easy to navigate.
We find the network security, protection, and web features most effective for threat prevention.
Sophos XG has facilitated better traffic management because the model we purchased is only utilizing resources at 40%. We have no bottlenecks, unlike the previous Cyber Room model that we purchased, which was at 85% resource utilization, causing traffic problems. With 40% resource utilization, we don't experience problems with all the features of the base firewall, such as IPS.
What needs improvement?
They could change their licensing model, simplify it, and make it more available to upgrade. We are looking into upgrading or refreshing these firewalls since they will be end of life. We are looking to replace it with another firewall with a five-year license, at least, so that we can survive.
For how long have I used the solution?
I have been working with Sophos XG since 2020.
What do I think about the scalability of the solution?
I am struggling with the licensing model of Sophos XG because we don't have a license. Our licenses expired and we're not supposed to renew the licenses at this time.
Which solution did I use previously and why did I switch?
We are looking into other brands, including FortiGate because it's closer to Sophos XG. I'm also looking at Sangfor because they say it has better web and network protection. Our objective is to find a solution that is price-wise and affordable for us, with longer coverage and good web application firewall features and network protection for five years license.
I haven't concluded my research on the advantages Sangfor has over Sophos XG yet, but Sangfor has better pricing and states that if the license expires, all the features until the day subscribed prior to termination of the license remain active. This is appealing for us to explore, and we will be asking for a model or POC for that product in the next few weeks. FortiGate comes with an appliance and is somewhat expensive. We're considering Sangfor, Sophos XG, and FortiGate because these are the appliances that we think are affordable for us.
What other advice do I have?
Sophos XG Firewall has improved our network security posture only partially because we don't have the license, so it's just the base license that we are using currently. When we had the license activated, there was no problem, but now that we don't have a license, it reverts back to the base license features only.
We are not so much concerned about the reporting and analytics tools in Sophos XG. I have seen that of Sophos XG 450; it's not comprehensive. I hope Sophos XG 4300 will be better with updated features for reporting because we had problems with minimal reports for the Sophos XG 450. I haven't seen the material white paper on Sophos XG 4300 on the reporting feature yet, but from what I've read, it's still not on par with FortiGate. I don't know about Sangfor yet, so we still have to check on that.
I would still recommend the Sophos XG firewall to others, particularly the Sophos XG 4300, depending on the price. I would also recommend some other vendors when it comes to firewall.
On a scale of 1-10, I rate Sophos XG an 8 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: May 20, 2025
Flag as inappropriateTechnical Services Lead at Telenet Solutions
The UTM features are useful for malware prevention and intrusion detection
Pros and Cons
- "Sophos XG's most effective features for threat detection and management are its UTM components, which are useful for malware prevention and intrusion detection."
- "Sophos XG has helped us reduce virus and malware attacks."
- "The firewall could be made more robust, particularly by simplifying two-factor authentication."
- "The firewall could be made more robust, particularly by simplifying two-factor authentication."
What is our primary use case?
We primarily use Sophos XG as edge routers and edge firewalls, also known as border firewalls. We configure rules where specific users are allowed internet access and use rules for policy routing. We also control traffic for specific services, such as directing emails to one service provider while normal internet usage goes to another.
How has it helped my organization?
Sophos XG has helped us reduce virus and malware attacks. This allows our IT team to spend less time on troubleshooting and more on productive work. The ability to control what comes into and goes out of the network improves overall efficiency.
What is most valuable?
Sophos XG's most effective features for threat detection and management are its UTM components, which are useful for malware prevention and intrusion detection.
What needs improvement?
The firewall could be made more robust, particularly by simplifying two-factor authentication. It should also improve SD WAN capabilities. Additionally, there are issues with site-to-site VPNs dropping connections, which can be frustrating.
For how long have I used the solution?
We have been using the solution since 2018.
What do I think about the stability of the solution?
Stability is generally okay. Customers have used the equipment all the way to end of life without major issues.
What do I think about the scalability of the solution?
Scalability is not very flexible. You can't upgrade memory or storage on a specific model, which limits scalability.
How are customer service and support?
The quality of support varies. The team handling application control is very good, but we have had bad experiences with the VPN support team. It all depends on the specific team you are dealing with.
How would you rate customer service and support?
Neutral
How was the initial setup?
The setup is user-friendly and quite straightforward, especially for basic configurations.
What was our ROI?
Sophos XG reduces virus and malware attacks, addressing network efficiency and cost savings indirectly by minimizing the time spent on troubleshooting.
What's my experience with pricing, setup cost, and licensing?
Pricing is reasonable. You get a perpetual license. That said, you must pay for support and updates. The cost depends on the package you are in, such as full threat management or basic.
Which other solutions did I evaluate?
We have also worked with Fortinet Firewalls and Palo Alto. Price-wise, Sophos XG is reasonable when comparing similar models.
What other advice do I have?
When recommending Sophos, we consider the customer's specific requirements and infrastructure compatibility. Sophos is user-friendly and suitable for environments without highly technical staff because it is easy to manage.
I'd rate the solution eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Last updated: Nov 26, 2024
Flag as inappropriateSoftware Developer/ IT Analyst Individual Contributor at AIICO Capital Limited
Secure, duel switch capabilities, and good support
Pros and Cons
- "Most of the features Sophos XG has are valuable. However, if I have two different ISP, I'm able to create an automatic switch between the two ISPs. I can do the same thing for the cloud as well. If I have two subnets coming from the cloud, I'm able to create a type of switch between both of them where if there is traffic on one and has the traffic drop, I'm able to switch to the other ISP without any problems. It's a normal feature and I get to enjoy the ability to switch between services with no issues."
- "We recently did an upgrade on the Sophos XG firmware and we were surprised that after the upgrade, the automatic switch actually we were using did not work anymore."
What is our primary use case?
We are using the Sophos XG in a different manner than the typical use case. We have the physical box, and we are using Sophos XG on the cloud.
We have two different types. We have two different Sophos XG we're running. We're running one on the Microsoft Azure cloud which mostly all security on the cloud goes through the Sophos XG. The second Sophos XG is running on our own physical local data center.
We are doing something similar to an IPsec between Azure and the local data center. So we are doing an IPsec between the two. We connected all our resources and we mostly run the applications on Microsoft Azure. Were now are doing IPsec between the two data centers.
What is most valuable?
Most of the features Sophos XG has are valuable. However, if I have two different ISP, I'm able to create an automatic switch between the two ISPs. I can do the same thing for the cloud as well. If I have two subnets coming from the cloud, I'm able to create a type of switch between both of them where if there is traffic on one and has the traffic drop, I'm able to switch to the other ISP without any problems. It's a normal feature and I get to enjoy the ability to switch between services with no issues.
Security is one of the major reasons we are deploying Sophos XG in our process.
What needs improvement?
We recently did an upgrade on the Sophos XG firmware and we were surprised that after the upgrade, the automatic switch actually we were using did not work anymore.
We try to understand exactly why it wasn't working with the new 18.5 firmware, but we could not figure it out. I realized that I was stuck with the main ISP. If there's an outage, it was not reliable on the network any longer.
We had to reverse, back to the old firmware even though we were still trying to fix the new version. It is a very efficient feature for our operation. If it was not there, it could make the workings of our operation inefficient. It is one of the best features of Sophos XG. It makes operations very efficient. You don't have to worry about anything at all. We are using the entire Sophos package, such as Sophos endpoint, Sophos XGR, Sophos ZGR.
The documentation can improve with Sophos XG. This will allow our network engineer to work better with the solution. Additionally, they can improve the ability to filter down devices. Recently we were faced with a challenge where we needed to restrict mobile phone users on the network but we realized that we couldn't do this with the solution.
Recently I was looking at the Cisco Meraki solution, to see what it can do in terms of capacity. There's one feature that stood out to me, and that feature has the ability to implement some policies. Organizations need to have security policies in place. I would like the ability to create policies.
For how long have I used the solution?
I have been using Sophos XG for approximately two and a half years.
What do I think about the scalability of the solution?
We have approximately 60 people that are working on Sophos XG. However, the number is higher because Microsoft Azure routes every customer through the firewall. We have multiple layers and the traffic passes through Cloudflare and then gets directed to the Sophos XG on Microsoft Azure. The Sophos XG on Azure does all the filtering and routing to the private IP, allowing us not to use the public IP.
The DMs are private, and approximately 14,000 customers pass through the Sophos XG and Microsoft Azure
How are customer service and support?
The support from Sophos XG is very good. We can easily relate to the support.
I would rate the support from Sophos XG a two out of five. You cannot have good support without good documentation.
If you look at the software environment now, anywhere you go, you see the documentation for everything that has been done. Sophos XG has documentation, however, you should not need to have a certification to be able to understand it.
Which solution did I use previously and why did I switch?
I have used Sophos Cyberoam previously.
How was the initial setup?
If we had better documentation we would be able to implement Sophos XG better for the organization's exact specifications. When you have already come up with your networking strategy, presented it to the company, then you find out the new framework doesn't conform with the organizational strategy. You have to start going back and receiving approval for a new strategy. However, you are not even sure what the strategy is going to be with the new framework, because everything has changed. Most of the automatic resources stop working.
There is a high chance I do not even know why it is not working or what the major issue is. We have realized the package wasn't switching and we did a lot of troubleshooting for almost a week to understand why. We switch over to our old firewall, then we finally understood that it was something that has to do with the new 18.5 firmware in Sophos XG. Immediately we switch back to the old firmware, this fixed out problems we were having at that point.
I would rate the implementation of Sophos XG a two out of five.
What about the implementation team?
The initial deployment was done approximately three years ago and it was done by a third party because of some complex considerations, such as the VOIP Gateway.
However, since the initial implementation, we have been managing it by our own in-house network engineers and every modification to the network has been done in-house.
We have three network engineers, that work on the solution and the network. They can manage all the features and securities. The amount of people needed to maintain the solution depends on the organization's architecture.
What was our ROI?
In information security, the only way you rate ROI is by the level of information you're securing. I will ask myself how much is the information I'm securing is worth? The worth of what I'm securing will determine the amount of cost that I'm spending on the information secured. If I were to judge it that way, the ROI is high.
I would rate the ROI of Sophos XG a five out of five.
What's my experience with pricing, setup cost, and licensing?
We pay for two licenses for the use of Sophos XG annually and it is a flat fee. We do not have everyone going through both of the Sophos XG firewalls a the same time and the Sophos XG on Microsoft Azure is only accessible from the VPN.
Sophos XG has changed its pricing model for extreme protection.
I rate the price of Sophos XG a two out of five.
Which other solutions did I evaluate?
When we were evaluating other solutions we looked at Barracuda and it had an old GUI. This was an issue when we were making decisions between Barracuda and Sophos XG.
What other advice do I have?
The solution has served its purpose in my organization.
I rate Sophos XG a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
CTO at Kingsway Hospitals
A great UI with very intuitive features; comprehensive documentation ensuring issues are easily resolved
Pros and Cons
- "Great interface and in-built help is very intuitive."
- "Lacking network access control, user profiling and analytics dashboards."
What is our primary use case?
Our primary use case of this solution is for protection and to have better governance for our LAN usage. I've got a lot of people working from outside on the corporate infra and all policy based decisions happen there. The solution is basically a firewall that protects us from various internet threats, but other than that provides controlled and properly managed access using various rules of VPN and other fingerprints of people logging in. I'm the CTO of the company and we are customers of Sophos.
What is most valuable?
The interface is great and easy to understand. Any firewall engineer who has medium to moderate experience on bylaws, can easily understand the UI. The language presented on various features and the in-built help, is very intuitive. If you have a problem you can figure it out there and then. As a result, there is less probability that we'll call tech support.
What needs improvement?
The solution really needs some additional features like network access control. If they could incorporate some user profiling and present the analytics of the login user usage patterns, or a typical proper management dashboard to take a decision on the firewall rules, that would be useful. Basically, MI's and the dashboard could be more user friendly. The information is there but the dashboards are not in a graphical format. In short, I'd like to see network access control, user profiling and analytics dashboards. It would make the solution a more competitive product on the market.
For how long have I used the solution?
I've been using this solution for over four years.
What do I think about the stability of the solution?
This is a stable solution. I haven't had any firewall crashes or any non-performing rules for over two years. We are a hospital so all the lights of all the devices should be on 24/7, 365 days a year.
We manage and control around 250-300 internal users. There would probably be another 75-100 logging in externally.
What do I think about the scalability of the solution?
This is definitely a scalable solution. The way we've configured it, if a device goes down, it can be shut off and removed from the network for repairs or updates and our second firewall automatically takes the load.
How are customer service and technical support?
We only used technical support during our initial deployment. After that, we didn't need support because the product was working perfectly well. We trained ourselves on the newer software and we are capable of managing and maintaining our own firewalls. In addition, Sophos provides online documentation which is very user friendly. If you follow the steps you get the result.
Which solution did I use previously and why did I switch?
I previously used Cisco's firewall ASA and it was extensively implemented in my earlier role. The main reason to migrate to Sophos was due to their aggressiveness in terms of pricing but also the fact that they had features that Cisco did not have.
How was the initial setup?
The initial setup was very straightforward. Deployment took somewhere between six and eight hours.
What's my experience with pricing, setup cost, and licensing?
There's no annual licensing fee. When we purchased the product, it was with a five year agreement bundled in with the product price and the recent rollout is not yet five years old. When we renew, we'll renegotiate. I can't differentiate between the product costs and the licensing costs at this point. We're very lucky that we get one of the best deals in the country in terms of pricing. The Sophos-backed pre-sales and implementation team were very cooperative and collaborative which really helped us make the decision to choose Sophos.
What other advice do I have?
I would definitely recommend this solution but it's only suitable if it fits the needs of the company so I would suggest carrying out some research. Why does the company need a firewall? What rules do they want to deploy on the firewall? Based on the answers to those questions the company can make a call.
I would rate this solution a nine out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Technical Engineer at Harnssen Group Limited
Easy to set up with good technical support and good stability
Pros and Cons
- "We've deployed quite a number for our users and our customers, and the feedback is quite positive in terms of management and also administration."
- "XG is at its end of life. People are moving to XGS."
What is most valuable?
I enjoy synchronized security, where you have to synchronize both the firewall and the endpoint. When I deploy a firewall, I integrate it with the endpoint so that they can send the security heartbeat from the endpoint to the firewall. In the Sophos firewall, there's deep inspection, which works quite well. Sophos has the web application firewall inbuilt. This is unlike other firewalls, where you have to integrate with another standalone web application firewall. Being inbuilt in Sophos, you just have to configure an application so that it's more of a policy, and you're good to go. It's pretty simple in terms of the user.
We've deployed quite a number for our users and our customers, and the feedback is quite positive in terms of management and also administration.
The technical support is pretty good.
The initial setup is easy.
There's quite a number of items on offer. When you look at Gartner, it's doing well. The uptake in the market has been wonderful and currently, it's competing with other top firewalls such as Check Point, Fortinet, and Palo Alto.
What needs improvement?
XG is at its end of life. People are moving to XGS. With those changes on the horizon, a client might end up in, maybe 10 years, having four or five appliances, which they might not use. I don't know what Sophos is doing to maybe change this. Right now, we've moved from XG to XGS.
Another feature, which might be good and which other vendors are maybe exploring is the NAC. Sophos doesn't have a NAC solution.
Maybe they can improve on their WAF. Currently, they have the inbuilt.
They could work on their SD-WAN solution. I have seen it. It's not that competitive compared to other vendors. We've had some device issues.
For how long have I used the solution?
I've been dealing with the solution for the last four years.
What do I think about the stability of the solution?
In terms of when it's in the network, it's stable compared to other firewalls, where I have had some issues. I had a case with another firewall, which the client changed to Sophos and it was not that stable as the client had to go and actually restart the firewall. The challenge comes in terms of stability when, let's say, the engineer doing the scoping does the round-sizing for the firewall. This causes the IPS to become overloaded or overworked, so it disconnects the traffic at the port level. In terms of stability, I might say sometimes we might experience challenges maybe when the sizing is not done correctly. That's why we might experience that disconnect at the interface level where the internet gets disconnected, however, that's the case of sizing, not the product itself. In terms of stability, it's stable in the network.
How are customer service and support?
In terms of Sophos' support, they have been wonderful. I had a device issue and I found the return policy to be quite simple.
Their technical support is pretty straightforward. When you raise a ticket, the feedback is immediate, and you are assigned a support person. It's been a wonderful experience.
Even to the end-user, it's a pretty straightforward system that they have. A user would just log into support.id, then key in their credentials and raise a support ticket. It's pretty simple.
Which solution did I use previously and why did I switch?
I'm also familiar with Check Point, FortiGate, and Palo Alto. We also used to use Sonic Wall, however, we've moved to Sophos.
How was the initial setup?
The initial setup is pretty straightforward. It's not overly complex.
Which other solutions did I evaluate?
I've compared Check Point, CloudGen Network Security, and Sophos XG previously for clients. Not being biased to any vendor, normally, in this region, what normally happens is the budget. You might recommend Check Point to a customer, however, Check Point is a bit expensive, so you might end up losing the deal. What you would recommend, is Check Point as the Quantum, as the firewall. Sophos is doing quite well in terms of the endpoint for the workstations and the servers, the physical and the virtual. Likely it would be a good idea to recommend Sophos Security. That said, if the client has the budget, you'd recommend Check Point as a firewall. It's always good to do a bit of comparison and advise the client as to what is best for them.
What other advice do I have?
We've actually deployed and supported quite a number of the products, from XG105 to XG3430.
Sophos is on-prem mostly, however, now there's another product for Sophos, for the endpoints, which is cloud-based.
I'd rate the solution at a ten out of ten. It's one of the best products. We have deployed quite a number of them - almost 20 - and I've not seen any of my clients complain.
Disclosure: My company has a business relationship with this vendor other than being a customer: reseller

Buyer's Guide
Download our free Sophos XG Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
Check Point NGFW
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
Fortinet FortiGate-VM
SonicWall NSa
Sophos XGS
Untangle NG Firewall
KerioControl
Buyer's Guide
Download our free Sophos XG Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos XG 210 vs Fortigate FG 100E
- What Is The Biggest Difference Between Sophos UTM and Sophos XG?
- What is the biggest difference between Sophos XG and FortiGate?
- Which firewall is better and why: Sophos XG 210 or Fortinet FortiGate 100E?
- Which solution do you prefer: Fortinet FortiGate or Sophos XG?
- What are the main differences in features between Sophos XG and FortiGate 80F?
- Which solution do you prefer: Fortinet FortiGate or Sophos XG?
- How does Meraki MX compare with Sophos XG?
- Which firewall to choose for an SMB to prevent malware damage: Cisco Firepower or Sophos XG?
- Looking for a technical comparison between Sophos XG550 and Fortinet FortiGate 600E