I primarily use the solution as a firewall. It's running on our data centers and all of our offices.
Chief Technology Officer at a healthcare company with 501-1,000 employees
Simple to set up with a good GUI, but lacks features
Pros and Cons
- "The initial setup is pretty simple."
- "Their tech support is not great."
What is our primary use case?
What is most valuable?
It has a simple GUI, which is good.
The initial setup is pretty simple.
What needs improvement?
Unfortunately, there are quite a few negatives with them.
Their tech support is not great.
The features on offer are lacking.
Basically what they don't have is proper bandwidth management for multiple WAN ports and multiple WAN ports to multiple VPN WANs. Meaning, if I have it on both sides on both the main side and on the secondary side, two internet connections, I can't bond the two of them together into a single VPN and have bandwidth managed between the two of them.
If I want to go ahead and make a VPN, right now, I have two internet connections on each side. I have to make a failover a group of four VPNs for it to go ahead and failover between them.
You're getting into a lot of rules. It's a lot of extra rules, et cetera, that has to be done. They don't have simple pointing systems where you could go ahead and make rules saying, "Hey, here's the route". They're not fully route-based VPN rules yet. You literally have to take down all the routes all over the place in order to make updates. It's tedious.
Basically, we had the problem where we moved certain ranges from one data center to another data center. It took us about an hour of downtime to do that. We had to go ahead and we had to reset VLANs and we had re-setup all the VPNs in all the different places we reconnected. We don't have two sites, we have 25 sites. It was a lot of work.
For how long have I used the solution?
I've used the solution for about three years at this point.
Buyer's Guide
Sophos XG
April 2025

Learn what your peers think about Sophos XG. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
What do I think about the stability of the solution?
It has its bugs and we can't get answers due to the fact that technical support is outsourced. There are some bugs that we keep running into that tech support can't figure out what to do. The bigger problem is the log systems aren't big enough for them to actually capture all the logs that happen.
How are customer service and support?
Technical support is an issue. About six months after we bought it to a year after we bought it, they outsourced all their tech support to India. Literally beforehand, they were an American-based tech support company and they actually had full product knowledge. The Indian-based tech support doesn't have the product knowledge and there was a language barrier. They could speak English, however, they didn't understand us very well.
We were told that they stopped doing outsource and they are rehiring their own internal staff again for tech support. We're hoping that we're going to be able to get better tech support again.
How was the initial setup?
The initial setup is pretty straightforward and simple. It's not overly difficult. I don't consider it to be complex.
What's my experience with pricing, setup cost, and licensing?
We bought it as is. We bought it with four years of support. However, I can't speak to how much it costs.
What other advice do I have?
I'd advise users considering the solution that, if you have quite a bit of sites, it's going to get a lot of work to do, to fix things up. It makes more sense if you have minimal sites.
I'd rate the solution at a six out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

CEO at Haniya Technologies
Strong in security, scalable, and good performance
Pros and Cons
- "Sophos firewalls are scalable. They are pretty strong in security. So, when they provide any kind of firewall, they provide all the features such as anti-spam, antivirus, etc."
- "Its price should be improved. Its features are pretty okay, but the price is the area where we have to fight more. They should do something about the price structure."
What is our primary use case?
Firewall is not our expertise, but we do sell it as per the requirement of the customer or if they ask for it.
Most of the firewalls are on-prem. What we deliver is the hardware. It is appliance-based.
What is most valuable?
Sophos firewalls are scalable. They are pretty strong in security. So, when they provide any kind of firewall, they provide all the features such as anti-spam, antivirus, etc.
What needs improvement?
Its price should be improved. Its features are pretty okay, but the price is the area where we have to fight more. They should do something about the price structure.
For how long have I used the solution?
It has been a couple of years.
What do I think about the stability of the solution?
It is stable. Its performance is very good. They have now stopped calling it a firewall. They're calling it a Unified Threat Management (UTM) solution.
What do I think about the scalability of the solution?
It is scalable in the sense that if they are using a small model or a small box of firewall and there is an increase in their network and the number of users, they can move that small box to a bigger model. So, if they are using a firewall and they want to scale it up, they can go to the next model.
Sophos has more than 1,000 customers.
How are customer service and technical support?
Our clients have a good system of support over here. They have full support. They get support from the distributors, from the partners, and then directly from Sophos.
Which solution did I use previously and why did I switch?
We are a partner of Sophos and Fortinet. We work with Sophos much more than we work with Fortinet.
How was the initial setup?
If it is a small model and a small network, it takes about two days. You need at least two people for its deployment and maintenance.
What's my experience with pricing, setup cost, and licensing?
Its price should be better. Initially, the clients have to pay for the appliance. Then, they have to pay for the software that is installed on the appliance. Depending on whether they have a one-year, two-year, or three-year license, they just have to renew the license of the software after it expires. They don't have to renew the appliance license. So, they have to pay for the appliance only once, and after that, they just renew the software license. That's all.
What other advice do I have?
I would definitely recommend Sophos to others. I would rate it a nine out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Sophos XG
April 2025

Learn what your peers think about Sophos XG. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
CIO LATAM at i-Track Systems Development, S.A. de C.V.
Great cost benefits, reliable, easy to set up, and scalable
Pros and Cons
- "The most valuable feature of this solution is that the license offers everything."
- "It is complicated to get the reports if you are not experienced with Sophos."
What is our primary use case?
We implement different security solutions. We also integrate the different environments and secure them, based on the customer's needs.
Our customers are from banking or financial institutions, insurance institutions, telecommunication companies, advocacy companies, construction companies, and retail companies.
What is most valuable?
The most valuable feature of this solution is that the license offers everything. You don't have to purchase a license for the VPN, or the mobile VPN, or for any other features that the firewall works with. That is the best thing about Sophos.
They include everything on the firewall as a base and if you want other exclusive services or to add more security to your service, you would have to purchase the full license.
To me, the cost benefits are the best.
What needs improvement?
They can improve all indicators, all KPIs, all the scores, the consoles, and the monitors. These are all areas that need improvement.
These areas need to be more clear for the customers. You have to have good experience working with Sophos to know how to get to the forums and to get to the information that you want from the beginning.
It is complicated to get the reports if you are not experienced with Sophos. For example, if you want to get a report on what the firewall is doing, you have to be a very experienced engineer.
For how long have I used the solution?
We have been using Sophos XG for three years.
The version we use is up to the customer and their environment's needs. For example, if the customer has a small infrastructure, we implement a small firewall, which could be an XG 115 or an XG 125.
For larger companies, we implement an XG 450 or XG 500.
What do I think about the stability of the solution?
The stability is very good. Stability is the main reason we use Sophos.
We have no complaints about the reliability, performance, or stability. It's a very strong product.
We are currently building the security architecture and we are trying to build according to the customer's requirements. The plan is for 35% growth in the next three years.
Our clients are usually medium to large-sized businesses.
We currently have 23 engineers to maintain this solution.
What do I think about the scalability of the solution?
Depending on the firewall that you are using, or that you purchase with the biggest supply end, you can add other cards that can grow with some other services.
How are customer service and technical support?
We provide technical support to the customers. We provide our own SOC to support the security solution and we complement the Sophos support plan.
Their technical support is fair, as well as the forums. Today there are only webinars, but we are trying to keep up with the latest technologies and trends.
We are also trying to keep up on how the hackers work because we are working with different associations of security worldwide that way we know the best way to protect our customers and what we need to sell to our customers.
Which solution did I use previously and why did I switch?
We work with several brands. Sophos is in the top sales.
Previous to Sophos XG, we were working with Sophos and Cyberoam.
How was the initial setup?
The initial setup is straightforward. It's easy, using the wizard.
If you go outside the wizard and you are not an experienced engineer, it could get a little tricky.
Our implementation strategy is to have clear communication with the customer. Implementation is based on 99% of the information that the customer is providing to your other anything else.
It can take five days to deploy.
What's my experience with pricing, setup cost, and licensing?
The license includes most of the features that are necessary, but the basis of the firewall does not include everything, which helps us to continue to sell.
When comparing with Palo Alto and Cisco, Sophos is cheaper.
Which other solutions did I evaluate?
The top three solutions that we sell and that the customers consider are Sophos, Palo Alto, and Cisco.
The main difference is the pricing.
What other advice do I have?
We try to sell some cloud services but in Mexico, customers are not familiar with the cloud services yet. We are starting to grow, but it is very common that customers prefer services on-premises.
We do not only plan for the sales, but we also plan with the customers and their growth, and how we are going to increase their services. We also consider what will be selling to the customers in the next three years. We plan with the customer, as well.
When we sell a firewall, it is not for sale for right now, it's for sale for long-term use. We build long-term relationships with our clients.
My suggestion to others who are interested in using this solution is to try it. The only way to know how well it works is to try it.
Sophos XG is an excellent solution and I would rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Chief Executive Officer at Spokes network
This solution enables effective internet control and efficient web filtering for small to medium businesses
Pros and Cons
- "Customer service and support for Sophos XG is excellent, and I would rate it as a ten."
What is our primary use case?
We mostly deploy Sophos XG to our customers because we are an IT system integrator. Our primary use case involves working with small to medium businesses to control internet usage, perform web filtering, application control, and manage bandwidth.
What is most valuable?
Sophos XG is popular among small to medium businesses, allowing them to control internet usage, perform web filtering, application control, and manage bandwidth. Additionally, AI assists in configuration, offering clues when users are stuck, which enhances user convenience and efficiency.
What needs improvement?
There is interest in seeing more features related to AI and customization in future releases.
For how long have I used the solution?
I have been working with Sophos XG for at least five to six years.
What was my experience with deployment of the solution?
The installation process is straightforward and easy due to the training we receive. In new site setups, it's quick, but migrating from one vendor to another requires more planning and can take a couple of days.
What do I think about the stability of the solution?
I would rate the stability of Sophos XG as nine out of ten.
What do I think about the scalability of the solution?
I would rate the scalability of Sophos XG as nine out of ten.
How are customer service and support?
Customer service and support for Sophos XG is excellent, and I would rate it as a ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I worked with other vendors like Cisco, Palo Alto, and Microsoft long ago.
How was the initial setup?
The initial setup varies by scenario: it's quick for new sites, but it takes longer for vendor migrations due to the need for seamless planning.
What about the implementation team?
I have a dedicated team of five engineers who handle installations.
What was our ROI?
There are cost savings compared to competitors, providing more financial benefits.
What's my experience with pricing, setup cost, and licensing?
Sophos XG offers good pricing compared to competitors. While there are extra expenses for additional features, overall licensing costs are well-regarded.
What other advice do I have?
I would rate Sophos XG as a nine out of ten. The cost savings make it suitable for small to medium businesses with 50 to 300 users. Overall, I am very satisfied with the product.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
Last updated: Feb 28, 2025
Flag as inappropriateIT Manager MIS at a non-profit with 1-10 employees
The configuration complexity, limited port availability and higher price compared to competitors are the main drawbacks
Pros and Cons
- "The most significant aspect is the protection it offers."
- "The training manual provided to users lacks proper guidance on configuration procedures."
What is our primary use case?
We use Sophos XG for ensuring security, implementing web filtering, enforcing policies, and blocking traffic as needed.
How has it helped my organization?
I appreciate its interface, but I find that the available ports are insufficient. I've encountered limitations, often finding that three to four ports are not adequate for our needs.
It stands out with its side-to-side VPN and SSL VPN capabilities.
What is most valuable?
The most significant aspect is the protection it offers.
What needs improvement?
I encountered an issue while implementing web filtering for users. Specifically, when attempting to access reports detailing which sites users are visiting, the diagnostic report fails to display the complete URLs of the websites visited. This becomes particularly problematic when users utilize proxy software to bypass the firewall, as it renders tracking their website visits nearly impossible. Training presents a major challenge as there are numerous features available, such as IPS and IDS, which many network administrators are unfamiliar with and tend to leave disabled. Users are unable to enable these features themselves due to their lack of understanding of their functionalities and configuration processes. The training manual provided to users lacks proper guidance on configuration procedures. The content outlined in the user manual differs significantly from the live configuration process.
For how long have I used the solution?
I have been working with it for approximately six years.
What do I think about the stability of the solution?
There are several glitches in the new firewall. One particular issue arises when applying filtering settings. The firewall fails to unblock sites without requiring a restart to save and execute the changes properly.
What do I think about the scalability of the solution?
We have a multitude of distinct sites, amounting to a total of six to seven thousand users in total.
Which solution did I use previously and why did I switch?
Our experience with Fortinet was better compared to Sophos. Also, configuring Fortinet is much easier than configuring Sophos.
How was the initial setup?
Installation is not straightforward; it's a bit complex. For instance, when setting up two ISP connections and terminating them on two firewalls, the process involves configuring LAN and WAN interfaces separately, along with DNS and routing configurations in different tabs. Many users may find these functions unfamiliar. It would be more convenient if all functions related to traffic routing were consolidated into a single tab for easier management. Maintenance is also challenging.
What's my experience with pricing, setup cost, and licensing?
The price of Sophos in PTR is significantly higher compared to Fortinet.
What other advice do I have?
Overall, I would rate it three out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Associate Technical Director at INTELEC3
Simple to configure and implement, good pricing, and suitable for medium-sized enterprises
Pros and Cons
- "I like it for its simplicity. It is very simple to configure and implement. It is a very good product for medium-sized organizations."
- "There should be web caching to improve bandwidth utilization. It should have a very good caching feature. That's because we are in a very poor continent, and the connectivity cost is very high. We have low bandwidth, and the intensive usage of bandwidth is not easy here in Africa. If they improve services for web caching, it would be better."
What is our primary use case?
We use it for network protection. We use Sophos XG as a firewall in our own company, and we have also implemented it for customers. I have been using Sophos XG for a small office for my own family.
We have also implemented Sophos Email Gateway for government mailing servers. It is not so elaborate, but for basic usage, it works very well.
We have implemented version 17 to the latest version of Sophos XG.
What is most valuable?
I like it for its simplicity. It is very simple to configure and implement. It is a very good product for medium-sized organizations.
What needs improvement?
There should be web caching to improve bandwidth utilization. It should have a very good caching feature. That's because we are in a very poor continent, and the connectivity cost is very high. We have low bandwidth, and the intensive usage of bandwidth is not easy here in Africa. If they improve services for web caching, it would be better.
It should also support a feature for Virtual Domains. Similar to FortiGate, we should be able to use a single device to create two or more virtual units. Such a feature is useful for separating the traffic between departments in a large enterprise.
When I try to use Sophos for Email Gateway, it's not easy to check a user in the LDAP directory. It's not as good as other products, such as HCL Domino. Sophos is good, but it is not so good. When we use the LDAP filter to select some users, we have small problems, but overall, Sophos is very good for me.
Their support in Africa is not so good, which is a problem. Their support can be improved.
For how long have I used the solution?
I have been using Sophos technology for four years.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
Generally, when we implement a Sophos product, we do the sizing and plan the resources based on the expected traffic. We anticipate the resource usage for one or two years, which helps with scalability, but it is a product for medium enterprises. In my company, we have around 20 employees.
How are customer service and support?
Their account manager and support in Africa are not so good. Their community support is very good, and a lot of times, I use their community when I need any kind of support, and I get a response for my issue.
Which solution did I use previously and why did I switch?
I use Sophos and Fortinet. I sometimes also use Cisco Firepower. We are an integrator in West Africa, and my choice also depends on a customer's choice. Sometimes, they are telecom operators, and sometimes, they are small companies, such as non-governmental organizations.
How was the initial setup?
It is very easy to implement.
What's my experience with pricing, setup cost, and licensing?
Its price is good. All features are grouped in the same license. It is an all-in-one license, and the license price is acceptable.
What other advice do I have?
I would rate it a nine out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Managing Director at GCET
Reliable, user-friendly, and provides good endpoint protection
Pros and Cons
- "Sophos XG is easy to use."
- "The only area that requires improvement is scalability."
What is our primary use case?
The majority of our customers use Sophos XG as a traditional firewall. Some use it for endpoint protection, which is similar to anti-virus.
We also have customers that have SD-WAN as part of their use case. For the most part, it is a firewall, it depends on what the customer environment looks like that would determine how you're going to configure the appliance to work for the customer.
Technology can deliver what you want based on your environment, what you do may differ from what others do.
We have customers from insurance, some oil, and gas, as well as some from the banking sector. Based on the technicality and the peculiarities of the environment, we must explain the technology, of how Fortinet delivers its own firewall, and also others such as Check Point, and Palo Alto deliver their own firewall.
With the explanation given the customer can choose the solution, they want in their environment.
What is most valuable?
Sophos XG is easy to use.
What needs improvement?
The only area that requires improvement is scalability.
I understand why scalability is difficult in all firewalls. I understand why it is difficult in our firewalls. If you want to scale, you can scale vertically or horizontally. That is the world of scalability. However, you cannot do so for the firewall. It's a forklift, you have to buy a new appliance.
For how long have I used the solution?
We have been deploying Sophos XG for our customers for many years.
What do I think about the stability of the solution?
The stability is based on the environment.
What do I think about the scalability of the solution?
Every firewall solution has a different level of scalability. The majority of firewalls are based on the user. Scalability, in Sophos XG, requires a forklift.
The scalability could be improved.
We have between 12 and 16 customers.
How are customer service and support?
I have never contacted technical support.
How was the initial setup?
We have deployed more Sophos this year than in any previous year.
I have six engineers dedicated to deploying and maintaining the solution.
What's my experience with pricing, setup cost, and licensing?
It is a price-based solution, not based on technology.
Licensing fees are paid on a yearly basis.
What other advice do I have?
I would recommend this solution to others who are interested in using it.
I would rate Sophos XG an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
IT Advisor at Silopor SA
Easy to use, easy to install, and easy to monitor
Pros and Cons
- "It is very easy to use. You can configure and monitor everything from one unique dashboard."
- "Its price should be improved. It should be cheaper."
What is our primary use case?
We use it for the protection of our network. We also have a product from Sophos for ransomware protection using which we are able to protect our network from ransomware. All of our solutions are from Sophos, and we have everything integrated.
What is most valuable?
We can define which systems can be accessed from outside of our company. We can define the connection rules for inside and outside of the company. It is easy to implement or modify rules.
It is very easy to use. You can configure and monitor everything from one unique dashboard. It is also easy to install.
What needs improvement?
Its price should be improved. It should be cheaper.
In terms of features, I am happy, and I don't need more features. The firewall is perfect, but the antivirus could be better. It would be useful if the antivirus was less heavy and had better performance.
For how long have I used the solution?
I have been using this solution for two years.
What do I think about the stability of the solution?
It is stable. We receive the updates online. They provide the updates at a good frequency.
What do I think about the scalability of the solution?
It is scalable to a limit. If the size of the network grows, you will have to buy new equipment. If you need just a few more connections, you will able to work with the existing system.
Currently, we have 16 users who are using it. We don't have any plans to increase its usage because our company is in liquidation. If the government decides, we can have more projects, but, as of now, we are in liquidation. We are keeping things working for now, and we plan to keep using this solution, but there are no investments.
How are customer service and technical support?
We have support from the supplier of our firewall, and if needed, we also get support from the people who develop our software.
How was the initial setup?
It is easy to install. Our company is at three locations. It takes two days to install it at all locations. It takes one day for one location and another day for the other two locations.
What about the implementation team?
For the first installation, we took the help of the supplier. Since then, we do it ourselves. We don't have teams attached directly to the system. We have two or three IT guys who work with this system, but we can have support from the maintenance team.
What's my experience with pricing, setup cost, and licensing?
Currently, we have a contract for three years. It would be good if its price is reduced before we renew the contract. We will buy the equipment if it is cheaper.
What other advice do I have?
I'm happy with what I am getting. I haven't faced any problems. Everything is integrated, and it is easy to install and easy to control.
I would rate Sophos XG a nine out of ten. I am very satisfied with this solution.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Sophos XG Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
Check Point NGFW
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
Fortinet FortiGate-VM
SonicWall NSa
Sophos XGS
Untangle NG Firewall
KerioControl
Buyer's Guide
Download our free Sophos XG Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos XG 210 vs Fortigate FG 100E
- What Is The Biggest Difference Between Sophos UTM and Sophos XG?
- What is the biggest difference between Sophos XG and FortiGate?
- Which firewall is better and why: Sophos XG 210 or Fortinet FortiGate 100E?
- Which solution do you prefer: Fortinet FortiGate or Sophos XG?
- What are the main differences in features between Sophos XG and FortiGate 80F?
- Which solution do you prefer: Fortinet FortiGate or Sophos XG?
- How does Meraki MX compare with Sophos XG?
- Which firewall to choose for an SMB to prevent malware damage: Cisco Firepower or Sophos XG?
- Looking for a technical comparison between Sophos XG550 and Fortinet FortiGate 600E